Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2023-52906

    In the Linux kernel, the following vulnerability has been resolved: net/sched: act_mpls: Fix warning during failed attribute validation The 'TCA_MPLS_LABEL' attribute is of 'NLA_U32' type, but has a validation type of 'NLA_VALIDATE_FUNCTION'. This is an... Read more

    Affected Products : linux_kernel
    • Published: Aug. 21, 2024
    • Modified: Sep. 13, 2024
  • 7.8

    HIGH
    CVE-2024-41856

    Illustrator versions 28.5, 27.9.4, 28.6, 27.9.5 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction i... Read more

    Affected Products : macos windows illustrator
    • Published: Aug. 14, 2024
    • Modified: Sep. 13, 2024
  • 8.7

    HIGH
    CVE-2024-7939

    A stored Cross-site Scripting (XSS) vulnerability affecting 3DSwym in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.... Read more

    Affected Products : 3dexperience 3dexperience
    • Published: Sep. 02, 2024
    • Modified: Sep. 13, 2024
  • 8.7

    HIGH
    CVE-2024-7932

    A stored Cross-site Scripting (XSS) vulnerability affecting 3DDashboard in 3DSwymer on Release 3DEXPERIENCE R2024x allows an attacker to execute arbitrary script code in user's browser session.... Read more

    Affected Products : 3dexperience 3dexperience
    • Published: Sep. 02, 2024
    • Modified: Sep. 13, 2024
  • 9.1

    CRITICAL
    CVE-2024-34785

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 12, 2024
    • Modified: Sep. 12, 2024
  • 9.1

    CRITICAL
    CVE-2024-34783

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 12, 2024
    • Modified: Sep. 12, 2024
  • 9.1

    CRITICAL
    CVE-2024-34779

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 12, 2024
    • Modified: Sep. 12, 2024
  • 9.1

    CRITICAL
    CVE-2024-32848

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 12, 2024
    • Modified: Sep. 12, 2024
  • 9.1

    CRITICAL
    CVE-2024-32846

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 12, 2024
    • Modified: Sep. 12, 2024
  • 9.1

    CRITICAL
    CVE-2024-32845

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 12, 2024
    • Modified: Sep. 12, 2024
  • 9.1

    CRITICAL
    CVE-2024-32843

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 12, 2024
    • Modified: Sep. 12, 2024
  • 9.1

    CRITICAL
    CVE-2024-32842

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 12, 2024
    • Modified: Sep. 12, 2024
  • 9.1

    CRITICAL
    CVE-2024-32840

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 12, 2024
    • Modified: Sep. 12, 2024
  • 10.0

    CRITICAL
    CVE-2024-29847

    Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 12, 2024
    • Modified: Sep. 12, 2024
  • 8.8

    HIGH
    CVE-2024-8322

    Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 10, 2024
    • Modified: Sep. 12, 2024
  • 6.7

    MEDIUM
    CVE-2024-8441

    An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 10, 2024
    • Modified: Sep. 12, 2024
  • 8.6

    HIGH
    CVE-2024-8321

    Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 10, 2024
    • Modified: Sep. 12, 2024
  • 5.3

    MEDIUM
    CVE-2024-8320

    Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 10, 2024
    • Modified: Sep. 12, 2024
  • 9.8

    CRITICAL
    CVE-2024-8191

    SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.... Read more

    Affected Products : endpoint_manager
    • Published: Sep. 10, 2024
    • Modified: Sep. 12, 2024
  • 7.5

    HIGH
    CVE-2024-43783

    The Apollo Router Core is a configurable, high-performance graph router written in Rust to run a federated supergraph that uses Apollo Federation 2. Instances of the Apollo Router running versions >=1.21.0 and < 1.52.1 are impacted by a denial of service ... Read more

    • Published: Aug. 27, 2024
    • Modified: Sep. 12, 2024
Showing 20 of 292830 Results