Show filters
423 Total Results
Displaying 131-140 of 423
Sort by:
Attacker Value
Unknown

CVE-2024-9379

Disclosure Date: October 08, 2024 (last updated October 12, 2024)
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
Attacker Value
Unknown

CVE-2024-9167

Disclosure Date: October 08, 2024 (last updated October 09, 2024)
Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.
0
Attacker Value
Unknown

CVE-2024-7612

Disclosure Date: October 08, 2024 (last updated December 19, 2024)
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.
Attacker Value
Unknown

CVE-2024-47011

Disclosure Date: October 08, 2024 (last updated October 17, 2024)
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information
Attacker Value
Unknown

CVE-2024-47010

Disclosure Date: October 08, 2024 (last updated October 17, 2024)
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
Attacker Value
Unknown

CVE-2024-47009

Disclosure Date: October 08, 2024 (last updated October 17, 2024)
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
Attacker Value
Unknown

CVE-2024-47008

Disclosure Date: October 08, 2024 (last updated October 17, 2024)
Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.
Attacker Value
Unknown

CVE-2024-47007

Disclosure Date: October 08, 2024 (last updated October 17, 2024)
A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.
Attacker Value
Unknown

CVE-2024-8963

Disclosure Date: September 19, 2024 (last updated September 21, 2024)
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
Attacker Value
Unknown

CVE-2024-37397

Disclosure Date: September 12, 2024 (last updated September 12, 2024)
An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.
0