Show filters
594 Total Results
Displaying 21-30 of 594
Sort by:
Attacker Value
Unknown

CVE-2024-11772

Disclosure Date: December 10, 2024 (last updated January 18, 2025)
Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Attacker Value
Unknown

CVE-2024-11639

Disclosure Date: December 10, 2024 (last updated January 18, 2025)
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access
Attacker Value
Unknown

CVE-2024-49353

Disclosure Date: November 26, 2024 (last updated January 05, 2025)
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data 4.0.0 through 5.0.2 does not properly check inputs to resources that are used concurrently, which might lead to unexpected states, possibly resulting in a crash.
0
Attacker Value
Unknown

CVE-2024-21939

Disclosure Date: November 12, 2024 (last updated December 19, 2024)
Incorrect default permissions in the AMD Cloud Manageability Service (ACMS) Software installation directory could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
Attacker Value
Unknown

CVE-2022-4974

Disclosure Date: October 16, 2024 (last updated October 16, 2024)
The Freemius SDK, as used by hundreds of WordPress plugin and theme developers, was vulnerable to Cross-Site Request Forgery and Information disclosure due to missing capability checks and nonce protection on the _get_debug_log, _get_db_option, and the _set_db_option functions in versions up to, and including 2.4.2. Any WordPress plugin or theme running a version of Freemius less than 2.4.3 is vulnerable.
Attacker Value
Unknown

CVE-2024-9381

Disclosure Date: October 08, 2024 (last updated October 17, 2024)
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
Attacker Value
Unknown

CVE-2024-9380

Disclosure Date: October 08, 2024 (last updated October 12, 2024)
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
Attacker Value
Unknown

CVE-2024-9379

Disclosure Date: October 08, 2024 (last updated October 12, 2024)
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
Attacker Value
Unknown

CVE-2024-8963

Disclosure Date: September 19, 2024 (last updated September 21, 2024)
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
Attacker Value
Unknown

CVE-2024-8190

Disclosure Date: September 10, 2024 (last updated September 17, 2024)
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.