7.2
CVE-2024-9381 -
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
7.2
CVE-2024-9380 -
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
6.5
CVE-2024-9379 -
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
8.2
CVE-2024-9124 - Rockwell Automation PowerFlex 6000T CIP Security denial-of-service Vulnerability
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlexยฎ 600T. If the device is overloaded with requests, it will become unavailable. The device may require a power cycle to recover it if it does not re-establish a connection after it stops receiving requests.
8.8
CVE-2024-7612 -
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.
3.5
CVE-2024-47951 -
In JetBrains TeamCity before 2024.07.3 stored XSS was possible via server global settings
3.5
CVE-2024-47950 -
In JetBrains TeamCity before 2024.07.3 stored XSS was possible in Backup configuration settings
4.9
CVE-2024-47949 -
In JetBrains TeamCity before 2024.07.3 path traversal allowed backup file write to arbitrary location
4.9
CVE-2024-47948 -
In JetBrains TeamCity before 2024.07.3 path traversal leading to information disclosure was possible via server backups
4.3
CVE-2024-47161 -
In JetBrains TeamCity before 2024.07.3 password could be exposed via Sonar runner REST API