9.1
CVE-2024-6593 - WatchGuard Firebox Single Sign-On Agent Management Interface Authentication Bypass
Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. This issue affects Authentication Gateway: through 12.10.2.
9.1
CVE-2024-6592 - WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass
Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows Authentication Bypass.This issue affects the Authentication Gateway: through 1…
6.4
CVE-2024-8858 - Elementor Addons by Livemesh <= 8.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via …
The Elementor Addons by Livemesh plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘piechart_settings’ parameter in all versions up to, and including, 8.5 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Con…
8.8
CVE-2024-7479 - Improper signature verification of VPN driver installation in TeamViewer Remote Clients
Improper verification of cryptographic signature during installation of a VPN driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and install …
8.8
CVE-2024-7481 - Improper signature verification of Printer driver installation in TeamViewer Remote Clients
Improper verification of cryptographic signature during installation of a Printer driver via the TeamViewer_service.exe component of TeamViewer Remote Clients prior version 15.58.4 for Windows allows an attacker with local unprivileged access on a Windows system to elevate their privileges and inst…
7.3
CVE-2024-45817 - x86: Deadlock in vlapic_error()
In x86's APIC (Advanced Programmable Interrupt Controller) architecture, error conditions are reported in a status register. Furthermore, the OS can opt to receive an interrupt when a new error occurs. It is possible to configure the error interrupt with an illegal vector, which generates an erro…
7.5
CVE-2024-31146 - PCI device pass-through with shared resources
When multiple devices share resources and one of them is to be passed through to a guest, security of the entire system and of respective guests individually cannot really be guaranteed without knowing internals of any of the involved guests. Therefore such a configuration cannot really be securit…
7.5
CVE-2024-31145 - error handling in x86 IOMMU identity mapping
Certain PCI devices in a system might be assigned Reserved Memory Regions (specified via Reserved Memory Region Reporting, "RMRR") for Intel VT-d or Unity Mapping ranges for AMD-Vi. These are typically used for platform tasks such as legacy USB emulation. Since the precise purpose of these region…
5.5
CVE-2024-9169 - litespeed cache <= 6.4.1 - Authenticated (Administrator+) Stored Cross-Site Scripting
The LiteSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via plugin debug settings in all versions up to, and including, 6.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permis…
7.5
CVE-2024-8175 - CODESYS: web server vulnerable to DoS
An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.