8.2

CVSS3.1

CVE-2024-37397 -

An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.

πŸ“… Published: Sept. 12, 2024, 1:09 a.m. πŸ”„ Last Modified: July 10, 2025, 9:23 p.m.

7.2

CVSS3.1

CVE-2024-32848 -

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

πŸ“… Published: Sept. 12, 2024, 1:09 a.m. πŸ”„ Last Modified: Sept. 12, 2024, 10:35 p.m.

7.2

CVSS3.1

CVE-2024-34785 -

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

πŸ“… Published: Sept. 12, 2024, 1:09 a.m. πŸ”„ Last Modified: Sept. 12, 2024, 10:35 p.m.

7.2

CVSS3.1

CVE-2024-32843 -

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

πŸ“… Published: Sept. 12, 2024, 1:09 a.m. πŸ”„ Last Modified: Sept. 12, 2024, 10:35 p.m.

7.2

CVSS3.1

CVE-2024-32845 -

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

πŸ“… Published: Sept. 12, 2024, 1:09 a.m. πŸ”„ Last Modified: Sept. 12, 2024, 10:35 p.m.

7.2

CVSS3.1

CVE-2024-32846 -

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

πŸ“… Published: Sept. 12, 2024, 1:09 a.m. πŸ”„ Last Modified: Sept. 12, 2024, 10:35 p.m.

7.2

CVSS3.1

CVE-2024-32842 -

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

πŸ“… Published: Sept. 12, 2024, 1:09 a.m. πŸ”„ Last Modified: Sept. 12, 2024, 10:35 p.m.

5.3

CVSS4.0

CVE-2024-8707 - δΊ‘θ―Ύη½‘η»œη§‘ζŠ€ζœ‰ι™ε…¬εΈ Yunke Online School System Appadmin.php downfile path traversal

A vulnerability was found in δΊ‘θ―Ύη½‘η»œη§‘ζŠ€ζœ‰ι™ε…¬εΈ Yunke Online School System up to 3.0.6. It has been declared as problematic. This vulnerability affects the function downfile of the file application/admin/controller/Appadmin.php. The manipulation of the argument url leads to path traversal. The attack can b…

πŸ“… Published: Sept. 12, 2024, 12:31 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.1

CVSS3.1

CVE-2024-40457 -

No-IP Dynamic Update Client (DUC) v3.x uses cleartext credentials that may occur on a command line or in a file. NOTE: the vendor's position is that cleartext in /etc/default/noip-duc is recommended and is the intentional behavior.

πŸ“… Published: Sept. 12, 2024, midnight πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.3

CVSS3.1

CVE-2024-34336 -

User enumeration vulnerability in ORDAT FOSS-Online before v2.24.01 allows attackers to determine if an account exists in the application by comparing the server responses of the forgot password functionality.

πŸ“… Published: Sept. 12, 2024, midnight πŸ”„ Last Modified: Sept. 18, 2024, 8:32 p.m.
Total resulsts: 349182
Page 8591 of 34,919
Β« previous page Β» next page
Filters