8.2

CVSS3.1

CVE-2024-44105 -

Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to obtain OS credentials.

πŸ“… Published: Sept. 10, 2024, 8:43 p.m. πŸ”„ Last Modified: June 12, 2025, 5:15 p.m.

8.8

CVSS3.1

CVE-2024-44104 -

An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

πŸ“… Published: Sept. 10, 2024, 8:41 p.m. πŸ”„ Last Modified: June 12, 2025, 5:15 p.m.

8.8

CVSS3.1

CVE-2024-44103 -

DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

πŸ“… Published: Sept. 10, 2024, 8:39 p.m. πŸ”„ Last Modified: June 12, 2025, 5:15 p.m.

7.8

CVSS3.1

CVE-2024-8012 -

An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

πŸ“… Published: Sept. 10, 2024, 8:37 p.m. πŸ”„ Last Modified: June 12, 2025, 5:15 p.m.

7.2

CVSS3.1

CVE-2024-8190 -

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.

πŸ“… Published: Sept. 10, 2024, 8:33 p.m. πŸ”„ Last Modified: Oct. 24, 2025, 2:48 p.m.

0.0

CVE-2024-8677 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Sept. 10, 2024, 8:02 p.m. πŸ”„ Last Modified: Feb. 11, 2025, 2:15 a.m.

8.7

CVSS4.0

CVE-2024-8232 - iniNet Solutions SpiderControl SCADA Web Server Unrestricted Upload of File with Dangerous Type

SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious files without authentication.

πŸ“… Published: Sept. 10, 2024, 7:44 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.9

CVSS4.0

CVE-2024-8655 - Mercury MNVR816 web-static file access

A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unknown part of the file /web-static/. The manipulation leads to files or directories accessible. It is possible to initiate the attack remotely. The exploit has been disclosed to th…

πŸ“… Published: Sept. 10, 2024, 7:31 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

0.0

CVE-2024-8674 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

πŸ“… Published: Sept. 10, 2024, 7:30 p.m. πŸ”„ Last Modified: Feb. 11, 2025, 2:15 a.m.

8.8

CVSS3.1

CVE-2024-8504 - VICIdial Authenticated Remote Code Execution

An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.

πŸ“… Published: Sept. 10, 2024, 7:23 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 8605 of 34,919
Β« previous page Β» next page
Filters