7.8

CVSS3.1

CVE-2024-11597 -

Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve local privilege escalation.

πŸ“… Published: Dec. 11, 2024, 4:49 p.m. πŸ”„ Last Modified: Jan. 23, 2025, 8:02 p.m.

7.8

CVSS3.1

CVE-2024-8496 -

Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation.

πŸ“… Published: Dec. 11, 2024, 4:43 p.m. πŸ”„ Last Modified: Dec. 14, 2024, 4:55 a.m.

7.8

CVSS3.1

CVE-2024-9845 -

Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.

πŸ“… Published: Dec. 11, 2024, 4:41 p.m. πŸ”„ Last Modified: Dec. 19, 2024, 4:55 a.m.

7.8

CVSS3.1

CVE-2024-10251 -

Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation.

πŸ“… Published: Dec. 11, 2024, 4:40 p.m. πŸ”„ Last Modified: Dec. 20, 2024, 4:55 a.m.

6.3

CVSS3.1

CVE-2024-28141 - Cross-Site Request-Forgery

The web application is not protected against cross-site request forgery attacks. Therefore, an attacker can trick users into performing actions on the application when they visit an attacker-controlled website or click on a malicious link. E.g. an attacker can forge malicious links to reset the adm…

πŸ“… Published: Dec. 11, 2024, 3:54 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

7.6

CVSS4.0

CVE-2024-47758 - GLPI vulnerable to account takeover without privilege escalation through the API

GLPI is a free asset and IT management software package. Starting in version 9.3.0 and prior to version 10.0.17, an authenticated user can use the API to take control of any user that have the same or a lower level of privileges. Version 10.0.17 contains a patch for this issue.

πŸ“… Published: Dec. 11, 2024, 3:50 p.m. πŸ”„ Last Modified: Feb. 6, 2025, 3:21 p.m.

6.1

CVSS3.1

CVE-2024-28140 - Violation of Least Privilege Principle

The scanner device boots into a kiosk mode by default and opens the Scan2Net interface in a browser window. This browser is run with the permissions of the root user. There are also several other applications running as root user.Β This can be confirmed by running "ps aux" as the root user and obser…

πŸ“… Published: Dec. 11, 2024, 3:48 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.8

CVSS3.1

CVE-2024-28139 - Privilege escalation through sudo misconfiguration

The www-data user can elevate its privileges because sudo is configured to allow the execution of the mount command as root without a password. Therefore, the privileges can be escalated to the root user. The risk has been accepted by the vendor and won't be fixed in the near future.

πŸ“… Published: Dec. 11, 2024, 3:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.5

CVSS4.0

CVE-2024-53677 - Apache Struts: Mixing setters for uploaded files and normal fields can allow bypass file upload che…

File upload logic in Apache Struts is flawed.Β An attacker can manipulate file upload params to enable paths traversal and under some circumstances this can lead to uploading a malicious file which can be used to perform Remote Code Execution. This issue affects Apache Struts: from 2.0.0 before 6.4…

πŸ“… Published: Dec. 11, 2024, 3:35 p.m. πŸ”„ Last Modified: July 15, 2025, 4:30 p.m.

4.7

CVSS3.1

CVE-2024-50585 - Reflected Cross-Site Scripting

Users who click on a malicious link or visit a website under the control of an attacker can be infected with arbitrary JavaScript which is running in the context of the "Numerix License Server Administration System Login" (nlslogin.jsp) page.Β The vulnerability can be triggered by sending a speciall…

πŸ“… Published: Dec. 11, 2024, 2:59 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 346685
Page 7274 of 34,669
Β« previous page Β» next page
Filters