CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2024-8322

    Last Modified: 12 Sept 2024

    Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.

    Published: 10 Sept 2024
    5.8
    Medium

    CVE-2024-8321

    Last Modified: 12 Sept 2024

    Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.

    Published: 10 Sept 2024
    5.3
    Medium

    CVE-2024-8320

    Last Modified: 12 Sept 2024

    Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.

    Published: 10 Sept 2024
    7.8
    High

    CVE-2024-8191

    Last Modified: 12 Sept 2024

    SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-44107

    Last Modified: 12 Jun 2025

    DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges and achieve arbitrary code execution.

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-44106

    Last Modified: 12 Jun 2025

    Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

    Published: 10 Sept 2024
    8.2
    High

    CVE-2024-44105

    Last Modified: 12 Jun 2025

    Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to obtain OS credentials.

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-44104

    Last Modified: 12 Jun 2025

    An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-44103

    Last Modified: 12 Jun 2025

    DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

    Published: 10 Sept 2024
    7.8
    High

    CVE-2024-8012

    Last Modified: 12 Jun 2025

    An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

    Published: 10 Sept 2024
    7.2
    High

    CVE-2024-8190

    Last Modified: 24 Oct 2025

    An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.

    Published: 10 Sept 2024
    —
    Unknown

    CVE-2024-8677

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 10 Sept 2024
    8.7
    High

    CVE-2024-8232

    Last Modified: 15 Apr 2026

    SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious files without authentication.

    Published: 10 Sept 2024
    6.9
    Medium

    CVE-2024-8655

    Last Modified: 15 Apr 2026

    A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unknown part of the file /web-static/. The manipulation leads to files or directories accessible. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 10 Sept 2024
    —
    Unknown

    CVE-2024-8674

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-8504

    Last Modified: 15 Apr 2026

    An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.

    Published: 10 Sept 2024
    9.8
    Critical

    CVE-2024-8503

    Last Modified: 15 Apr 2026

    An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.

    Published: 10 Sept 2024
    10
    Critical

    CVE-2024-45409

    Last Modified: 21 Nov 2024

    The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as arbitrary user within the vulnerable system. This vulnerability is fixed in 1.17.0 and 1.12.3.

    Published: 10 Sept 2024
    7.4
    High

    CVE-2024-45596

    Last Modified: 17 Nov 2025

    Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authentication URL did not include redirect query string. This happens because on that endpoint for both OpenId and Oauth2 Directus is using the respond middleware, which by default will try to cache GET requests that met some conditions. Although, those conditions do not include this scenario, when an unauthenticated request returns user credentials. This vulnerability is fixed in 10.13.3 and 11.1.0.

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-37980

    Last Modified: 7 Jan 2025

    Microsoft SQL Server Elevation of Privilege Vulnerability

    Published: 10 Sept 2024
    8.4
    High

    CVE-2024-38194

    Last Modified: 31 Dec 2024

    An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network.

    Published: 10 Sept 2024
    7.3
    High

    CVE-2024-43495

    Last Modified: 31 Dec 2024

    Windows libarchive Remote Code Execution Vulnerability

    Published: 10 Sept 2024
    9.8
    Critical

    CVE-2024-43491

    Last Modified: 31 Dec 2024

    Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability. This servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Note: Windows 10, version 1507 reached the end of support (EOS) on May 9, 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions. Only Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support.

    Published: 10 Sept 2024
    6.5
    Medium

    CVE-2024-43487

    Last Modified: 31 Dec 2024

    Windows Mark of the Web Security Feature Bypass Vulnerability

    Published: 10 Sept 2024
    7.8
    High

    CVE-2024-30073

    Last Modified: 31 Dec 2024

    Windows Security Zone Mapping Security Feature Bypass Vulnerability

    Published: 10 Sept 2024
    8.5
    High

    CVE-2024-43479

    Last Modified: 31 Dec 2024

    Microsoft Power Automate Desktop Remote Code Execution Vulnerability

    Published: 10 Sept 2024
    7.6
    High

    CVE-2024-43476

    Last Modified: 31 Dec 2024

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

    Published: 10 Sept 2024
    7.3
    High

    CVE-2024-43475

    Last Modified: 31 Dec 2024

    Microsoft Windows Admin Center Information Disclosure Vulnerability

    Published: 10 Sept 2024
    7.3
    High

    CVE-2024-43470

    Last Modified: 31 Dec 2024

    Azure Network Watcher VM Agent Elevation of Privilege Vulnerability

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-43469

    Last Modified: 31 Dec 2024

    Azure CycleCloud Remote Code Execution Vulnerability

    Published: 10 Sept 2024
    6.5
    Medium

    CVE-2024-43466

    Last Modified: 31 Dec 2024

    Microsoft SharePoint Server Denial of Service Vulnerability

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-43461

    Last Modified: 30 Dec 2025

    Windows MSHTML Platform Spoofing Vulnerability

    Published: 10 Sept 2024
    7.7
    High

    CVE-2024-43458

    Last Modified: 31 Dec 2024

    Windows Networking Information Disclosure Vulnerability

    Published: 10 Sept 2024
    7.8
    High

    CVE-2024-43457

    Last Modified: 31 Dec 2024

    Windows Setup and Deployment Elevation of Privilege Vulnerability

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-43455

    Last Modified: 31 Dec 2024

    Windows Remote Desktop Licensing Service Spoofing Vulnerability

    Published: 10 Sept 2024
    7.1
    High

    CVE-2024-43454

    Last Modified: 31 Dec 2024

    Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

    Published: 10 Sept 2024
    7.5
    High

    CVE-2024-38119

    Last Modified: 31 Dec 2024

    Windows Network Address Translation (NAT) Remote Code Execution Vulnerability

    Published: 10 Sept 2024
    8.1
    High

    CVE-2024-38045

    Last Modified: 31 Dec 2024

    Windows TCP/IP Remote Code Execution Vulnerability

    Published: 10 Sept 2024
    8.1
    High

    CVE-2024-21416

    Last Modified: 31 Dec 2024

    Windows TCP/IP Remote Code Execution Vulnerability

    Published: 10 Sept 2024
    7.5
    High

    CVE-2024-38263

    Last Modified: 31 Dec 2024

    Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-38260

    Last Modified: 31 Dec 2024

    Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability

    Published: 10 Sept 2024
    8.8
    High

    CVE-2024-38259

    Last Modified: 31 Dec 2024

    Microsoft Management Console Remote Code Execution Vulnerability

    Published: 10 Sept 2024
    6.5
    Medium

    CVE-2024-38258

    Last Modified: 31 Dec 2024

    Windows Remote Desktop Licensing Service Information Disclosure Vulnerability

    Published: 10 Sept 2024
    7.5
    High

    CVE-2024-38257

    Last Modified: 31 Dec 2024

    Microsoft AllJoyn API Information Disclosure Vulnerability

    Published: 10 Sept 2024
    7
    High

    CVE-2024-38248

    Last Modified: 31 Dec 2024

    Windows Storage Elevation of Privilege Vulnerability

    Published: 10 Sept 2024
    7.8
    High

    CVE-2024-38247

    Last Modified: 31 Dec 2024

    Windows Graphics Component Elevation of Privilege Vulnerability

    Published: 10 Sept 2024
    7
    High

    CVE-2024-38246

    Last Modified: 31 Dec 2024

    Win32k Elevation of Privilege Vulnerability

    Published: 10 Sept 2024
    7.8
    High

    CVE-2024-38245

    Last Modified: 31 Dec 2024

    Kernel Streaming Service Driver Elevation of Privilege Vulnerability

    Published: 10 Sept 2024
    7.8
    High

    CVE-2024-38244

    Last Modified: 31 Dec 2024

    Kernel Streaming Service Driver Elevation of Privilege Vulnerability

    Published: 10 Sept 2024
    7.8
    High

    CVE-2024-38243

    Last Modified: 31 Dec 2024

    Kernel Streaming Service Driver Elevation of Privilege Vulnerability

    Published: 10 Sept 2024