CVE-2024-8322
Last Modified: 12 Sept 2024Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.
CVE-2024-8321
Last Modified: 12 Sept 2024Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.
CVE-2024-8320
Last Modified: 12 Sept 2024Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.
CVE-2024-8191
Last Modified: 12 Sept 2024SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
CVE-2024-44107
Last Modified: 12 Jun 2025DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges and achieve arbitrary code execution.
CVE-2024-44106
Last Modified: 12 Jun 2025Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.
CVE-2024-44105
Last Modified: 12 Jun 2025Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to obtain OS credentials.
CVE-2024-44104
Last Modified: 12 Jun 2025An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.
CVE-2024-44103
Last Modified: 12 Jun 2025DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.
CVE-2024-8012
Last Modified: 12 Jun 2025An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.
CVE-2024-8190
Last Modified: 24 Oct 2025An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
CVE-2024-8677
Last Modified: 11 Feb 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-8232
Last Modified: 15 Apr 2026SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious files without authentication.
CVE-2024-8655
Last Modified: 15 Apr 2026A vulnerability was found in Mercury MNVR816 up to 2.0.1.0.5. It has been classified as problematic. This affects an unknown part of the file /web-static/. The manipulation leads to files or directories accessible. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2024-8674
Last Modified: 11 Feb 2025This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2024-8504
Last Modified: 15 Apr 2026An attacker with authenticated access to VICIdial as an "agent" can execute arbitrary shell commands as the "root" user. This attack can be chained with CVE-2024-8503 to execute arbitrary shell commands starting from an unauthenticated perspective.
CVE-2024-8503
Last Modified: 15 Apr 2026An unauthenticated attacker can leverage a time-based SQL injection vulnerability in VICIdial to enumerate database records. By default, VICIdial stores plaintext credentials within the database.
CVE-2024-45409
Last Modified: 21 Nov 2024The Ruby SAML library is for implementing the client side of a SAML authorization. Ruby-SAML in <= 12.2 and 1.13.0 <= 1.16.0 does not properly verify the signature of the SAML Response. An unauthenticated attacker with access to any signed saml document (by the IdP) can thus forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as arbitrary user within the vulnerable system. This vulnerability is fixed in 1.17.0 and 1.12.3.
CVE-2024-45596
Last Modified: 17 Nov 2025Directus is a real-time API and App dashboard for managing SQL database content. An unauthenticated user can access credentials of last authenticated user via OpenID or OAuth2 where the authentication URL did not include redirect query string. This happens because on that endpoint for both OpenId and Oauth2 Directus is using the respond middleware, which by default will try to cache GET requests that met some conditions. Although, those conditions do not include this scenario, when an unauthenticated request returns user credentials. This vulnerability is fixed in 10.13.3 and 11.1.0.
CVE-2024-37980
Last Modified: 7 Jan 2025Microsoft SQL Server Elevation of Privilege Vulnerability
CVE-2024-38194
Last Modified: 31 Dec 2024An authenticated attacker can exploit an improper authorization vulnerability in Azure Web Apps to elevate privileges over a network.
CVE-2024-43495
Last Modified: 31 Dec 2024Windows libarchive Remote Code Execution Vulnerability
CVE-2024-43491
Last Modified: 31 Dec 2024Microsoft is aware of a vulnerability in Servicing Stack that has rolled back the fixes for some vulnerabilities affecting Optional Components on Windows 10, version 1507 (initial version released July 2015). This means that an attacker could exploit these previously mitigated vulnerabilities on Windows 10, version 1507 (Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB) systems that have installed the Windows security update released on March 12, 2024—KB5035858 (OS Build 10240.20526) or other updates released until August 2024. All later versions of Windows 10 are not impacted by this vulnerability. This servicing stack vulnerability is addressed by installing the September 2024 Servicing stack update (SSU KB5043936) AND the September 2024 Windows security update (KB5043083), in that order. Note: Windows 10, version 1507 reached the end of support (EOS) on May 9, 2017 for devices running the Pro, Home, Enterprise, Education, and Enterprise IoT editions. Only Windows 10 Enterprise 2015 LTSB and Windows 10 IoT Enterprise 2015 LTSB editions are still under support.
CVE-2024-43487
Last Modified: 31 Dec 2024Windows Mark of the Web Security Feature Bypass Vulnerability
CVE-2024-30073
Last Modified: 31 Dec 2024Windows Security Zone Mapping Security Feature Bypass Vulnerability
CVE-2024-43479
Last Modified: 31 Dec 2024Microsoft Power Automate Desktop Remote Code Execution Vulnerability
CVE-2024-43476
Last Modified: 31 Dec 2024Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2024-43475
Last Modified: 31 Dec 2024Microsoft Windows Admin Center Information Disclosure Vulnerability
CVE-2024-43470
Last Modified: 31 Dec 2024Azure Network Watcher VM Agent Elevation of Privilege Vulnerability
CVE-2024-43469
Last Modified: 31 Dec 2024Azure CycleCloud Remote Code Execution Vulnerability
CVE-2024-43466
Last Modified: 31 Dec 2024Microsoft SharePoint Server Denial of Service Vulnerability
CVE-2024-43461
Last Modified: 30 Dec 2025Windows MSHTML Platform Spoofing Vulnerability
CVE-2024-43458
Last Modified: 31 Dec 2024Windows Networking Information Disclosure Vulnerability
CVE-2024-43457
Last Modified: 31 Dec 2024Windows Setup and Deployment Elevation of Privilege Vulnerability
CVE-2024-43455
Last Modified: 31 Dec 2024Windows Remote Desktop Licensing Service Spoofing Vulnerability
CVE-2024-43454
Last Modified: 31 Dec 2024Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2024-38119
Last Modified: 31 Dec 2024Windows Network Address Translation (NAT) Remote Code Execution Vulnerability
CVE-2024-38045
Last Modified: 31 Dec 2024Windows TCP/IP Remote Code Execution Vulnerability
CVE-2024-21416
Last Modified: 31 Dec 2024Windows TCP/IP Remote Code Execution Vulnerability
CVE-2024-38263
Last Modified: 31 Dec 2024Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2024-38260
Last Modified: 31 Dec 2024Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
CVE-2024-38259
Last Modified: 31 Dec 2024Microsoft Management Console Remote Code Execution Vulnerability
CVE-2024-38258
Last Modified: 31 Dec 2024Windows Remote Desktop Licensing Service Information Disclosure Vulnerability
CVE-2024-38257
Last Modified: 31 Dec 2024Microsoft AllJoyn API Information Disclosure Vulnerability
CVE-2024-38248
Last Modified: 31 Dec 2024Windows Storage Elevation of Privilege Vulnerability
CVE-2024-38247
Last Modified: 31 Dec 2024Windows Graphics Component Elevation of Privilege Vulnerability
CVE-2024-38246
Last Modified: 31 Dec 2024Win32k Elevation of Privilege Vulnerability
CVE-2024-38245
Last Modified: 31 Dec 2024Kernel Streaming Service Driver Elevation of Privilege Vulnerability
CVE-2024-38244
Last Modified: 31 Dec 2024Kernel Streaming Service Driver Elevation of Privilege Vulnerability
CVE-2024-38243
Last Modified: 31 Dec 2024Kernel Streaming Service Driver Elevation of Privilege Vulnerability
