Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2025-01-14 CVE-2025-21403 Unspecified vulnerability in Microsoft On-Prem Data Gateway 3000.198.9
On-Premises Data Gateway Information Disclosure Vulnerability
network
high complexity
microsoft
6.4
2025-01-14 CVE-2025-21405 Unspecified vulnerability in Microsoft Visual Studio 2022
Visual Studio Elevation of Privilege Vulnerability
local
low complexity
microsoft
7.3
2025-01-14 CVE-2025-23366 A flaw was found in the HAL Console in the Wildfly component, which does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output used as a web page that is served to other users.
network
low complexity
CWE-79
6.5
2025-01-14 CVE-2024-13159 Unspecified vulnerability in Ivanti Endpoint Manager 2021.1.1/2022/2024
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
network
low complexity
ivanti
7.5
2025-01-14 CVE-2024-13160 Unspecified vulnerability in Ivanti Endpoint Manager 2021.1.1/2022/2024
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
network
low complexity
ivanti
7.5
2025-01-14 CVE-2024-13161 Unspecified vulnerability in Ivanti Endpoint Manager 2021.1.1/2022/2024
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
network
low complexity
ivanti
7.5
2025-01-14 CVE-2025-21178 Unspecified vulnerability in Microsoft Visual Studio 2022
Visual Studio Remote Code Execution Vulnerability
network
low complexity
microsoft
8.8
2025-01-14 CVE-2025-21186 Unspecified vulnerability in Microsoft 365 Apps, Access and Office
Microsoft Access Remote Code Execution Vulnerability
local
low complexity
microsoft
7.8
2025-01-14 CVE-2025-21187 Unspecified vulnerability in Microsoft Power Automate for Desktop
Microsoft Power Automate Remote Code Execution Vulnerability
local
low complexity
microsoft
7.8
2025-01-14 CVE-2025-21193 Unspecified vulnerability in Microsoft products
Active Directory Federation Server Spoofing Vulnerability
network
low complexity
microsoft
6.5