Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-09-12 CVE-2024-34779 SQL Injection vulnerability in Ivanti Endpoint Manager
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti CWE-89
7.2
2024-09-12 CVE-2024-34783 SQL Injection vulnerability in Ivanti Endpoint Manager
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti CWE-89
7.2
2024-09-12 CVE-2024-34785 SQL Injection vulnerability in Ivanti Endpoint Manager
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti CWE-89
7.2
2024-09-12 CVE-2024-8708 Cross-site Scripting vulnerability in Mayurik Best House Rental Management System 1.0
A vulnerability was found in SourceCodester Best House Rental Management System 1.0.
network
low complexity
mayurik CWE-79
6.1
2024-09-11 CVE-2024-7889 Unspecified vulnerability in Citrix Workspace
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
local
low complexity
citrix
7.3
2024-09-11 CVE-2024-7890 Unspecified vulnerability in Citrix Workspace
Local privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Workspace app for Windows
local
low complexity
citrix
7.3
2024-09-11 CVE-2024-8692 Weak Password Recovery Mechanism for Forgotten Password vulnerability in Tduckcloud Tduckpro
A vulnerability classified as critical was found in TDuckCloud TDuckPro up to 6.3.
network
low complexity
tduckcloud CWE-640
critical
9.8
2024-09-11 CVE-2024-20304 Memory Leak vulnerability in Cisco IOS XR
A vulnerability in the multicast traceroute version 2 (Mtrace2) feature of Cisco IOS XR Software could allow an unauthenticated, remote attacker to exhaust the UDP packet memory of an affected device. This vulnerability exists because the Mtrace2 code does not properly handle packet memory.
network
low complexity
cisco CWE-401
7.5
2024-09-11 CVE-2024-20317 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the handling of specific Ethernet frames by Cisco IOS XR Software for various Cisco Network Convergence System (NCS) platforms could allow an unauthenticated, adjacent attacker to cause critical priority packets to be dropped, resulting in a denial of service (DoS) condition. This vulnerability is due to incorrect classification of certain types of Ethernet frames that are received on an interface.
low complexity
cisco
7.4
2024-09-11 CVE-2024-20343 Unspecified vulnerability in Cisco IOS XR
A vulnerability in the CLI of Cisco IOS XR Software could allow an authenticated, local attacker to read any file in the file system of the underlying Linux operating system.
local
low complexity
cisco
5.5