Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2024-11-12 CVE-2024-8495 NULL Pointer Dereference vulnerability in Ivanti Connect Secure 22.7/7.1/7.4
A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to cause a denial of service.
network
low complexity
ivanti CWE-476
7.5
2024-11-12 CVE-2024-9420 Use After Free vulnerability in Ivanti Connect Secure 7.1/7.4
A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution
network
low complexity
ivanti CWE-416
8.8
2024-11-12 CVE-2024-11125 Cross-Site Request Forgery (CSRF) vulnerability in Get-Simple Getsimplecms 3.3.16
A vulnerability was found in GetSimpleCMS 3.3.16 and classified as problematic.
network
low complexity
get-simple CWE-352
4.3
2024-11-12 CVE-2024-11127 SQL Injection vulnerability in Anisha JOB Recruitment 1.0
A vulnerability was found in code-projects Job Recruitment up to 1.0.
network
low complexity
anisha CWE-89
8.8
2024-11-12 CVE-2024-11130 Cross-site Scripting vulnerability in Zzcms
A vulnerability was found in ZZCMS up to 2023.
network
low complexity
zzcms CWE-79
4.8
2024-11-12 CVE-2024-37365 Unspecified vulnerability in Rockwellautomation Factorytalk View 14.0
A remote code execution vulnerability exists in the affected product.
local
low complexity
rockwellautomation
7.8
2024-11-12 CVE-2024-50386 Unspecified vulnerability in Apache Cloudstack
Account users in Apache CloudStack by default are allowed to register templates to be downloaded directly to the primary storage for deploying instances.
network
low complexity
apache
critical
9.9
2024-11-12 CVE-2024-11124 SQL Injection vulnerability in Timgeyssens Ui-O-Matic
A vulnerability has been found in TimGeyssens UIOMatic 5 and classified as critical.
network
low complexity
timgeyssens CWE-89
7.2
2024-11-12 CVE-2024-29119 Unspecified vulnerability in Siemens Spectrum Power 7 2.20/2.30/23Q3
A vulnerability has been identified in Spectrum Power 7 (All versions < V24Q3).
local
low complexity
siemens
7.8
2024-11-12 CVE-2024-36140 Cross-site Scripting vulnerability in Siemens Ozw672 Firmware and Ozw772 Firmware
A vulnerability has been identified in OZW672 (All versions < V5.2), OZW772 (All versions < V5.2).
network
low complexity
siemens CWE-79
5.4