Vulnerabilities > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-08-13 CVE-2024-7743 Server-Side Request Forgery (SSRF) vulnerability in Ltcms 1.0.20
A vulnerability was found in wanglongcn ltcms 1.0.20.
network
low complexity
ltcms CWE-918
critical
9.8
2024-08-13 CVE-2024-7740 Server-Side Request Forgery (SSRF) vulnerability in Ltcms 1.0.20
A vulnerability has been found in wanglongcn ltcms 1.0.20 and classified as critical.
network
low complexity
ltcms CWE-918
critical
9.8
2024-08-13 CVE-2024-7569 Unspecified vulnerability in Ivanti Neurons for Itsm 2023.2/2023.3/2023.4
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
network
low complexity
ivanti
critical
9.8
2024-08-13 CVE-2024-7593 Improper Authentication vulnerability in Ivanti Virtual Traffic Management
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
network
low complexity
ivanti CWE-287
critical
9.8
2024-08-13 CVE-2024-38063 Unspecified vulnerability in Microsoft products
Windows TCP/IP Remote Code Execution Vulnerability
network
low complexity
microsoft
critical
9.8
2024-08-13 CVE-2024-38108 Cross-site Scripting vulnerability in Microsoft Azure Stack HUB
Azure Stack Hub Spoofing Vulnerability
network
low complexity
microsoft CWE-79
critical
9.3
2024-08-13 CVE-2024-38159 Unspecified vulnerability in Microsoft Windows 10 1607 and Windows Server 2016
Windows Network Virtualization Remote Code Execution Vulnerability
network
low complexity
microsoft
critical
9.1
2024-08-13 CVE-2024-38160 Unspecified vulnerability in Microsoft Windows 10 1607 and Windows Server 2016
Windows Network Virtualization Remote Code Execution Vulnerability
network
low complexity
microsoft
critical
9.1
2024-08-13 CVE-2024-38199 Unspecified vulnerability in Microsoft products
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
network
low complexity
microsoft
critical
9.8
2024-08-13 CVE-2023-26211 Cross-site Scripting vulnerability in Fortinet Fortisoar
An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authenticated, remote attacker to inject arbitrary web script or HTML via the Communications module.
network
low complexity
fortinet CWE-79
critical
9.0