Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2024-11-12 CVE-2024-50323 SQL Injection vulnerability in Ivanti Endpoint Manager
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution.
local
low complexity
ivanti CWE-89
7.8
2024-11-12 CVE-2024-50324 Path Traversal vulnerability in Ivanti Endpoint Manager
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti CWE-22
7.2
2024-11-12 CVE-2024-50326 SQL Injection vulnerability in Ivanti Endpoint Manager
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti CWE-89
7.2
2024-11-12 CVE-2024-50327 SQL Injection vulnerability in Ivanti Endpoint Manager
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti CWE-89
7.2
2024-11-12 CVE-2024-50328 SQL Injection vulnerability in Ivanti Endpoint Manager
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti CWE-89
7.2
2024-11-12 CVE-2024-50329 Path Traversal vulnerability in Ivanti Endpoint Manager
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution.
network
low complexity
ivanti CWE-22
8.8
2024-11-12 CVE-2024-50331 Out-of-bounds Read vulnerability in Ivanti Avalanche
An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.
network
low complexity
ivanti CWE-125
7.5
2024-11-12 CVE-2024-11127 SQL Injection vulnerability in Anisha JOB Recruitment 1.0
A vulnerability was found in code-projects Job Recruitment up to 1.0.
network
low complexity
anisha CWE-89
8.8
2024-11-12 CVE-2024-11124 SQL Injection vulnerability in Timgeyssens Ui-O-Matic
A vulnerability has been found in TimGeyssens UIOMatic 5 and classified as critical.
network
low complexity
timgeyssens CWE-89
7.2
2024-11-12 CVE-2024-29119 Unspecified vulnerability in Siemens Spectrum Power 7 2.20/2.30/23Q3
A vulnerability has been identified in Spectrum Power 7 (All versions < V24Q3).
local
low complexity
siemens
7.8