1611
|
- |
|
-
|
-
|
Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2024-13163
|
2025-01-15 03:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1612
|
- |
|
-
|
-
|
SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code …
|
CWE-89
SQL Injection
|
CVE-2024-13162
|
2025-01-15 03:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1613
|
- |
|
-
|
-
|
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
|
CWE-36
Absolute Path Traversal
|
CVE-2024-13161
|
2025-01-15 03:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1614
|
- |
|
-
|
-
|
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
|
CWE-36
Absolute Path Traversal
|
CVE-2024-13160
|
2025-01-15 03:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1615
|
- |
|
-
|
-
|
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
|
CWE-36
Absolute Path Traversal
|
CVE-2024-13159
|
2025-01-15 03:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1616
|
- |
|
-
|
-
|
An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to …
|
CWE-22 CWE-426
Path Traversal Untrusted Search Path
|
CVE-2024-13158
|
2025-01-15 03:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1617
|
- |
|
-
|
-
|
In Apache Linkis <1.7.0, due to the lack of effective filtering
of parameters, an attacker configuring malicious Mysql JDBC parameters in the DataSource Manager Module will
allow the attacker to re…
|
-
|
CVE-2024-45627
|
2025-01-15 03:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1618
|
- |
|
-
|
-
|
Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This issue affects Security Kit: from 0.0.0 before 2.0.3.
|
-
|
CVE-2024-13275
|
2025-01-15 03:15 |
2025-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1619
|
- |
|
-
|
-
|
A vulnerability was found in SourceCodester Task Reminder System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Maintenance Sect…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2025-0464
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1620
|
- |
|
-
|
-
|
A vulnerability was found in Shanghai Lingdang Information Technology Lingdang CRM up to 8.6.0.0. It has been classified as critical. Affected is an unknown function of the file /crm/weixinmp/index.p…
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2025-0463
|
2025-01-15 02:15 |
2025-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|