NA - CVE-2024-7612 - Insecure permissions in Ivanti EPMM before...
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to access or modify sensitive configuration files without proper authorization.
NA - CVE-2024-8626 - Due to a memory leak, a denial-of-service...
Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on...
NA - CVE-2024-9124 - A denial-of-service vulnerability exists in the...
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device is overloaded with requests, it will become unavailable. The device may require a power cycle to...
NA - CVE-2024-9167 - Under specific circumstances, insecure...
Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.
NA - CVE-2024-9379 - SQL injection in the admin web console of...
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
NA - CVE-2024-9380 - An OS command injection vulnerability in the...
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
Medium - CVE-2024-9620 - A flaw was found in Event-Driven Automation...
A flaw was found in Event-Driven Automation (EDA) in Ansible Automation Platform (AAP), which lacks encryption of sensitive information. An attacker with network access could exploit this...
Medium - CVE-2024-9621 - A vulnerability was found in Quarkus CXF....
A vulnerability was found in Quarkus CXF. Passwords and other secrets may appear in the application log in spite of the user configuring them to be hidden. This issue requires some special...
Medium - CVE-2024-9622 - A vulnerability was found in the...
A vulnerability was found in the resteasy-netty4 library arising from improper handling of HTTP requests using smuggling techniques. When an HTTP smuggling request with an ASCII control character...