2024 CVE Vulnerabilities
39,223 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13170 | HIGH | 7.5 | 2.2% | Jan 14, 2025 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd... |
| CVE-2024-13169 | HIGH | 7.8 | 0.4% | Jan 14, 2025 | An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upda... |
| CVE-2024-13168 | HIGH | 7.5 | 2.1% | Jan 14, 2025 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd... |
| CVE-2024-13167 | HIGH | 7.5 | 2.1% | Jan 14, 2025 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd... |
| CVE-2024-13166 | HIGH | 7.5 | 2.0% | Jan 14, 2025 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd... |
| CVE-2024-13165 | HIGH | 7.5 | 2.1% | Jan 14, 2025 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd... |
| CVE-2024-13164 | HIGH | 7.8 | 0.4% | Jan 14, 2025 | An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security ... |
| CVE-2024-13163 | HIGH | 7.8 | 9.2% | Jan 14, 2025 | Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 S... |
| CVE-2024-13162 | HIGH | 7.2 | 64.2% | Jan 14, 2025 | SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allow... |
| CVE-2024-13161 | HIGH | 7.5 | 88.5% | Jan 14, 2025 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up... |
| CVE-2024-13160 | HIGH | 7.5 | 89.7% | Jan 14, 2025 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up... |
| CVE-2024-13159 | HIGH | 7.5 | 99.8% | Jan 14, 2025 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up... |
| CVE-2024-13158 | HIGH | 7.2 | 2.8% | Jan 14, 2025 | An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 S... |
| CVE-2024-12747 | MEDIUM | 5.6 | 0.4% | Jan 14, 2025 | A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rs... |
| CVE-2024-12088 | HIGH | 7.5 | 4.6% | Jan 14, 2025 | A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic... |
| CVE-2024-12087 | HIGH | 7.5 | 2.2% | Jan 14, 2025 | A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a defaul... |
| CVE-2024-12086 | MEDIUM | 6.8 | 1.8% | Jan 14, 2025 | A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's mach... |
| CVE-2024-12085 | HIGH | 7.5 | 8.8% | Jan 14, 2025 | A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to m... |
| CVE-2024-53563 | MEDIUM | 5.4 | 0.2% | Jan 14, 2025 | A stored cross-site scripting (XSS) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to ex... |
| CVE-2024-53561 | HIGH | 8.7 | 0.6% | Jan 14, 2025 | A remote code execution (RCE) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute ... |
| CVE-2024-52898 | MEDIUM | 6.2 | 0.2% | Jan 14, 2025 | IBM MQ 9.3 LTS, 9.3 CD, 9.4 LTS, and 9.4 CD web console could allow a local user to obtain sensitive information when a ... |
| CVE-2024-45627 | MEDIUM | 5.9 | 0.3% | Jan 14, 2025 | In Apache Linkis <1.7.0, due to the lack of effective filtering of parameters, an attacker configuring malicious Mysql J... |
| CVE-2024-13181 | CRITICAL | 9.8 | 32.4% | Jan 14, 2025 | Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authenticatio... |
| CVE-2024-13180 | HIGH | 7.5 | 27.8% | Jan 14, 2025 | Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive infor... |
| CVE-2024-13179 | CRITICAL | 9.8 | 61.8% | Jan 14, 2025 | Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authenticatio... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now