2024 CVE Vulnerabilities

39,256 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-49375CRITICAL9Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the...
CVE-2024-48857HIGH7.5NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated atta...
CVE-2024-48856CRITICAL9.8Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker ...
CVE-2024-48855HIGH7.5Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker ...
CVE-2024-48854HIGH7.5Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to...
CVE-2024-53996——Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA po...
CVE-2024-13172HIGH7.8Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Sec...
CVE-2024-13171HIGH7.8Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Se...
CVE-2024-13170HIGH7.5An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd...
CVE-2024-13169HIGH7.8An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upda...
CVE-2024-13168HIGH7.5An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd...
CVE-2024-13167HIGH7.5An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd...
CVE-2024-13166HIGH7.5An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd...
CVE-2024-13165HIGH7.5An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd...
CVE-2024-13164HIGH7.8An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security ...
CVE-2024-13163HIGH7.8Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 S...
CVE-2024-13162HIGH7.2SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allow...
CVE-2024-13161HIGH7.5Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up...
CVE-2024-13160HIGH7.5Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up...
CVE-2024-13159HIGH7.5Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up...
CVE-2024-13158HIGH7.2An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 S...
CVE-2024-12747MEDIUM5.6A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rs...
CVE-2024-12088HIGH7.5A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic...
CVE-2024-12087HIGH7.5A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a defaul...
CVE-2024-12086MEDIUM6.8A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's mach...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now