2024 CVE Vulnerabilities
39,256 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-49375 | CRITICAL | 9 | 0.9% | Jan 14, 2025 | Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the... |
| CVE-2024-48857 | HIGH | 7.5 | 0.4% | Jan 14, 2025 | NULL pointer dereference in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated atta... |
| CVE-2024-48856 | CRITICAL | 9.8 | 0.6% | Jan 14, 2025 | Out-of-bounds write in the PCX image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker ... |
| CVE-2024-48855 | HIGH | 7.5 | 0.4% | Jan 14, 2025 | Out-of-bounds read in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker ... |
| CVE-2024-48854 | HIGH | 7.5 | 0.4% | Jan 14, 2025 | Off-by-one error in the TIFF image codec in QNX SDP versions 8.0, 7.1 and 7.0 could allow an unauthenticated attacker to... |
| CVE-2024-53996 | — | — | — | Jan 14, 2025 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA po... |
| CVE-2024-13172 | HIGH | 7.8 | 0.5% | Jan 14, 2025 | Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Sec... |
| CVE-2024-13171 | HIGH | 7.8 | 17.6% | Jan 14, 2025 | Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Se... |
| CVE-2024-13170 | HIGH | 7.5 | 2.2% | Jan 14, 2025 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd... |
| CVE-2024-13169 | HIGH | 7.8 | 0.4% | Jan 14, 2025 | An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upda... |
| CVE-2024-13168 | HIGH | 7.5 | 2.1% | Jan 14, 2025 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd... |
| CVE-2024-13167 | HIGH | 7.5 | 2.1% | Jan 14, 2025 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd... |
| CVE-2024-13166 | HIGH | 7.5 | 2.0% | Jan 14, 2025 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd... |
| CVE-2024-13165 | HIGH | 7.5 | 2.1% | Jan 14, 2025 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd... |
| CVE-2024-13164 | HIGH | 7.8 | 0.4% | Jan 14, 2025 | An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security ... |
| CVE-2024-13163 | HIGH | 7.8 | 9.2% | Jan 14, 2025 | Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 S... |
| CVE-2024-13162 | HIGH | 7.2 | 64.2% | Jan 14, 2025 | SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allow... |
| CVE-2024-13161 | HIGH | 7.5 | 88.5% | Jan 14, 2025 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up... |
| CVE-2024-13160 | HIGH | 7.5 | 89.7% | Jan 14, 2025 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up... |
| CVE-2024-13159 | HIGH | 7.5 | 99.8% | Jan 14, 2025 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up... |
| CVE-2024-13158 | HIGH | 7.2 | 2.8% | Jan 14, 2025 | An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 S... |
| CVE-2024-12747 | MEDIUM | 5.6 | 0.4% | Jan 14, 2025 | A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rs... |
| CVE-2024-12088 | HIGH | 7.5 | 4.6% | Jan 14, 2025 | A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic... |
| CVE-2024-12087 | HIGH | 7.5 | 2.2% | Jan 14, 2025 | A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a defaul... |
| CVE-2024-12086 | MEDIUM | 6.8 | 1.8% | Jan 14, 2025 | A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's mach... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now