2024 CVE Vulnerabilities
39,218 CVEs published in 2024.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2024-13166 | HIGH | 7.5 | 2.0% | Jan 14, 2025 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd... |
| CVE-2024-13165 | HIGH | 7.5 | 2.1% | Jan 14, 2025 | An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd... |
| CVE-2024-13164 | HIGH | 7.8 | 0.4% | Jan 14, 2025 | An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security ... |
| CVE-2024-13163 | HIGH | 7.8 | 9.2% | Jan 14, 2025 | Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 S... |
| CVE-2024-13162 | HIGH | 7.2 | 64.2% | Jan 14, 2025 | SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allow... |
| CVE-2024-13161 | HIGH | 7.5 | 88.5% | Jan 14, 2025 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up... |
| CVE-2024-13160 | HIGH | 7.5 | 89.7% | Jan 14, 2025 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up... |
| CVE-2024-13159 | HIGH | 7.5 | 99.8% | Jan 14, 2025 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up... |
| CVE-2024-13158 | HIGH | 7.2 | 2.8% | Jan 14, 2025 | An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 S... |
| CVE-2024-12088 | HIGH | 7.5 | 4.6% | Jan 14, 2025 | A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic... |
| CVE-2024-12087 | HIGH | 7.5 | 2.2% | Jan 14, 2025 | A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a defaul... |
| CVE-2024-12085 | HIGH | 7.5 | 8.8% | Jan 14, 2025 | A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to m... |
| CVE-2024-53561 | HIGH | 8.7 | 0.6% | Jan 14, 2025 | A remote code execution (RCE) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute ... |
| CVE-2024-13180 | HIGH | 7.5 | 27.8% | Jan 14, 2025 | Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive infor... |
| CVE-2024-10811 | HIGH | 7.5 | 3.2% | Jan 14, 2025 | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up... |
| CVE-2024-10630 | HIGH | 7 | 0.2% | Jan 14, 2025 | A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to ... |
| CVE-2024-42444 | HIGH | 7.8 | 0.1% | Jan 14, 2025 | APTIOV contains a vulnerability in BIOS where an attacker may cause a TOCTOU Race Condition by local means. Successful e... |
| CVE-2024-39803 | HIGH | 7.2 | 1.2% | Jan 14, 2025 | Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030... |
| CVE-2024-39802 | HIGH | 7.2 | 0.8% | Jan 14, 2025 | Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030... |
| CVE-2024-39801 | HIGH | 7.2 | 1.3% | Jan 14, 2025 | Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030... |
| CVE-2024-39800 | HIGH | 7.2 | 1.8% | Jan 14, 2025 | Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavli... |
| CVE-2024-39799 | HIGH | 7.2 | 1.3% | Jan 14, 2025 | Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavli... |
| CVE-2024-39798 | HIGH | 7.2 | 1.8% | Jan 14, 2025 | Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavli... |
| CVE-2024-39795 | HIGH | 7.2 | 1.5% | Jan 14, 2025 | Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 ... |
| CVE-2024-39794 | HIGH | 7.2 | 1.0% | Jan 14, 2025 | Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 ... |
Check if your code is affected by 2024 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now