2024 CVE Vulnerabilities

39,218 CVEs published in 2024.

Filter:HIGHClear
CVE IDSeverityCVSSDescription
CVE-2024-13166HIGH7.5An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd...
CVE-2024-13165HIGH7.5An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Upd...
CVE-2024-13164HIGH7.8An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security ...
CVE-2024-13163HIGH7.8Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 S...
CVE-2024-13162HIGH7.2SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allow...
CVE-2024-13161HIGH7.5Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up...
CVE-2024-13160HIGH7.5Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up...
CVE-2024-13159HIGH7.5Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up...
CVE-2024-13158HIGH7.2An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 S...
CVE-2024-12088HIGH7.5A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic...
CVE-2024-12087HIGH7.5A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a defaul...
CVE-2024-12085HIGH7.5A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to m...
CVE-2024-53561HIGH8.7A remote code execution (RCE) vulnerability in Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 allows attackers to execute ...
CVE-2024-13180HIGH7.5Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive infor...
CVE-2024-10811HIGH7.5Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up...
CVE-2024-10630HIGH7A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to ...
CVE-2024-42444HIGH7.8APTIOV contains a vulnerability in BIOS where an attacker may cause a TOCTOU Race Condition by local means. Successful e...
CVE-2024-39803HIGH7.2Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030...
CVE-2024-39802HIGH7.2Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030...
CVE-2024-39801HIGH7.2Multiple buffer overflow vulnerabilities exist in the qos.cgi qos_settings() functionality of Wavlink AC3000 M33A8.V5030...
CVE-2024-39800HIGH7.2Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavli...
CVE-2024-39799HIGH7.2Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavli...
CVE-2024-39798HIGH7.2Multiple external config control vulnerabilities exists in the openvpn.cgi openvpn_server_setup() functionality of Wavli...
CVE-2024-39795HIGH7.2Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 ...
CVE-2024-39794HIGH7.2Multiple external config control vulnerabilities exist in the nas.cgi set_nas() proftpd functionality of Wavlink AC3000 ...

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now