Latest CVE Feed
-
7.5
HIGHCVE-2024-13170
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2024-13169
An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-13168
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-13167
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-13166
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-13165
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2024-13164
An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2024-13163
Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
-
7.2
HIGHCVE-2024-13162
SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
9.8
CRITICALCVE-2024-13161
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.... Read more
Affected Products : endpoint_manager- Actively Exploited
- Published: Jan. 14, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-13160
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.... Read more
Affected Products : endpoint_manager- Actively Exploited
- Published: Jan. 14, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Path Traversal
-
9.8
CRITICALCVE-2024-13159
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.... Read more
Affected Products : endpoint_manager- Actively Exploited
- Published: Jan. 14, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Path Traversal
-
7.2
HIGHCVE-2024-13158
An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Misconfiguration
-
5.6
MEDIUMCVE-2024-12747
A flaw was found in rsync. This vulnerability arises from a race condition during rsync's handling of symbolic links. Rsync's default behavior when encountering symbolic links is to skip them. If an attacker replaced a regular file with a symbolic link at... Read more
Affected Products : enterprise_linux- Published: Jan. 14, 2025
- Modified: Jun. 02, 2025
- Vuln Type: Race Condition
-
7.5
HIGHCVE-2024-12088
A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which ... Read more
Affected Products : enterprise_linux enterprise_linux_server_aus openshift_container_platform enterprise_linux_eus enterprise_linux_for_ibm_z_systems_eus enterprise_linux_for_power_little_endian enterprise_linux_for_power_little_endian_eus enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions rsync enterprise_linux_for_ibm_z_systems +10 more products- Published: Jan. 14, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Path Traversal
-
7.5
HIGHCVE-2024-12087
A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the ... Read more
Affected Products : enterprise_linux enterprise_linux_server_aus enterprise_linux_eus enterprise_linux_for_ibm_z_systems_eus enterprise_linux_for_power_little_endian enterprise_linux_for_power_little_endian_eus enterprise_linux_server_for_power_little_endian_update_services_for_sap_solutions rsync suse_linux enterprise_linux_for_ibm_z_systems +8 more products- Published: Jan. 14, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Path Traversal
-
6.8
MEDIUMCVE-2024-12086
A flaw was found in rsync. It could allow a server to enumerate the contents of an arbitrary file from the client's machine. This issue occurs when files are being copied from a client to a server. During this process, the rsync server will send checksums... Read more
Affected Products : enterprise_linux openshift_container_platform rsync suse_linux linux nixos arch_linux smartos almalinux- Published: Jan. 14, 2025
- Modified: Jun. 20, 2025
- Vuln Type: Information Disclosure
-
7.5
HIGHCVE-2024-12085
A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uniniti... Read more
Affected Products : enterprise_linux enterprise_linux_server enterprise_linux_server_aus enterprise_linux_server_tus openshift_container_platform enterprise_linux_eus openshift enterprise_linux_for_ibm_z_systems_eus enterprise_linux_for_power_little_endian enterprise_linux_for_power_little_endian_eus +13 more products- Published: Jan. 14, 2025
- Modified: Aug. 12, 2025
- Vuln Type: Memory Corruption
-
6.1
MEDIUMCVE-2025-23081
Cross-Site Request Forgery (CSRF), Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - DataTransfer Extension allows Cross Site Request Forgery, Cross-Site Scripting... Read more
Affected Products : mediawiki- Published: Jan. 14, 2025
- Modified: Mar. 13, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.3
MEDIUMCVE-2025-23080
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - OpenBadges Extension allows Cross-Site Scripting (XSS).This issue affects Mediawiki - OpenBadges Extension: from ... Read more
Affected Products :- Published: Jan. 14, 2025
- Modified: Jan. 14, 2025
- Vuln Type: Cross-Site Scripting