← Global Threat Landscape
CVE-2024-29824
CWE-89
Critical
97.8
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
Source: NVD
Signals
- CVSS
- 8.8
- High · v3.1
- EPSS
- 99.93%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Oct 2024
- Fix commit
- No known fix commit
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-89
- Published
- 31 May 2024
- Last modified 30 Oct 2025
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2024-29824Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time