Vulnerability index

Browse CVEs

61 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.0 CVE-2025-0282 KEVEPSS 100% A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for … Connect Secure Mitigation only Fix from $2,3002025-01-08 CRITICAL 9.1 CVE-2024-8963 KEVEPSS 99% Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. Endpoint Manager Cloud Services Appliance Mitigation only Fix from $2,3002024-09-19 HIGH 7.2 CVE-2024-8190 KEVEPSS 89% An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to … Cloud Services Appliance Mitigation only Fix from $1,9502024-09-10 CRITICAL 9.1 CVE-2024-38652EPSS 8% Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via a… Avalanche Mitigation only Fix from $2,3002024-08-14 HIGH 7.5 CVE-2024-38653EPSS 92% XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server. Avalanche Mitigation only Fix from $1,9502024-08-14 HIGH 7.5 CVE-2024-36136 An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS. Avalanche Mitigation only Fix from $1,9502024-08-14 HIGH 7.5 CVE-2024-37399EPSS 28% A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting i… Avalanche Mitigation only Fix from $1,9502024-08-14 HIGH 7.2 CVE-2024-37373 Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE. Avalanche Mitigation only Fix from $1,9502024-08-14 HIGH 8.0 CVE-2024-37381 An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute… Endpoint Manager Mitigation only Fix from $1,9502024-07-29 CRITICAL 9.8 CVE-2024-21894EPSS 19% A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious us… Connect Secure Mitigation only Fix from $2,3002024-04-04 HIGH 8.2 CVE-2024-22053 A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malicious us… Connect Secure Mitigation only Fix from $1,9502024-04-04 HIGH 7.5 CVE-2024-22052 A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated m… Connect Secure Mitigation only Fix from $1,9502024-04-04 MEDIUM 5.3 CVE-2024-22023 An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticate… Connect Secure Mitigation only Fix from $1,6002024-04-04 HIGH 8.3 CVE-2024-22024EPSS 95% An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gate… Connect Secure Mitigation only Fix from $1,9502024-02-13 HIGH 8.8 CVE-2024-21888EPSS 87% A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elev… Connect Secure Mitigation only Fix from $1,9502024-01-31 HIGH 8.2 CVE-2024-21893 KEVEPSS 100% A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivant… Connect Secure Mitigation only Fix from $1,9502024-01-31 MEDIUM 6.5 CVE-2023-41474EPSS 38% Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.… Avalanche No fix yet Fix from $1,6002024-01-25 CRITICAL 9.1 CVE-2024-21887 KEVEPSS 100% A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticate… Connect Secure Mitigation only Fix from $2,3002024-01-12 HIGH 8.2 CVE-2023-46805 KEVEPSS 100% An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restr… Connect Secure Mitigation only Fix from $1,9502024-01-12 HIGH 7.5 CVE-2023-39340 A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker can send a specific request which may lead to Denial o… Connect Secure No fix yet Fix from $1,9502023-12-16 HIGH 7.8 CVE-2023-41720 A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appl… Connect Secure Mitigation only Fix from $1,9502023-12-14 HIGH 7.2 CVE-2023-41719 A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a specific we… Connect Secure Mitigation only Fix from $1,9502023-12-14 HIGH 7.8 CVE-2023-41718 When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having cont… Secure Access Client No fix yet Fix from $1,9502023-11-15 MEDIUM 5.5 CVE-2023-38544 A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be e… Secure Access Client Mitigation only Fix from $1,6002023-11-15 HIGH 7.2 CVE-2022-21828 A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified … Incapptic Connect No fix yet Fix from $1,9502022-03-04 HIGH 8.8 CVE-2021-22908EPSS 69% A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shar… Connect Secure Mitigation only Fix from $1,9502021-05-27 HIGH 8.8 CVE-2021-22894 KEVEPSS 41% A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as th… Connect Secure Mitigation only Fix from $1,9502021-05-27 HIGH 8.8 CVE-2021-22899 KEVEPSS 23% A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execut… Connect Secure Mitigation only Fix from $1,9502021-05-27 CRITICAL 10.0 CVE-2021-22893 KEVEPSS 47% Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pul… Connect Secure Mitigation only Fix from $2,3002021-04-23 CRITICAL 9.9 CVE-2020-13774 An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain r… Endpoint Manager Mitigation only Fix from $2,3002020-11-12