Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.0
CVE-2025-0282 KEVEPSS 100%
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for …
Connect Secure
Mitigation only
CRITICAL 9.1
CVE-2024-8963 KEVEPSS 99%
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
Endpoint Manager Cloud Services Appliance
Mitigation only
HIGH 7.2
CVE-2024-8190 KEVEPSS 89%
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to …
Cloud Services Appliance
Mitigation only
CRITICAL 9.1
CVE-2024-38652EPSS 8%
Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via a…
Avalanche
Mitigation only
HIGH 7.5
CVE-2024-38653EPSS 92%
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
Avalanche
Mitigation only
HIGH 7.5
CVE-2024-36136
An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
Avalanche
Mitigation only
HIGH 7.5
CVE-2024-37399EPSS 28%
A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting i…
Avalanche
Mitigation only
HIGH 7.2
CVE-2024-37373
Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.
Avalanche
Mitigation only
HIGH 8.0
CVE-2024-37381
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute…
Endpoint Manager
Mitigation only
CRITICAL 9.8
CVE-2024-21894EPSS 19%
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious us…
Connect Secure
Mitigation only
HIGH 8.2
CVE-2024-22053
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x
22.x) and Ivanti Policy Secure allows an unauthenticated malicious us…
Connect Secure
Mitigation only
HIGH 7.5
CVE-2024-22052
A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated m…
Connect Secure
Mitigation only
MEDIUM 5.3
CVE-2024-22023
An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticate…
Connect Secure
Mitigation only
HIGH 8.3
CVE-2024-22024EPSS 95%
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gate…
Connect Secure
Mitigation only
HIGH 8.8
CVE-2024-21888EPSS 87%
A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elev…
Connect Secure
Mitigation only
HIGH 8.2
CVE-2024-21893 KEVEPSS 100%
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivant…
Connect Secure
Mitigation only
MEDIUM 6.5
CVE-2023-41474EPSS 38%
Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.…
Avalanche
No fix yet
CRITICAL 9.1
CVE-2024-21887 KEVEPSS 100%
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticate…
Connect Secure
Mitigation only
HIGH 8.2
CVE-2023-46805 KEVEPSS 100%
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restr…
Connect Secure
Mitigation only
HIGH 7.5
CVE-2023-39340
A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker can send a specific request which may lead to Denial o…
Connect Secure
No fix yet
HIGH 7.8
CVE-2023-41720
A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appl…
Connect Secure
Mitigation only
HIGH 7.2
CVE-2023-41719
A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a specific we…
Connect Secure
Mitigation only
HIGH 7.8
CVE-2023-41718
When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having cont…
Secure Access Client
No fix yet
MEDIUM 5.5
CVE-2023-38544
A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be e…
Secure Access Client
Mitigation only
HIGH 7.2
CVE-2022-21828
A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified …
Incapptic Connect
No fix yet
HIGH 8.8
CVE-2021-22908EPSS 69%
A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shar…
Connect Secure
Mitigation only
HIGH 8.8
CVE-2021-22894 KEVEPSS 41%
A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as th…
Connect Secure
Mitigation only
HIGH 8.8
CVE-2021-22899 KEVEPSS 23%
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execut…
Connect Secure
Mitigation only
CRITICAL 10.0
CVE-2021-22893 KEVEPSS 47%
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pul…
Connect Secure
Mitigation only
CRITICAL 9.9
CVE-2020-13774
An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain r…
Endpoint Manager
Mitigation only