Vulnerability index

Browse CVEs

35 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 10.0 CVE-2026-10520 KEVEPSS 100% An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achie… Standalone Sentry 10.5.2 / 10.6.2+ Fix from $2,3002026-06-09 HIGH 7.2 CVE-2026-6973 KEVEPSS 34% An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative… Endpoint Manager Mobile 12.6.1.1+ Fix from $1,9502026-05-07 HIGH 7.5 CVE-2026-1603 KEVEPSS 81% An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credenti… Endpoint Manager 2024+ Fix from $1,9502026-02-10 CRITICAL 9.8 CVE-2026-1281 KEVEPSS 82% A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. Endpoint Manager Mobile after 12.5.0.0 Fix from $2,3002026-01-29 CRITICAL 9.8 CVE-2026-1340 KEVEPSS 86% A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. Endpoint Manager Mobile after 12.7.0.0 Fix from $2,3002026-01-29 HIGH 8.8 CVE-2025-4428 KEVEPSS 86% Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers t… Endpoint Manager Mobile 11.12.0.5 / 12.3.0.2+ Fix from $1,9502025-05-13 HIGH 7.5 CVE-2025-4427 KEVEPSS 100% An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources wit… Endpoint Manager Mobile 11.12.0.5 / 12.3.0.2+ Fix from $1,9502025-05-13 CRITICAL 9.8 CVE-2025-22457 KEVEPSS 100% A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways… Connect Secure 22.7 / 22.8+ Fix from $2,3002025-04-03 HIGH 7.5 CVE-2024-13159 KEVEPSS 100% Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthen… Endpoint Manager 2022+ Fix from $1,9502025-01-14 HIGH 7.5 CVE-2024-13160 KEVEPSS 91% Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthen… Endpoint Manager 2022+ Fix from $1,9502025-01-14 HIGH 7.5 CVE-2024-13161 KEVEPSS 90% Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthen… Endpoint Manager 2022+ Fix from $1,9502025-01-14 CRITICAL 9.0 CVE-2025-0282 KEVEPSS 100% A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for … Connect Secure Mitigation only Fix from $2,3002025-01-08 HIGH 7.2 CVE-2024-9379 KEVEPSS 43% SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitra… Endpoint Manager Cloud Services Appliance 5.0.2+ Fix from $1,9502024-10-08 HIGH 7.2 CVE-2024-9380 KEVEPSS 63% An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin p… Endpoint Manager Cloud Services Appliance 5.0.2+ Fix from $1,9502024-10-08 CRITICAL 9.1 CVE-2024-8963 KEVEPSS 99% Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. Endpoint Manager Cloud Services Appliance Mitigation only Fix from $2,3002024-09-19 HIGH 7.2 CVE-2024-8190 KEVEPSS 89% An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to … Cloud Services Appliance Mitigation only Fix from $1,9502024-09-10 CRITICAL 9.8 CVE-2024-7593 KEVEPSS 100% Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker t… Virtual Traffic Manager Patch available Fix from $2,3002024-08-13 HIGH 8.8 CVE-2024-29824 KEVEPSS 100% An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network… Endpoint Manager 2022+ Fix from $1,9502024-05-31 HIGH 8.2 CVE-2024-21893 KEVEPSS 100% A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivant… Connect Secure Mitigation only Fix from $1,9502024-01-31 CRITICAL 9.1 CVE-2024-21887 KEVEPSS 100% A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticate… Connect Secure Mitigation only Fix from $2,3002024-01-12 HIGH 8.2 CVE-2023-46805 KEVEPSS 100% An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restr… Connect Secure Mitigation only Fix from $1,9502024-01-12 CRITICAL 9.8 CVE-2023-38035 KEVEPSS 100% A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentica… Mobileiron Sentry after 9.18.0 Fix from $2,3002023-08-21 CRITICAL 9.8 CVE-2023-35082 KEVEPSS 100% An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of t… Endpoint Manager Mobile 11.11.0+ Fix from $2,3002023-08-15 HIGH 7.2 CVE-2023-35081 KEVEPSS 64% A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated admini… Endpoint Manager Mobile 11.8.1.2 / 11.9.1.2+ Fix from $1,9502023-08-03 CRITICAL 9.8 CVE-2023-35078 KEVEPSS 100% An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application wi… Endpoint Manager Mobile 11.8.1.1 / 11.9.1.1+ Fix from $2,3002023-07-25 CRITICAL 9.8 CVE-2021-44529 KEVEPSS 99% A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited… Endpoint Manager Cloud Services Appliance after 4.5 Fix from $2,3002021-12-08 HIGH 8.8 CVE-2021-22894 KEVEPSS 41% A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as th… Connect Secure Mitigation only Fix from $1,9502021-05-27 HIGH 8.8 CVE-2021-22899 KEVEPSS 23% A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execut… Connect Secure Mitigation only Fix from $1,9502021-05-27 HIGH 7.2 CVE-2021-22900 KEVEPSS 14% A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to pe… Connect Secure after 9.1 Fix from $1,9502021-05-27 CRITICAL 10.0 CVE-2021-22893 KEVEPSS 47% Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pul… Connect Secure Mitigation only Fix from $2,3002021-04-23