Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Connect Secure HIGH 8.2
CVE-2024-22053

A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malicious us…

Mitigation only
Fix from $1,950 2024-04-04
Connect Secure HIGH 7.5
CVE-2024-22052

A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated m…

Mitigation only
Fix from $1,950 2024-04-04
Connect Secure MEDIUM 5.3
CVE-2024-22023

An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticate…

Mitigation only
Fix from $1,600 2024-04-04
Neurons For Itsm CRITICAL 9.9
CVE-2023-46808

An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful explo…

Fix: 2023.4+
Fix from $2,300 2024-03-31
Standalone Sentry HIGH 8.8
CVE-2023-41724EPSS 13%

A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlyin…

Fix: 9.19.0+
Fix from $1,950 2024-03-31
Connect Secure HIGH 8.3
CVE-2024-22024EPSS 95%

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gate…

Mitigation only
Fix from $1,950 2024-02-13
Connect Secure HIGH 8.8
CVE-2024-21888EPSS 87%

A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elev…

Mitigation only
Fix from $1,950 2024-01-31
Connect Secure HIGH 8.2
CVE-2024-21893 KEVEPSS 100%

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivant…

Mitigation only
Fix from $1,950 2024-01-31
Avalanche MEDIUM 6.5
CVE-2023-41474EPSS 38%

Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.…

No fix yet
Fix from $1,600 2024-01-25
Connect Secure CRITICAL 9.1
CVE-2024-21887 KEVEPSS 100%

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticate…

Mitigation only
Fix from $2,300 2024-01-12
Connect Secure HIGH 8.2
CVE-2023-46805 KEVEPSS 100%

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restr…

Mitigation only
Fix from $1,950 2024-01-12
Endpoint Manager HIGH 8.8
CVE-2023-39336EPSS 10%

An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal net…

Fix: 2022+
Fix from $1,950 2024-01-09
Avalanche HIGH 7.5
CVE-2023-46804

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $1,950 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46261EPSS 11%

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46263EPSS 82%

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve…

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46264EPSS 90%

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve…

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46265

An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF).

Fix: after 6.4.1
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.1
CVE-2023-46266

An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.

Fix: after 6.4.1
Fix from $2,300 2023-12-19
Avalanche HIGH 7.5
CVE-2023-46262EPSS 83%

An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Con…

Fix: after 6.4.1
Fix from $1,950 2023-12-19
Avalanche HIGH 7.5
CVE-2023-46803

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $1,950 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46224EPSS 7%

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46225EPSS 11%

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46257EPSS 11%

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46258EPSS 7%

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46259EPSS 11%

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46260EPSS 10%

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46216EPSS 36%

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46217EPSS 36%

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46220EPSS 11%

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46221EPSS 7%

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $2,300 2023-12-19