Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Avalanche CRITICAL 9.8
CVE-2023-46222EPSS 7%

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-46223EPSS 7%

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.8
CVE-2023-41727EPSS 36%

An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Avalanche CRITICAL 9.1
CVE-2021-22962EPSS 91%

An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.

Fix: 6.4.2+
Fix from $2,300 2023-12-19
Connect Secure HIGH 7.5
CVE-2023-39340

A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker can send a specific request which may lead to Denial o…

No fix yet
Fix from $1,950 2023-12-16
Connect Secure HIGH 7.8
CVE-2023-41720

A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appl…

Mitigation only
Fix from $1,950 2023-12-14
Connect Secure HIGH 7.2
CVE-2023-41719

A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a specific we…

Mitigation only
Fix from $1,950 2023-12-14
Endpoint Manager Mobile CRITICAL 9.8
CVE-2023-39335

A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate …

Fix: 11.9.0 / 11.10.0.4+
Fix from $2,300 2023-11-15
Endpoint Manager Mobile CRITICAL 9.1
CVE-2023-39337

A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access …

Fix: 11.10.0.4 / 11.11.0.2+
Fix from $2,300 2023-11-15
Secure Access Client HIGH 7.8
CVE-2023-38543

A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to explo…

Fix: 22.6+
Fix from $1,950 2023-11-15
Secure Access Client HIGH 7.8
CVE-2023-41718

When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having cont…

No fix yet
Fix from $1,950 2023-11-15
Secure Access Client MEDIUM 5.5
CVE-2023-38544

A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be e…

Mitigation only
Fix from $1,600 2023-11-15
Secure Access Client HIGH 7.8
CVE-2023-35080

A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulne…

Fix: 22.6+
Fix from $1,950 2023-11-15
Secure Access Client HIGH 7.8
CVE-2023-38043

A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to explo…

Fix: 22.6+
Fix from $1,950 2023-11-15
Avalanche HIGH 7.8
CVE-2023-41725

Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability

Fix: 6.4.1.236+
Fix from $1,950 2023-11-03
Avalanche HIGH 7.8
CVE-2023-41726

Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability

Fix: 6.4.1.236+
Fix from $1,950 2023-11-03
Avalanche HIGH 7.8
CVE-2022-43554

Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability

Fix: 6.4.1.236+
Fix from $1,950 2023-11-03
Avalanche HIGH 7.8
CVE-2022-43555

Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability

Fix: 6.4.1.236+
Fix from $1,950 2023-11-03
Automation HIGH 7.8
CVE-2022-44569

A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.

Fix: 2023.4+
Fix from $1,950 2023-11-03
Secure Access Client HIGH 7.0
CVE-2023-38041

A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is ini…

Fix: 22.6+
Fix from $1,950 2023-10-25
Endpoint Manager CRITICAL 9.8
CVE-2023-35084

Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions…

Fix: 2022+
Fix from $2,300 2023-10-18
Endpoint Manager MEDIUM 6.5
CVE-2023-35083

Allows an authenticated attacker with network access to read arbitrary files on Endpoint Manager recently discovered on 2022 SU3 and all previous ver…

Fix: 2022+
Fix from $1,600 2023-10-18
Endpoint Manager MEDIUM 6.5
CVE-2023-38344

An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFileContents SOAP action exposed…

Fix: 2022+
Fix from $1,600 2023-09-21
Endpoint Manager HIGH 7.5
CVE-2023-38343

An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity referen…

Fix: 2022+
Fix from $1,950 2023-09-21
Mobileiron Sentry CRITICAL 9.8
CVE-2023-38035 KEVEPSS 100%

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentica…

Fix: after 9.18.0
Fix from $2,300 2023-08-21
Endpoint Manager Mobile CRITICAL 9.8
CVE-2023-35082 KEVEPSS 100%

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of t…

Fix: 11.11.0+
Fix from $2,300 2023-08-15
Avalanche CRITICAL 9.8
CVE-2023-32560EPSS 99%

An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execut…

Fix: 6.4.1+
Fix from $2,300 2023-08-10
Avalanche CRITICAL 9.8
CVE-2023-32562EPSS 46%

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve…

Fix: 6.4.1+
Fix from $2,300 2023-08-10
Avalanche CRITICAL 9.8
CVE-2023-32563EPSS 89%

An unauthenticated attacker could achieve the code execution through a RemoteControl server.

Fix: 6.4.1+
Fix from $2,300 2023-08-10
Avalanche CRITICAL 9.8
CVE-2023-32564EPSS 44%

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve…

Fix: 6.4.1+
Fix from $2,300 2023-08-10