Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Avalanche CRITICAL 9.1
CVE-2023-32565

An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in v…

Fix: 6.4.1+
Fix from $2,300 2023-08-10
Avalanche HIGH 7.5
CVE-2023-32561

A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authentication bypa…

Fix: 6.4.1+
Fix from $1,950 2023-08-10
Desktop \& Server Management HIGH 7.8
CVE-2023-28129

DSM 2022.2 SU2 and all prior versions allows a local low privileged account to execute arbitrary OS commands as the DSM software installation user.

Fix: 2022.2+
Fix from $1,950 2023-08-10
Avalanche CRITICAL 9.8
CVE-2023-32567

Ivanti Avalanche decodeToMap XML External Entity Processing. Fixed in version 6.4.1.236

Fix: 6.4.1+
Fix from $2,300 2023-08-10
Avalanche CRITICAL 9.1
CVE-2023-32566

An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in v…

Fix: 6.4.1+
Fix from $2,300 2023-08-10
Endpoint Manager Mobile HIGH 7.2
CVE-2023-35081 KEVEPSS 64%

A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated admini…

Fix: 11.8.1.2 / 11.9.1.2+
Fix from $1,950 2023-08-03
Endpoint Manager Mobile CRITICAL 9.8
CVE-2023-35078 KEVEPSS 100%

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application wi…

Fix: 11.8.1.1 / 11.9.1.1+
Fix from $2,300 2023-07-25
Endpoint Manager HIGH 7.5
CVE-2023-35077

An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update to Ivanti AV Product version 7…

Fix: 7.9.1.285+
Fix from $1,950 2023-07-21
Endpoint Manager CRITICAL 9.8
CVE-2023-28323

A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit…

Fix: 2022+
Fix from $2,300 2023-07-01
Endpoint Manager CRITICAL 9.8
CVE-2023-28324EPSS 13%

A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execu…

Fix: after 2022
Fix from $2,300 2023-07-01
Avalanche HIGH 7.5
CVE-2023-28127EPSS 59%

A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure.

Fix: after 6.3.4.153
Fix from $1,950 2023-05-09
Avalanche HIGH 7.2
CVE-2023-28128EPSS 85%

An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve…

Fix: after 6.3.4.153
Fix from $1,950 2023-05-09
Avalanche MEDIUM 5.9
CVE-2023-28125

An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the serv…

Fix: after 6.3.4.153
Fix from $1,600 2023-05-09
Avalanche MEDIUM 5.9
CVE-2023-28126EPSS 67%

An authentication bypass vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to gain access by exploiting the Set…

Fix: after 6.3.4.153
Fix from $1,600 2023-05-09
Avalanche CRITICAL 9.8
CVE-2022-36974EPSS 84%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio…

Fix: 6.3.4+
Fix from $2,300 2023-03-29
Avalanche CRITICAL 9.8
CVE-2022-36975EPSS 7%

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exist…

Fix: 6.3.4+
Fix from $2,300 2023-03-29
Avalanche CRITICAL 9.8
CVE-2022-36976EPSS 7%

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exist…

Fix: 6.3.4+
Fix from $2,300 2023-03-29
Avalanche CRITICAL 9.8
CVE-2022-36977EPSS 7%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio…

Fix: 6.3.4+
Fix from $2,300 2023-03-29
Avalanche CRITICAL 9.8
CVE-2022-36978EPSS 7%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio…

Fix: 6.3.4+
Fix from $2,300 2023-03-29
Avalanche CRITICAL 9.8
CVE-2022-36979EPSS 7%

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication…

Fix: 6.3.4+
Fix from $2,300 2023-03-29
Avalanche CRITICAL 9.8
CVE-2022-36981EPSS 83%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication…

Fix: 6.3.4+
Fix from $2,300 2023-03-29
Avalanche CRITICAL 9.8
CVE-2022-36983

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche. Authentication is not required to …

Fix: 6.3.4+
Fix from $2,300 2023-03-29
Avalanche HIGH 8.8
CVE-2022-36973EPSS 6%

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication…

Fix: 6.3.4+
Fix from $1,950 2023-03-29
Avalanche HIGH 8.1
CVE-2022-36980EPSS 83%

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication…

Fix: 6.3.4+
Fix from $1,950 2023-03-29
Avalanche HIGH 7.5
CVE-2022-36982EPSS 74%

This vulnerability allows remote attackers to read arbitrary files on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication i…

Fix: 6.3.4+
Fix from $1,950 2023-03-29
Avalanche CRITICAL 9.8
CVE-2022-36972EPSS 7%

This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exist…

Fix: 6.3.4+
Fix from $2,300 2023-03-29
Avalanche HIGH 8.8
CVE-2022-36971EPSS 15%

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authenticatio…

Fix: 6.3.4+
Fix from $1,950 2023-03-29
Avalanche HIGH 7.5
CVE-2022-44574EPSS 65%

An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific…

Fix: 6.4.0+
Fix from $1,950 2023-03-10
Endpoint Manager CRITICAL 9.8
CVE-2022-27773

A privilege escalation vulnerability is identified in Ivanti EPM (LANDesk Management Suite) that allows a user to execute commands with elevated priv…

Fix: 2021.1+
Fix from $2,300 2022-12-05
Endpoint Manager HIGH 7.8
CVE-2022-35259

XML Injection with Endpoint Manager 2022. 3 and below causing a download of a malicious file to run and possibly execute to gain unauthorized privile…

Fix: after 2022.3
Fix from $1,950 2022-12-05