Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Connect Secure HIGH 7.5
CVE-2022-35254

An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R1…

Fix: 9.1+
Fix from $1,950 2022-12-05
Connect Secure HIGH 7.5
CVE-2022-35258

An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R1…

Fix: 9.1+
Fix from $1,950 2022-12-05
Connect Secure MEDIUM 5.4
CVE-2022-21826EPSS 45%

Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignor…

Fix: 9.1+
Fix from $1,600 2022-09-30
Endpoint Manager MEDIUM 6.7
CVE-2022-30121

The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is…

Fix: 2021.1.1+
Fix from $1,600 2022-09-23
Connect Secure HIGH 7.2
CVE-2021-44720

In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > P…

Fix: 9.1+
Fix from $1,950 2022-08-12
Incapptic Connect HIGH 8.8
CVE-2022-22572

A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. The vulnerability affects…

Fix: 1.40.2+
Fix from $1,950 2022-04-11
Dsm Remote HIGH 7.8
CVE-2022-27088

Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges.

Fix: after 6.3.1.1862
Fix from $1,950 2022-04-11
Avalanche HIGH 7.5
CVE-2021-30497EPSS 97%

Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter…

Patch available
Fix from $1,950 2022-04-06
Incapptic Connect HIGH 7.2
CVE-2022-21828

A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified …

No fix yet
Fix from $1,950 2022-03-04
Service Manager MEDIUM 6.1
CVE-2021-38560

Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.

Patch available
Fix from $1,600 2022-02-01
Workspace Control MEDIUM 5.5
CVE-2022-21823

A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with lo…

Fix: 10.7.30.0+
Fix from $1,600 2022-01-10
Workspace Control HIGH 7.5
CVE-2019-19138

Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity.

Fix: 10.4.50.0+
Fix from $1,950 2021-12-15
Endpoint Manager Cloud Services Appliance CRITICAL 9.8
CVE-2021-44529 KEVEPSS 99%

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited…

Fix: after 4.5
Fix from $2,300 2021-12-08
Avalanche CRITICAL 9.8
CVE-2021-42127EPSS 66%

A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via …

Fix: 6.3.3+
Fix from $2,300 2021-12-07
Avalanche CRITICAL 9.8
CVE-2021-42128

An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise…

Fix: 6.3.3+
Fix from $2,300 2021-12-07
Avalanche HIGH 8.8
CVE-2021-42124

An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a …

Fix: 6.3.3+
Fix from $1,950 2021-12-07
Avalanche HIGH 8.8
CVE-2021-42125EPSS 82%

An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dan…

Fix: 6.3.3+
Fix from $1,950 2021-12-07
Avalanche HIGH 8.8
CVE-2021-42126

An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to per…

Fix: 6.3.3+
Fix from $1,950 2021-12-07
Avalanche HIGH 8.8
CVE-2021-42129EPSS 77%

A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary…

Fix: 6.3.3+
Fix from $1,950 2021-12-07
Avalanche HIGH 8.8
CVE-2021-42130EPSS 62%

A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to p…

Fix: 6.3.3+
Fix from $1,950 2021-12-07
Avalanche HIGH 8.8
CVE-2021-42131EPSS 67%

A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege esca…

Fix: 6.3.3+
Fix from $1,950 2021-12-07
Avalanche HIGH 8.8
CVE-2021-42132EPSS 70%

A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary…

Fix: 6.3.3+
Fix from $1,950 2021-12-07
Avalanche HIGH 8.1
CVE-2021-42133

An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform…

Fix: 6.3.3+
Fix from $1,950 2021-12-07
Connect Secure HIGH 7.5
CVE-2021-22965

A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed r…

Fix: 9.1+
Fix from $1,950 2021-11-19
Workspace Control HIGH 7.8
CVE-2021-36235

An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges can bypass File and Folder Sec…

Fix: 10.6.30.0+
Fix from $1,950 2021-09-01
Connect Secure HIGH 7.2
CVE-2021-22934

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or compromised Pulse Connect Secure device in a load…

Fix: 9.1+
Fix from $1,950 2021-08-16
Connect Secure HIGH 7.2
CVE-2021-22935

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web …

Fix: 9.1+
Fix from $1,950 2021-08-16
Connect Secure HIGH 7.2
CVE-2021-22937EPSS 8%

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted ar…

Fix: 9.1+
Fix from $1,950 2021-08-16
Connect Secure HIGH 7.2
CVE-2021-22938

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web …

Fix: 9.1+
Fix from $1,950 2021-08-16
Connect Secure MEDIUM 6.5
CVE-2021-22933

A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciousl…

Fix: 9.1+
Fix from $1,600 2021-08-16