Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Connect Secure HIGH 7.5
CVE-2025-5462

A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8…

Fix: 22.7 / 22.8+
Fix from $1,950 2025-08-12
Desktop \& Server Management MEDIUM 5.7
CVE-2024-38648

A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user crede…

Fix: 2024.2+
Fix from $1,600 2025-07-12
Avalanche CRITICAL 9.8
CVE-2023-38036

A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overflow that …

Fix: 6.4.1+
Fix from $2,300 2025-07-12
Endpoint Manager Mobile HIGH 7.2
CVE-2025-6771EPSS 17%

OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker w…

Fix: 12.3.0.3 / 12.4.0.3+
Fix from $1,950 2025-07-08
Connect Secure MEDIUM 5.5
CVE-2025-5464

Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authenticated attacker to obtain t…

Fix: 22.7+
Fix from $1,600 2025-07-08
Endpoint Manager HIGH 7.2
CVE-2025-7037

SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin pri…

Fix: 2022+
Fix from $1,950 2025-07-08
Endpoint Manager HIGH 8.4
CVE-2025-6995

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticate…

Fix: 2022+
Fix from $1,950 2025-07-08
Endpoint Manager HIGH 8.4
CVE-2025-6996

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticate…

Fix: 2022+
Fix from $1,950 2025-07-08
Endpoint Manager Mobile HIGH 7.2
CVE-2025-6770EPSS 16%

OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to …

Fix: 12.3.0.3 / 12.4.0.3+
Fix from $1,950 2025-07-08
Connect Secure MEDIUM 5.5
CVE-2025-5463

Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 …

Fix: 22.7+
Fix from $1,600 2025-07-08
Workspace Control HIGH 7.8
CVE-2025-5353

A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials.

Fix: 10.19.10.0+
Fix from $1,950 2025-06-10
Workspace Control HIGH 7.8
CVE-2025-22455

A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentials.

Fix: 10.19.10.0+
Fix from $1,950 2025-06-10
Workspace Control HIGH 7.3
CVE-2025-22463

A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment passwor…

Fix: 10.19.10.0+
Fix from $1,950 2025-06-10
Endpoint Manager Mobile HIGH 8.8
CVE-2025-4428 KEVEPSS 86%

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers t…

Fix: 11.12.0.5 / 12.3.0.2+
Fix from $1,950 2025-05-13
Endpoint Manager Mobile HIGH 7.5
CVE-2025-4427 KEVEPSS 100%

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources wit…

Fix: 11.12.0.5 / 12.3.0.2+
Fix from $1,950 2025-05-13
Neurons For Itsm CRITICAL 9.8
CVE-2025-22462

An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote …

Fix: 2023.4+
Fix from $2,300 2025-05-13
Cloud Services Appliance HIGH 7.8
CVE-2025-22460

Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.

Fix: 5.0.5+
Fix from $1,950 2025-05-13
Endpoint Manager CRITICAL 9.6
CVE-2025-22466

Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtain admin …

Fix: 2022+
Fix from $2,300 2025-04-08
Endpoint Manager HIGH 7.2
CVE-2025-22461

SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privile…

Fix: 2022+
Fix from $1,950 2025-04-08
Endpoint Manager MEDIUM 6.1
CVE-2025-22464

An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with …

Fix: 2022+
Fix from $1,600 2025-04-08
Endpoint Manager MEDIUM 6.1
CVE-2025-22465

Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbit…

Fix: 2022+
Fix from $1,600 2025-04-08
Endpoint Manager HIGH 7.8
CVE-2025-22458

DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.

Fix: 2022+
Fix from $1,950 2025-04-08
Connect Secure CRITICAL 9.8
CVE-2025-22457 KEVEPSS 100%

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways…

Fix: 22.7 / 22.8+
Fix from $2,300 2025-04-03
Secure Access Client HIGH 7.8
CVE-2025-22454

Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privilege…

Fix: 22.7+
Fix from $1,950 2025-03-11
Connect Secure HIGH 8.8
CVE-2025-22467

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code executio…

Fix: after 22.7
Fix from $1,950 2025-02-11
Cloud Services Appliance HIGH 7.2
CVE-2024-47908EPSS 22%

OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achi…

Fix: 5.0.5+
Fix from $1,950 2025-02-11
Secure Access Client HIGH 7.1
CVE-2024-13813

Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files.

Fix: 22.8+
Fix from $1,950 2025-02-11
Connect Secure MEDIUM 6.1
CVE-2024-13830

Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attac…

Fix: 22.7+
Fix from $1,600 2025-02-11
Connect Secure HIGH 7.2
CVE-2024-10644

Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attack…

Fix: 22.7+
Fix from $1,950 2025-02-11
Cloud Services Appliance MEDIUM 5.3
CVE-2024-11771

Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality.

Fix: 5.0.5+
Fix from $1,600 2025-02-11