Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Desktop \& Server Management HIGH 7.1
CVE-2024-7572

Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.

Fix: 2024.3.5740+
Fix from $1,950 2024-12-10
Standalone Sentry MEDIUM 5.5
CVE-2024-8540

Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive applicatio…

Fix: 9.20.2+
Fix from $1,600 2024-12-10
Cloud Services Appliance CRITICAL 9.8
CVE-2024-11639

An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access

Fix: 5.0.3+
Fix from $2,300 2024-12-10
Connect Secure HIGH 7.2
CVE-2024-11633

Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote co…

Fix: 22.7+
Fix from $1,950 2024-12-10
Connect Secure HIGH 7.2
CVE-2024-11634

Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated att…

Fix: 22.7+
Fix from $1,950 2024-12-10
Cloud Services Appliance HIGH 7.2
CVE-2024-11772EPSS 8%

Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve…

Fix: 5.0.3+
Fix from $1,950 2024-12-10
Cloud Services Appliance HIGH 7.2
CVE-2024-11773EPSS 24%

SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitra…

Fix: 5.0.3+
Fix from $1,950 2024-12-10
Endpoint Manager HIGH 7.1
CVE-2024-10256

Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.

Fix: 9.7.703 / 2024.4+
Fix from $1,950 2024-12-10
Connect Secure CRITICAL 9.1
CVE-2024-39710

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote aut…

Fix: 22.7+
Fix from $2,300 2024-11-13
Connect Secure CRITICAL 9.1
CVE-2024-39711

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote au…

Fix: 22.7+
Fix from $2,300 2024-11-13
Connect Secure CRITICAL 9.1
CVE-2024-39712

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote aut…

Fix: 22.7+
Fix from $2,300 2024-11-13
Connect Secure CRITICAL 9.1
CVE-2024-38656

Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote aut…

Fix: 22.7+
Fix from $2,300 2024-11-13
Secure Access Client HIGH 7.8
CVE-2024-37398

Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

Fix: 22.7+
Fix from $1,950 2024-11-13
Connect Secure HIGH 7.8
CVE-2024-39709

Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (N…

Fix: 9.1 / 22.6+
Fix from $1,950 2024-11-13
Connect Secure HIGH 7.5
CVE-2024-37400

An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigger an infinite loop, causing …

Fix: 22.7+
Fix from $1,950 2024-11-13
Connect Secure HIGH 7.5
CVE-2024-38649

An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remote unauthenticated attacker to…

Fix: 9.1 / 22.7+
Fix from $1,950 2024-11-13
Connect Secure HIGH 7.2
CVE-2024-38655

Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows…

Fix: 22.7+
Fix from $1,950 2024-11-13
Endpoint Manager HIGH 7.8
CVE-2024-34787EPSS 18%

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated at…

Fix: 2022+
Fix from $1,950 2024-11-13
Endpoint Manager HIGH 7.2
CVE-2024-34780

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta…

Fix: 2022+
Fix from $1,950 2024-11-13
Endpoint Manager HIGH 7.2
CVE-2024-34781EPSS 68%

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta…

Fix: 2022+
Fix from $1,950 2024-11-13
Endpoint Manager HIGH 7.2
CVE-2024-34782

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta…

Fix: 2022+
Fix from $1,950 2024-11-13
Endpoint Manager HIGH 7.2
CVE-2024-34784

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta…

Fix: 2022+
Fix from $1,950 2024-11-13
Endpoint Manager HIGH 7.2
CVE-2024-37376

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta…

Fix: 2022+
Fix from $1,950 2024-11-13
Endpoint Manager HIGH 7.2
CVE-2024-32839

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta…

Fix: 2022+
Fix from $1,950 2024-11-13
Endpoint Manager HIGH 7.2
CVE-2024-32841

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta…

Fix: 2022+
Fix from $1,950 2024-11-13
Endpoint Manager HIGH 7.2
CVE-2024-32844

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta…

Fix: 2022+
Fix from $1,950 2024-11-13
Endpoint Manager HIGH 7.2
CVE-2024-32847

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta…

Fix: 2022+
Fix from $1,950 2024-11-13
Secure Access Client HIGH 7.1
CVE-2024-8539

Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration f…

Fix: 22.7+
Fix from $1,950 2024-11-12
Secure Access Client MEDIUM 5.5
CVE-2024-9843

A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.

Fix: 22.7+
Fix from $1,600 2024-11-12
Secure Access Client HIGH 7.8
CVE-2024-7571

Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

Fix: 22.7+
Fix from $1,950 2024-11-12