Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Connect Secure HIGH 7.2
CVE-2024-11005

Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Ap…

Fix: 9.1 / 22.7+
Fix from $1,950 2024-11-12
Connect Secure HIGH 7.2
CVE-2024-11006

Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Ap…

Fix: 9.1 / 22.7+
Fix from $1,950 2024-11-12
Connect Secure MEDIUM 6.1
CVE-2024-11004

Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attac…

Fix: 22.7+
Fix from $1,600 2024-11-12
Connect Secure HIGH 8.8
CVE-2024-9420

A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote aut…

Fix: 9.1 / 22.7+
Fix from $1,950 2024-11-12
Connect Secure HIGH 7.5
CVE-2024-8495

A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthen…

Fix: 22.7+
Fix from $1,950 2024-11-12
Endpoint Manager CRITICAL 9.8
CVE-2024-50330EPSS 40%

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated at…

Fix: 2022+
Fix from $2,300 2024-11-12
Endpoint Manager HIGH 8.8
CVE-2024-50329

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated a…

Fix: 2022+
Fix from $1,950 2024-11-12
Avalanche HIGH 7.5
CVE-2024-50331

An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.

Fix: 6.4.6+
Fix from $1,950 2024-11-12
Endpoint Manager HIGH 7.2
CVE-2024-50327

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta…

Fix: 2022+
Fix from $1,950 2024-11-12
Endpoint Manager HIGH 7.2
CVE-2024-50328

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta…

Fix: 2022+
Fix from $1,950 2024-11-12
Endpoint Manager HIGH 7.8
CVE-2024-50322EPSS 6%

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated at…

Fix: 2022+
Fix from $1,950 2024-11-12
Endpoint Manager HIGH 7.8
CVE-2024-50323

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated att…

Fix: 2022+
Fix from $1,950 2024-11-12
Avalanche HIGH 7.5
CVE-2024-50321

An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

Fix: 6.4.6+
Fix from $1,950 2024-11-12
Endpoint Manager HIGH 7.2
CVE-2024-50324EPSS 19%

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated att…

Fix: 2022+
Fix from $1,950 2024-11-12
Endpoint Manager HIGH 7.2
CVE-2024-50326EPSS 26%

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta…

Fix: 2022+
Fix from $1,950 2024-11-12
Avalanche HIGH 7.5
CVE-2024-50317

A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

Fix: 6.4.6+
Fix from $1,950 2024-11-12
Avalanche HIGH 7.5
CVE-2024-50318

A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

Fix: 6.4.6+
Fix from $1,950 2024-11-12
Avalanche HIGH 7.5
CVE-2024-50319

An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

Fix: 6.4.6+
Fix from $1,950 2024-11-12
Avalanche HIGH 7.5
CVE-2024-50320EPSS 40%

An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

Fix: 6.4.6+
Fix from $1,950 2024-11-12
Connect Secure HIGH 7.8
CVE-2024-47906

Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1…

Fix: 9.1 / 22.7+
Fix from $1,950 2024-11-12
Connect Secure HIGH 7.5
CVE-2024-47907

A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of…

Fix: 22.7+
Fix from $1,950 2024-11-12
Connect Secure HIGH 7.2
CVE-2024-11007

Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Ap…

Fix: 22.7+
Fix from $1,950 2024-11-12
Connect Secure HIGH 8.8
CVE-2024-37404EPSS 70%

Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a…

Fix: 9.1 / 22.7+
Fix from $1,950 2024-10-18
Desktop \& Server Management HIGH 7.8
CVE-2024-29213

Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified …

Fix: 2024.2+
Fix from $1,950 2024-10-18
Desktop \& Server Management HIGH 7.8
CVE-2024-29821

Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified …

Fix: 2024.2+
Fix from $1,950 2024-10-18
Endpoint Manager Cloud Services Appliance HIGH 7.2
CVE-2024-9381EPSS 16%

Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.

Fix: 5.0.2+
Fix from $1,950 2024-10-08
Velocity License Server HIGH 7.8
CVE-2024-9167

Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achi…

Fix: 5.2+
Fix from $1,950 2024-10-08
Endpoint Manager Cloud Services Appliance HIGH 7.2
CVE-2024-9379 KEVEPSS 43%

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitra…

Fix: 5.0.2+
Fix from $1,950 2024-10-08
Endpoint Manager Cloud Services Appliance HIGH 7.2
CVE-2024-9380 KEVEPSS 63%

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin p…

Fix: 5.0.2+
Fix from $1,950 2024-10-08
Avalanche CRITICAL 9.8
CVE-2024-47010EPSS 38%

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

Fix: 6.4.5+
Fix from $2,300 2024-10-08