Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Endpoint Manager Mobile HIGH 7.8
CVE-2024-7612

Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.

Fix: 12.0.0.5 / 12.1.0.4+
Fix from $1,950 2024-10-08
Avalanche HIGH 7.5
CVE-2024-47011EPSS 56%

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information

Fix: 6.4.5+
Fix from $1,950 2024-10-08
Avalanche CRITICAL 9.8
CVE-2024-47009

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

Fix: 6.4.5+
Fix from $2,300 2024-10-08
Avalanche HIGH 7.5
CVE-2024-47007

A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a den…

Fix: 6.4.5+
Fix from $1,950 2024-10-08
Avalanche HIGH 7.5
CVE-2024-47008EPSS 47%

Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.

Fix: 6.4.5+
Fix from $1,950 2024-10-08
Endpoint Manager Cloud Services Appliance CRITICAL 9.1
CVE-2024-8963 KEVEPSS 99%

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

Mitigation only
Fix from $2,300 2024-09-19
Endpoint Manager HIGH 8.2
CVE-2024-37397EPSS 59%

An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remot…

Fix: 2022+
Fix from $1,950 2024-09-12
Endpoint Manager HIGH 7.2
CVE-2024-32848EPSS 43%

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…

Fix: 2022+
Fix from $1,950 2024-09-12
Endpoint Manager HIGH 7.2
CVE-2024-34779EPSS 24%

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…

Fix: 2022+
Fix from $1,950 2024-09-12
Endpoint Manager HIGH 7.2
CVE-2024-34783EPSS 43%

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…

Fix: 2022+
Fix from $1,950 2024-09-12
Endpoint Manager HIGH 7.2
CVE-2024-34785EPSS 25%

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…

Fix: 2022+
Fix from $1,950 2024-09-12
Endpoint Manager CRITICAL 9.8
CVE-2024-29847EPSS 53%

Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated att…

Fix: 2022+
Fix from $2,300 2024-09-12
Endpoint Manager HIGH 7.2
CVE-2024-32840EPSS 25%

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…

Fix: 2022+
Fix from $1,950 2024-09-12
Endpoint Manager HIGH 7.2
CVE-2024-32842

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…

Fix: 2022+
Fix from $1,950 2024-09-12
Endpoint Manager HIGH 7.2
CVE-2024-32843

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…

Fix: 2022+
Fix from $1,950 2024-09-12
Endpoint Manager HIGH 7.2
CVE-2024-32845EPSS 24%

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…

Fix: 2022+
Fix from $1,950 2024-09-12
Endpoint Manager HIGH 7.2
CVE-2024-32846

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…

Fix: 2022+
Fix from $1,950 2024-09-12
Endpoint Manager HIGH 8.8
CVE-2024-8322

Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access …

Fix: 2022+
Fix from $1,950 2024-09-10
Endpoint Manager HIGH 8.6
CVE-2024-8321

Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to i…

Fix: 2022+
Fix from $1,950 2024-09-10
Endpoint Manager MEDIUM 6.7
CVE-2024-8441

An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin…

Fix: 2022+
Fix from $1,600 2024-09-10
Endpoint Manager MEDIUM 5.3
CVE-2024-8320

Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to s…

Fix: 2022+
Fix from $1,600 2024-09-10
Endpoint Manager CRITICAL 9.8
CVE-2024-8191EPSS 20%

SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achie…

Fix: 2022+
Fix from $2,300 2024-09-10
Workspace Control HIGH 7.8
CVE-2024-44106

Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticate…

Fix: 10.18.99.0+
Fix from $1,950 2024-09-10
Workspace Control HIGH 7.8
CVE-2024-44107

DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escala…

Fix: 10.18.99.0+
Fix from $1,950 2024-09-10
Workspace Control HIGH 7.8
CVE-2024-8012

An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenti…

Fix: 10.18.99.0+
Fix from $1,950 2024-09-10
Cloud Services Appliance HIGH 7.2
CVE-2024-8190 KEVEPSS 89%

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to …

Mitigation only
Fix from $1,950 2024-09-10
Workspace Control HIGH 7.8
CVE-2024-44103

DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escala…

Fix: 10.18.99.0+
Fix from $1,950 2024-09-10
Workspace Control HIGH 7.8
CVE-2024-44104

An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before …

Fix: 10.18.99.0+
Fix from $1,950 2024-09-10
Workspace Control HIGH 7.8
CVE-2024-44105

Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a loc…

Fix: 10.18.99.0+
Fix from $1,950 2024-09-10
Avalanche CRITICAL 9.1
CVE-2024-38652EPSS 8%

Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via a…

Mitigation only
Fix from $2,300 2024-08-14