Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Avalanche HIGH 7.5
CVE-2024-38653EPSS 92%

XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

Mitigation only
Fix from $1,950 2024-08-14
Avalanche HIGH 7.5
CVE-2024-36136

An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.

Mitigation only
Fix from $1,950 2024-08-14
Avalanche HIGH 7.5
CVE-2024-37399EPSS 28%

A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting i…

Mitigation only
Fix from $1,950 2024-08-14
Avalanche HIGH 7.2
CVE-2024-37373

Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.

Mitigation only
Fix from $1,950 2024-08-14
Neurons For Itsm CRITICAL 9.8
CVE-2024-7569

An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to…

Patch available
Fix from $2,300 2024-08-13
Virtual Traffic Manager CRITICAL 9.8
CVE-2024-7593 KEVEPSS 100%

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker t…

Patch available
Fix from $2,300 2024-08-13
Neurons For Itsm HIGH 8.1
CVE-2024-7570

Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position t…

Patch available
Fix from $1,950 2024-08-13
Endpoint Manager Mobile HIGH 8.8
CVE-2024-36131

An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary com…

Fix: 12.1.0.1+
Fix from $1,950 2024-08-07
Endpoint Manager Mobile HIGH 7.5
CVE-2024-36132

Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive…

Fix: 12.1.0.1+
Fix from $1,950 2024-08-07
Docs\@work MEDIUM 5.5
CVE-2024-37403

Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, r…

Fix: 2.26.0+
Fix from $1,600 2024-08-07
Endpoint Manager Mobile CRITICAL 9.8
CVE-2024-36130

An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute …

Fix: 12.1.0.1+
Fix from $2,300 2024-08-07
Endpoint Manager Mobile MEDIUM 6.5
CVE-2024-34788

An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive in…

Fix: 12.1.0.1+
Fix from $1,600 2024-08-07
Endpoint Manager HIGH 8.0
CVE-2024-37381

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute…

Mitigation only
Fix from $1,950 2024-07-29
Endpoint Manager HIGH 8.0
CVE-2024-29829EPSS 8%

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network t…

Fix: 2022+
Fix from $1,950 2024-05-31
Endpoint Manager HIGH 8.0
CVE-2024-29830EPSS 8%

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network t…

Fix: 2022+
Fix from $1,950 2024-05-31
Endpoint Manager HIGH 8.0
CVE-2024-29846EPSS 8%

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network t…

Fix: 2022+
Fix from $1,950 2024-05-31
Avalanche HIGH 7.2
CVE-2024-29848EPSS 64%

An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbit…

Fix: 6.4.3.602+
Fix from $1,950 2024-05-31
Endpoint Manager HIGH 8.8
CVE-2024-29823EPSS 100%

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network…

Fix: 2022+
Fix from $1,950 2024-05-31
Endpoint Manager HIGH 8.8
CVE-2024-29824 KEVEPSS 100%

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network…

Fix: 2022+
Fix from $1,950 2024-05-31
Endpoint Manager HIGH 8.8
CVE-2024-29825EPSS 100%

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network…

Fix: 2022+
Fix from $1,950 2024-05-31
Endpoint Manager HIGH 8.8
CVE-2024-29826EPSS 100%

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network…

Fix: 2022+
Fix from $1,950 2024-05-31
Endpoint Manager HIGH 8.8
CVE-2024-29827EPSS 72%

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network…

Fix: 2022+
Fix from $1,950 2024-05-31
Endpoint Manager HIGH 8.0
CVE-2024-29828EPSS 8%

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network t…

Fix: 2022+
Fix from $1,950 2024-05-31
Neurons For Itsm HIGH 8.8
CVE-2024-22059

A SQL injection vulnerability in web component of Ivanti Neurons for ITSM allows a remote authenticated user to read/modify/delete information in the…

Fix: 2023.3+
Fix from $1,950 2024-05-31
Endpoint Manager HIGH 8.8
CVE-2024-29822EPSS 64%

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network…

Fix: 2022+
Fix from $1,950 2024-05-31
Endpoint Manager HIGH 7.8
CVE-2024-22058

A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated permissio…

Fix: after 2021.1
Fix from $1,950 2024-05-31
Secure Access Client HIGH 7.8
CVE-2023-38042

A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.

Fix: 22.7+
Fix from $1,950 2024-05-31
Secure Access Client HIGH 7.3
CVE-2023-46810

A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as ro…

Fix: 22.7+
Fix from $1,950 2024-05-31
Endpoint Manager Mobile MEDIUM 6.7
CVE-2023-46806

An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access …

Fix: 12.1.0.0+
Fix from $1,600 2024-05-22
Endpoint Manager Mobile MEDIUM 6.7
CVE-2023-46807

An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify d…

Fix: 12.1.0.0+
Fix from $1,600 2024-05-22