Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Endpoint Manager Mobile MEDIUM 6.7
CVE-2024-22026

A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitra…

Fix: 12.1.0.0+
Fix from $1,600 2024-05-22
Pulse Secure Desktop Client HIGH 7.8
CVE-2023-34298

Pulse Secure Client SetupService Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate …

Fix: 9.1+
Fix from $1,950 2024-05-03
Avalanche HIGH 7.5
CVE-2024-23527

An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthentica…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-25
Avalanche CRITICAL 9.8
CVE-2024-29204

A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute ar…

Fix: 6.4.3.528+
Fix from $2,300 2024-04-19
Avalanche HIGH 8.8
CVE-2024-27975

An Use-after-free vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute ar…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 8.8
CVE-2024-27976

A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 8.1
CVE-2024-27977

A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete arbitrary files, th…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 7.1
CVE-2024-27984

A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete specific type of fi…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche MEDIUM 6.5
CVE-2024-27978

A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to …

Fix: 6.4.3.528+
Fix from $1,600 2024-04-19
Avalanche CRITICAL 9.8
CVE-2024-24996EPSS 32%

A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute ar…

Fix: 6.4.3.528+
Fix from $2,300 2024-04-19
Avalanche HIGH 8.8
CVE-2024-24997

A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 8.8
CVE-2024-24998

A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 8.8
CVE-2024-24999

A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 8.8
CVE-2024-25000

A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 7.5
CVE-2024-24995

A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 8.8
CVE-2024-23534

An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitra…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 8.8
CVE-2024-23535EPSS 68%

A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 8.8
CVE-2024-24992EPSS 71%

A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 8.8
CVE-2024-24994EPSS 68%

A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 7.5
CVE-2024-24993

A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche MEDIUM 6.5
CVE-2024-24991

A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to …

Fix: 6.4.3.528+
Fix from $1,600 2024-04-19
Avalanche HIGH 7.5
CVE-2024-23526

An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthentica…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 7.5
CVE-2024-23528

An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthentica…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 7.5
CVE-2024-23529

An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthentica…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 7.5
CVE-2024-23530

An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthentica…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 7.5
CVE-2024-23531

An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perfor…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche HIGH 7.5
CVE-2024-23532

An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perfo…

Fix: 6.4.3.528+
Fix from $1,950 2024-04-19
Avalanche MEDIUM 6.5
CVE-2024-23533

An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticate…

Fix: 6.4.3.528+
Fix from $1,600 2024-04-19
Avalanche CRITICAL 9.8
CVE-2024-22061

A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arb…

Fix: 6.4.3.528+
Fix from $2,300 2024-04-19
Connect Secure CRITICAL 9.8
CVE-2024-21894EPSS 19%

A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious us…

Mitigation only
Fix from $2,300 2024-04-04