Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2023-46222EPSS 7%
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …
Avalanche
6.4.2+
CRITICAL 9.8
CVE-2023-46223EPSS 7%
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …
Avalanche
6.4.2+
CRITICAL 9.8
CVE-2023-41727EPSS 36%
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service …
Avalanche
6.4.2+
CRITICAL 9.1
CVE-2021-22962EPSS 91%
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.
Avalanche
6.4.2+
HIGH 7.5
CVE-2023-39340
A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker can send a specific request which may lead to Denial o…
Connect Secure
No fix yet
HIGH 7.8
CVE-2023-41720
A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appl…
Connect Secure
Mitigation only
HIGH 7.2
CVE-2023-41719
A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a specific we…
Connect Secure
Mitigation only
CRITICAL 9.8
CVE-2023-39335
A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate …
Endpoint Manager Mobile
11.9.0 / 11.10.0.4+
CRITICAL 9.1
CVE-2023-39337
A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access …
Endpoint Manager Mobile
11.10.0.4 / 11.11.0.2+
HIGH 7.8
CVE-2023-38543
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to explo…
Secure Access Client
22.6+
HIGH 7.8
CVE-2023-41718
When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having cont…
Secure Access Client
No fix yet
MEDIUM 5.5
CVE-2023-38544
A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be e…
Secure Access Client
Mitigation only
HIGH 7.8
CVE-2023-35080
A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulne…
Secure Access Client
22.6+
HIGH 7.8
CVE-2023-38043
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to explo…
Secure Access Client
22.6+
HIGH 7.8
CVE-2023-41725
Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability
Avalanche
6.4.1.236+
HIGH 7.8
CVE-2023-41726
Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability
Avalanche
6.4.1.236+
HIGH 7.8
CVE-2022-43554
Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability
Avalanche
6.4.1.236+
HIGH 7.8
CVE-2022-43555
Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability
Avalanche
6.4.1.236+
HIGH 7.8
CVE-2022-44569
A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication.
Automation
2023.4+
HIGH 7.0
CVE-2023-38041
A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is ini…
Secure Access Client
22.6+
CRITICAL 9.8
CVE-2023-35084
Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions…
Endpoint Manager
2022+
MEDIUM 6.5
CVE-2023-35083
Allows an authenticated attacker with network access to read arbitrary files on Endpoint Manager recently discovered on 2022 SU3 and all previous ver…
Endpoint Manager
2022+
MEDIUM 6.5
CVE-2023-38344
An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFileContents SOAP action exposed…
Endpoint Manager
2022+
HIGH 7.5
CVE-2023-38343
An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity referen…
Endpoint Manager
2022+
CRITICAL 9.8
CVE-2023-38035 KEVEPSS 100%
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentica…
Mobileiron Sentry
after 9.18.0
CRITICAL 9.8
CVE-2023-35082 KEVEPSS 100%
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of t…
Endpoint Manager Mobile
11.11.0+
CRITICAL 9.8
CVE-2023-32560EPSS 99%
An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execut…
Avalanche
6.4.1+
CRITICAL 9.8
CVE-2023-32562EPSS 46%
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve…
Avalanche
6.4.1+
CRITICAL 9.8
CVE-2023-32563EPSS 89%
An unauthenticated attacker could achieve the code execution through a RemoteControl server.
Avalanche
6.4.1+
CRITICAL 9.8
CVE-2023-32564EPSS 44%
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve…
Avalanche
6.4.1+