Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2023-46222EPSS 7% An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service … Avalanche 6.4.2+ Fix from $2,3002023-12-19 CRITICAL 9.8 CVE-2023-46223EPSS 7% An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service … Avalanche 6.4.2+ Fix from $2,3002023-12-19 CRITICAL 9.8 CVE-2023-41727EPSS 36% An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service … Avalanche 6.4.2+ Fix from $2,3002023-12-19 CRITICAL 9.1 CVE-2021-22962EPSS 91% An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Avalanche 6.4.2+ Fix from $2,3002023-12-19 HIGH 7.5 CVE-2023-39340 A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker can send a specific request which may lead to Denial o… Connect Secure No fix yet Fix from $1,9502023-12-16 HIGH 7.8 CVE-2023-41720 A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appl… Connect Secure Mitigation only Fix from $1,9502023-12-14 HIGH 7.2 CVE-2023-41719 A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a specific we… Connect Secure Mitigation only Fix from $1,9502023-12-14 CRITICAL 9.8 CVE-2023-39335 A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate … Endpoint Manager Mobile 11.9.0 / 11.10.0.4+ Fix from $2,3002023-11-15 CRITICAL 9.1 CVE-2023-39337 A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access … Endpoint Manager Mobile 11.10.0.4 / 11.11.0.2+ Fix from $2,3002023-11-15 HIGH 7.8 CVE-2023-38543 A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to explo… Secure Access Client 22.6+ Fix from $1,9502023-11-15 HIGH 7.8 CVE-2023-41718 When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having cont… Secure Access Client No fix yet Fix from $1,9502023-11-15 MEDIUM 5.5 CVE-2023-38544 A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be e… Secure Access Client Mitigation only Fix from $1,6002023-11-15 HIGH 7.8 CVE-2023-35080 A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulne… Secure Access Client 22.6+ Fix from $1,9502023-11-15 HIGH 7.8 CVE-2023-38043 A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to explo… Secure Access Client 22.6+ Fix from $1,9502023-11-15 HIGH 7.8 CVE-2023-41725 Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability Avalanche 6.4.1.236+ Fix from $1,9502023-11-03 HIGH 7.8 CVE-2023-41726 Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability Avalanche 6.4.1.236+ Fix from $1,9502023-11-03 HIGH 7.8 CVE-2022-43554 Ivanti Avalanche Smart Device Service Missing Authentication Local Privilege Escalation Vulnerability Avalanche 6.4.1.236+ Fix from $1,9502023-11-03 HIGH 7.8 CVE-2022-43555 Ivanti Avalanche Printer Device Service Missing Authentication Local Privilege Escalation Vulnerability Avalanche 6.4.1.236+ Fix from $1,9502023-11-03 HIGH 7.8 CVE-2022-44569 A locally authenticated attacker with low privileges can bypass authentication due to insecure inter-process communication. Automation 2023.4+ Fix from $1,9502023-11-03 HIGH 7.0 CVE-2023-38041 A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is ini… Secure Access Client 22.6+ Fix from $1,9502023-10-25 CRITICAL 9.8 CVE-2023-35084 Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions… Endpoint Manager 2022+ Fix from $2,3002023-10-18 MEDIUM 6.5 CVE-2023-35083 Allows an authenticated attacker with network access to read arbitrary files on Endpoint Manager recently discovered on 2022 SU3 and all previous ver… Endpoint Manager 2022+ Fix from $1,6002023-10-18 MEDIUM 6.5 CVE-2023-38344 An issue was discovered in Ivanti Endpoint Manager before 2022 SU4. A file disclosure vulnerability exists in the GetFileContents SOAP action exposed… Endpoint Manager 2022+ Fix from $1,6002023-09-21 HIGH 7.5 CVE-2023-38343 An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity referen… Endpoint Manager 2022+ Fix from $1,9502023-09-21 CRITICAL 9.8 CVE-2023-38035 KEVEPSS 100% A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentica… Mobileiron Sentry after 9.18.0 Fix from $2,3002023-08-21 CRITICAL 9.8 CVE-2023-35082 KEVEPSS 100% An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of t… Endpoint Manager Mobile 11.11.0+ Fix from $2,3002023-08-15 CRITICAL 9.8 CVE-2023-32560EPSS 99% An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execut… Avalanche 6.4.1+ Fix from $2,3002023-08-10 CRITICAL 9.8 CVE-2023-32562EPSS 46% An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve… Avalanche 6.4.1+ Fix from $2,3002023-08-10 CRITICAL 9.8 CVE-2023-32563EPSS 89% An unauthenticated attacker could achieve the code execution through a RemoteControl server. Avalanche 6.4.1+ Fix from $2,3002023-08-10 CRITICAL 9.8 CVE-2023-32564EPSS 44% An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve… Avalanche 6.4.1+ Fix from $2,3002023-08-10