Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2022-35254
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R1…
Connect Secure
9.1+
HIGH 7.5
CVE-2022-35258
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R1…
Connect Secure
9.1+
MEDIUM 5.4
CVE-2022-21826EPSS 45%
Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignor…
Connect Secure
9.1+
MEDIUM 6.7
CVE-2022-30121
The “LANDesk(R) Management Agent” service exposes a socket and once connected, it is possible to launch commands only for signed executables. This is…
Endpoint Manager
2021.1.1+
HIGH 7.2
CVE-2021-44720
In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > P…
Connect Secure
9.1+
HIGH 8.8
CVE-2022-22572
A non-admin user with user management permission can escalate his privilege to admin user via password reset functionality. The vulnerability affects…
Incapptic Connect
1.40.2+
HIGH 7.8
CVE-2022-27088
Ivanti DSM Remote <= 6.3.1.1862 is vulnerable to an unquoted service path allowing local users to launch processes with elevated privileges.
Dsm Remote
after 6.3.1.1862
HIGH 7.5
CVE-2021-30497EPSS 97%
Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter…
Avalanche
Patch available
HIGH 7.2
CVE-2022-21828
A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified …
Incapptic Connect
No fix yet
MEDIUM 6.1
CVE-2021-38560
Ivanti Service Manager 2021.1 allows reflected XSS via the appName parameter associated with ConfigDB calls, such as in RelocateAttachments.aspx.
Service Manager
Patch available
MEDIUM 5.5
CVE-2022-21823
A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with lo…
Workspace Control
10.7.30.0+
HIGH 7.5
CVE-2019-19138
Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity.
Workspace Control
10.4.50.0+
CRITICAL 9.8
CVE-2021-44529 KEVEPSS 99%
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited…
Endpoint Manager Cloud Services Appliance
after 4.5
CRITICAL 9.8
CVE-2021-42127EPSS 66%
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via …
Avalanche
6.3.3+
CRITICAL 9.8
CVE-2021-42128
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise…
Avalanche
6.3.3+
HIGH 8.8
CVE-2021-42124
An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a …
Avalanche
6.3.3+
HIGH 8.8
CVE-2021-42125EPSS 82%
An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dan…
Avalanche
6.3.3+
HIGH 8.8
CVE-2021-42126
An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to per…
Avalanche
6.3.3+
HIGH 8.8
CVE-2021-42129EPSS 77%
A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary…
Avalanche
6.3.3+
HIGH 8.8
CVE-2021-42130EPSS 62%
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to p…
Avalanche
6.3.3+
HIGH 8.8
CVE-2021-42131EPSS 67%
A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege esca…
Avalanche
6.3.3+
HIGH 8.8
CVE-2021-42132EPSS 70%
A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary…
Avalanche
6.3.3+
HIGH 8.1
CVE-2021-42133
An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform…
Avalanche
6.3.3+
HIGH 7.5
CVE-2021-22965
A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed r…
Connect Secure
9.1+
HIGH 7.8
CVE-2021-36235
An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges can bypass File and Folder Sec…
Workspace Control
10.6.30.0+
HIGH 7.2
CVE-2021-22934
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or compromised Pulse Connect Secure device in a load…
Connect Secure
9.1+
HIGH 7.2
CVE-2021-22935
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web …
Connect Secure
9.1+
HIGH 7.2
CVE-2021-22937EPSS 8%
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted ar…
Connect Secure
9.1+
HIGH 7.2
CVE-2021-22938
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web …
Connect Secure
9.1+
MEDIUM 6.5
CVE-2021-22933
A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciousl…
Connect Secure
9.1+