Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-62388 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62389 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62390 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62391 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62392 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62383 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62384 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62385 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62386 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-62387 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 MEDIUM 6.5 CVE-2025-11623 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002025-10-13 HIGH 8.8 CVE-2025-9713EPSS 15% Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User int… Endpoint Manager 2024+ Fix from $1,9502025-10-13 HIGH 7.8 CVE-2025-11622 Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges. Endpoint Manager 2024+ Fix from $1,9502025-10-13 HIGH 8.8 CVE-2025-55147 CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neuro… Connect Secure 22.7 / 22.8+ Fix from $1,9502025-09-09 HIGH 8.8 CVE-2025-9712EPSS 21% Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve … Endpoint Manager 2022+ Fix from $1,9502025-09-09 HIGH 8.8 CVE-2025-9872EPSS 14% Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve … Endpoint Manager 2022+ Fix from $1,9502025-09-09 HIGH 7.6 CVE-2025-55148 Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723… Connect Secure 22.7 / 22.8+ Fix from $1,9502025-09-09 MEDIUM 5.4 CVE-2025-8711 CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neuro… Connect Secure 22.7 / 22.8+ Fix from $1,6002025-09-09 MEDIUM 5.4 CVE-2025-8712 Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 22.8R2.3-72… Neurons For Secure Access 22.7 / 22.8+ Fix from $1,6002025-09-09 HIGH 8.9 CVE-2025-55145 Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723… Neurons For Secure Access 22.7 / 22.8+ Fix from $1,9502025-09-09 HIGH 8.8 CVE-2025-55142 Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723… Connect Secure 22.7 / 22.8+ Fix from $1,9502025-09-09 MEDIUM 6.1 CVE-2025-55143 Reflected text injection in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-… Connect Secure 22.7 / 22.8+ Fix from $1,6002025-09-09 MEDIUM 5.4 CVE-2025-55144 Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723… Connect Secure 22.7 / 22.8+ Fix from $1,6002025-09-09 HIGH 8.8 CVE-2025-55141 Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723… Connect Secure 22.7 / 22.8+ Fix from $1,9502025-09-09 MEDIUM 6.8 CVE-2025-55139 SSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neuro… Connect Secure 22.7 / 22.8+ Fix from $1,6002025-09-09 HIGH 8.8 CVE-2025-8310 Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attack… Virtual Application Delivery Controller 22.9+ Fix from $1,9502025-08-12 HIGH 7.2 CVE-2025-8296 SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL que… Avalanche 6.4.8.8008+ Fix from $1,9502025-08-12 HIGH 7.2 CVE-2025-8297 Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to… Avalanche 6.4.8.8008+ Fix from $1,9502025-08-12 MEDIUM 5.5 CVE-2025-5468 Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gate… Connect Secure 22.7 / 22.8+ Fix from $1,6002025-08-12 HIGH 7.5 CVE-2025-5456 A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before … Connect Secure 22.7 / 22.8+ Fix from $1,9502025-08-12