Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2025-5462
A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8…
Connect Secure
22.7 / 22.8+
MEDIUM 5.7
CVE-2024-38648
A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user crede…
Desktop \& Server Management
2024.2+
CRITICAL 9.8
CVE-2023-38036
A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overflow that …
Avalanche
6.4.1+
HIGH 7.2
CVE-2025-6771EPSS 17%
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker w…
Endpoint Manager Mobile
12.3.0.3 / 12.4.0.3+
MEDIUM 5.5
CVE-2025-5464
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authenticated attacker to obtain t…
Connect Secure
22.7+
HIGH 7.2
CVE-2025-7037
SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin pri…
Endpoint Manager
2022+
HIGH 8.4
CVE-2025-6995
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticate…
Endpoint Manager
2022+
HIGH 8.4
CVE-2025-6996
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticate…
Endpoint Manager
2022+
HIGH 7.2
CVE-2025-6770EPSS 16%
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to …
Endpoint Manager Mobile
12.3.0.3 / 12.4.0.3+
MEDIUM 5.5
CVE-2025-5463
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 …
Connect Secure
22.7+
HIGH 7.8
CVE-2025-5353
A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials.
Workspace Control
10.19.10.0+
HIGH 7.8
CVE-2025-22455
A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentials.
Workspace Control
10.19.10.0+
HIGH 7.3
CVE-2025-22463
A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment passwor…
Workspace Control
10.19.10.0+
HIGH 8.8
CVE-2025-4428 KEVEPSS 86%
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers t…
Endpoint Manager Mobile
11.12.0.5 / 12.3.0.2+
HIGH 7.5
CVE-2025-4427 KEVEPSS 100%
An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources wit…
Endpoint Manager Mobile
11.12.0.5 / 12.3.0.2+
CRITICAL 9.8
CVE-2025-22462
An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote …
Neurons For Itsm
2023.4+
HIGH 7.8
CVE-2025-22460
Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.
Cloud Services Appliance
5.0.5+
CRITICAL 9.6
CVE-2025-22466
Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtain admin …
Endpoint Manager
2022+
HIGH 7.2
CVE-2025-22461
SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privile…
Endpoint Manager
2022+
MEDIUM 6.1
CVE-2025-22464
An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with …
Endpoint Manager
2022+
MEDIUM 6.1
CVE-2025-22465
Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbit…
Endpoint Manager
2022+
HIGH 7.8
CVE-2025-22458
DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.
Endpoint Manager
2022+
CRITICAL 9.8
CVE-2025-22457 KEVEPSS 100%
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways…
Connect Secure
22.7 / 22.8+
HIGH 7.8
CVE-2025-22454
Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privilege…
Secure Access Client
22.7+
HIGH 8.8
CVE-2025-22467
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code executio…
Connect Secure
after 22.7
HIGH 7.2
CVE-2024-47908EPSS 22%
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achi…
Cloud Services Appliance
5.0.5+
HIGH 7.1
CVE-2024-13813
Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files.
Secure Access Client
22.8+
MEDIUM 6.1
CVE-2024-13830
Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attac…
Connect Secure
22.7+
HIGH 7.2
CVE-2024-10644
Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attack…
Connect Secure
22.7+
MEDIUM 5.3
CVE-2024-11771
Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality.
Cloud Services Appliance
5.0.5+