Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2025-5462 A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8… Connect Secure 22.7 / 22.8+ Fix from $1,9502025-08-12 MEDIUM 5.7 CVE-2024-38648 A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user crede… Desktop \& Server Management 2024.2+ Fix from $1,6002025-07-12 CRITICAL 9.8 CVE-2023-38036 A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overflow that … Avalanche 6.4.1+ Fix from $2,3002025-07-12 HIGH 7.2 CVE-2025-6771EPSS 17% OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker w… Endpoint Manager Mobile 12.3.0.3 / 12.4.0.3+ Fix from $1,9502025-07-08 MEDIUM 5.5 CVE-2025-5464 Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authenticated attacker to obtain t… Connect Secure 22.7+ Fix from $1,6002025-07-08 HIGH 7.2 CVE-2025-7037 SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin pri… Endpoint Manager 2022+ Fix from $1,9502025-07-08 HIGH 8.4 CVE-2025-6995 Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticate… Endpoint Manager 2022+ Fix from $1,9502025-07-08 HIGH 8.4 CVE-2025-6996 Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticate… Endpoint Manager 2022+ Fix from $1,9502025-07-08 HIGH 7.2 CVE-2025-6770EPSS 16% OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to … Endpoint Manager Mobile 12.3.0.3 / 12.4.0.3+ Fix from $1,9502025-07-08 MEDIUM 5.5 CVE-2025-5463 Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 … Connect Secure 22.7+ Fix from $1,6002025-07-08 HIGH 7.8 CVE-2025-5353 A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials. Workspace Control 10.19.10.0+ Fix from $1,9502025-06-10 HIGH 7.8 CVE-2025-22455 A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentials. Workspace Control 10.19.10.0+ Fix from $1,9502025-06-10 HIGH 7.3 CVE-2025-22463 A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment passwor… Workspace Control 10.19.10.0+ Fix from $1,9502025-06-10 HIGH 8.8 CVE-2025-4428 KEVEPSS 86% Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers t… Endpoint Manager Mobile 11.12.0.5 / 12.3.0.2+ Fix from $1,9502025-05-13 HIGH 7.5 CVE-2025-4427 KEVEPSS 100% An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources wit… Endpoint Manager Mobile 11.12.0.5 / 12.3.0.2+ Fix from $1,9502025-05-13 CRITICAL 9.8 CVE-2025-22462 An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote … Neurons For Itsm 2023.4+ Fix from $2,3002025-05-13 HIGH 7.8 CVE-2025-22460 Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges. Cloud Services Appliance 5.0.5+ Fix from $1,9502025-05-13 CRITICAL 9.6 CVE-2025-22466 Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtain admin … Endpoint Manager 2022+ Fix from $2,3002025-04-08 HIGH 7.2 CVE-2025-22461 SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privile… Endpoint Manager 2022+ Fix from $1,9502025-04-08 MEDIUM 6.1 CVE-2025-22464 An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with … Endpoint Manager 2022+ Fix from $1,6002025-04-08 MEDIUM 6.1 CVE-2025-22465 Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbit… Endpoint Manager 2022+ Fix from $1,6002025-04-08 HIGH 7.8 CVE-2025-22458 DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System. Endpoint Manager 2022+ Fix from $1,9502025-04-08 CRITICAL 9.8 CVE-2025-22457 KEVEPSS 100% A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways… Connect Secure 22.7 / 22.8+ Fix from $2,3002025-04-03 HIGH 7.8 CVE-2025-22454 Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privilege… Secure Access Client 22.7+ Fix from $1,9502025-03-11 HIGH 8.8 CVE-2025-22467 A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code executio… Connect Secure after 22.7 Fix from $1,9502025-02-11 HIGH 7.2 CVE-2024-47908EPSS 22% OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achi… Cloud Services Appliance 5.0.5+ Fix from $1,9502025-02-11 HIGH 7.1 CVE-2024-13813 Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files. Secure Access Client 22.8+ Fix from $1,9502025-02-11 MEDIUM 6.1 CVE-2024-13830 Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attac… Connect Secure 22.7+ Fix from $1,6002025-02-11 HIGH 7.2 CVE-2024-10644 Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attack… Connect Secure 22.7+ Fix from $1,9502025-02-11 MEDIUM 5.3 CVE-2024-11771 Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality. Cloud Services Appliance 5.0.5+ Fix from $1,6002025-02-11