Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2024-7572 Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files. Desktop \& Server Management 2024.3.5740+ Fix from $1,9502024-12-10 MEDIUM 5.5 CVE-2024-8540 Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive applicatio… Standalone Sentry 9.20.2+ Fix from $1,6002024-12-10 CRITICAL 9.8 CVE-2024-11639 An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access Cloud Services Appliance 5.0.3+ Fix from $2,3002024-12-10 HIGH 7.2 CVE-2024-11633 Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote co… Connect Secure 22.7+ Fix from $1,9502024-12-10 HIGH 7.2 CVE-2024-11634 Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated att… Connect Secure 22.7+ Fix from $1,9502024-12-10 HIGH 7.2 CVE-2024-11772EPSS 8% Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve… Cloud Services Appliance 5.0.3+ Fix from $1,9502024-12-10 HIGH 7.2 CVE-2024-11773EPSS 24% SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitra… Cloud Services Appliance 5.0.3+ Fix from $1,9502024-12-10 HIGH 7.1 CVE-2024-10256 Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files. Endpoint Manager 9.7.703 / 2024.4+ Fix from $1,9502024-12-10 CRITICAL 9.1 CVE-2024-39710 Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote aut… Connect Secure 22.7+ Fix from $2,3002024-11-13 CRITICAL 9.1 CVE-2024-39711 Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote au… Connect Secure 22.7+ Fix from $2,3002024-11-13 CRITICAL 9.1 CVE-2024-39712 Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote aut… Connect Secure 22.7+ Fix from $2,3002024-11-13 CRITICAL 9.1 CVE-2024-38656 Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote aut… Connect Secure 22.7+ Fix from $2,3002024-11-13 HIGH 7.8 CVE-2024-37398 Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. Secure Access Client 22.7+ Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-39709 Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (N… Connect Secure 9.1 / 22.6+ Fix from $1,9502024-11-13 HIGH 7.5 CVE-2024-37400 An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigger an infinite loop, causing … Connect Secure 22.7+ Fix from $1,9502024-11-13 HIGH 7.5 CVE-2024-38649 An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1(Not Applicable to 9.1Rx) allows a remote unauthenticated attacker to… Connect Secure 9.1 / 22.7+ Fix from $1,9502024-11-13 HIGH 7.2 CVE-2024-38655 Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows… Connect Secure 22.7+ Fix from $1,9502024-11-13 HIGH 7.8 CVE-2024-34787EPSS 18% Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated at… Endpoint Manager 2022+ Fix from $1,9502024-11-13 HIGH 7.2 CVE-2024-34780 SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta… Endpoint Manager 2022+ Fix from $1,9502024-11-13 HIGH 7.2 CVE-2024-34781EPSS 68% SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta… Endpoint Manager 2022+ Fix from $1,9502024-11-13 HIGH 7.2 CVE-2024-34782 SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta… Endpoint Manager 2022+ Fix from $1,9502024-11-13 HIGH 7.2 CVE-2024-34784 SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta… Endpoint Manager 2022+ Fix from $1,9502024-11-13 HIGH 7.2 CVE-2024-37376 SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta… Endpoint Manager 2022+ Fix from $1,9502024-11-13 HIGH 7.2 CVE-2024-32839 SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta… Endpoint Manager 2022+ Fix from $1,9502024-11-13 HIGH 7.2 CVE-2024-32841 SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta… Endpoint Manager 2022+ Fix from $1,9502024-11-13 HIGH 7.2 CVE-2024-32844 SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta… Endpoint Manager 2022+ Fix from $1,9502024-11-13 HIGH 7.2 CVE-2024-32847 SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta… Endpoint Manager 2022+ Fix from $1,9502024-11-13 HIGH 7.1 CVE-2024-8539 Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration f… Secure Access Client 22.7+ Fix from $1,9502024-11-12 MEDIUM 5.5 CVE-2024-9843 A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service. Secure Access Client 22.7+ Fix from $1,6002024-11-12 HIGH 7.8 CVE-2024-7571 Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. Secure Access Client 22.7+ Fix from $1,9502024-11-12