Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2024-11005 Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Ap… Connect Secure 9.1 / 22.7+ Fix from $1,9502024-11-12 HIGH 7.2 CVE-2024-11006 Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Ap… Connect Secure 9.1 / 22.7+ Fix from $1,9502024-11-12 MEDIUM 6.1 CVE-2024-11004 Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attac… Connect Secure 22.7+ Fix from $1,6002024-11-12 HIGH 8.8 CVE-2024-9420 A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote aut… Connect Secure 9.1 / 22.7+ Fix from $1,9502024-11-12 HIGH 7.5 CVE-2024-8495 A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthen… Connect Secure 22.7+ Fix from $1,9502024-11-12 CRITICAL 9.8 CVE-2024-50330EPSS 40% SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated at… Endpoint Manager 2022+ Fix from $2,3002024-11-12 HIGH 8.8 CVE-2024-50329 Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated a… Endpoint Manager 2022+ Fix from $1,9502024-11-12 HIGH 7.5 CVE-2024-50331 An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory. Avalanche 6.4.6+ Fix from $1,9502024-11-12 HIGH 7.2 CVE-2024-50327 SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta… Endpoint Manager 2022+ Fix from $1,9502024-11-12 HIGH 7.2 CVE-2024-50328 SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta… Endpoint Manager 2022+ Fix from $1,9502024-11-12 HIGH 7.8 CVE-2024-50322EPSS 6% Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated at… Endpoint Manager 2022+ Fix from $1,9502024-11-12 HIGH 7.8 CVE-2024-50323 SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated att… Endpoint Manager 2022+ Fix from $1,9502024-11-12 HIGH 7.5 CVE-2024-50321 An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service. Avalanche 6.4.6+ Fix from $1,9502024-11-12 HIGH 7.2 CVE-2024-50324EPSS 19% Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated att… Endpoint Manager 2022+ Fix from $1,9502024-11-12 HIGH 7.2 CVE-2024-50326EPSS 26% SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated atta… Endpoint Manager 2022+ Fix from $1,9502024-11-12 HIGH 7.5 CVE-2024-50317 A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service. Avalanche 6.4.6+ Fix from $1,9502024-11-12 HIGH 7.5 CVE-2024-50318 A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service. Avalanche 6.4.6+ Fix from $1,9502024-11-12 HIGH 7.5 CVE-2024-50319 An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service. Avalanche 6.4.6+ Fix from $1,9502024-11-12 HIGH 7.5 CVE-2024-50320EPSS 40% An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service. Avalanche 6.4.6+ Fix from $1,9502024-11-12 HIGH 7.8 CVE-2024-47906 Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1… Connect Secure 9.1 / 22.7+ Fix from $1,9502024-11-12 HIGH 7.5 CVE-2024-47907 A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of… Connect Secure 22.7+ Fix from $1,9502024-11-12 HIGH 7.2 CVE-2024-11007 Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Ap… Connect Secure 22.7+ Fix from $1,9502024-11-12 HIGH 8.8 CVE-2024-37404EPSS 70% Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a… Connect Secure 9.1 / 22.7+ Fix from $1,9502024-10-18 HIGH 7.8 CVE-2024-29213 Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified … Desktop \& Server Management 2024.2+ Fix from $1,9502024-10-18 HIGH 7.8 CVE-2024-29821 Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified … Desktop \& Server Management 2024.2+ Fix from $1,9502024-10-18 HIGH 7.2 CVE-2024-9381EPSS 16% Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions. Endpoint Manager Cloud Services Appliance 5.0.2+ Fix from $1,9502024-10-08 HIGH 7.8 CVE-2024-9167 Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achi… Velocity License Server 5.2+ Fix from $1,9502024-10-08 HIGH 7.2 CVE-2024-9379 KEVEPSS 43% SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitra… Endpoint Manager Cloud Services Appliance 5.0.2+ Fix from $1,9502024-10-08 HIGH 7.2 CVE-2024-9380 KEVEPSS 63% An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin p… Endpoint Manager Cloud Services Appliance 5.0.2+ Fix from $1,9502024-10-08 CRITICAL 9.8 CVE-2024-47010EPSS 38% Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication. Avalanche 6.4.5+ Fix from $2,3002024-10-08