Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.8
CVE-2024-7612
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.
Endpoint Manager Mobile
12.0.0.5 / 12.1.0.4+
HIGH 7.5
CVE-2024-47011EPSS 56%
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information
Avalanche
6.4.5+
CRITICAL 9.8
CVE-2024-47009
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
Avalanche
6.4.5+
HIGH 7.5
CVE-2024-47007
A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a den…
Avalanche
6.4.5+
HIGH 7.5
CVE-2024-47008EPSS 47%
Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.
Avalanche
6.4.5+
CRITICAL 9.1
CVE-2024-8963 KEVEPSS 99%
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
Endpoint Manager Cloud Services Appliance
Mitigation only
HIGH 8.2
CVE-2024-37397EPSS 59%
An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remot…
Endpoint Manager
2022+
HIGH 7.2
CVE-2024-32848EPSS 43%
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…
Endpoint Manager
2022+
HIGH 7.2
CVE-2024-34779EPSS 24%
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…
Endpoint Manager
2022+
HIGH 7.2
CVE-2024-34783EPSS 43%
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…
Endpoint Manager
2022+
HIGH 7.2
CVE-2024-34785EPSS 25%
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…
Endpoint Manager
2022+
CRITICAL 9.8
CVE-2024-29847EPSS 53%
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated att…
Endpoint Manager
2022+
HIGH 7.2
CVE-2024-32840EPSS 25%
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…
Endpoint Manager
2022+
HIGH 7.2
CVE-2024-32842
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…
Endpoint Manager
2022+
HIGH 7.2
CVE-2024-32843
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…
Endpoint Manager
2022+
HIGH 7.2
CVE-2024-32845EPSS 24%
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…
Endpoint Manager
2022+
HIGH 7.2
CVE-2024-32846
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges…
Endpoint Manager
2022+
HIGH 8.8
CVE-2024-8322
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access …
Endpoint Manager
2022+
HIGH 8.6
CVE-2024-8321
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to i…
Endpoint Manager
2022+
MEDIUM 6.7
CVE-2024-8441
An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin…
Endpoint Manager
2022+
MEDIUM 5.3
CVE-2024-8320
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to s…
Endpoint Manager
2022+
CRITICAL 9.8
CVE-2024-8191EPSS 20%
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achie…
Endpoint Manager
2022+
HIGH 7.8
CVE-2024-44106
Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticate…
Workspace Control
10.18.99.0+
HIGH 7.8
CVE-2024-44107
DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escala…
Workspace Control
10.18.99.0+
HIGH 7.8
CVE-2024-8012
An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenti…
Workspace Control
10.18.99.0+
HIGH 7.2
CVE-2024-8190 KEVEPSS 89%
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to …
Cloud Services Appliance
Mitigation only
HIGH 7.8
CVE-2024-44103
DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escala…
Workspace Control
10.18.99.0+
HIGH 7.8
CVE-2024-44104
An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before …
Workspace Control
10.18.99.0+
HIGH 7.8
CVE-2024-44105
Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a loc…
Workspace Control
10.18.99.0+
CRITICAL 9.1
CVE-2024-38652EPSS 8%
Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via a…
Avalanche
Mitigation only