Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2024-7612 Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components. Endpoint Manager Mobile 12.0.0.5 / 12.1.0.4+ Fix from $1,9502024-10-08 HIGH 7.5 CVE-2024-47011EPSS 56% Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information Avalanche 6.4.5+ Fix from $1,9502024-10-08 CRITICAL 9.8 CVE-2024-47009 Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication. Avalanche 6.4.5+ Fix from $2,3002024-10-08 HIGH 7.5 CVE-2024-47007 A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a den… Avalanche 6.4.5+ Fix from $1,9502024-10-08 HIGH 7.5 CVE-2024-47008EPSS 47% Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information. Avalanche 6.4.5+ Fix from $1,9502024-10-08 CRITICAL 9.1 CVE-2024-8963 KEVEPSS 99% Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality. Endpoint Manager Cloud Services Appliance Mitigation only Fix from $2,3002024-09-19 HIGH 8.2 CVE-2024-37397EPSS 59% An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remot… Endpoint Manager 2022+ Fix from $1,9502024-09-12 HIGH 7.2 CVE-2024-32848EPSS 43% An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges… Endpoint Manager 2022+ Fix from $1,9502024-09-12 HIGH 7.2 CVE-2024-34779EPSS 24% An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges… Endpoint Manager 2022+ Fix from $1,9502024-09-12 HIGH 7.2 CVE-2024-34783EPSS 43% An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges… Endpoint Manager 2022+ Fix from $1,9502024-09-12 HIGH 7.2 CVE-2024-34785EPSS 25% An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges… Endpoint Manager 2022+ Fix from $1,9502024-09-12 CRITICAL 9.8 CVE-2024-29847EPSS 53% Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated att… Endpoint Manager 2022+ Fix from $2,3002024-09-12 HIGH 7.2 CVE-2024-32840EPSS 25% An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges… Endpoint Manager 2022+ Fix from $1,9502024-09-12 HIGH 7.2 CVE-2024-32842 An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges… Endpoint Manager 2022+ Fix from $1,9502024-09-12 HIGH 7.2 CVE-2024-32843 An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges… Endpoint Manager 2022+ Fix from $1,9502024-09-12 HIGH 7.2 CVE-2024-32845EPSS 24% An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges… Endpoint Manager 2022+ Fix from $1,9502024-09-12 HIGH 7.2 CVE-2024-32846 An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges… Endpoint Manager 2022+ Fix from $1,9502024-09-12 HIGH 8.8 CVE-2024-8322 Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access … Endpoint Manager 2022+ Fix from $1,9502024-09-10 HIGH 8.6 CVE-2024-8321 Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to i… Endpoint Manager 2022+ Fix from $1,9502024-09-10 MEDIUM 6.7 CVE-2024-8441 An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin… Endpoint Manager 2022+ Fix from $1,6002024-09-10 MEDIUM 5.3 CVE-2024-8320 Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to s… Endpoint Manager 2022+ Fix from $1,6002024-09-10 CRITICAL 9.8 CVE-2024-8191EPSS 20% SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achie… Endpoint Manager 2022+ Fix from $2,3002024-09-10 HIGH 7.8 CVE-2024-44106 Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticate… Workspace Control 10.18.99.0+ Fix from $1,9502024-09-10 HIGH 7.8 CVE-2024-44107 DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escala… Workspace Control 10.18.99.0+ Fix from $1,9502024-09-10 HIGH 7.8 CVE-2024-8012 An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenti… Workspace Control 10.18.99.0+ Fix from $1,9502024-09-10 HIGH 7.2 CVE-2024-8190 KEVEPSS 89% An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to … Cloud Services Appliance Mitigation only Fix from $1,9502024-09-10 HIGH 7.8 CVE-2024-44103 DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escala… Workspace Control 10.18.99.0+ Fix from $1,9502024-09-10 HIGH 7.8 CVE-2024-44104 An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before … Workspace Control 10.18.99.0+ Fix from $1,9502024-09-10 HIGH 7.8 CVE-2024-44105 Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a loc… Workspace Control 10.18.99.0+ Fix from $1,9502024-09-10 CRITICAL 9.1 CVE-2024-38652EPSS 8% Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via a… Avalanche Mitigation only Fix from $2,3002024-08-14