Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2024-38653EPSS 92%
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
Avalanche
Mitigation only
HIGH 7.5
CVE-2024-36136
An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
Avalanche
Mitigation only
HIGH 7.5
CVE-2024-37399EPSS 28%
A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting i…
Avalanche
Mitigation only
HIGH 7.2
CVE-2024-37373
Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.
Avalanche
Mitigation only
CRITICAL 9.8
CVE-2024-7569
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to…
Neurons For Itsm
Patch available
CRITICAL 9.8
CVE-2024-7593 KEVEPSS 100%
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker t…
Virtual Traffic Manager
Patch available
HIGH 8.1
CVE-2024-7570
Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position t…
Neurons For Itsm
Patch available
HIGH 8.8
CVE-2024-36131
An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary com…
Endpoint Manager Mobile
12.1.0.1+
HIGH 7.5
CVE-2024-36132
Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive…
Endpoint Manager Mobile
12.1.0.1+
MEDIUM 5.5
CVE-2024-37403
Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, r…
Docs\@work
2.26.0+
CRITICAL 9.8
CVE-2024-36130
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute …
Endpoint Manager Mobile
12.1.0.1+
MEDIUM 6.5
CVE-2024-34788
An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive in…
Endpoint Manager Mobile
12.1.0.1+
HIGH 8.0
CVE-2024-37381
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute…
Endpoint Manager
Mitigation only
HIGH 8.0
CVE-2024-29829EPSS 8%
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network t…
Endpoint Manager
2022+
HIGH 8.0
CVE-2024-29830EPSS 8%
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network t…
Endpoint Manager
2022+
HIGH 8.0
CVE-2024-29846EPSS 8%
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network t…
Endpoint Manager
2022+
HIGH 7.2
CVE-2024-29848EPSS 64%
An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbit…
Avalanche
6.4.3.602+
HIGH 8.8
CVE-2024-29823EPSS 100%
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network…
Endpoint Manager
2022+
HIGH 8.8
CVE-2024-29824 KEVEPSS 100%
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network…
Endpoint Manager
2022+
HIGH 8.8
CVE-2024-29825EPSS 100%
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network…
Endpoint Manager
2022+
HIGH 8.8
CVE-2024-29826EPSS 100%
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network…
Endpoint Manager
2022+
HIGH 8.8
CVE-2024-29827EPSS 72%
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network…
Endpoint Manager
2022+
HIGH 8.0
CVE-2024-29828EPSS 8%
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network t…
Endpoint Manager
2022+
HIGH 8.8
CVE-2024-22059
A SQL injection vulnerability in web component of Ivanti Neurons for ITSM allows a remote authenticated user to read/modify/delete information in the…
Neurons For Itsm
2023.3+
HIGH 8.8
CVE-2024-29822EPSS 64%
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network…
Endpoint Manager
2022+
HIGH 7.8
CVE-2024-22058
A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated permissio…
Endpoint Manager
after 2021.1
HIGH 7.8
CVE-2023-38042
A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.
Secure Access Client
22.7+
HIGH 7.3
CVE-2023-46810
A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as ro…
Secure Access Client
22.7+
MEDIUM 6.7
CVE-2023-46806
An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access …
Endpoint Manager Mobile
12.1.0.0+
MEDIUM 6.7
CVE-2023-46807
An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify d…
Endpoint Manager Mobile
12.1.0.0+