Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-38653EPSS 92% XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server. Avalanche Mitigation only Fix from $1,9502024-08-14 HIGH 7.5 CVE-2024-36136 An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS. Avalanche Mitigation only Fix from $1,9502024-08-14 HIGH 7.5 CVE-2024-37399EPSS 28% A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting i… Avalanche Mitigation only Fix from $1,9502024-08-14 HIGH 7.2 CVE-2024-37373 Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE. Avalanche Mitigation only Fix from $1,9502024-08-14 CRITICAL 9.8 CVE-2024-7569 An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to… Neurons For Itsm Patch available Fix from $2,3002024-08-13 CRITICAL 9.8 CVE-2024-7593 KEVEPSS 100% Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker t… Virtual Traffic Manager Patch available Fix from $2,3002024-08-13 HIGH 8.1 CVE-2024-7570 Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position t… Neurons For Itsm Patch available Fix from $1,9502024-08-13 HIGH 8.8 CVE-2024-36131 An insecure deserialization vulnerability in web component of EPMM prior to 12.1.0.1 allows an authenticated remote attacker to execute arbitrary com… Endpoint Manager Mobile 12.1.0.1+ Fix from $1,9502024-08-07 HIGH 7.5 CVE-2024-36132 Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive… Endpoint Manager Mobile 12.1.0.1+ Fix from $1,9502024-08-07 MEDIUM 5.5 CVE-2024-37403 Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, r… Docs\@work 2.26.0+ Fix from $1,6002024-08-07 CRITICAL 9.8 CVE-2024-36130 An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute … Endpoint Manager Mobile 12.1.0.1+ Fix from $2,3002024-08-07 MEDIUM 6.5 CVE-2024-34788 An improper authentication vulnerability in web component of EPMM prior to 12.1.0.1 allows a remote malicious user to access potentially sensitive in… Endpoint Manager Mobile 12.1.0.1+ Fix from $1,6002024-08-07 HIGH 8.0 CVE-2024-37381 An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute… Endpoint Manager Mitigation only Fix from $1,9502024-07-29 HIGH 8.0 CVE-2024-29829EPSS 8% An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network t… Endpoint Manager 2022+ Fix from $1,9502024-05-31 HIGH 8.0 CVE-2024-29830EPSS 8% An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network t… Endpoint Manager 2022+ Fix from $1,9502024-05-31 HIGH 8.0 CVE-2024-29846EPSS 8% An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network t… Endpoint Manager 2022+ Fix from $1,9502024-05-31 HIGH 7.2 CVE-2024-29848EPSS 64% An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbit… Avalanche 6.4.3.602+ Fix from $1,9502024-05-31 HIGH 8.8 CVE-2024-29823EPSS 100% An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network… Endpoint Manager 2022+ Fix from $1,9502024-05-31 HIGH 8.8 CVE-2024-29824 KEVEPSS 100% An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network… Endpoint Manager 2022+ Fix from $1,9502024-05-31 HIGH 8.8 CVE-2024-29825EPSS 100% An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network… Endpoint Manager 2022+ Fix from $1,9502024-05-31 HIGH 8.8 CVE-2024-29826EPSS 100% An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network… Endpoint Manager 2022+ Fix from $1,9502024-05-31 HIGH 8.8 CVE-2024-29827EPSS 72% An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network… Endpoint Manager 2022+ Fix from $1,9502024-05-31 HIGH 8.0 CVE-2024-29828EPSS 8% An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network t… Endpoint Manager 2022+ Fix from $1,9502024-05-31 HIGH 8.8 CVE-2024-22059 A SQL injection vulnerability in web component of Ivanti Neurons for ITSM allows a remote authenticated user to read/modify/delete information in the… Neurons For Itsm 2023.3+ Fix from $1,9502024-05-31 HIGH 8.8 CVE-2024-29822EPSS 64% An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network… Endpoint Manager 2022+ Fix from $1,9502024-05-31 HIGH 7.8 CVE-2024-22058 A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated permissio… Endpoint Manager after 2021.1 Fix from $1,9502024-05-31 HIGH 7.8 CVE-2023-38042 A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM. Secure Access Client 22.7+ Fix from $1,9502024-05-31 HIGH 7.3 CVE-2023-46810 A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as ro… Secure Access Client 22.7+ Fix from $1,9502024-05-31 MEDIUM 6.7 CVE-2023-46806 An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access … Endpoint Manager Mobile 12.1.0.0+ Fix from $1,6002024-05-22 MEDIUM 6.7 CVE-2023-46807 An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify d… Endpoint Manager Mobile 12.1.0.0+ Fix from $1,6002024-05-22