Vulnerability index

Browse CVEs

61 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Connect Secure CRITICAL 9.0
CVE-2025-0282 KEVEPSS 100%

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for …

Mitigation only
Fix from $2,300 2025-01-08
Endpoint Manager Cloud Services Appliance CRITICAL 9.1
CVE-2024-8963 KEVEPSS 99%

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

Mitigation only
Fix from $2,300 2024-09-19
Cloud Services Appliance HIGH 7.2
CVE-2024-8190 KEVEPSS 89%

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to …

Mitigation only
Fix from $1,950 2024-09-10
Avalanche CRITICAL 9.1
CVE-2024-38652EPSS 8%

Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via a…

Mitigation only
Fix from $2,300 2024-08-14
Avalanche HIGH 7.5
CVE-2024-38653EPSS 92%

XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

Mitigation only
Fix from $1,950 2024-08-14
Avalanche HIGH 7.5
CVE-2024-36136

An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.

Mitigation only
Fix from $1,950 2024-08-14
Avalanche HIGH 7.5
CVE-2024-37399EPSS 28%

A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting i…

Mitigation only
Fix from $1,950 2024-08-14
Avalanche HIGH 7.2
CVE-2024-37373

Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.

Mitigation only
Fix from $1,950 2024-08-14
Endpoint Manager HIGH 8.0
CVE-2024-37381

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute…

Mitigation only
Fix from $1,950 2024-07-29
Connect Secure CRITICAL 9.8
CVE-2024-21894EPSS 19%

A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious us…

Mitigation only
Fix from $2,300 2024-04-04
Connect Secure HIGH 8.2
CVE-2024-22053

A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malicious us…

Mitigation only
Fix from $1,950 2024-04-04
Connect Secure HIGH 7.5
CVE-2024-22052

A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated m…

Mitigation only
Fix from $1,950 2024-04-04
Connect Secure MEDIUM 5.3
CVE-2024-22023

An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticate…

Mitigation only
Fix from $1,600 2024-04-04
Connect Secure HIGH 8.3
CVE-2024-22024EPSS 95%

An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gate…

Mitigation only
Fix from $1,950 2024-02-13
Connect Secure HIGH 8.8
CVE-2024-21888EPSS 87%

A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elev…

Mitigation only
Fix from $1,950 2024-01-31
Connect Secure HIGH 8.2
CVE-2024-21893 KEVEPSS 100%

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivant…

Mitigation only
Fix from $1,950 2024-01-31
Avalanche MEDIUM 6.5
CVE-2023-41474EPSS 38%

Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.…

No fix yet
Fix from $1,600 2024-01-25
Connect Secure CRITICAL 9.1
CVE-2024-21887 KEVEPSS 100%

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticate…

Mitigation only
Fix from $2,300 2024-01-12
Connect Secure HIGH 8.2
CVE-2023-46805 KEVEPSS 100%

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restr…

Mitigation only
Fix from $1,950 2024-01-12
Connect Secure HIGH 7.5
CVE-2023-39340

A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker can send a specific request which may lead to Denial o…

No fix yet
Fix from $1,950 2023-12-16
Connect Secure HIGH 7.8
CVE-2023-41720

A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (ICS) appl…

Mitigation only
Fix from $1,950 2023-12-14
Connect Secure HIGH 7.2
CVE-2023-41719

A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a specific we…

Mitigation only
Fix from $1,950 2023-12-14
Secure Access Client HIGH 7.8
CVE-2023-41718

When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having cont…

No fix yet
Fix from $1,950 2023-11-15
Secure Access Client MEDIUM 5.5
CVE-2023-38544

A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be e…

Mitigation only
Fix from $1,600 2023-11-15
Incapptic Connect HIGH 7.2
CVE-2022-21828

A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified …

No fix yet
Fix from $1,950 2022-03-04
Connect Secure HIGH 8.8
CVE-2021-22908EPSS 69%

A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shar…

Mitigation only
Fix from $1,950 2021-05-27
Connect Secure HIGH 8.8
CVE-2021-22894 KEVEPSS 41%

A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as th…

Mitigation only
Fix from $1,950 2021-05-27
Connect Secure HIGH 8.8
CVE-2021-22899 KEVEPSS 23%

A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execut…

Mitigation only
Fix from $1,950 2021-05-27
Connect Secure CRITICAL 10.0
CVE-2021-22893 KEVEPSS 47%

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pul…

Mitigation only
Fix from $2,300 2021-04-23
Endpoint Manager CRITICAL 9.9
CVE-2020-13774

An unrestricted file-upload issue in EditLaunchPadDialog.aspx in Ivanti Endpoint Manager 2019.1 and 2020.1 allows an authenticated attacker to gain r…

Mitigation only
Fix from $2,300 2020-11-12