VYPR

Vendor CVEs

Ivanti

All CVEs

515 total · sorted by risk
  • CVE-2019-11510CriKEVMay 8, 2019
    risk 0.94cvss 10.0epss 1.00

    In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability .

  • CVE-2023-38035CriKEVAug 21, 2023
    risk 0.93cvss 9.8epss 1.00

    A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.

  • CVE-2021-44529CriKEVDec 8, 2021
    risk 0.93cvss 9.8epss 0.99

    A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).

  • CVE-2023-35082CriKEVAug 15, 2023
    risk 0.90cvss 9.8epss 1.00

    An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

  • CVE-2023-35078CriKEVJul 25, 2023
    risk 0.90cvss 9.8epss 1.00

    An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

  • CVE-2024-21887CriKEVJan 12, 2024
    risk 0.88cvss 9.1epss 1.00

    A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.

  • CVE-2025-22457CriKEVApr 3, 2025
    risk 0.87cvss 9.0epss 1.00

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.

  • CVE-2025-0282CriKEVJan 8, 2025
    risk 0.87cvss 9.0epss 1.00

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.

  • CVE-2024-7593CriKEVAug 13, 2024
    risk 0.87cvss 9.8epss 1.00

    Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.

  • CVE-2021-22893CriKEVApr 23, 2021
    risk 0.87cvss 10.0epss 0.47

    Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code…

  • CVE-2026-1340CriKEVJan 29, 2026
    risk 0.85cvss 9.8epss 0.84

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

  • CVE-2026-1281CriKEVJan 29, 2026
    risk 0.85cvss 9.8epss 0.82

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

  • CVE-2024-13159CriKEVJan 14, 2025
    risk 0.84cvss 9.8epss 1.00

    Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

  • CVE-2024-13161CriKEVJan 14, 2025
    risk 0.83cvss 9.8epss 0.90

    Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

  • CVE-2024-13160CriKEVJan 14, 2025
    risk 0.83cvss 9.8epss 0.91

    Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

  • CVE-2024-21893HigKEVJan 31, 2024
    risk 0.82cvss 8.2epss 1.00

    A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.

  • CVE-2023-46805HigKEVJan 12, 2024
    risk 0.82cvss 8.2epss 1.00

    An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks.

  • CVE-2024-8963CriKEVSep 19, 2024
    risk 0.81cvss 9.4epss 0.99

    Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

  • CVE-2024-29824HigKEVMay 31, 2024
    risk 0.80cvss 8.8epss 1.00

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

  • CVE-2026-10520CriKEVJun 9, 2026
    risk 0.77cvss 10.0epss 1.00

    An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

  • CVE-2019-11539HigKEVApr 26, 2019
    risk 0.76cvss 7.2epss 0.99

    In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before…

  • CVE-2023-32560CriAug 10, 2023
    risk 0.75cvss 9.8epss 0.99

    An attacker can send a specially crafted message to the Wavelink Avalanche Manager, which could result in service disruption or arbitrary code execution. Thanks to a Researcher at Tenable for finding and reporting. Fixed in version 6.4.1.

  • CVE-2026-1603HigKEVFeb 10, 2026
    risk 0.74cvss 8.6epss 0.81

    An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

  • CVE-2021-22894HigKEVMay 27, 2021
    risk 0.73cvss 8.8epss 0.41

    A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.

  • CVE-2023-46264CriDec 19, 2023
    risk 0.71cvss 9.8epss 0.90

    An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.

  • CVE-2023-32563CriAug 10, 2023
    risk 0.71cvss 9.8epss 0.90

    An unauthenticated attacker could achieve the code execution through a RemoteControl server.

  • CVE-2021-22899HigKEVMay 27, 2021
    risk 0.71cvss 8.8epss 0.22

    A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature

  • CVE-2023-46263CriDec 19, 2023
    risk 0.70cvss 9.8epss 0.82

    An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.

  • CVE-2022-36981CriMar 29, 2023
    risk 0.70cvss 9.8epss 0.83

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.3.101. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within…

  • CVE-2022-36974CriMar 29, 2023
    risk 0.70cvss 9.8epss 0.84

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists…

  • CVE-2020-8260HigKEVOct 28, 2020
    risk 0.70cvss 7.2epss 0.96

    A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.

  • CVE-2021-42127CriDec 7, 2021
    risk 0.69cvss 9.8epss 0.66

    A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service.

  • CVE-2025-4428HigKEVMay 13, 2025
    risk 0.68cvss 7.2epss 0.85

    Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

  • CVE-2024-29847CriSep 12, 2024
    risk 0.68cvss 9.8epss 0.53

    Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

  • CVE-2023-28324CriJul 1, 2023
    risk 0.68cvss 9.8epss 0.13

    A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.

  • CVE-2024-50330CriNov 12, 2024
    risk 0.67cvss 9.8epss 0.41

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution.

  • CVE-2023-46217CriDec 19, 2023
    risk 0.67cvss 9.8epss 0.36

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

  • CVE-2023-46216CriDec 19, 2023
    risk 0.67cvss 9.8epss 0.36

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

  • CVE-2023-41727CriDec 19, 2023
    risk 0.67cvss 9.8epss 0.36

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.

  • CVE-2023-32564CriAug 10, 2023
    risk 0.67cvss 9.8epss 0.44

    An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.

  • CVE-2023-32562CriAug 10, 2023
    risk 0.67cvss 9.8epss 0.46

    An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.3.x and below that could allow an attacker to achieve a remove code execution. Fixed in version 6.4.1.

  • CVE-2024-37404HigOct 18, 2024
    risk 0.66cvss 8.8epss 0.71

    Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.

  • CVE-2024-8190HigKEVSep 10, 2024
    risk 0.66cvss 7.2epss 0.89

    An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.

  • CVE-2024-24996CriApr 19, 2024
    risk 0.66cvss 9.8epss 0.32

    A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute arbitrary commands.

  • CVE-2021-22962CriDec 19, 2023
    risk 0.66cvss 9.1epss 0.91

    An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.

  • CVE-2020-8243HigKEVSep 30, 2020
    risk 0.66cvss 7.2epss 0.91

    A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.

  • CVE-2025-10573CriDec 9, 2025
    risk 0.65cvss 9.6epss 0.34

    Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.

  • CVE-2025-22467CriFeb 11, 2025
    risk 0.65cvss 9.9epss 0.04

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.

  • CVE-2024-11639CriDec 10, 2024
    risk 0.65cvss 10.0epss 0.05

    An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access

  • CVE-2024-29826HigMay 31, 2024
    risk 0.65cvss 8.8epss 1.00

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

Page 1 of 11