VYPR

Vendor CVEs

Ivanti

All CVEs

525 total · sorted by risk
  • CVE-2021-22936MedAug 16, 2021
    risk 0.40cvss 6.1epss 0.01

    A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter.

  • CVE-2020-8262MedOct 28, 2020
    risk 0.40cvss 6.1epss 0.02

    A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface.

  • CVE-2020-8238MedSep 30, 2020
    risk 0.40cvss 6.1epss 0.02

    A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Scripting (XSS).

  • CVE-2020-8204MedJul 30, 2020
    risk 0.40cvss 6.1epss 0.02

    A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page.

  • CVE-2018-20814MedJun 28, 2019
    risk 0.40cvss 6.1epss 0.02

    An XSS issue was found with Psaldownload.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.3R2 before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX or PPS 5.2RX.

  • CVE-2018-20808MedJun 28, 2019
    risk 0.40cvss 6.1epss 0.02

    An XSS issue has been found with rd.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R3 due to improper header sanitization. This is not applicable to 8.1RX.

  • CVE-2018-20807MedJun 28, 2019
    risk 0.40cvss 6.1epss 0.02

    An XSS issue has been found in welcome.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1.x before 8.1R12, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 due to one of the URL parameters not being sanitized properly.

  • CVE-2019-11507MedMay 8, 2019
    risk 0.40cvss 6.1epss 0.04

    In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page.

  • CVE-2019-11543MedApr 26, 2019
    risk 0.40cvss 6.1epss 0.03

    XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, and 5.2RX before 5.2R12.1.

  • CVE-2018-14366MedSep 6, 2018
    risk 0.40cvss 6.1epss 0.02

    download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.

  • CVE-2016-4789MedMay 26, 2016
    risk 0.40cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the system configuration section in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject arbitrary web script or…

  • CVE-2024-13843MedFeb 11, 2025
    risk 0.39cvss 6.0epss 0.00

    Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.

  • CVE-2024-13842MedFeb 11, 2025
    risk 0.39cvss 6.0epss 0.00

    A hardcoded key in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.

  • CVE-2023-28125MedMay 9, 2023
    risk 0.39cvss 5.9epss 0.02

    An improper authentication vulnerability exists in Avalanche Premise versions 6.3.x and below that could allow an attacker to gain access to the server by registering to receive messages from the server and perform an authentication bypass.

  • CVE-2022-21826MedSep 30, 2022
    risk 0.39cvss 5.4epss 0.45

    Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket. This body ends up prefixing the next HTTP…

  • CVE-2025-43716MedApr 23, 2025
    risk 0.38cvss 5.8epss 0.01

    A directory traversal vulnerability exists in Ivanti LANDesk Management Gateway through 4.2-1.9. By appending %3F.php to the URI of the /client/index.php endpoint, an attacker can bypass access controls and gain unauthorized access to various endpoints such as…

  • CVE-2024-8321MedSep 10, 2024
    risk 0.38cvss 5.8epss 0.02

    Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.

  • CVE-2016-4788MedMay 26, 2016
    risk 0.38cvss 5.8epss 0.02

    Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read an unspecified system file via unknown vectors.

  • CVE-2026-4913MedApr 14, 2026
    risk 0.37cvss 5.7epss 0.01

    Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to retain access when their account has been disabled.

  • CVE-2024-38648MedJul 12, 2025
    risk 0.37cvss 5.7epss 0.01

    A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.

  • CVE-2025-5468MedAug 12, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local…

  • CVE-2025-0292MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.01

    SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to access internal network services.

  • CVE-2025-5463MedJul 8, 2025
    risk 0.36cvss 5.5epss 0.00

    Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a local authenticated attacker to obtain that information.

  • CVE-2024-37403MedAug 7, 2024
    risk 0.36cvss 5.5epss 0.00

    Ivanti Docs@Work for Android, before 2.26.0 is affected by the 'Dirty Stream' vulnerability. The application fails to properly sanitize file names, resulting in a path traversal-affiliated vulnerability. This potentially enables other malicious apps on the device to read…

  • CVE-2023-38544MedNov 15, 2023
    risk 0.36cvss 5.5epss 0.00

    A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on the affected system.

  • CVE-2022-21823MedJan 10, 2022
    risk 0.36cvss 5.5epss 0.00

    A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an unspecified attack vector.

  • CVE-2020-12880MedJul 27, 2020
    risk 0.36cvss 5.5epss 0.00

    An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the…

  • CVE-2020-11533MedApr 4, 2020
    risk 0.36cvss 5.5epss 0.00

    Ivanti Workspace Control before 10.4.30.0, when SCCM integration is enabled, allows local users to obtain sensitive information (keying material).

  • CVE-2018-15590MedOct 15, 2018
    risk 0.36cvss 5.5epss 0.01

    An issue was discovered in Ivanti Workspace Control before 10.3.0.0 and RES One Workspace, when file and folder security are configured. A local authenticated user can bypass file and folder security restriction by leveraging an unspecified attack vector.

  • CVE-2016-4790MedMay 26, 2016
    risk 0.36cvss 5.5epss 0.01

    Cross-site scripting (XSS) vulnerability in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2026-4914MedApr 14, 2026
    risk 0.35cvss 5.4epss 0.00

    Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information from other user sessions. User interaction is required.

  • CVE-2025-8712MedSep 9, 2025
    risk 0.35cvss 5.4epss 0.00

    Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with…

  • CVE-2025-8711MedSep 9, 2025
    risk 0.35cvss 5.4epss 0.00

    CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to execute limited…

  • CVE-2025-55144MedSep 9, 2025
    risk 0.35cvss 5.4epss 0.01

    Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with…

  • CVE-2024-11771MedFeb 11, 2025
    risk 0.35cvss 5.3epss 0.01

    Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality.

  • CVE-2024-8320MedSep 10, 2024
    risk 0.35cvss 5.3epss 0.01

    Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.

  • CVE-2024-22023MedApr 4, 2024
    risk 0.35cvss 5.3epss 0.03

    An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a…

  • CVE-2020-13773MedNov 16, 2020
    risk 0.35cvss 5.4epss 0.01

    Ivanti Endpoint Manager through 2020.1.1 allows XSS via /LDMS/frm_splitfrm.aspx, /LDMS/licensecheck.aspx, /LDMS/frm_splitcollapse.aspx, /LDMS/alert_log.aspx, /LDMS/ServerList.aspx, /LDMS/frm_coremainfrm.aspx, /LDMS/frm_findfrm.aspx, /LDMS/frm_taskfrm.aspx, and…

  • CVE-2020-13772MedNov 16, 2020
    risk 0.35cvss 5.3epss 0.02

    In /ldclient/ldprov.cgi in Ivanti Endpoint Manager through 2020.1.1, an attacker is able to disclose information about the server operating system, local pathnames, and environment variables with no authentication required.

  • CVE-2020-8217MedJul 30, 2020
    risk 0.35cvss 5.4epss 0.01

    A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used for Citrix ICA.

  • CVE-2018-20811MedJun 28, 2019
    risk 0.35cvss 5.3epss 0.02

    A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12.

  • CVE-2016-4792MedMay 26, 2016
    risk 0.35cvss 5.3epss 0.02

    Pulse Connect Secure (PCS) 8.2 before 8.2r1 allows remote attackers to disclose sign in pages via unspecified vectors.

  • CVE-2024-9843MedNov 12, 2024
    risk 0.33cvss 5.0epss 0.00

    A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.

  • CVE-2025-55146MedSep 9, 2025
    risk 0.32cvss 4.9epss 0.01

    An unchecked return value in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker…

  • CVE-2025-5466MedAug 12, 2025
    risk 0.32cvss 4.9epss 0.01

    XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to…

  • CVE-2023-39339MedJul 12, 2025
    risk 0.32cvss 4.9epss 0.01

    A vulnerability exists on all versions of Ivanti Policy Secure below 22.6R1 where an authenticated administrator can perform an arbitrary file read via a maliciously crafted web request.

  • CVE-2025-5451MedJul 8, 2025
    risk 0.32cvss 4.9epss 0.01

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to trigger a denial of service.

  • CVE-2024-38657MedFeb 21, 2025
    risk 0.32cvss 4.9epss 0.02

    External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.

  • CVE-2024-47909MedNov 12, 2024
    risk 0.32cvss 4.9epss 0.01

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.

  • CVE-2024-47905MedNov 12, 2024
    risk 0.32cvss 4.9epss 0.01

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.

Page 10 of 11