VYPR

Vendor CVEs

Ivanti

All CVEs

525 total · sorted by risk
  • CVE-2024-47909MedNov 12, 2024
    risk 0.32cvss 4.9epss 0.01

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.

  • CVE-2024-47905MedNov 12, 2024
    risk 0.32cvss 4.9epss 0.01

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.

  • CVE-2024-22060MedMay 31, 2024
    risk 0.32cvss 4.9epss 0.01

    An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, high privileged user to write arbitrary files into sensitive directories of ITSM server.

  • CVE-2020-8256MedSep 30, 2020
    risk 0.32cvss 4.9epss 0.03

    A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.

  • CVE-2020-8221MedJul 30, 2020
    risk 0.32cvss 4.9epss 0.02

    A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbitrary files via the administrator web interface.

  • CVE-2025-10986MedOct 14, 2025
    risk 0.31cvss 4.7epss 0.01

    Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write data in unintended locations on disk.

  • CVE-2025-22459MedApr 8, 2025
    risk 0.31cvss 4.8epss 0.00

    Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic between clients and servers.

  • CVE-2024-29211MedNov 13, 2024
    risk 0.31cvss 4.7epss 0.00

    A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.

  • CVE-2022-22571MedApr 11, 2022
    risk 0.31cvss 4.8epss 0.01

    An authenticated high privileged user can perform a stored XSS attack due to incorrect output encoding in Incapptic connect and affects all current versions.

  • CVE-2026-7431MedMay 12, 2026
    risk 0.29cvss 4.4epss 0.00

    An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section.

  • CVE-2024-38654MedNov 13, 2024
    risk 0.29cvss 4.4epss 0.00

    Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service.

  • CVE-2019-12376MedJun 3, 2019
    risk 0.29cvss 4.5epss 0.01

    Use of a hard-coded encryption key in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to full managed endpoint compromise by an authenticated user with read privileges.

  • CVE-2024-8322MedSep 10, 2024
    risk 0.28cvss 4.3epss 0.01

    Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.

  • CVE-2020-8261MedOct 28, 2020
    risk 0.28cvss 4.3epss 0.02

    A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection.

  • CVE-2020-8216MedJul 30, 2020
    risk 0.28cvss 4.3epss 0.02

    An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to find meeting details, if they know the Meeting ID.

  • CVE-2026-14902MedJul 14, 2026
    risk 0.26cvss 4.0epss 0.01

    An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs.

  • CVE-2007-1674Apr 18, 2007
    risk 0.09cvss —epss 0.73

    Stack-based buffer overflow in the Alert Service (aolnsrvr.exe) in LANDesk Management Suite 8.7 allows remote attackers to execute arbitrary code via a crafted packet to port 65535/UDP.

  • CVE-2012-1195Feb 18, 2012
    risk 0.08cvss —epss 0.68

    Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup web service in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension via a…

  • CVE-2012-1196Feb 18, 2012
    risk 0.07cvss —epss 0.56

    Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagement Console 9.0.3 allows remote attackers to delete arbitrary files via a .. (dot dot) in the filename parameter in a SetTaskLogByFile SOAP request.

  • CVE-2010-2892Nov 15, 2010
    risk 0.03cvss —epss 0.04

    gsb/drivers.php in LANDesk Management Gateway 4.0 through 4.0-1.48 and 4.2 through 4.2-1.8 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the DRIVES parameter, as demonstrated by a cross-site request forgery (CSRF) attack.

  • CVE-2008-6195Feb 20, 2009
    risk 0.03cvss —epss 0.03

    Directory traversal vulnerability in the PXE TFTP Service (PXEMTFTP.exe) in LANDesk Management Suite (LDMS) 8.80.1.1 and earlier allows remote attackers to read arbitrary files via a subdirectory name followed by ".." sequences, a different vulnerability than CVE-2008-1643.

  • CVE-2008-2468Sep 18, 2008
    risk 0.01cvss —epss 0.10

    Multiple buffer overflows in the QIP Server Service (aka qipsrvr.exe) in LANDesk Management Suite, Security Suite, and Server Manager 8.8 and earlier allow remote attackers to execute arbitrary code via a crafted heal request, related to the StringToMap and StringSize arguments.

  • CVE-2014-5361Apr 21, 2015
    risk 0.00cvss —epss 0.01

    Multiple cross-site request forgery (CSRF) vulnerabilities in Landesk Management Suite 9.6 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) start, (2) stop, or (3) restart services via a request to remote/serverServices.aspx.

  • CVE-2014-5360Feb 3, 2015
    risk 0.00cvss —epss 0.01

    Cross-site scripting (XSS) vulnerability in the admin interface in LANDESK Management Suite before 9.6 SP1 allows remote attackers to inject arbitrary web script or HTML via the AMTVersion parameter to remote/serverlist_grouptree.aspx.

  • CVE-2008-1643Apr 2, 2008
    risk 0.00cvss —epss 0.02

    Directory traversal vulnerability in the PXE TFTP Service (PXEMTFTP.exe) in LANDesk Management Suite (LDMS) 8.7 SP5 and earlier and 8.8 allows remote attackers to read arbitrary files via unspecified vectors.

Page 11 of 11