VYPR

Vendor CVEs

Ivanti

All CVEs

515 total · sorted by risk
  • CVE-2019-11540CriApr 26, 2019
    risk 0.64cvss 9.8epss 0.08

    In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthenticated, remote attacker can conduct a session hijacking attack.

  • CVE-2018-6320CriSep 6, 2018
    risk 0.64cvss 9.8epss 0.04

    A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an http(s) Host header received from the browser is trusted…

  • CVE-2016-3147CriJan 23, 2017
    risk 0.64cvss 9.8epss 0.06

    Buffer overflow in the collector.exe listener of the Landesk Management Suite 10.0.0.271 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large packet.

  • CVE-2024-7569CriAug 13, 2024
    risk 0.63cvss 9.6epss 0.02

    An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.

  • CVE-2024-29827HigMay 31, 2024
    risk 0.63cvss 8.8epss 0.72

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

  • CVE-2024-24994HigApr 19, 2024
    risk 0.63cvss 8.8epss 0.68

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2024-24992HigApr 19, 2024
    risk 0.63cvss 8.8epss 0.71

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2024-23535HigApr 19, 2024
    risk 0.63cvss 8.8epss 0.68

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2021-42132HigDec 7, 2021
    risk 0.63cvss 8.8epss 0.70

    A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.

  • CVE-2021-42131HigDec 7, 2021
    risk 0.63cvss 8.8epss 0.67

    A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.

  • CVE-2021-42129HigDec 7, 2021
    risk 0.63cvss 8.8epss 0.77

    A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.

  • CVE-2021-22908HigMay 27, 2021
    risk 0.63cvss 8.8epss 0.69

    A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. As of version 9.1R3, this permission is not enabled by default.

  • CVE-2026-8043CriMay 12, 2026
    risk 0.62cvss 9.6epss 0.01

    External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.

  • CVE-2026-6973HigKEVMay 7, 2026
    risk 0.62cvss 7.2epss 0.34

    An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

  • CVE-2024-29822HigMay 31, 2024
    risk 0.62cvss 8.8epss 0.64

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

  • CVE-2024-22024HigFeb 13, 2024
    risk 0.62cvss 8.3epss 0.95

    An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources without authentication.

  • CVE-2021-42130HigDec 7, 2021
    risk 0.62cvss 8.8epss 0.62

    A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution.

  • CVE-2024-47908CriFeb 11, 2025
    risk 0.61cvss 9.1epss 0.22

    OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-11773CriDec 10, 2024
    risk 0.61cvss 9.1epss 0.24

    SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

  • CVE-2020-8218HigKEVJul 30, 2020
    risk 0.61cvss 7.2epss 0.32

    A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

  • CVE-2024-11772CriDec 10, 2024
    risk 0.60cvss 9.1epss 0.08

    Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-38652CriAug 14, 2024
    risk 0.60cvss 9.1epss 0.08

    Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.

  • CVE-2021-22900HigKEVMay 27, 2021
    risk 0.60cvss 7.2epss 0.14

    A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web interface.

  • CVE-2025-9712HigSep 9, 2025
    risk 0.59cvss 8.8epss 0.21

    Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

  • CVE-2024-10644CriFeb 11, 2025
    risk 0.59cvss 9.1epss 0.03

    Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-11634CriDec 10, 2024
    risk 0.59cvss 9.1epss 0.02

    Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)

  • CVE-2024-11633CriDec 10, 2024
    risk 0.59cvss 9.1epss 0.02

    Argument injection in Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution

  • CVE-2024-39712CriNov 13, 2024
    risk 0.59cvss 9.1epss 0.02

    Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-39711CriNov 13, 2024
    risk 0.59cvss 9.1epss 0.02

    Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-39710CriNov 13, 2024
    risk 0.59cvss 9.1epss 0.02

    Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-38656CriNov 13, 2024
    risk 0.59cvss 9.1epss 0.02

    Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-11006CriNov 12, 2024
    risk 0.59cvss 9.1epss 0.02

    Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-11005CriNov 12, 2024
    risk 0.59cvss 9.1epss 0.02

    Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-11007CriNov 12, 2024
    risk 0.59cvss 9.1epss 0.02

    Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2023-46266CriDec 19, 2023
    risk 0.59cvss 9.1epss 0.03

    An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.

  • CVE-2023-39337CriNov 15, 2023
    risk 0.59cvss 9.1epss 0.02

    A security vulnerability in EPMM Versions 11.10, 11.9 and 11.8 older allows a threat actor with knowledge of an enrolled device identifier to access and extract sensitive information, including device and environment configuration details, as well as secrets. This vulnerability…

  • CVE-2023-32565CriAug 10, 2023
    risk 0.59cvss 9.1epss 0.02

    An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.

  • CVE-2023-32566CriAug 10, 2023
    risk 0.59cvss 9.1epss 0.02

    An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. Fixed in version 6.4.1.

  • CVE-2022-36980HigMar 29, 2023
    risk 0.59cvss 8.1epss 0.83

    This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within…

  • CVE-2019-12373CriJun 3, 2019
    risk 0.59cvss 9.0epss 0.01

    Improper access control and open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote disclosure of administrator passwords.

  • CVE-2026-5787HigMay 7, 2026
    risk 0.58cvss 8.9epss 0.01

    An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.

  • CVE-2026-5786HigMay 7, 2026
    risk 0.58cvss 8.8epss 0.06

    An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.

  • CVE-2025-9713HigOct 13, 2025
    risk 0.58cvss 8.8epss 0.15

    Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

  • CVE-2025-9872HigSep 9, 2025
    risk 0.58cvss 8.8epss 0.14

    Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

  • CVE-2025-55145HigSep 9, 2025
    risk 0.58cvss 8.9epss 0.01

    Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker to…

  • CVE-2024-9379MedKEVOct 8, 2024
    risk 0.58cvss 6.5epss 0.43

    SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.

  • CVE-2024-37397HigSep 12, 2024
    risk 0.58cvss 8.2epss 0.59

    An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.

  • CVE-2023-41724HigMar 31, 2024
    risk 0.58cvss 8.8epss 0.13

    A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network.

  • CVE-2023-39336HigJan 9, 2024
    risk 0.58cvss 8.8epss 0.10

    An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the need for authentication. Under specific circumstances, this…

  • CVE-2022-36973HigMar 29, 2023
    risk 0.58cvss 8.8epss 0.06

    This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within…

Page 3 of 11