VYPR

Vendor CVEs

Ivanti

All CVEs

515 total · sorted by risk
  • CVE-2024-29846HigMay 31, 2024
    risk 0.53cvss 8.0epss 0.08

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

  • CVE-2024-29830HigMay 31, 2024
    risk 0.53cvss 8.0epss 0.08

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

  • CVE-2024-29829HigMay 31, 2024
    risk 0.53cvss 8.0epss 0.08

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

  • CVE-2024-29828HigMay 31, 2024
    risk 0.53cvss 8.0epss 0.08

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

  • CVE-2023-38551HigMay 31, 2024
    risk 0.53cvss 8.2epss 0.01

    A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.

  • CVE-2024-27977HigApr 19, 2024
    risk 0.53cvss 8.1epss 0.02

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete arbitrary files, thereby leading to Denial-of-Service.

  • CVE-2023-28127HigMay 9, 2023
    risk 0.53cvss 7.5epss 0.59

    A path traversal vulnerability exists in Avalanche version 6.3.x and below that when exploited could result in possible information disclosure.

  • CVE-2021-42133HigDec 7, 2021
    risk 0.53cvss 8.1epss 0.03

    An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform an arbitrary file write.

  • CVE-2020-8206HigJul 30, 2020
    risk 0.53cvss 8.1epss 0.03

    An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP.

  • CVE-2019-12374HigJun 3, 2019
    risk 0.53cvss 8.1epss 0.03

    A SQL Injection vulnerability exists in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 due to improper username sanitization in the Basic Authentication implementation in core/provisioning.secure/ProvisioningSecure.asmx in…

  • CVE-2019-11213HigApr 12, 2019
    risk 0.53cvss 8.1epss 0.03

    In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end user, a related issue to CVE-2019-1573. (The endpoint would need to be already compromised for…

  • CVE-2024-13171HigJan 14, 2025
    risk 0.52cvss 7.8epss 0.18

    Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.

  • CVE-2024-13162HigJan 14, 2025
    risk 0.52cvss 7.2epss 0.64

    SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-2024-32848.

  • CVE-2024-13179HigJan 14, 2025
    risk 0.52cvss 7.3epss 0.62

    Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.

  • CVE-2024-34787HigNov 13, 2024
    risk 0.52cvss 7.8epss 0.18

    Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.

  • CVE-2024-34781HigNov 13, 2024
    risk 0.52cvss 7.2epss 0.68

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-47008HigOct 8, 2024
    risk 0.52cvss 7.5epss 0.47

    Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.

  • CVE-2024-8191HigSep 10, 2024
    risk 0.52cvss 7.8epss 0.20

    SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.

  • CVE-2024-37381HigJul 29, 2024
    risk 0.52cvss 8.0epss 0.03

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute arbitrary code.

  • CVE-2024-29848HigMay 31, 2024
    risk 0.52cvss 7.2epss 0.64

    An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.

  • CVE-2019-11542HigApr 26, 2019
    risk 0.52cvss 7.2epss 0.66

    In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before…

  • CVE-2026-8110HigMay 12, 2026
    risk 0.51cvss 7.8epss 0.00

    Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges.

  • CVE-2026-7432HigMay 12, 2026
    risk 0.51cvss 7.8epss 0.00

    A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM

  • CVE-2026-3483HigMar 10, 2026
    risk 0.51cvss 7.8epss 0.00

    An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.

  • CVE-2025-13662HigDec 9, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required.

  • CVE-2025-11622HigOct 13, 2025
    risk 0.51cvss 7.8epss 0.01

    Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges.

  • CVE-2025-22460HigMay 13, 2025
    risk 0.51cvss 7.8epss 0.00

    Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.

  • CVE-2025-22458HigApr 8, 2025
    risk 0.51cvss 7.8epss 0.00

    DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.

  • CVE-2025-22454HigMar 11, 2025
    risk 0.51cvss 7.8epss 0.00

    Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

  • CVE-2024-13172HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.01

    Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.

  • CVE-2024-13169HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.00

    An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.

  • CVE-2024-13164HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.00

    An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.

  • CVE-2024-13163HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.09

    Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.

  • CVE-2024-13180HigJan 14, 2025
    risk 0.51cvss 7.5epss 0.28

    Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.

  • CVE-2024-10630HigJan 14, 2025
    risk 0.51cvss 7.8epss 0.00

    A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality.

  • CVE-2024-9845HigDec 11, 2024
    risk 0.51cvss 7.8epss 0.00

    Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.

  • CVE-2024-8496HigDec 11, 2024
    risk 0.51cvss 7.8epss 0.00

    Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation.

  • CVE-2024-11598HigDec 11, 2024
    risk 0.51cvss 7.8epss 0.00

    Under specific circumstances, insecure permissions in Ivanti Application Control before version 2024.3 HF1, 2024.1 HF2, or 2023.3 HF3 allows a local authenticated attacker to achieve local privilege escalation.

  • CVE-2024-11597HigDec 11, 2024
    risk 0.51cvss 7.8epss 0.00

    Under specific circumstances, insecure permissions in Ivanti Performance Manager before version 2024.3 HF1, 2024.1 HF1, or 2023.3 HF1 allows a local authenticated attacker to achieve local privilege escalation.

  • CVE-2024-10251HigDec 11, 2024
    risk 0.51cvss 7.8epss 0.00

    Under specific circumstances, insecure permissions in Ivanti Security Controls before version 2024.4.1 allows a local authenticated attacker to achieve local privilege escalation.

  • CVE-2024-39709HigNov 13, 2024
    risk 0.51cvss 7.8epss 0.00

    Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalate their privileges.

  • CVE-2024-37398HigNov 13, 2024
    risk 0.51cvss 7.8epss 0.00

    Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

  • CVE-2024-7571HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.

  • CVE-2024-50323HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.01

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.

  • CVE-2024-50322HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.06

    Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.

  • CVE-2024-50320HigNov 12, 2024
    risk 0.51cvss 7.5epss 0.41

    An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-47906HigNov 12, 2024
    risk 0.51cvss 7.8epss 0.00

    Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges.

  • CVE-2024-29821HigOct 18, 2024
    risk 0.51cvss 7.8epss 0.00

    Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.

  • CVE-2024-29213HigOct 18, 2024
    risk 0.51cvss 7.8epss 0.00

    Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.

  • CVE-2024-9167HigOct 8, 2024
    risk 0.51cvss 7.8epss 0.00

    Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.

Page 5 of 11