VYPR

Vendor CVEs

Ivanti

All CVEs

515 total · sorted by risk
  • CVE-2024-50326HigNov 12, 2024
    risk 0.49cvss 7.2epss 0.26

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-50321HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-50319HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.01

    An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-50318HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-50317HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-47907HigNov 12, 2024
    risk 0.49cvss 7.5epss 0.01

    A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-47007HigOct 8, 2024
    risk 0.49cvss 7.5epss 0.02

    A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-34785HigSep 12, 2024
    risk 0.49cvss 7.2epss 0.25

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-34779HigSep 12, 2024
    risk 0.49cvss 7.2epss 0.24

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-32845HigSep 12, 2024
    risk 0.49cvss 7.2epss 0.24

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-32840HigSep 12, 2024
    risk 0.49cvss 7.2epss 0.25

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-36136HigAug 14, 2024
    risk 0.49cvss 7.5epss 0.02

    An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.

  • CVE-2024-36132HigAug 7, 2024
    risk 0.49cvss 7.5epss 0.01

    Insufficient verification of authentication controls in EPMM prior to 12.1.0.1 allows a remote attacker to bypass authentication and access sensitive resources.

  • CVE-2024-29205HigApr 25, 2024
    risk 0.49cvss 7.5epss 0.02

    An Improper Check for Unusual or Exceptional Conditions vulnerability in the web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a remote unauthenticated attacker to send specially crafted requests in-order-to cause service disruptions.

  • CVE-2024-23527HigApr 25, 2024
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.

  • CVE-2024-24995HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.02

    A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2024-24993HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.02

    A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.

  • CVE-2024-23532HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks. In certain conditions this could also lead to remote code execution.

  • CVE-2024-23531HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.02

    An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory.

  • CVE-2024-23530HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.

  • CVE-2024-23529HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.

  • CVE-2024-23528HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.

  • CVE-2024-23526HigApr 19, 2024
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.

  • CVE-2024-22052HigApr 4, 2024
    risk 0.49cvss 7.5epss 0.04

    A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack

  • CVE-2023-46804HigDec 19, 2023
    risk 0.49cvss 7.5epss 0.04

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).

  • CVE-2023-46803HigDec 19, 2023
    risk 0.49cvss 7.5epss 0.04

    An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).

  • CVE-2023-39340HigDec 16, 2023
    risk 0.49cvss 7.5epss 0.02

    A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker can send a specific request which may lead to Denial of Service (DoS) of the appliance.

  • CVE-2023-38343HigSep 21, 2023
    risk 0.49cvss 7.5epss 0.01

    An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side…

  • CVE-2023-32561HigAug 10, 2023
    risk 0.49cvss 7.5epss 0.02

    A previously generated artifact by an administrator could be accessed by an attacker. The contents of this artifact could lead to authentication bypass. Fixed in version 6.4.1.

  • CVE-2023-35077HigJul 21, 2023
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update to Ivanti AV Product version 7.9.1.285 or above.

  • CVE-2022-35258HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.03

    An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust…

  • CVE-2022-35254HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.03

    An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust…

  • CVE-2019-19138HigDec 15, 2021
    risk 0.49cvss 7.5epss 0.02

    Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity.

  • CVE-2021-22965HigNov 19, 2021
    risk 0.49cvss 7.5epss 0.02

    A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device.

  • CVE-2018-20809HigJun 28, 2019
    risk 0.49cvss 7.5epss 0.03

    A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and Pulse Policy Secure 5.4RX before 5.4R5. This is not applicable to PCS 8.1RX.

  • CVE-2019-11541HigApr 26, 2019
    risk 0.49cvss 7.5epss 0.04

    In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.

  • CVE-2018-6316HigFeb 15, 2018
    risk 0.49cvss 7.5epss 0.02

    Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting when using the Application Control module on Ivanti…

  • CVE-2016-4786HigMay 26, 2016
    risk 0.49cvss 7.5epss 0.02

    Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r3, 8.0 before 8.0r11, and 7.4 before 7.4r13.4 allow remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.

  • CVE-2026-7821HigMay 7, 2026
    risk 0.48cvss 7.4epss 0.01

    Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance…

  • CVE-2025-10985HigOct 14, 2025
    risk 0.48cvss 7.2epss 0.21

    OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2025-10243HigOct 14, 2025
    risk 0.48cvss 7.2epss 0.21

    OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2025-10242HigOct 14, 2025
    risk 0.48cvss 7.2epss 0.21

    OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2025-6771HigJul 8, 2025
    risk 0.48cvss 7.2epss 0.16

    OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution

  • CVE-2025-6770HigJul 8, 2025
    risk 0.48cvss 7.2epss 0.13

    OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution

  • CVE-2024-50324HigNov 12, 2024
    risk 0.48cvss 7.2epss 0.18

    Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-9381HigOct 8, 2024
    risk 0.48cvss 7.2epss 0.16

    Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.

  • CVE-2024-47009HigOct 8, 2024
    risk 0.48cvss 7.3epss 0.02

    Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

  • CVE-2019-11508HigMay 8, 2019
    risk 0.48cvss 7.2epss 0.15

    In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) can exploit Directory Traversal to execute arbitrary code on the appliance.

  • CVE-2026-10727HigJun 9, 2026
    risk 0.47cvss 7.2epss 0.14

    An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root

  • CVE-2026-8051HigMay 12, 2026
    risk 0.47cvss 7.2epss 0.02

    OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Page 7 of 11