VYPR

Vendor CVEs

Ivanti

All CVEs

515 total · sorted by risk
  • CVE-2025-8297HigAug 12, 2025
    risk 0.47cvss 7.2epss 0.01

    Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to achieve remote code execution

  • CVE-2025-8296HigAug 12, 2025
    risk 0.47cvss 7.2epss 0.01

    SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL queries. In certain conditions, this can also lead to remote code execution

  • CVE-2025-7037HigJul 8, 2025
    risk 0.47cvss 7.2epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database

  • CVE-2025-22463HigJun 10, 2025
    risk 0.47cvss 7.3epss 0.00

    A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment password.

  • CVE-2025-22461HigApr 8, 2025
    risk 0.47cvss 7.2epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privileges to achieve code execution.

  • CVE-2024-13158HigJan 14, 2025
    risk 0.47cvss 7.2epss 0.03

    An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2025-0283HigJan 8, 2025
    risk 0.47cvss 7.0epss 0.17

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.

  • CVE-2024-38655HigNov 13, 2024
    risk 0.47cvss 7.2epss 0.02

    Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-37376HigNov 13, 2024
    risk 0.47cvss 7.2epss 0.03

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-34784HigNov 13, 2024
    risk 0.47cvss 7.2epss 0.02

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-34782HigNov 13, 2024
    risk 0.47cvss 7.2epss 0.02

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-34780HigNov 13, 2024
    risk 0.47cvss 7.2epss 0.02

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-32847HigNov 13, 2024
    risk 0.47cvss 7.2epss 0.03

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-32844HigNov 13, 2024
    risk 0.47cvss 7.2epss 0.02

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-32841HigNov 13, 2024
    risk 0.47cvss 7.2epss 0.03

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-32839HigNov 13, 2024
    risk 0.47cvss 7.2epss 0.03

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-9842HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.

  • CVE-2024-50328HigNov 12, 2024
    risk 0.47cvss 7.2epss 0.02

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-50327HigNov 12, 2024
    risk 0.47cvss 7.2epss 0.01

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-32846HigSep 12, 2024
    risk 0.47cvss 7.2epss 0.02

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-32843HigSep 12, 2024
    risk 0.47cvss 7.2epss 0.02

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-32842HigSep 12, 2024
    risk 0.47cvss 7.2epss 0.02

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-37373HigAug 14, 2024
    risk 0.47cvss 7.2epss 0.02

    Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.

  • CVE-2023-46810HigMay 31, 2024
    risk 0.47cvss 7.3epss 0.00

    A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as root.

  • CVE-2023-41719HigDec 14, 2023
    risk 0.47cvss 7.2epss 0.03

    A vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker impersonating an administrator may craft a specific web request which may lead to remote code execution.

  • CVE-2021-44720HigAug 12, 2022
    risk 0.47cvss 7.2epss 0.03

    In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write…

  • CVE-2022-21828HigMar 4, 2022
    risk 0.47cvss 7.2epss 0.04

    A user with high privilege access to the Incapptic Connect web console can remotely execute code on the Incapptic Connect server using a unspecified attack vector in Incapptic Connect version 1.40.0, 1.39.1, 1.39.0, 1.38.1, 1.38.0, 1.37.1, 1.37.0, 1.36.0, 1.35.5, 1.35.4 and…

  • CVE-2021-22938HigAug 16, 2021
    risk 0.47cvss 7.2epss 0.02

    A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter in the administrator web console.

  • CVE-2021-22937HigAug 16, 2021
    risk 0.47cvss 7.2epss 0.08

    A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface.

  • CVE-2021-22935HigAug 16, 2021
    risk 0.47cvss 7.2epss 0.02

    A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter.

  • CVE-2021-22934HigAug 16, 2021
    risk 0.47cvss 7.2epss 0.05

    A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or compromised Pulse Connect Secure device in a load-balanced configuration to perform a buffer overflow via a malicious crafted web request.

  • CVE-2020-15352HigOct 27, 2020
    risk 0.47cvss 7.2epss 0.03

    An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

  • CVE-2020-8219HigJul 30, 2020
    risk 0.47cvss 7.2epss 0.02

    An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full administrator.

  • CVE-2014-5362HigSep 19, 2017
    risk 0.47cvss 7.2epss 0.03

    The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving ASPX pages from third-party sites via the d parameter to (1) ldms/sm_actionfrm.asp or (2) remote/frm_coremainfrm.aspx; or the (3) top…

  • CVE-2026-5788HigMay 7, 2026
    risk 0.46cvss 7.0epss 0.01

    An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

  • CVE-2025-13661HigDec 9, 2025
    risk 0.46cvss 7.1epss 0.01

    Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required.

  • CVE-2025-10918HigNov 11, 2025
    risk 0.46cvss 7.1epss 0.00

    Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk

  • CVE-2024-13813HigFeb 11, 2025
    risk 0.46cvss 7.1epss 0.00

    Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files.

  • CVE-2024-9844HigDec 10, 2024
    risk 0.46cvss 7.1epss 0.01

    Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker to bypass restrictions.

  • CVE-2024-7572HigDec 10, 2024
    risk 0.46cvss 7.1epss 0.00

    Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.

  • CVE-2024-10256HigDec 10, 2024
    risk 0.46cvss 7.1epss 0.00

    Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.

  • CVE-2024-8539HigNov 12, 2024
    risk 0.46cvss 7.1epss 0.00

    Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files.

  • CVE-2024-27984HigApr 19, 2024
    risk 0.46cvss 7.1epss 0.02

    A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete specific type of files and/or cause denial of service.

  • CVE-2023-38041HigOct 25, 2023
    risk 0.46cvss 7.0epss 0.01

    A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system.

  • CVE-2023-41474MedJan 25, 2024
    risk 0.45cvss 6.5epss 0.38

    Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.

  • CVE-2025-55139MedSep 9, 2025
    risk 0.44cvss 6.8epss 0.01

    SSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to…

  • CVE-2023-39338MedJul 12, 2025
    risk 0.44cvss 6.8epss 0.01

    Enables an authenticated user (enrolled device) to access a service protected by Sentry even if they are not authorized according to the sentry policy to access that service. It does not enable the user to authenticate to or use the service, it just provides the tunnel access.

  • CVE-2024-12058MedFeb 11, 2025
    risk 0.44cvss 6.8epss 0.01

    External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.

  • CVE-2024-8441MedSep 10, 2024
    risk 0.44cvss 6.7epss 0.00

    An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.

  • CVE-2024-22026MedMay 22, 2024
    risk 0.44cvss 6.7epss 0.01

    A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.

Page 8 of 11