ivanti

496 tracked vulnerabilities.

CVE-2022-36972 CRITICAL
Ivanti Avalanche 6.3.2.3490-6.3.4 - SQL Injection via ProfileDaoImpl
Mar 29, 2023
CVSS 9.8
EPSS 0.31
CVE-2022-36971 HIGH
Ivanti Avalanche 6.3.2.3490-6.3.4 - Remote Code Execution via JwtTokenUtility Deserialization
Mar 29, 2023
CVSS 8.8
EPSS 0.86
CVE-2022-44574 HIGH
Ivanti Avalanche < 6.4.0 - Unauthenticated Property Modification via Specific Port
Mar 10, 2023
CVSS 7.5
EPSS 0.22
CVE-2022-35259 HIGH
Endpoint Manager <2022.3 - Code Injection
Dec 05, 2022
CVSS 7.8
EPSS 0.01
CVE-2022-35258 HIGH
Ivanti <9.1R14.3, <9.1R15.2, <9.1R16.2, <22.2R4 - DoS
Dec 05, 2022
CVSS 7.5
EPSS 0.10
CVE-2022-35254 HIGH
Ivanti Connect Secure < 9.1R14.3, 9.1R15.2, 9.1R16.2, 22.2R4 - Unauthenticated Denial of Service
Dec 05, 2022
CVSS 7.5
EPSS 0.10
CVE-2022-27773 CRITICAL
Ivanti Endpoint Manager < 2021.1 - Privilege Escalation via Incorrect Default Permissions
Dec 05, 2022
CVSS 9.8
EPSS 0.07
CVE-2022-21826 MEDIUM
Ivanti Connect Secure - HTTP Request Smuggling via POST Content-Length Mismanagement
Sep 30, 2022
CVSS 5.4
EPSS 0.06
CVE-2022-30121 MEDIUM
Ivanti Endpoint Manager < 2021.1.1 - Privilege Escalation via LANDesk Management Agent Service
Sep 23, 2022
CVSS 6.7
EPSS 0.00
CVE-2022-22572 HIGH
Incapptic Connect <1.40.1 - Privilege Escalation
Apr 11, 2022
CVSS 8.8
EPSS 0.20
CVE-2022-22571 MEDIUM
Ivanti Incapptic Connect < 1.40.3 - Authenticated Stored Cross-Site Scripting
Apr 11, 2022
CVSS 4.8
EPSS 0.00
CVE-2022-27088 HIGH
Ivanti DSM Remote <6.3.1.1862 - Privilege Escalation
Apr 11, 2022
CVSS 7.8
EPSS 0.00
CVE-2022-21828 HIGH
Ivanti Incapptic Connect 1.35.3-1.40.0 - Authenticated Remote Code Execution via Untrusted Data Deserialization
Mar 04, 2022
CVSS 7.2
EPSS 0.15
CVE-2022-21823 MEDIUM
Ivanti Workspace Control <2021.2 - Info Disclosure
Jan 10, 2022
CVSS 5.5
EPSS 0.00
CVE-2021-22962 CRITICAL
Ivanti Avalanche < 6.4.2 - Sensitive Data Leakage and Denial of Service
Dec 19, 2023
CVSS 9.1
EPSS 0.28
CVE-2021-44720 HIGH
Ivanti Pulse Connect Secure < 9.1R12 - Unauthenticated Privilege Escalation via Hard-coded Credentials in Targets.cgi
Aug 12, 2022
CVSS 7.2
EPSS 0.03
CVE-2021-30497 HIGH NUCLEI
Ivanti Avalanche (Premise) 6.3.2 - Path Traversal
Apr 06, 2022
CVSS 7.5
EPSS 0.93
CVE-2021-38560 MEDIUM
Ivanti Service Manager 2021.1 - XSS
Feb 01, 2022
CVSS 6.1
EPSS 0.01
CVE-2021-44529 CRITICAL KEVNUCLEI
Ivanti Endpoint Manager Cloud Services Appliance < 4.5 - Unauthenticated Remote Code Execution
Dec 08, 2021
CVSS 9.8
EPSS 0.94
CVE-2021-42133 HIGH
Ivanti Avalanche <6.3.3 - Privilege Escalation
Dec 07, 2021
CVSS 8.1
EPSS 0.14
CVE-2021-42132 HIGH
Ivanti Avalanche < 6.3.3 - Authenticated Command Injection via Inforail Service
Dec 07, 2021
CVSS 8.8
EPSS 0.70
CVE-2021-42131 HIGH
Ivanti Avalanche < 6.3.3 - SQL Injection via Inforail Service
Dec 07, 2021
CVSS 8.8
EPSS 0.27
CVE-2021-42130 HIGH
Ivanti Avalanche < 6.3.3 - Remote Code Execution via Deserialization of Untrusted Data
Dec 07, 2021
CVSS 8.8
EPSS 0.77
CVE-2021-42129 HIGH
Ivanti Avalanche < 6.3.3 - Authenticated Command Injection via Inforail Service
Dec 07, 2021
CVSS 8.8
EPSS 0.70
CVE-2021-42128 CRITICAL
Ivanti Avalanche < 6.3.3 - Privilege Escalation via Enterprise Server Service
Dec 07, 2021
CVSS 9.8
EPSS 0.17