ivanti

496 tracked vulnerabilities.

CVE-2024-34784 HIGH
Ivanti Endpoint Manager < 2022 - Authenticated SQL Injection
Nov 13, 2024
CVSS 7.2
EPSS 0.06
CVE-2024-34782 HIGH
Ivanti Endpoint Manager < 2022 SU6 November Security Update - Authenticated SQL Injection
Nov 13, 2024
CVSS 7.2
EPSS 0.06
CVE-2024-34781 HIGH
Ivanti Endpoint Manager < 2022 SU6 November Security Update - Authenticated SQL Injection
Nov 13, 2024
CVSS 7.2
EPSS 0.68
CVE-2024-34780 HIGH
Ivanti Endpoint Manager < 2022 SU6 November Security Update - Authenticated SQL Injection
Nov 13, 2024
CVSS 7.2
EPSS 0.06
CVE-2024-32847 HIGH
Ivanti Endpoint Manager < 2022 SU6 November Security Update - Authenticated SQL Injection
Nov 13, 2024
CVSS 7.2
EPSS 0.11
CVE-2024-32844 HIGH
Ivanti Endpoint Manager < 2022 SU6 November Security Update - Authenticated SQL Injection
Nov 13, 2024
CVSS 7.2
EPSS 0.06
CVE-2024-32841 HIGH
Ivanti Endpoint Manager SQL Injection (Auth Required)
Nov 13, 2024
CVSS 7.2
EPSS 0.09
CVE-2024-32839 HIGH
Ivanti Endpoint Manager < 2022 SU6 November Security Update - Authenticated SQL Injection
Nov 13, 2024
CVSS 7.2
EPSS 0.09
CVE-2024-29211 MEDIUM
Ivanti Secure Access Client <22.7R4 - Privilege Escalation
Nov 13, 2024
CVSS 4.7
EPSS 0.00
CVE-2024-9843 MEDIUM
Ivanti Secure Access Client < 22.7R4 - Unauthenticated Denial of Service via Buffer Over-Read
Nov 12, 2024
CVSS 5.0
EPSS 0.00
CVE-2024-9842 HIGH
Ivanti Secure Access Client < 22.7R4 - Authenticated Arbitrary Folder Creation via Incorrect Permissions
Nov 12, 2024
CVSS 7.3
EPSS 0.00
CVE-2024-8539 HIGH
Ivanti Secure Access Client <22.7R3 - Privilege Escalation
Nov 12, 2024
CVSS 7.1
EPSS 0.00
CVE-2024-7571 HIGH
Ivanti Secure Access Client <22.7R4 - Privilege Escalation
Nov 12, 2024
CVSS 7.8
EPSS 0.00
CVE-2024-11006 CRITICAL
Ivanti Connect Secure < 22.7R2.1 and Policy Secure < 22.7R1.1 - Authenticated Remote Code Execution
Nov 12, 2024
CVSS 9.1
EPSS 0.18
CVE-2024-11005 CRITICAL
Ivanti Connect Secure < 22.7R2.1 and Policy Secure < 22.7R1.1 - Authenticated Remote Code Execution
Nov 12, 2024
CVSS 9.1
EPSS 0.18
CVE-2024-11004 MEDIUM
Ivanti Connect Secure < 22.7 and Policy Secure < 22.7 - Unauthenticated Reflected Cross-Site Scripting
Nov 12, 2024
CVSS 6.1
EPSS 0.00
CVE-2024-9420 HIGH
Ivanti Connect Secure < 22.7R2.3 and < 9.1R18.9 - Authenticated Remote Code Execution via Use-After-Free
Nov 12, 2024
CVSS 8.8
EPSS 0.19
CVE-2024-8495 HIGH
Ivanti Connect/Ivanti Policy Secure <22.7R2.1/<22.7R1.1 - DoS
Nov 12, 2024
CVSS 7.5
EPSS 0.05
CVE-2024-50331 HIGH
Ivanti Avalanche < 6.4.6 - Unauthenticated Out-of-bounds Read
Nov 12, 2024
CVSS 7.5
EPSS 0.04
CVE-2024-50330 CRITICAL
Ivanti Endpoint Manager SQL Injection (Unauthenticated)
Nov 12, 2024
CVSS 9.8
EPSS 0.77
CVE-2024-50329 HIGH
Ivanti Endpoint Manager < 2022 SU6 November Security Update - Unauthenticated Path Traversal and Remote Code Execution
Nov 12, 2024
CVSS 8.8
EPSS 0.25
CVE-2024-50328 HIGH
Ivanti Endpoint Manager < 2022 SU6 November Security Update - Authenticated SQL Injection
Nov 12, 2024
CVSS 7.2
EPSS 0.18
CVE-2024-50327 HIGH
Ivanti Endpoint Manager SQL Injection (Auth Required)
Nov 12, 2024
CVSS 7.2
EPSS 0.10
CVE-2024-50326 HIGH
Ivanti Endpoint Manager < 2022 SU6 November Security Update - Authenticated SQL Injection
Nov 12, 2024
CVSS 7.2
EPSS 0.68
CVE-2024-50324 HIGH
Ivanti Endpoint Manager < 2022 SU6 November Security Update - Authenticated Path Traversal and Remote Code Execution
Nov 12, 2024
CVSS 7.2
EPSS 0.79