Filtered by vendor Ivanti Subscriptions
Total 320 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2024-39710 1 Ivanti 2 Connect Secure, Policy Secure 2024-11-13 N/A
Argument injection in Ivanti Connect Secure before version 22.7R2 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-38649 1 Ivanti 1 Connect Secure 2024-11-13 N/A
An out-of-bounds write in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-37400 1 Ivanti 1 Connect Secure 2024-11-13 N/A
An out of bounds read in Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to trigger an infinite loop, causing a denial of service.
CVE-2024-9420 1 Ivanti 2 Connect Secure, Policy Secure 2024-11-13 8.8 High
A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution.
CVE-2024-11005 1 Ivanti 2 Connect Secure, Policy Secure 2024-11-13 9.1 Critical
Command injection in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-50331 1 Ivanti 1 Avalanche 2024-11-13 7.5 High
An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.
CVE-2024-11006 1 Ivanti 2 Connect Secure, Policy Secure 2024-11-13 9.1 Critical
Command injection in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-8539 1 Ivanti 1 Secure Access Client 2024-11-13 7.1 High
Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files.
CVE-2024-9843 1 Ivanti 1 Secure Access Client 2024-11-13 5 Medium
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
CVE-2024-39712 1 Ivanti 2 Connect Secure, Policy Secure 2024-11-13 N/A
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-38655 1 Ivanti 2 Connect Secure, Policy Secure 2024-11-13 N/A
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-29824 1 Ivanti 1 Endpoint Manager 2024-11-05 8.8 High
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
CVE-2024-9167 1 Ivanti 1 Velocity License Server 2024-11-04 7.8 High
Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.
CVE-2024-36130 1 Ivanti 1 Endpoint Manager Mobile 2024-10-24 9.8 Critical
An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.
CVE-2023-35077 2 Ivanti, Microsoft 2 Endpoint Manager, Windows 2024-10-24 7.5 High
An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update to Ivanti AV Product version 7.9.1.285 or above.
CVE-2024-29821 1 Ivanti 1 Desktop \& Server Management 2024-10-21 N/A
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
CVE-2024-29213 1 Ivanti 1 Desktop \& Server Management 2024-10-21 N/A
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
CVE-2024-37404 1 Ivanti 2 Connect Secure, Policy Secure 2024-10-21 N/A
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.
CVE-2023-41474 1 Ivanti 1 Avalanche 2024-10-18 6.5 Medium
Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.
CVE-2024-7612 1 Ivanti 1 Endpoint Manager Mobile 2024-10-17 8.8 High
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.