CVEs (77)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin pr...Show more |
1Ivanti 2Connect Secure Policy SecureJan 17, 2025 Nov 12, 2024 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required. |
A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9
and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution |
A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to cause a denial of service. |
1Ivanti 2Connect Secure Policy SecureNov 18, 2024 Nov 12, 2024 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service. |
Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to e...Show more |
1Ivanti 2Connect Secure Policy SecureNov 18, 2024 Nov 12, 2024 N/A· v4 4.9 MEDIUM· v3 N/A· v2 A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service. |
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin pr...Show more |
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution. |
1Ivanti 2Connect Secure Policy SecureNov 21, 2024 Apr 4, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service the...Show more |
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service the...Show more |
A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the...Show more |
1Ivanti 2Connect Secure Policy SecureNov 21, 2024 Apr 4, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated attacker to send specially crafted XML requests in-order-to temporari...Show more |
1Ivanti 3Connect Secure Policy SecureZero Trust Access GatewayOct 31, 2025 Feb 13, 2024 N/A· v4 8.3 HIGH· v3 N/A· v2 An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker to access certain restricted resources wi...Show more |
1Ivanti 3Connect Secure Neurons For Zero Trust AccessPolicy SecureOct 30, 2025 Jan 31, 2024 N/A· v4 8.2 HIGH· v3 N/A· v2 A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resou...Show more |
A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator. |
1Ivanti 2Connect Secure Policy SecureOct 31, 2025 Jan 12, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrar...Show more |
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks. |
1Ivanti 3Connect Secure Neurons For Zero Trust AccessPolicy SecureNov 21, 2024 Dec 5, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior...Show more |
1Ivanti 3Connect Secure Neurons For Zero Trust AccessPolicy SecureApr 24, 2025 Dec 5, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior...Show more |