← Back

Ivanti

ivanti

492 CVEs • 41 products

Products (41)

Click to collapse
Toggle
Avalanche
avalanche
Policy Secure
policy_secure
Mobileiron
mobileiron
Automation
automation
Dsm Netinst
dsm_netinst
Dsm Remote
dsm_remote
Docs@work
docs@work
Xtraction
xtraction

CVEs (492)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ivanti
1Avalanche
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
1Ivanti
1Avalanche
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
1Ivanti
1Avalanche
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
1Ivanti
2Connect Secure
Policy Secure
Jun 17, 2026
Nov 12, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
1Ivanti
1Connect Secure
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A stack-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.
1Ivanti
2Connect Secure
Policy Secure
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to e...Show more
Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges.Show less
1Ivanti
2Connect Secure
Policy Secure
Jun 17, 2026
Nov 12, 2024
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
1Ivanti
2Connect Secure
Policy Secure
Jun 17, 2026
Nov 12, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin pr...Show more
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.Show less
1Ivanti
2Connect Secure
Policy Secure
Jun 17, 2026
Oct 18, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.
1Ivanti
1Desktop & Server Management
Jun 17, 2026
Oct 18, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
1Ivanti
1Desktop & Server Management
Jun 17, 2026
Oct 18, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
1Ivanti
1Endpoint Manager Cloud Services Appliance
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
1Ivanti
1Endpoint Manager Cloud Services Appliance
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
1Ivanti
1Endpoint Manager Cloud Services Appliance
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
1Ivanti
1Velocity License Server
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.
1Ivanti
1Endpoint Manager Mobile
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.
1Ivanti
1Avalanche
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information
1Ivanti
1Avalanche
Jun 17, 2026
Oct 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
1Ivanti
1Avalanche
Jun 17, 2026
Oct 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
1Ivanti
1Avalanche
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.