← Back

Ivanti

ivanti

492 CVEs • 41 products

Products (41)

Click to collapse
Toggle
Avalanche
avalanche
Policy Secure
policy_secure
Mobileiron
mobileiron
Automation
automation
Dsm Netinst
dsm_netinst
Dsm Remote
dsm_remote
Docs@work
docs@work
Xtraction
xtraction

CVEs (492)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ivanti
1Avalanche
Jun 17, 2026
Jun 29, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access privileges can read the encrypted passwords for users who authenticate via LDAP to Avalanche services. T...Show more
An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access privileges can read the encrypted passwords for users who authenticate via LDAP to Avalanche services. These passwords are stored in the Avalanche databases. This issue only affects customers who have enabled LDAP authentication in their configuration.Show less
1Ivanti
1Endpoint Security
Jun 17, 2026
Feb 15, 2018
N/A· v4
7.5 HIGH· v3
6.0 MEDIUM· v2
Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting...Show more
Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting when using the Application Control module on Ivanti Endpoint Security in lockdown mode.Show less
1Ivanti
1Endpoint Manager
May 13, 2026
Dec 11, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Ivanti Service Desk (formerly LANDESK Management Suite) versions between 2016.3 and 2017.3, an Unrestricted Direct Object Reference leads to referencing/updating objects belonging to other users. In other words, a nor...Show more
In Ivanti Service Desk (formerly LANDESK Management Suite) versions between 2016.3 and 2017.3, an Unrestricted Direct Object Reference leads to referencing/updating objects belonging to other users. In other words, a normal user can send requests to a specific URI with the target user's username in an HTTP payload in order to retrieve a key/token and use it to access/update objects belonging to other users. Such objects could be user profiles, tickets, incidents, etc.Show less
2Ivanti
Pulsesecure
3Connect Secure
Pulse Connect SecurePulse Policy Secure
May 13, 2026
Aug 29, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8, and 5.1R1 through 5.1R10 allow remote attackers to hijack the authentication of...Show more
diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8, and 5.1R1 through 5.1R10 allow remote attackers to hijack the authentication of administrators for requests to start tcpdump, related to the lack of anti-CSRF tokens.Show less
1Ivanti
1Landesk Management Suite
May 13, 2026
Jan 23, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Buffer overflow in the collector.exe listener of the Landesk Management Suite 10.0.0.271 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large packet.
1Ivanti
1Connect Secure
May 6, 2026
May 26, 2016
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
Pulse Connect Secure (PCS) 8.2 before 8.2r1 allows remote attackers to disclose sign in pages via unspecified vectors.
2Ivanti
Pulsesecure
2Connect Secure
Pulse Connect Secure
May 6, 2026
May 26, 2016
N/A· v4
8.6 HIGH· v3
6.4 MEDIUM· v2
The administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote administrators to enumerate files, read arbitrary files, and con...Show more
The administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote administrators to enumerate files, read arbitrary files, and conduct server side request forgery (SSRF) attacks via unspecified vectors.Show less
2Ivanti
Pulsesecure
2Connect Secure
Pulse Connect Secure
May 6, 2026
May 26, 2016
N/A· v4
5.5 MEDIUM· v3
3.5 LOW· v2
Cross-site scripting (XSS) vulnerability in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject...Show more
Cross-site scripting (XSS) vulnerability in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
2Ivanti
Pulsesecure
2Connect Secure
Pulse Connect Secure
May 6, 2026
May 26, 2016
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in the system configuration section in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13....Show more
Cross-site scripting (XSS) vulnerability in the system configuration section in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.Show less
2Ivanti
Pulsesecure
2Connect Secure
Pulse Connect Secure
May 6, 2026
May 26, 2016
N/A· v4
5.8 MEDIUM· v3
5.0 MEDIUM· v2
Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read an unspecified system file via unknown vectors.
2Ivanti
Pulsesecure
2Connect Secure
Pulse Connect Secure
May 6, 2026
May 26, 2016
N/A· v4
10.0 CRITICAL· v3
6.4 MEDIUM· v2
Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read sensitive system authentication files in an unspecified directory via unknown vecto...Show more
Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read sensitive system authentication files in an unspecified directory via unknown vectors.Show less
2Ivanti
Pulsesecure
2Connect Secure
Pulse Connect Secure
May 6, 2026
May 26, 2016
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r3, 8.0 before 8.0r11, and 7.4 before 7.4r13.4 allow remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.