Vulnerabilities (CVE)

Filtered by vendor Ivanti Subscribe
Total 495 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-32840 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.2 HIGH
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-32839 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.2 HIGH
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-29848 1 Ivanti 1 Avalanche 2026-06-17 N/A 7.2 HIGH
An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.
CVE-2024-29847 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 9.8 CRITICAL
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
CVE-2024-29846 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.0 HIGH
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
CVE-2024-29830 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.0 HIGH
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
CVE-2024-29829 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.0 HIGH
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
CVE-2024-29828 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.0 HIGH
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
CVE-2024-29827 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.8 HIGH
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
CVE-2024-29826 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.8 HIGH
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
CVE-2024-29825 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.8 HIGH
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
CVE-2024-29824 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.8 HIGH
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
CVE-2024-29823 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.8 HIGH
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
CVE-2024-29822 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.8 HIGH
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
CVE-2024-29821 1 Ivanti 1 Desktop \& Server Management 2026-06-17 N/A 7.8 HIGH
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
CVE-2024-29213 1 Ivanti 1 Desktop \& Server Management 2026-06-17 N/A 7.8 HIGH
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
CVE-2024-29211 1 Ivanti 1 Secure Access Client 2026-06-17 N/A 4.7 MEDIUM
A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.
CVE-2024-29204 1 Ivanti 1 Avalanche 2026-06-17 N/A 9.8 CRITICAL
A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands
CVE-2024-27984 1 Ivanti 1 Avalanche 2026-06-17 N/A 7.1 HIGH
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete specific type of files and/or cause denial of service.
CVE-2024-27978 1 Ivanti 1 Avalanche 2026-06-17 N/A 6.5 MEDIUM
A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.