Vulnerabilities (CVE)

Filtered by vendor Ivanti Subscribe
Total 495 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-9845 1 Ivanti 1 Automation 2026-06-17 N/A 7.8 HIGH
Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation.
CVE-2024-9844 1 Ivanti 1 Connect Secure 2026-06-17 N/A 7.1 HIGH
Insufficient server-side controls in Secure Application Manager of Ivanti Connect Secure before version 22.7R2.4 allows a remote authenticated attacker to bypass restrictions.
CVE-2024-9843 2 Apple, Ivanti 2 Macos, Secure Access Client 2026-06-17 N/A 5.0 MEDIUM
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
CVE-2024-9842 2 Ivanti, Microsoft 2 Secure Access Client, Windows 2026-06-17 N/A 7.3 HIGH
Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.
CVE-2024-9420 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 8.8 HIGH
A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution
CVE-2024-9381 1 Ivanti 1 Endpoint Manager Cloud Services Appliance 2026-06-17 N/A 7.2 HIGH
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
CVE-2024-9380 1 Ivanti 1 Endpoint Manager Cloud Services Appliance 2026-06-17 N/A 7.2 HIGH
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
CVE-2024-9379 1 Ivanti 1 Endpoint Manager Cloud Services Appliance 2026-06-17 N/A 6.5 MEDIUM
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
CVE-2024-9167 1 Ivanti 1 Velocity License Server 2026-06-17 N/A 7.8 HIGH
Under specific circumstances, insecure permissions in Ivanti Velocity License Server before version 5.2 allows a local authenticated attacker to achieve local privilege escalation.
CVE-2024-8963 1 Ivanti 1 Endpoint Manager Cloud Services Appliance 2026-06-17 N/A 9.4 CRITICAL
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
CVE-2024-8540 1 Ivanti 1 Standalone Sentry 2026-06-17 N/A 8.8 HIGH
Insecure permissions in Ivanti Sentry before versions 9.20.2 and 10.0.2 or 10.1.0 allow a local authenticated attacker to modify sensitive application components.
CVE-2024-8539 4 Apple, Ivanti, Linux and 1 more 4 Macos, Secure Access Client, Linux Kernel and 1 more 2026-06-17 N/A 7.1 HIGH
Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files.
CVE-2024-8496 1 Ivanti 1 Workspace Control 2026-06-17 N/A 7.8 HIGH
Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation.
CVE-2024-8495 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 7.5 HIGH
A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-8441 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 6.7 MEDIUM
An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.
CVE-2024-8322 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 4.3 MEDIUM
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.
CVE-2024-8321 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 5.8 MEDIUM
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.
CVE-2024-8320 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 5.3 MEDIUM
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.
CVE-2024-8191 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.8 HIGH
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
CVE-2024-8190 1 Ivanti 1 Cloud Services Appliance 2026-06-17 N/A 7.2 HIGH
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.