Vulnerabilities (CVE)

Filtered by vendor Ivanti Subscribe
Total 495 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-8012 1 Ivanti 1 Workspace Control 2026-06-17 N/A 7.8 HIGH
An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.
CVE-2024-7612 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 8.8 HIGH
Insecure permissions in Ivanti EPMM before 12.1.0.4 allow a local authenticated attacker to modify sensitive application components.
CVE-2024-7593 1 Ivanti 1 Virtual Traffic Manager 2026-06-17 N/A 9.8 CRITICAL
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
CVE-2024-7572 1 Ivanti 1 Desktop \& Server Management 2026-06-17 N/A 7.1 HIGH
Insufficient permissions in Ivanti DSM before version 2024.3.5740 allows a local authenticated attacker to delete arbitrary files.
CVE-2024-7571 2 Ivanti, Microsoft 2 Secure Access Client, Windows 2026-06-17 N/A 7.8 HIGH
Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
CVE-2024-7570 1 Ivanti 1 Neurons For Itsm 2026-06-17 N/A 8.3 HIGH
Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.
CVE-2024-7569 1 Ivanti 1 Neurons For Itsm 2026-06-17 N/A 9.6 CRITICAL
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
CVE-2024-50331 1 Ivanti 1 Avalanche 2026-06-17 N/A 7.5 HIGH
An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.
CVE-2024-50330 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 9.8 CRITICAL
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution.
CVE-2024-50329 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.8 HIGH
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
CVE-2024-50328 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.2 HIGH
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-50327 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.2 HIGH
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-50326 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.2 HIGH
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-50324 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.2 HIGH
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-50323 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.8 HIGH
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.
CVE-2024-50322 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.8 HIGH
Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code execution. User interaction is required.
CVE-2024-50321 1 Ivanti 1 Avalanche 2026-06-17 N/A 7.5 HIGH
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-50320 1 Ivanti 1 Avalanche 2026-06-17 N/A 7.5 HIGH
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-50319 1 Ivanti 1 Avalanche 2026-06-17 N/A 7.5 HIGH
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-50318 1 Ivanti 1 Avalanche 2026-06-17 N/A 7.5 HIGH
A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.