Skip to content
Noroxi

ivanti records

504 published records for vendor ivanti.

All records

504 records
  • In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    ivanti · connect secureMay 8, 2019

  • An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    ivanti · standalone sentryJun 9, 2026

  • Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated a

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    ivanti · virtual traffic managerAug 13, 2024

  • An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appli

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    ivanti · endpoint manager mobileJul 25, 2023

  • An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resou

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    ivanti · endpoint manager mobileAug 15, 2023

  • A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    ivanti · connect secureApr 3, 2025

  • A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass a

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    ivanti · mobileiron sentryAug 21, 2023

  • A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code wit

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    ivanti · endpoint manager cloud services applianceDec 8, 2021

  • A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    ivanti · endpoint manager mobileJan 29, 2026

  • A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    ivanti · endpoint manager mobileJan 29, 2026

  • A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an aut

    CriticalCVSS 9.1KEVWeaponizedEPSS 100%

    ivanti · connect secureJan 12, 2024

  • A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neu

    CriticalCVSS 9.0KEVWeaponizedEPSS 100%

    ivanti · connect secureJan 8, 2025

  • Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

    CriticalCVSS 9.1KEVWeaponizedEPSS 99%

    ivanti · endpoint manager cloud services applianceSep 19, 2024

  • An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the sam

    HighCVSS 8.8KEVWeaponizedEPSS 100%

    ivanti · endpoint managerMay 31, 2024

  • A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x)

    HighCVSS 8.2KEVWeaponizedEPSS 100%

    ivanti · connect secureJan 31, 2024

  • An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to acc

    HighCVSS 8.2KEVWeaponizedEPSS 100%

    ivanti · connect secureJan 12, 2024

  • Remote Code Execution

    HighCVSS 8.8KEVWeaponizedEPSS 87%

    ivanti · endpoint manager mobileMay 13, 2025

  • Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    ivanti · endpoint managerJan 14, 2025

  • Authentication Bypass

    HighCVSS 7.5KEVWeaponizedEPSS 100%

    ivanti · endpoint manager mobileMay 13, 2025

  • In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 an

    HighCVSS 7.2KEVWeaponizedEPSS 99%

    ivanti · connect secureApr 25, 2019

  • A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code e

    HighCVSS 7.2KEVWeaponizedEPSS 96%

    ivanti · connect secureOct 28, 2020

  • Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote

    HighCVSS 7.5KEVWeaponizedEPSS 91%

    ivanti · endpoint managerJan 14, 2025

  • Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote

    HighCVSS 7.5KEVWeaponizedEPSS 90%

    ivanti · endpoint managerJan 14, 2025

  • An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored

    HighCVSS 7.5KEVWeaponizedEPSS 88%

    ivanti · endpoint managerFeb 10, 2026

  • A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to

    HighCVSS 7.2KEVWeaponizedEPSS 91%

    ivanti · connect secureSep 30, 2020