Перейти к содержимому
Noroxi

Записи ivanti

504 опубликованных записей вендора ivanti.

Профиль для исследователя

Попали в KEV
35 · 6,9 %
С эксплойтом
39 · 7,7 %
Pre-auth RCE
45
С записью об исправлении
12,5 %
Медиана: публикация → KEV
27 дн.

Все записи

504 записей
  • CVE-2019-11510
    100Срочно

    In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    ivanti · connect secure8 мая 2019 г.

  • CVE-2026-10520
    100Срочно

    An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    ivanti · standalone sentry9 июн. 2026 г.

  • CVE-2024-7593
    99Срочно

    Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated a

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    ivanti · virtual traffic manager13 авг. 2024 г.

  • CVE-2023-35078
    99Срочно

    An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appli

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    ivanti · endpoint manager mobile25 июл. 2023 г.

  • CVE-2023-35082
    99Срочно

    An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resou

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    ivanti · endpoint manager mobile15 авг. 2023 г.

  • CVE-2025-22457
    99Срочно

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    ivanti · connect secure3 апр. 2025 г.

  • CVE-2023-38035
    99Срочно

    A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass a

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    ivanti · mobileiron sentry21 авг. 2023 г.

  • CVE-2021-44529
    99Срочно

    A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code wit

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    ivanti · endpoint manager cloud services appliance8 дек. 2021 г.

  • CVE-2026-1281
    99Срочно

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    ivanti · endpoint manager mobile29 янв. 2026 г.

  • CVE-2026-1340
    99Срочно

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    ivanti · endpoint manager mobile29 янв. 2026 г.

  • CVE-2024-21887
    96Срочно

    A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an aut

    КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 100 %

    ivanti · connect secure12 янв. 2024 г.

  • CVE-2025-0282
    96Срочно

    A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neu

    КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %

    ivanti · connect secure8 янв. 2025 г.

  • CVE-2024-8963
    96Срочно

    Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

    КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 99 %

    ivanti · endpoint manager cloud services appliance19 сент. 2024 г.

  • CVE-2024-29824
    95Срочно

    An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the sam

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 100 %

    ivanti · endpoint manager31 мая 2024 г.

  • CVE-2024-21893
    92Срочно

    A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x)

    ВысокаяCVSS 8,2KEVГотовый эксплойтEPSS 100 %

    ivanti · connect secure31 янв. 2024 г.

  • CVE-2023-46805
    92Срочно

    An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to acc

    ВысокаяCVSS 8,2KEVГотовый эксплойтEPSS 100 %

    ivanti · connect secure12 янв. 2024 г.

  • CVE-2025-4428
    91Срочно

    Remote Code Execution

    ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 87 %

    ivanti · endpoint manager mobile13 мая 2025 г.

  • CVE-2024-13159
    90Срочно

    Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %

    ivanti · endpoint manager14 янв. 2025 г.

  • CVE-2025-4427
    90Срочно

    Authentication Bypass

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %

    ivanti · endpoint manager mobile13 мая 2025 г.

  • CVE-2019-11539
    88Срочно

    In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 an

    ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 99 %

    ivanti · connect secure25 апр. 2019 г.

  • CVE-2020-8260
    87Срочно

    A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code e

    ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 96 %

    ivanti · connect secure28 окт. 2020 г.

  • CVE-2024-13160
    87Срочно

    Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 91 %

    ivanti · endpoint manager14 янв. 2025 г.

  • CVE-2024-13161
    87Срочно

    Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 90 %

    ivanti · endpoint manager14 янв. 2025 г.

  • CVE-2026-1603
    86Срочно

    An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored

    ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 88 %

    ivanti · endpoint manager10 февр. 2026 г.

  • CVE-2020-8243
    85Срочно

    A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to

    ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 91 %

    ivanti · connect secure30 сент. 2020 г.