Записи ivanti
504 опубликованных записей вендора ivanti.
Профиль для исследователя
- Попали в KEV
- 35 · 6,9 %
- С эксплойтом
- 39 · 7,7 %
- Pre-auth RCE
- 45
- С записью об исправлении
- 12,5 %
- Медиана: публикация → KEV
- 27 дн.
Повторяющиеся классы
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')67
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')42
- CWE-787 Out-of-bounds Write27
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-502 Deserialization of Untrusted Data19
- CWE-434 Unrestricted Upload of File with Dangerous Type19
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
504 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2019-11510Готовый эксплойт | In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attackivanti · connect secure · CWE-22 | Критическая10,0 | KEV | 100,0 % | 8 мая 2019 г. |
100Срочно | CVE-2026-10520Готовый эксплойт | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated userivanti · standalone sentry · CWE-78 | Критическая10,0 | KEV | 99,9 % | 9 июн. 2026 г. |
99Срочно | CVE-2024-7593Готовый эксплойт | Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated aivanti · virtual traffic manager · CWE-287 | Критическая9,8 | KEV | 100,0 % | 13 авг. 2024 г. |
99Срочно | CVE-2023-35078Готовый эксплойт | An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appliivanti · endpoint manager mobile · CWE-287 | Критическая9,8 | KEV | 100,0 % | 25 июл. 2023 г. |
99Срочно | CVE-2023-35082Готовый эксплойт | An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resouivanti · endpoint manager mobile · CWE-287 | Критическая9,8 | KEV | 100,0 % | 15 авг. 2023 г. |
99Срочно | CVE-2025-22457Готовый эксплойт | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTAivanti · connect secure · CWE-121 | Критическая9,8 | KEV | 100,0 % | 3 апр. 2025 г. |
99Срочно | CVE-2023-38035Готовый эксплойт | A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass aivanti · mobileiron sentry · CWE-863 | Критическая9,8 | KEV | 100,0 % | 21 авг. 2023 г. |
99Срочно | CVE-2021-44529Готовый эксплойт | A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code witivanti · endpoint manager cloud services appliance · CWE-94 | Критическая9,8 | KEV | 99,1 % | 8 дек. 2021 г. |
99Срочно | CVE-2026-1281Готовый эксплойт | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.ivanti · endpoint manager mobile · CWE-94 | Критическая9,8 | KEV | 98,7 % | 29 янв. 2026 г. |
99Срочно | CVE-2026-1340Готовый эксплойт | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.ivanti · endpoint manager mobile · CWE-94 | Критическая9,8 | KEV | 98,6 % | 29 янв. 2026 г. |
96Срочно | CVE-2024-21887Готовый эксплойт | A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an autivanti · connect secure · CWE-77 | Критическая9,1 | KEV | 100,0 % | 12 янв. 2024 г. |
96Срочно | CVE-2025-0282Готовый эксплойт | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neuivanti · connect secure · CWE-121 | Критическая9,0 | KEV | 100,0 % | 8 янв. 2025 г. |
96Срочно | CVE-2024-8963Готовый эксплойт | Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.ivanti · endpoint manager cloud services appliance · CWE-22 | Критическая9,1 | KEV | 98,6 % | 19 сент. 2024 г. |
95Срочно | CVE-2024-29824Готовый эксплойт | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the samivanti · endpoint manager · CWE-89 | Высокая8,8 | KEV | 99,9 % | 31 мая 2024 г. |
92Срочно | CVE-2024-21893Готовый эксплойт | A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) ivanti · connect secure · CWE-918 | Высокая8,2 | KEV | 100,0 % | 31 янв. 2024 г. |
92Срочно | CVE-2023-46805Готовый эксплойт | An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to accivanti · connect secure · CWE-287 | Высокая8,2 | KEV | 100,0 % | 12 янв. 2024 г. |
91Срочно | CVE-2025-4428Готовый эксплойт | Remote Code Executionivanti · endpoint manager mobile · CWE-94 | Высокая8,8 | KEV | 86,5 % | 13 мая 2025 г. |
90Срочно | CVE-2024-13159Готовый эксплойт | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remoteivanti · endpoint manager · CWE-36 | Высокая7,5 | KEV | 100,0 % | 14 янв. 2025 г. |
90Срочно | CVE-2025-4427Готовый эксплойт | Authentication Bypassivanti · endpoint manager mobile · CWE-288 | Высокая7,5 | KEV | 99,9 % | 13 мая 2025 г. |
88Срочно | CVE-2019-11539Готовый эксплойт | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 anivanti · connect secure · CWE-78 | Высокая7,2 | KEV | 98,5 % | 25 апр. 2019 г. |
87Срочно | CVE-2020-8260Готовый эксплойт | A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code eivanti · connect secure · CWE-434 | Высокая7,2 | KEV | 96,5 % | 28 окт. 2020 г. |
87Срочно | CVE-2024-13160Готовый эксплойт | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remoteivanti · endpoint manager · CWE-36 | Высокая7,5 | KEV | 91,2 % | 14 янв. 2025 г. |
87Срочно | CVE-2024-13161Готовый эксплойт | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remoteivanti · endpoint manager · CWE-36 | Высокая7,5 | KEV | 90,1 % | 14 янв. 2025 г. |
86Срочно | CVE-2026-1603Готовый эксплойт | An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific storedivanti · endpoint manager · CWE-288 | Высокая7,5 | KEV | 87,6 % | 10 февр. 2026 г. |
85Срочно | CVE-2020-8243Готовый эксплойт | A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template toivanti · connect secure · CWE-94 | Высокая7,2 | KEV | 90,8 % | 30 сент. 2020 г. |
- CVE-2019-11510100Срочно
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %ivanti · connect secure8 мая 2019 г.
- CVE-2026-10520100Срочно
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %ivanti · standalone sentry9 июн. 2026 г.
- CVE-2024-759399Срочно
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ivanti · virtual traffic manager13 авг. 2024 г.
- CVE-2023-3507899Срочно
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appli
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ivanti · endpoint manager mobile25 июл. 2023 г.
- CVE-2023-3508299Срочно
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resou
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ivanti · endpoint manager mobile15 авг. 2023 г.
- CVE-2025-2245799Срочно
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ivanti · connect secure3 апр. 2025 г.
- CVE-2023-3803599Срочно
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %ivanti · mobileiron sentry21 авг. 2023 г.
- CVE-2021-4452999Срочно
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code wit
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %ivanti · endpoint manager cloud services appliance8 дек. 2021 г.
- CVE-2026-128199Срочно
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %ivanti · endpoint manager mobile29 янв. 2026 г.
- CVE-2026-134099Срочно
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %ivanti · endpoint manager mobile29 янв. 2026 г.
- CVE-2024-2188796Срочно
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an aut
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 100 %ivanti · connect secure12 янв. 2024 г.
- CVE-2025-028296Срочно
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neu
КритическаяCVSS 9,0KEVГотовый эксплойтEPSS 100 %ivanti · connect secure8 янв. 2025 г.
- CVE-2024-896396Срочно
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
КритическаяCVSS 9,1KEVГотовый эксплойтEPSS 99 %ivanti · endpoint manager cloud services appliance19 сент. 2024 г.
- CVE-2024-2982495Срочно
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the sam
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 100 %ivanti · endpoint manager31 мая 2024 г.
- CVE-2024-2189392Срочно
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x)
ВысокаяCVSS 8,2KEVГотовый эксплойтEPSS 100 %ivanti · connect secure31 янв. 2024 г.
- CVE-2023-4680592Срочно
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to acc
ВысокаяCVSS 8,2KEVГотовый эксплойтEPSS 100 %ivanti · connect secure12 янв. 2024 г.
- CVE-2025-442891Срочно
Remote Code Execution
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 87 %ivanti · endpoint manager mobile13 мая 2025 г.
- CVE-2024-1315990Срочно
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %ivanti · endpoint manager14 янв. 2025 г.
- CVE-2025-442790Срочно
Authentication Bypass
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %ivanti · endpoint manager mobile13 мая 2025 г.
- CVE-2019-1153988Срочно
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 an
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 99 %ivanti · connect secure25 апр. 2019 г.
- CVE-2020-826087Срочно
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code e
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 96 %ivanti · connect secure28 окт. 2020 г.
- CVE-2024-1316087Срочно
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 91 %ivanti · endpoint manager14 янв. 2025 г.
- CVE-2024-1316187Срочно
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 90 %ivanti · endpoint manager14 янв. 2025 г.
- CVE-2026-160386Срочно
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 88 %ivanti · endpoint manager10 февр. 2026 г.
- CVE-2020-824385Срочно
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 91 %ivanti · connect secure30 сент. 2020 г.