ivanti kayıtları
ivanti üreticisine ait 504 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 35 · %6,9
- Silahlaştırılmış
- 39 · %7,7
- Pre-auth RCE
- 45
- Düzeltme kaydı olan
- %12,5
- Yayından KEV’e ortanca
- 27 gün
Tekrar eden sınıflar
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')67
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')42
- CWE-787 Out-of-bounds Write27
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-502 Deserialization of Untrusted Data19
- CWE-434 Unrestricted Upload of File with Dangerous Type19
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
504 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
100Hemen | CVE-2019-11510Silahlaştırılmış | In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attackivanti · connect secure · CWE-22 | Kritik10,0 | KEV | %100,0 | 8 May 2019 |
100Hemen | CVE-2026-10520Silahlaştırılmış | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated userivanti · standalone sentry · CWE-78 | Kritik10,0 | KEV | %99,9 | 9 Haz 2026 |
99Hemen | CVE-2024-7593Silahlaştırılmış | Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated aivanti · virtual traffic manager · CWE-287 | Kritik9,8 | KEV | %100,0 | 13 Ağu 2024 |
99Hemen | CVE-2023-35078Silahlaştırılmış | An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appliivanti · endpoint manager mobile · CWE-287 | Kritik9,8 | KEV | %100,0 | 25 Tem 2023 |
99Hemen | CVE-2023-35082Silahlaştırılmış | An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resouivanti · endpoint manager mobile · CWE-287 | Kritik9,8 | KEV | %100,0 | 15 Ağu 2023 |
99Hemen | CVE-2025-22457Silahlaştırılmış | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTAivanti · connect secure · CWE-121 | Kritik9,8 | KEV | %100,0 | 3 Nis 2025 |
99Hemen | CVE-2023-38035Silahlaştırılmış | A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass aivanti · mobileiron sentry · CWE-863 | Kritik9,8 | KEV | %100,0 | 21 Ağu 2023 |
99Hemen | CVE-2021-44529Silahlaştırılmış | A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code witivanti · endpoint manager cloud services appliance · CWE-94 | Kritik9,8 | KEV | %99,1 | 8 Ara 2021 |
99Hemen | CVE-2026-1281Silahlaştırılmış | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.ivanti · endpoint manager mobile · CWE-94 | Kritik9,8 | KEV | %98,7 | 29 Oca 2026 |
99Hemen | CVE-2026-1340Silahlaştırılmış | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.ivanti · endpoint manager mobile · CWE-94 | Kritik9,8 | KEV | %98,6 | 29 Oca 2026 |
96Hemen | CVE-2024-21887Silahlaştırılmış | A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an autivanti · connect secure · CWE-77 | Kritik9,1 | KEV | %100,0 | 12 Oca 2024 |
96Hemen | CVE-2025-0282Silahlaştırılmış | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neuivanti · connect secure · CWE-121 | Kritik9,0 | KEV | %100,0 | 8 Oca 2025 |
96Hemen | CVE-2024-8963Silahlaştırılmış | Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.ivanti · endpoint manager cloud services appliance · CWE-22 | Kritik9,1 | KEV | %98,6 | 19 Eyl 2024 |
95Hemen | CVE-2024-29824Silahlaştırılmış | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the samivanti · endpoint manager · CWE-89 | Yüksek8,8 | KEV | %99,9 | 31 May 2024 |
92Hemen | CVE-2024-21893Silahlaştırılmış | A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) ivanti · connect secure · CWE-918 | Yüksek8,2 | KEV | %100,0 | 31 Oca 2024 |
92Hemen | CVE-2023-46805Silahlaştırılmış | An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to accivanti · connect secure · CWE-287 | Yüksek8,2 | KEV | %100,0 | 12 Oca 2024 |
91Hemen | CVE-2025-4428Silahlaştırılmış | Remote Code Executionivanti · endpoint manager mobile · CWE-94 | Yüksek8,8 | KEV | %86,5 | 13 May 2025 |
90Hemen | CVE-2024-13159Silahlaştırılmış | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remoteivanti · endpoint manager · CWE-36 | Yüksek7,5 | KEV | %100,0 | 14 Oca 2025 |
90Hemen | CVE-2025-4427Silahlaştırılmış | Authentication Bypassivanti · endpoint manager mobile · CWE-288 | Yüksek7,5 | KEV | %99,9 | 13 May 2025 |
88Hemen | CVE-2019-11539Silahlaştırılmış | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 anivanti · connect secure · CWE-78 | Yüksek7,2 | KEV | %98,5 | 25 Nis 2019 |
87Hemen | CVE-2020-8260Silahlaştırılmış | A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code eivanti · connect secure · CWE-434 | Yüksek7,2 | KEV | %96,5 | 28 Eki 2020 |
87Hemen | CVE-2024-13160Silahlaştırılmış | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remoteivanti · endpoint manager · CWE-36 | Yüksek7,5 | KEV | %91,2 | 14 Oca 2025 |
87Hemen | CVE-2024-13161Silahlaştırılmış | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remoteivanti · endpoint manager · CWE-36 | Yüksek7,5 | KEV | %90,1 | 14 Oca 2025 |
86Hemen | CVE-2026-1603Silahlaştırılmış | An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific storedivanti · endpoint manager · CWE-288 | Yüksek7,5 | KEV | %87,6 | 10 Şub 2026 |
85Hemen | CVE-2020-8243Silahlaştırılmış | A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template toivanti · connect secure · CWE-94 | Yüksek7,2 | KEV | %90,8 | 30 Eyl 2020 |
- CVE-2019-11510100Hemen
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100ivanti · connect secure8 May 2019
- CVE-2026-10520100Hemen
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user
KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100ivanti · standalone sentry9 Haz 2026
- CVE-2024-759399Hemen
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated a
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100ivanti · virtual traffic manager13 Ağu 2024
- CVE-2023-3507899Hemen
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appli
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100ivanti · endpoint manager mobile25 Tem 2023
- CVE-2023-3508299Hemen
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resou
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100ivanti · endpoint manager mobile15 Ağu 2023
- CVE-2025-2245799Hemen
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100ivanti · connect secure3 Nis 2025
- CVE-2023-3803599Hemen
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass a
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100ivanti · mobileiron sentry21 Ağu 2023
- CVE-2021-4452999Hemen
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code wit
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99ivanti · endpoint manager cloud services appliance8 Ara 2021
- CVE-2026-128199Hemen
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99ivanti · endpoint manager mobile29 Oca 2026
- CVE-2026-134099Hemen
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99ivanti · endpoint manager mobile29 Oca 2026
- CVE-2024-2188796Hemen
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an aut
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %100ivanti · connect secure12 Oca 2024
- CVE-2025-028296Hemen
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neu
KritikCVSS 9,0KEVSilahlaştırılmışEPSS %100ivanti · connect secure8 Oca 2025
- CVE-2024-896396Hemen
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
KritikCVSS 9,1KEVSilahlaştırılmışEPSS %99ivanti · endpoint manager cloud services appliance19 Eyl 2024
- CVE-2024-2982495Hemen
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the sam
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %100ivanti · endpoint manager31 May 2024
- CVE-2024-2189392Hemen
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x)
YüksekCVSS 8,2KEVSilahlaştırılmışEPSS %100ivanti · connect secure31 Oca 2024
- CVE-2023-4680592Hemen
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to acc
YüksekCVSS 8,2KEVSilahlaştırılmışEPSS %100ivanti · connect secure12 Oca 2024
- CVE-2025-442891Hemen
Remote Code Execution
YüksekCVSS 8,8KEVSilahlaştırılmışEPSS %87ivanti · endpoint manager mobile13 May 2025
- CVE-2024-1315990Hemen
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100ivanti · endpoint manager14 Oca 2025
- CVE-2025-442790Hemen
Authentication Bypass
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %100ivanti · endpoint manager mobile13 May 2025
- CVE-2019-1153988Hemen
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 an
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %99ivanti · connect secure25 Nis 2019
- CVE-2020-826087Hemen
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code e
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %96ivanti · connect secure28 Eki 2020
- CVE-2024-1316087Hemen
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %91ivanti · endpoint manager14 Oca 2025
- CVE-2024-1316187Hemen
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %90ivanti · endpoint manager14 Oca 2025
- CVE-2026-160386Hemen
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored
YüksekCVSS 7,5KEVSilahlaştırılmışEPSS %88ivanti · endpoint manager10 Şub 2026
- CVE-2020-824385Hemen
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to
YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %91ivanti · connect secure30 Eyl 2020