Show filters
423 Total Results
Displaying 191-200 of 423
Sort by:
Attacker Value
Unknown
CVE-2024-29822
Disclosure Date: May 31, 2024 (last updated October 04, 2024)
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2024-22060
Disclosure Date: May 31, 2024 (last updated June 01, 2024)
An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, high privileged user to write arbitrary files into sensitive directories of ITSM server.
0
Attacker Value
Unknown
CVE-2024-22059
Disclosure Date: May 31, 2024 (last updated June 01, 2024)
A SQL injection vulnerability in web component of Ivanti Neurons for ITSM allows a remote authenticated user to read/modify/delete information in the underlying database. This may also lead to DoS.
0
Attacker Value
Unknown
CVE-2024-22058
Disclosure Date: May 31, 2024 (last updated June 01, 2024)
A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated permissions in Ivanti EPM 2021.1 and older.
0
Attacker Value
Unknown
CVE-2023-46810
Disclosure Date: May 31, 2024 (last updated June 01, 2024)
A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as root.
0
Attacker Value
Unknown
CVE-2023-38551
Disclosure Date: May 31, 2024 (last updated June 01, 2024)
A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.
0
Attacker Value
Unknown
CVE-2023-38042
Disclosure Date: May 31, 2024 (last updated June 01, 2024)
A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.
0
Attacker Value
Unknown
CVE-2023-46807
Disclosure Date: May 22, 2024 (last updated May 23, 2024)
An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database.
0
Attacker Value
Unknown
CVE-2023-46806
Disclosure Date: May 22, 2024 (last updated May 23, 2024)
An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database.
0
Attacker Value
Unknown
CVE-2024-29205
Disclosure Date: April 25, 2024 (last updated April 25, 2024)
An Improper Check for Unusual or Exceptional Conditions vulnerability in the web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a remote unauthenticated attacker to send specially crafted requests in-order-to cause service disruptions.
0