Show filters
423 Total Results
Displaying 21-30 of 423
Sort by:
Attacker Value
Very High

CVE-2020-8218

Disclosure Date: July 30, 2020 (last updated February 21, 2025)
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
Attacker Value
Unknown

CVE-2024-7593

Disclosure Date: August 13, 2024 (last updated September 07, 2024)
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker to bypass authentication of the admin panel.
Attacker Value
Unknown

CVE-2023-39336

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the need for authentication. Under specific circumstances, this may also lead to RCE on the core server.
Attacker Value
Unknown

CVE-2023-35081

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.
Attacker Value
Very High

CVE-2020-8243

Disclosure Date: September 30, 2020 (last updated February 22, 2025)
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
Attacker Value
Unknown

CVE-2020-8204

Disclosure Date: July 30, 2020 (last updated February 21, 2025)
A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page.
Attacker Value
Unknown

CVE-2024-38657

Disclosure Date: February 21, 2025 (last updated February 21, 2025)
External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.
0
Attacker Value
Unknown

CVE-2025-22467

Disclosure Date: February 11, 2025 (last updated February 21, 2025)
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.
Attacker Value
Unknown

CVE-2024-47908

Disclosure Date: February 11, 2025 (last updated February 21, 2025)
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Attacker Value
Unknown

CVE-2024-13843

Disclosure Date: February 11, 2025 (last updated February 21, 2025)
Cleartext storage of information in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a local authenticated attacker with admin privileges to read sensitive data.