Vulnerabilities in ivanti

391 results
Vexday analysis

Ivanti apresenta 12 vulnerabilidades catalogadas, todas publicadas nos últimos 90 dias, indicando risco emergente e recente. Três são críticas (CVSS alto), mas nenhuma está sob exploração ativa confirmada no momento. A fraqueza dominante é CWE-732 (permissões incorretas), sugerindo problemas de controle de acesso que demandam priorização na correção.

CVE-2026-18127HIGHExternal control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full wrEPSS 0.7%CVE-2023-35080HIGHA vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploiEPSS 0.7%CVE-2026-1602MEDIUMSQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the dataEPSS 0.7%CVE-2025-55143MEDIUMReflected text injection in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway beforeEPSS 0.7%CVE-2026-14902MEDIUMAn open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary externaEPSS 0.7%CVE-2023-41720HIGHA vulnerability exists on all versions of Ivanti Connect Secure below 22.6R2 where an attacker with a foothold on an Ivanti Connect Secure (EPSS 0.7%CVE-2023-41725HIGHIvanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation VulnerabilityEPSS 0.7%CVE-2025-5451MEDIUMA stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remEPSS 0.7%CVE-2025-5466MEDIUMXEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and IvaEPSS 0.7%CVE-2023-38041HIGHA logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flEPSS 0.7%CVE-2024-50323HIGHSQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthentiEPSS 0.7%CVE-2025-55145HIGHMissing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.EPSS 0.6%CVE-2025-10986MEDIUMPath traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker withEPSS 0.6%CVE-2025-55147HIGHCSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and IvaEPSS 0.6%CVE-2023-41726HIGHIvanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation VulnerabilityEPSS 0.6%CVE-2025-22465MEDIUMReflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execEPSS 0.6%CVE-2025-13662HIGHImproper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1EPSS 0.6%CVE-2025-0292MEDIUMSSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attackeEPSS 0.6%CVE-2024-7570HIGHImproper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM pEPSS 0.6%CVE-2024-38648CRITICALA hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including uEPSS 0.6%