4.9

CVSS3.1

CVE-2024-22060 -

An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, high privileged user to write arbitrary files into sensitive directories of ITSM server.

πŸ“… Published: May 31, 2024, 5:38 p.m. πŸ”„ Last Modified: June 30, 2025, 6:28 p.m.

8.8

CVSS3.1

CVE-2024-29822 -

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

πŸ“… Published: May 31, 2024, 5:38 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:08 a.m.

8.8

CVSS3.1

CVE-2024-29826 -

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.

πŸ“… Published: May 31, 2024, 5:38 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:08 a.m.

8.0

CVSS3.1

CVE-2024-29828 -

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

πŸ“… Published: May 31, 2024, 5:38 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:08 a.m.

8.0

CVSS3.1

CVE-2024-29829 -

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

πŸ“… Published: May 31, 2024, 5:38 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:08 a.m.

7.2

CVSS3.1

CVE-2024-29848 -

An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.

πŸ“… Published: May 31, 2024, 5:38 p.m. πŸ”„ Last Modified: May 6, 2025, 2:43 p.m.

8.0

CVSS3.1

CVE-2024-29846 -

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

πŸ“… Published: May 31, 2024, 5:38 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:08 a.m.

8.2

CVSS3.0

CVE-2023-38551 -

A CRLF Injection vulnerability in Ivanti Connect Secure (9.x, 22.x) allows an authenticated high-privileged user to inject malicious code on a victim’s browser, thereby leading to cross-site scripting attack.

πŸ“… Published: May 31, 2024, 5:38 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.0

CVSS3.1

CVE-2024-29830 -

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.

πŸ“… Published: May 31, 2024, 5:38 p.m. πŸ”„ Last Modified: Nov. 21, 2024, 9:08 a.m.

7.8

CVSS3.0

CVE-2024-22058 -

A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated permissions in Ivanti EPM 2021.1 and older.

πŸ“… Published: May 31, 2024, 5:38 p.m. πŸ”„ Last Modified: June 20, 2025, 5:48 p.m.
Total resulsts: 349182
Page 9617 of 34,919
Β« previous page Β» next page
Filters