Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
Docs
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ivanti policy secure vulnerabilities and exploits
(subscribe to this query)
1000
VMScore
CVE-2024-21894
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack. In certain conditions this may le...
Ivanti Connect Secure
Ivanti Policy Secure
Ivanti Connect Secure 9.1
Ivanti Connect Secure 22.1
Ivanti Connect Secure 22.2
Ivanti Connect Secure 22.3
Ivanti Connect Secure 22.4
Ivanti Connect Secure 22.5
Ivanti Connect Secure 22.6
Ivanti Policy Secure 9.0
Ivanti Policy Secure 9.1
Ivanti Policy Secure 22.1
2 Github repositories
2 Articles
630
VMScore
CVE-2024-22023
An XML entity expansion or XEE vulnerability in SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted XML requests in-order-to temporarily cause resource exhaustion thereby resulting in a li...
Ivanti Connect Secure
Ivanti Policy Secure
Ivanti Connect Secure 9.1
Ivanti Connect Secure 22.1
Ivanti Connect Secure 22.2
Ivanti Connect Secure 22.3
Ivanti Connect Secure 22.4
Ivanti Connect Secure 22.5
Ivanti Connect Secure 22.6
Ivanti Policy Secure 9.0
Ivanti Policy Secure 9.1
Ivanti Policy Secure 22.1
1 Article
850
VMScore
CVE-2024-22052
A null pointer dereference vulnerability in IPSec component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack
Ivanti Connect Secure
Ivanti Policy Secure
Ivanti Connect Secure 9.1
Ivanti Connect Secure 22.1
Ivanti Connect Secure 22.2
Ivanti Connect Secure 22.3
Ivanti Connect Secure 22.4
Ivanti Connect Secure 22.5
Ivanti Connect Secure 22.6
Ivanti Policy Secure 9.0
Ivanti Policy Secure 9.1
Ivanti Policy Secure 22.1
1 Article
920
VMScore
CVE-2024-22053
A heap overflow vulnerability in IPSec component of Ivanti Connect Secure (9.x 22.x) and Ivanti Policy Secure allows an unauthenticated malicious user to send specially crafted requests in-order-to crash the service thereby causing a DoS attack or in certain conditions read conte...
Ivanti Connect Secure
Ivanti Policy Secure
Ivanti Connect Secure 9.1
Ivanti Connect Secure 22.1
Ivanti Connect Secure 22.2
Ivanti Connect Secure 22.3
Ivanti Connect Secure 22.4
Ivanti Connect Secure 22.5
Ivanti Connect Secure 22.6
Ivanti Policy Secure 9.0
Ivanti Policy Secure 9.1
Ivanti Policy Secure 22.1
1 Article
1000
VMScore
CVE-2024-21887
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance.
Ivanti Ics
Ivanti Ips
Ivanti Connect Secure 9.0
Ivanti Connect Secure 9.1
Ivanti Connect Secure 22.1
Ivanti Connect Secure 22.2
Ivanti Connect Secure 22.3
Ivanti Connect Secure 22.4
Ivanti Connect Secure 22.5
Ivanti Connect Secure 22.6
Ivanti Policy Secure 9.0
Ivanti Policy Secure 9.1
2 Metasploit modules
13 Github repositories
23 Articles
920
VMScore
CVE-2023-46805
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote malicious user to access restricted resources by bypassing control checks.
Ivanti Ics
Ivanti Ips
Ivanti Connect Secure 9.0
Ivanti Connect Secure 9.1
Ivanti Connect Secure 22.1
Ivanti Connect Secure 22.2
Ivanti Connect Secure 22.3
Ivanti Connect Secure 22.4
Ivanti Connect Secure 22.5
Ivanti Connect Secure 22.6
Ivanti Policy Secure 9.0
Ivanti Policy Secure 9.1
1 Metasploit module
15 Github repositories
19 Articles
980
VMScore
CVE-2024-21888
A privilege escalation vulnerability in web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a user to elevate privileges to that of an administrator.
Ivanti Connect Secure 9.0
Ivanti Connect Secure 22.0
Ivanti Policy Secure 22.0
Ivanti Policy Secure 9.0
Ivanti Ics
Ivanti Ips
Ivanti Connect Secure 9.1
Ivanti Connect Secure 21.9
Ivanti Connect Secure 21.12
Ivanti Connect Secure 22.1
Ivanti Connect Secure 22.2
Ivanti Connect Secure 22.3
2 Github repositories
3 Articles
820
VMScore
CVE-2024-11007
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.
Ivanti Connect Secure
Ivanti Connect Secure 22.7
Ivanti Policy Secure
Ivanti Policy Secure 22.7
590
VMScore
CVE-2024-47909
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
Ivanti Connect Secure
Ivanti Connect Secure 22.7
Ivanti Policy Secure
Ivanti Policy Secure 22.7
590
VMScore
CVE-2024-47905
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
Ivanti Connect Secure
Ivanti Connect Secure 22.7
Ivanti Policy Secure
Ivanti Policy Secure 22.7
Preferred Score:
VMScore
CVSSv2
CVSSv3
CVSSv4
EPSS
VMScore
Recommendations:
code execution
allegra
winrar
CVE-2025-6019
online teacher record management system
CVE-2025-52556
CVE-2025-6362
arbitrary code
inject
CVE-2025-34028
CVE-2025-6401
CVE-2025-5479
dnn.platform
Home
/
Search Results
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
5
NEXT »