Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
avalanche vulnerabilities and exploits
(subscribe to this query)
9.8
CVSSv3
CVE-2022-36983
This vulnerability allows remote malicious users to bypass authentication on affected installations of Ivanti Avalanche. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SetSettings class. The issue results from the lack of authent...
Ivanti Avalanche
7.5
CVSSv3
CVE-2022-44574
An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated malicious user to modify properties on specific port.
Ivanti Avalanche
8.2
CVSSv3
CVE-2021-34987
This vulnerability allows local malicious users to escalate privileges on affected installations of Parallels Desktop 16.5.1 (49187). An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The s...
Parallels Parallels Desktop 16.5.1
7.8
CVSSv3
CVE-2021-34986
This vulnerability allows local malicious users to escalate privileges on affected installations of Parallels Desktop 16.5.0 (49183). An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific...
Parallels Parallels Desktop 16.5.0
7.5
CVSSv3
CVE-2021-30497
Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter processed by the /AvalancheWeb/image endpoint is not verified to be within the scope of the image folder, e.g., the attacker can o...
Ivanti Avalanche 6.3.2
8.8
CVSSv3
CVE-2021-42125
An unrestricted file upload vulnerability exists in Ivanti Avalanche prior to 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files.
Ivanti Avalanche
8.8
CVSSv3
CVE-2021-42124
An improper access control vulnerability exists in Ivanti Avalanche prior to 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover.
Ivanti Avalanche
8.8
CVSSv3
CVE-2021-42129
A command injection vulnerability exists in Ivanti Avalanche prior to 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution.
Ivanti Avalanche
8.8
CVSSv3
CVE-2021-42130
A deserialization of untrusted data vulnerability exists in Ivanti Avalanche prior to 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution.
Ivanti Avalanche
8.8
CVSSv3
CVE-2021-42131
A SQL Injection vulnerability exists in Ivanti Avalance prior to 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation.
Ivanti Avalanche
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2020-4463
CVE-2024-29895
inject
CVE-2023-52689
CVE-2024-5049
CVE-2024-5051
privilege escalation
physical
CVE-2023-52676
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »