📦

avalanche

Vendor: ivanti

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 49 Remote Access
Total CVEs 123 Total Indexed
Avg. EPSS 21.49% Exploit Prob.
Latest CVE CVE-2025-8297 Aug 12

Security Vulnerability Index

Page 1 / 13
7.2 CVSS

Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to achieve remote code execution

EPSS: 11.38%
7.2 CVSS

SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL queries. In certain conditions, this can also lead to remote code execution

EPSS: 6.56%
9.8 CVSS

A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overflow that could result in service disruption or arbitrary code execution.

EPSS: 2.81%
7.3 CVSS

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.

EPSS: 0.73%
7.5 CVSS

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.

EPSS: 36.12%
7.3 CVSS

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.

EPSS: 1.22%
7.5 CVSS

An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.

EPSS: 5.50%
7.5 CVSS

An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

EPSS: 7.83%
7.5 CVSS

An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

EPSS: 50.58%
7.5 CVSS

An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

EPSS: 7.83%