📦

avalanche

Vendor: ivanti

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 49 Remote Access
Total CVEs 126 Total Indexed
Avg. EPSS 24.69% Exploit Prob.
Latest CVE CVE-2025-8297 Aug 12

Security Vulnerability Index

Page 1 / 13
7.2 CVSS

Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to achieve remote code execution

EPSS: 1.22%
7.2 CVSS

SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL queries. In certain conditions, this can also lead to remote code execution

EPSS: 1.10%
9.8 CVSS

A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overflow that could result in service disruption or arbitrary code execution.

EPSS: 1.82%
7.3 CVSS

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.

EPSS: 32.44%
7.5 CVSS

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.

EPSS: 27.76%
7.3 CVSS

Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.

EPSS: 61.81%
7.5 CVSS

An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.

EPSS: 1.07%
7.5 CVSS

An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

EPSS: 1.11%
7.5 CVSS

An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

EPSS: 31.24%
7.5 CVSS

An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

EPSS: 1.11%