📦

avalanche

Vendor: ivanti

Actively Exploited 0 CISA KEV List
PoC / Exploits 1 Code Available
Total RCEs 49 Remote Access
Total CVEs 123 Total Indexed
Avg. EPSS 21.49% Exploit Prob.
Latest CVE CVE-2025-8297 Aug 12

Security Vulnerability Index

Page 2 / 13
7.5 CVSS

A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

EPSS: 7.85%
7.5 CVSS

A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.

EPSS: 7.85%
7.5 CVSS

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information

EPSS: 53.19%
7.3 CVSS

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

EPSS: 0.90%
7.3 CVSS

Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.

EPSS: 0.51%
7.5 CVSS

Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.

EPSS: 37.21%
7.5 CVSS

A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.

EPSS: 3.98%
7.5 CVSS

XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.

EPSS: 90.73%
9.1 CVSS

Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.

EPSS: 7.12%
7.5 CVSS

A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.

EPSS: 45.10%