← Back

Endpoint Manager

endpoint_manager

Vendor: Ivanti • 116 CVEs

CVEs (116)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 10, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.6 HIGH· v3
N/A· v2
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 10, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Jul 29, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2024 flat allows an authenticated attacker within the same network to execute arbitrary code.
1Ivanti
1Endpoint Manager
Jun 17, 2026
May 31, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
1Ivanti
1Endpoint Manager
Jun 17, 2026
May 31, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
1Ivanti
1Endpoint Manager
Jun 17, 2026
May 31, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
1Ivanti
1Endpoint Manager
Jun 17, 2026
May 31, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an authenticated attacker within the same network to execute arbitrary code.
1Ivanti
1Endpoint Manager
Jun 17, 2026
May 31, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
1Ivanti
1Endpoint Manager
Jun 17, 2026
May 31, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
1Ivanti
1Endpoint Manager
Jun 17, 2026
May 31, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
1Ivanti
1Endpoint Manager
Jun 17, 2026
May 31, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
1Ivanti
1Endpoint Manager
Jun 17, 2026
May 31, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
1Ivanti
1Endpoint Manager
Jun 17, 2026
May 31, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
1Ivanti
1Endpoint Manager
Jun 17, 2026
May 31, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
A buffer overflow allows a low privilege user on the local machine that has the EPM Agent installed to execute arbitrary code with elevated permissions in Ivanti EPM 2021.1 and older.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Jan 9, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the n...Show more
An unspecified SQL Injection vulnerability in Ivanti Endpoint Manager released prior to 2022 SU 5 allows an attacker with access to the internal network to execute arbitrary SQL queries and retrieve output without the need for authentication. Under specific circumstances, this may also lead to RCE on the core server. Show less
1Ivanti
1Endpoint Manager
Jun 17, 2026
Oct 18, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Oct 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
Allows an authenticated attacker with network access to read arbitrary files on Endpoint Manager recently discovered on 2022 SU3 and all previous versions potentially leading to the leakage of sensitive information.