← Back

Ivanti

ivanti

492 CVEs • 41 products

Products (41)

Click to collapse
Toggle
Avalanche
avalanche
Policy Secure
policy_secure
Mobileiron
mobileiron
Automation
automation
Dsm Netinst
dsm_netinst
Dsm Remote
dsm_remote
Docs@work
docs@work
Xtraction
xtraction

CVEs (492)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ivanti
1Endpoint Manager
Jun 17, 2026
Dec 9, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Intera...Show more
Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required.Show less
1Ivanti
1Endpoint Manager
Jun 17, 2026
Dec 9, 2025
N/A· v4
8.0 HIGH· v3
N/A· v2
Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Dec 9, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to rem...Show more
Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required.Show less
1Ivanti
1Endpoint Manager
Jun 17, 2026
Dec 9, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Nov 11, 2025
N/A· v4
7.1 HIGH· v3
N/A· v2
Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk
1Ivanti
1Endpoint Manager Mobile
Jun 17, 2026
Oct 14, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write data in unintended locations on disk.
1Ivanti
1Endpoint Manager Mobile
Jun 17, 2026
Oct 14, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager Mobile
Jun 17, 2026
Oct 14, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager Mobile
Jun 17, 2026
Oct 14, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Oct 13, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Oct 13, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Oct 13, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Oct 13, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Oct 13, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Oct 13, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Oct 13, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Oct 13, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Oct 13, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Oct 13, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Oct 13, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.