← Back

Ivanti

ivanti

492 CVEs • 41 products

Products (41)

Click to collapse
Toggle
Avalanche
avalanche
Policy Secure
policy_secure
Mobileiron
mobileiron
Automation
automation
Dsm Netinst
dsm_netinst
Dsm Remote
dsm_remote
Docs@work
docs@work
Xtraction
xtraction

CVEs (492)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ivanti
1Avalanche
Jun 17, 2026
Oct 8, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.
1Ivanti
1Endpoint Manager Cloud Services Appliance
Jun 17, 2026
Sep 19, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 12, 2024
N/A· v4
8.2 HIGH· v3
N/A· v2
An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 12, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 12, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 12, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 12, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 12, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 12, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 12, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 12, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 12, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 12, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Deserialization of untrusted data in the agent portal of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 10, 2024
N/A· v4
6.7 MEDIUM· v3
N/A· v2
An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Weak authentication in Patch Management of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker to access restricted functionality.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.6 HIGH· v3
N/A· v2
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to isolate managed devices from the network.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 10, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Missing authentication in Network Isolation of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to spoof Network Isolation status of managed devices.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Sep 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL injection in the management console of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to achieve remote code execution.
1Ivanti
1Cloud Services Appliance
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privil...Show more
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.Show less
1Ivanti
1Workspace Control
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.