← Back

Ivanti

ivanti

492 CVEs • 41 products

Products (41)

Click to collapse
Toggle
Avalanche
avalanche
Policy Secure
policy_secure
Mobileiron
mobileiron
Automation
automation
Dsm Netinst
dsm_netinst
Dsm Remote
dsm_remote
Docs@work
docs@work
Xtraction
xtraction

CVEs (492)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Ivanti
4Connect Secure
Neurons For Secure AccessPolicy Secure+1 more
Jun 17, 2026
Aug 12, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix depl...Show more
A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to trigger a denial of service.Show less
1Ivanti
4Connect Secure
Neurons For Secure AccessPolicy Secure+1 more
Jun 17, 2026
Aug 12, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix d...Show more
A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to trigger a denial of service. CWE-125Show less
1Ivanti
1Desktop & Server Management
Jun 17, 2026
Jul 12, 2025
N/A· v4
5.7 MEDIUM· v3
N/A· v2
A hardcoded secret in Ivanti DSM before 2024.2 allows an authenticated attacker on an adjacent network to decrypt sensitive data including user credentials.
1Ivanti
1Policy Secure
Jun 17, 2026
Jul 12, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A vulnerability exists on all versions of Ivanti Policy Secure below 22.6R1 where an authenticated administrator can perform an arbitrary file read via a maliciously crafted web request.
1Ivanti
1Avalanche
Jun 17, 2026
Jul 12, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overflow that could result in service disruption or arbitrary code execution.
1Ivanti
1Endpoint Manager Mobile
Jun 17, 2026
Jul 8, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution
1Ivanti
1Connect Secure
Jun 17, 2026
Jul 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authenticated attacker to obtain that information.
1Ivanti
2Connect Secure
Policy Secure
Jun 17, 2026
Jul 8, 2025
N/A· v4
2.7 LOW· v3
N/A· v2
CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to write to a protected configuration file on disk...Show more
CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to write to a protected configuration file on disk.Show less
1Ivanti
2Connect Secure
Policy Secure
Jun 17, 2026
Jul 8, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to access internal network services.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Jul 8, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database
1Ivanti
1Endpoint Manager
Jun 17, 2026
Jul 8, 2025
N/A· v4
8.4 HIGH· v3
N/A· v2
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
1Ivanti
1Endpoint Manager
Jun 17, 2026
Jul 8, 2025
N/A· v4
8.4 HIGH· v3
N/A· v2
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
1Ivanti
1Endpoint Manager Mobile
Jun 17, 2026
Jul 8, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution
1Ivanti
2Connect Secure
Policy Secure
Jun 17, 2026
Jul 8, 2025
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a local authenticated attacker to obtain that information.
1Ivanti
2Connect Secure
Policy Secure
Jun 17, 2026
Jul 8, 2025
N/A· v4
4.9 MEDIUM· v3
N/A· v2
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to trigger a denial of service.
1Ivanti
2Connect Secure
Policy Secure
Jun 17, 2026
Jul 8, 2025
N/A· v4
2.7 LOW· v3
N/A· v2
Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated admin with read-only rights...Show more
Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated admin with read-only rights to modify settings that should be restricted.Show less
1Ivanti
1Workspace Control
Jun 17, 2026
Jun 10, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials.
1Ivanti
1Workspace Control
Jun 17, 2026
Jun 10, 2025
N/A· v4
7.3 HIGH· v3
N/A· v2
A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment password.
1Ivanti
1Workspace Control
Jun 17, 2026
Jun 10, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentials.
1Ivanti
1Endpoint Manager Mobile
Jun 17, 2026
May 13, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.