Vulnerabilities (CVE)

Filtered by vendor Ivanti Subscribe
Total 495 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-7432 2 Ivanti, Microsoft 2 Secure Access Client, Windows 2026-06-17 N/A 7.8 HIGH
A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM
CVE-2026-7431 2 Ivanti, Microsoft 2 Secure Access Client, Windows 2026-06-17 N/A 4.4 MEDIUM
An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section.
CVE-2026-6973 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 7.2 HIGH
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
CVE-2026-5788 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 7.0 HIGH
An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.
CVE-2026-5787 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 8.9 HIGH
An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.
CVE-2026-5786 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 8.8 HIGH
An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.
CVE-2026-3483 1 Ivanti 1 Desktop \& Server Management 2026-06-17 N/A 7.8 HIGH
An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.
CVE-2026-1603 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.6 HIGH
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
CVE-2026-1602 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 6.5 MEDIUM
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
CVE-2026-1340 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 9.8 CRITICAL
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
CVE-2026-1281 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 9.8 CRITICAL
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
CVE-2025-9872 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.8 HIGH
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
CVE-2025-9713 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.8 HIGH
Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
CVE-2025-9712 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.8 HIGH
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
CVE-2025-8712 1 Ivanti 4 Connect Secure, Neurons For Secure Access, Policy Secure and 1 more 2026-06-17 N/A 5.4 MEDIUM
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure restricted settings.
CVE-2025-8711 1 Ivanti 4 Connect Secure, Neurons For Secure Access, Policy Secure and 1 more 2026-06-17 N/A 5.4 MEDIUM
CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to execute limited actions on behalf of the victim user. User interaction is required.
CVE-2025-8310 1 Ivanti 1 Virtual Application Delivery Controller 2026-06-17 N/A 6.5 MEDIUM
Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attacker to take over admin accounts by resetting the password
CVE-2025-8297 1 Ivanti 1 Avalanche 2026-06-17 N/A 7.2 HIGH
Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to achieve remote code execution
CVE-2025-8296 1 Ivanti 1 Avalanche 2026-06-17 N/A 7.2 HIGH
SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL queries. In certain conditions, this can also lead to remote code execution
CVE-2025-7037 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.2 HIGH
SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database