Vulnerabilities (CVE)

Filtered by vendor Ivanti Subscribe
Total 495 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-22461 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.2 HIGH
SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privileges to achieve code execution.
CVE-2025-22460 1 Ivanti 1 Cloud Services Appliance 2026-06-17 N/A 7.8 HIGH
Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.
CVE-2025-22459 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 4.8 MEDIUM
Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic between clients and servers.
CVE-2025-22458 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.8 HIGH
DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.
CVE-2025-22455 1 Ivanti 1 Workspace Control 2026-06-17 N/A 8.8 HIGH
A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentials.
CVE-2025-22454 1 Ivanti 1 Secure Access Client 2026-06-17 N/A 7.8 HIGH
Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
CVE-2025-13662 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.8 HIGH
Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required.
CVE-2025-13661 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.1 HIGH
Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required.
CVE-2025-13659 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.8 HIGH
Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required.
CVE-2025-11623 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 6.5 MEDIUM
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
CVE-2025-11622 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.8 HIGH
Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges.
CVE-2025-10986 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 4.7 MEDIUM
Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write data in unintended locations on disk.
CVE-2025-10985 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 7.2 HIGH
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2025-10918 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.1 HIGH
Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk
CVE-2025-10573 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 9.6 CRITICAL
Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.
CVE-2025-10243 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 7.2 HIGH
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2025-10242 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 7.2 HIGH
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2025-0293 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 6.6 MEDIUM
CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to write to a protected configuration file on disk.
CVE-2025-0292 1 Ivanti 2 Connect Secure, Policy Secure 2026-06-17 N/A 5.5 MEDIUM
SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to access internal network services.
CVE-2025-0283 1 Ivanti 3 Connect Secure, Neurons For Zero-trust Access, Policy Secure 2026-06-17 N/A 7.0 HIGH
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.