Vulnerabilities (CVE)

Filtered by vendor Ivanti Subscribe
Total 424 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-13170 1 Ivanti 1 Endpoint Manager 2025-07-11 N/A 7.5 HIGH
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-13169 1 Ivanti 1 Endpoint Manager 2025-07-11 N/A 7.8 HIGH
An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.
CVE-2024-13168 1 Ivanti 1 Endpoint Manager 2025-07-11 N/A 7.5 HIGH
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-13164 1 Ivanti 1 Endpoint Manager 2025-07-11 N/A 7.8 HIGH
An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.
CVE-2024-13163 1 Ivanti 1 Endpoint Manager 2025-07-11 N/A 7.8 HIGH
Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.
CVE-2024-13165 1 Ivanti 1 Endpoint Manager 2025-07-11 N/A 7.5 HIGH
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-13166 1 Ivanti 1 Endpoint Manager 2025-07-11 N/A 7.5 HIGH
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-13167 1 Ivanti 1 Endpoint Manager 2025-07-11 N/A 7.5 HIGH
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.
CVE-2024-13162 1 Ivanti 1 Endpoint Manager 2025-07-11 N/A 7.2 HIGH
SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-2024-32848.
CVE-2025-6770 1 Ivanti 1 Endpoint Manager Mobile 2025-07-11 N/A 7.2 HIGH
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution
CVE-2025-6771 1 Ivanti 1 Endpoint Manager Mobile 2025-07-11 N/A 7.2 HIGH
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution
CVE-2025-6995 1 Ivanti 1 Endpoint Manager 2025-07-11 N/A 8.4 HIGH
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
CVE-2025-6996 1 Ivanti 1 Endpoint Manager 2025-07-11 N/A 8.4 HIGH
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.
CVE-2025-7037 1 Ivanti 1 Endpoint Manager 2025-07-11 N/A 7.2 HIGH
SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database
CVE-2024-39710 1 Ivanti 2 Connect Secure, Policy Secure 2025-07-11 N/A 9.1 CRITICAL
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-39711 1 Ivanti 2 Connect Secure, Policy Secure 2025-07-11 N/A 9.1 CRITICAL
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-39712 1 Ivanti 2 Connect Secure, Policy Secure 2025-07-11 N/A 9.1 CRITICAL
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2024-37397 1 Ivanti 1 Endpoint Manager 2025-07-10 N/A 8.2 HIGH
An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to leak API secrets.
CVE-2024-29821 1 Ivanti 1 Desktop \& Server Management 2025-07-10 N/A 7.8 HIGH
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.
CVE-2024-29213 1 Ivanti 1 Desktop \& Server Management 2025-07-10 N/A 7.8 HIGH
Ivanti DSM < version 2024.2 allows authenticated users on the local machine to run code with elevated privileges due to insecure ACL via unspecified attack vector.