Skip to main content

Vendor/product archive

ivanti / endpoint_manager CVEs

Beta · best-effort

116 CVEs tagged to ivanti / endpoint_manager13 Critical, 78 High, 25 Medium, 0 Low, 0 Unrated.

CVE-2026-8111

Published May 12, 2026

SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-8110

Published May 12, 2026

Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges.

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-8109

Published May 12, 2026

An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-1603

Published Feb 10, 2026

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

CVSS 8.6 · High
evidence mentions
9
Buzz score
68.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2026-1602

Published Feb 10, 2026

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

CVSS 6.5 · Medium
evidence mentions
4
Buzz score
29.1
Vendor/product tagsBeta · best-effort

CVE-2025-13662

Published Dec 9, 2025

Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attack…

CVSS 7.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-13661

Published Dec 9, 2025

Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User int…

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-13659

Published Dec 9, 2025

Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files…

CVSS 8.8 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-10573

Published Dec 9, 2025

Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator ses…

CVSS 9.6 · Critical
evidence mentions
6
Buzz score
32.5
Vendor/product tagsBeta · best-effort

CVE-2025-10918

Published Nov 11, 2025

Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk

CVSS 7.1 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-62392

Published Oct 13, 2025

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62391

Published Oct 13, 2025

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62390

Published Oct 13, 2025

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62389

Published Oct 13, 2025

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62388

Published Oct 13, 2025

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62387

Published Oct 13, 2025

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62386

Published Oct 13, 2025

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62385

Published Oct 13, 2025

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62384

Published Oct 13, 2025

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-62383

Published Oct 13, 2025

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-11623

Published Oct 13, 2025

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-9713

Published Oct 13, 2025

Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-11622

Published Oct 13, 2025

Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges.

CVSS 7.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-9872

Published Sep 9, 2025

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-9712

Published Sep 9, 2025

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User in…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 116 CVEsPage 1 of 5