Vulnerabilities (CVE)

Filtered by vendor Ivanti Subscribe
Filtered by product Endpoint Manager
Total 107 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2025-10918 1 Ivanti 1 Endpoint Manager 2025-11-17 N/A 7.1 HIGH
Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk
CVE-2025-9713 1 Ivanti 1 Endpoint Manager 2025-11-11 N/A 8.8 HIGH
Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
CVE-2025-11622 1 Ivanti 1 Endpoint Manager 2025-11-11 N/A 7.8 HIGH
Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges.
CVE-2024-29824 1 Ivanti 1 Endpoint Manager 2025-10-30 N/A 8.8 HIGH
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
CVE-2024-13159 1 Ivanti 1 Endpoint Manager 2025-10-24 N/A 9.8 CRITICAL
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
CVE-2024-13160 1 Ivanti 1 Endpoint Manager 2025-10-24 N/A 9.8 CRITICAL
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
CVE-2024-13161 1 Ivanti 1 Endpoint Manager 2025-10-24 N/A 9.8 CRITICAL
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
CVE-2025-11623 1 Ivanti 1 Endpoint Manager 2025-10-15 N/A 6.5 MEDIUM
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.
CVE-2025-62383 1 Ivanti 1 Endpoint Manager 2025-10-15 N/A 6.5 MEDIUM
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.
CVE-2025-62385 1 Ivanti 1 Endpoint Manager 2025-10-15 N/A 6.5 MEDIUM
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.
CVE-2025-62386 1 Ivanti 1 Endpoint Manager 2025-10-15 N/A 6.5 MEDIUM
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.
CVE-2025-62387 1 Ivanti 1 Endpoint Manager 2025-10-15 N/A 6.5 MEDIUM
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.
CVE-2025-62388 1 Ivanti 1 Endpoint Manager 2025-10-15 N/A 6.5 MEDIUM
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.
CVE-2025-62389 1 Ivanti 1 Endpoint Manager 2025-10-15 N/A 6.5 MEDIUM
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.
CVE-2025-62390 1 Ivanti 1 Endpoint Manager 2025-10-15 N/A 6.5 MEDIUM
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.
CVE-2025-62391 1 Ivanti 1 Endpoint Manager 2025-10-15 N/A 6.5 MEDIUM
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.
CVE-2025-62392 1 Ivanti 1 Endpoint Manager 2025-10-15 N/A 6.5 MEDIUM
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.
CVE-2025-62384 1 Ivanti 1 Endpoint Manager 2025-10-15 N/A 6.5 MEDIUM
SQL injection in Ivanti Endpoint Manager allows a remote authenticated attacker to read arbitrary data from the database.
CVE-2025-9712 1 Ivanti 1 Endpoint Manager 2025-10-10 N/A 8.8 HIGH
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
CVE-2025-9872 1 Ivanti 1 Endpoint Manager 2025-10-10 N/A 8.8 HIGH
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.