Vulnerabilities (CVE)

Filtered by vendor Ivanti Subscribe
Total 492 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2026-10523 1 Ivanti 1 Standalone Sentry 2026-06-22 N/A 9.9 CRITICAL
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts and obtain full administrative access
CVE-2026-8992 2 Ivanti, Microsoft 2 Secure Access Client, Windows 2026-06-17 N/A 8.8 HIGH
An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.
CVE-2026-8111 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.8 HIGH
SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.
CVE-2026-8110 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 7.8 HIGH
Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges.
CVE-2026-8109 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 6.5 MEDIUM
An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials.
CVE-2026-8051 1 Ivanti 1 Virtual Traffic Manager 2026-06-17 N/A 7.2 HIGH
OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
CVE-2026-8043 1 Ivanti 1 Xtraction 2026-06-17 N/A 9.6 CRITICAL
External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to information disclosure and possible client-side attacks.
CVE-2026-7821 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 7.4 HIGH
Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled device identity.
CVE-2026-7432 2 Ivanti, Microsoft 2 Secure Access Client, Windows 2026-06-17 N/A 7.8 HIGH
A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM
CVE-2026-7431 2 Ivanti, Microsoft 2 Secure Access Client, Windows 2026-06-17 N/A 4.4 MEDIUM
An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section.
CVE-2026-6973 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 7.2 HIGH
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.
CVE-2026-5788 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 7.0 HIGH
An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.
CVE-2026-5787 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 8.9 HIGH
An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates.
CVE-2026-5786 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 8.8 HIGH
An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.
CVE-2026-3483 1 Ivanti 1 Desktop \& Server Management 2026-06-17 N/A 7.8 HIGH
An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.
CVE-2026-1603 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 8.6 HIGH
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
CVE-2026-1602 1 Ivanti 1 Endpoint Manager 2026-06-17 N/A 6.5 MEDIUM
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
CVE-2026-1340 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 9.8 CRITICAL
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
CVE-2026-1281 1 Ivanti 1 Endpoint Manager Mobile 2026-06-17 N/A 9.8 CRITICAL
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
CVE-2026-10520 1 Ivanti 1 Standalone Sentry 2026-06-17 N/A 10.0 CRITICAL
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution