Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Xtraction MEDIUM 6.5
CVE-2026-14903

Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.

Fix: 2026.2.1+
Fix from $1,600 2026-07-14
Xtraction MEDIUM 6.1
CVE-2026-14902

An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs.

Fix: 2026.2.1+
Fix from $1,600 2026-07-14
Standalone Sentry CRITICAL 10.0
CVE-2026-10520 KEVEPSS 100%

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achie…

Fix: 10.5.2 / 10.6.2+
Fix from $2,300 2026-06-09
Standalone Sentry CRITICAL 9.8
CVE-2026-10523EPSS 52%

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated at…

Fix: 10.5.2 / 10.6.2+
Fix from $2,300 2026-06-09
Secure Access Client HIGH 8.8
CVE-2026-8992

An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arb…

Fix: after 22.7
Fix from $1,950 2026-05-22
Endpoint Manager HIGH 8.8
CVE-2026-8111

SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code exe…

Fix: after 2022
Fix from $1,950 2026-05-12
Xtraction CRITICAL 9.6
CVE-2026-8043

External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write ar…

Fix: 2026.2+
Fix from $2,300 2026-05-12
Endpoint Manager HIGH 7.8
CVE-2026-8110

Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate th…

Fix: after 2022
Fix from $1,950 2026-05-12
Virtual Traffic Manager HIGH 7.2
CVE-2026-8051

OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve …

Fix: after 22.8
Fix from $1,950 2026-05-12
Secure Access Client HIGH 7.0
CVE-2026-7432

A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM

Fix: after 22.7
Fix from $1,950 2026-05-12
Endpoint Manager MEDIUM 6.5
CVE-2026-8109

An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak acce…

Fix: after 2022
Fix from $1,600 2026-05-12
Endpoint Manager Mobile CRITICAL 9.1
CVE-2026-7821

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a …

Fix: 12.6.1.1+
Fix from $2,300 2026-05-07
Endpoint Manager Mobile HIGH 7.2
CVE-2026-6973 KEVEPSS 34%

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative…

Fix: 12.6.1.1+
Fix from $1,950 2026-05-07
Endpoint Manager Mobile CRITICAL 9.8
CVE-2026-5788

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitra…

Fix: 12.6.1.1+
Fix from $2,300 2026-05-07
Endpoint Manager Mobile CRITICAL 9.1
CVE-2026-5787

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impers…

Fix: 12.6.1.1+
Fix from $2,300 2026-05-07
Endpoint Manager Mobile HIGH 8.8
CVE-2026-5786EPSS 6%

An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to ga…

Fix: 12.6.1.1+
Fix from $1,950 2026-05-07
Desktop \& Server Management HIGH 7.8
CVE-2026-3483

An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.

Fix: 2026.1.1+
Fix from $1,950 2026-03-10
Endpoint Manager HIGH 7.5
CVE-2026-1603 KEVEPSS 81%

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credenti…

Fix: 2024+
Fix from $1,950 2026-02-10
Endpoint Manager MEDIUM 6.5
CVE-2026-1602

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Fix: 2024+
Fix from $1,600 2026-02-10
Endpoint Manager Mobile CRITICAL 9.8
CVE-2026-1281 KEVEPSS 82%

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Fix: after 12.5.0.0
Fix from $2,300 2026-01-29
Endpoint Manager Mobile CRITICAL 9.8
CVE-2026-1340 KEVEPSS 86%

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Fix: after 12.7.0.0
Fix from $2,300 2026-01-29
Endpoint Manager HIGH 8.0
CVE-2025-13661

Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of th…

Fix: 2024+
Fix from $1,950 2025-12-09
Endpoint Manager HIGH 7.8
CVE-2025-13662

Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a…

Fix: 2024+
Fix from $1,950 2025-12-09
Endpoint Manager HIGH 8.8
CVE-2025-13659

Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated atta…

Fix: 2024+
Fix from $1,950 2025-12-09
Endpoint Manager MEDIUM 6.1
CVE-2025-10573EPSS 33%

Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the c…

Fix: 2024+
Fix from $1,600 2025-12-09
Endpoint Manager HIGH 7.1
CVE-2025-10918

Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary…

Fix: 2024+
Fix from $1,950 2025-11-11
Endpoint Manager Mobile HIGH 7.2
CVE-2025-10242EPSS 21%

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad…

Fix: 12.4.0.4 / 12.5.0.4+
Fix from $1,950 2025-10-14
Endpoint Manager Mobile HIGH 7.2
CVE-2025-10243EPSS 21%

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad…

Fix: 12.4.0.4 / 12.5.0.4+
Fix from $1,950 2025-10-14
Endpoint Manager Mobile HIGH 7.2
CVE-2025-10985EPSS 21%

OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad…

Fix: 12.4.0.4 / 12.5.0.4+
Fix from $1,950 2025-10-14
Endpoint Manager Mobile MEDIUM 5.5
CVE-2025-10986

Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin pr…

Fix: 12.4.0.4 / 12.5.0.4+
Fix from $1,600 2025-10-14