Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 6.5
CVE-2026-14903
Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root.
Xtraction
2026.2.1+
MEDIUM 6.1
CVE-2026-14902
An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs.
Xtraction
2026.2.1+
CRITICAL 10.0
CVE-2026-10520 KEVEPSS 100%
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achie…
Standalone Sentry
10.5.2 / 10.6.2+
CRITICAL 9.8
CVE-2026-10523EPSS 52%
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated at…
Standalone Sentry
10.5.2 / 10.6.2+
HIGH 8.8
CVE-2026-8992
An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arb…
Secure Access Client
after 22.7
HIGH 8.8
CVE-2026-8111
SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code exe…
Endpoint Manager
after 2022
CRITICAL 9.6
CVE-2026-8043
External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write ar…
Xtraction
2026.2+
HIGH 7.8
CVE-2026-8110
Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate th…
Endpoint Manager
after 2022
HIGH 7.2
CVE-2026-8051
OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve …
Virtual Traffic Manager
after 22.8
HIGH 7.0
CVE-2026-7432
A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM
Secure Access Client
after 22.7
MEDIUM 6.5
CVE-2026-8109
An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak acce…
Endpoint Manager
after 2022
CRITICAL 9.1
CVE-2026-7821
Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a …
Endpoint Manager Mobile
12.6.1.1+
HIGH 7.2
CVE-2026-6973 KEVEPSS 34%
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative…
Endpoint Manager Mobile
12.6.1.1+
CRITICAL 9.8
CVE-2026-5788
An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitra…
Endpoint Manager Mobile
12.6.1.1+
CRITICAL 9.1
CVE-2026-5787
An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impers…
Endpoint Manager Mobile
12.6.1.1+
HIGH 8.8
CVE-2026-5786EPSS 6%
An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to ga…
Endpoint Manager Mobile
12.6.1.1+
HIGH 7.8
CVE-2026-3483
An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.
Desktop \& Server Management
2026.1.1+
HIGH 7.5
CVE-2026-1603 KEVEPSS 81%
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credenti…
Endpoint Manager
2024+
MEDIUM 6.5
CVE-2026-1602
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
Endpoint Manager
2024+
CRITICAL 9.8
CVE-2026-1281 KEVEPSS 82%
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Endpoint Manager Mobile
after 12.5.0.0
CRITICAL 9.8
CVE-2026-1340 KEVEPSS 86%
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Endpoint Manager Mobile
after 12.7.0.0
HIGH 8.0
CVE-2025-13661
Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of th…
Endpoint Manager
2024+
HIGH 7.8
CVE-2025-13662
Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a…
Endpoint Manager
2024+
HIGH 8.8
CVE-2025-13659
Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated atta…
Endpoint Manager
2024+
MEDIUM 6.1
CVE-2025-10573EPSS 33%
Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the c…
Endpoint Manager
2024+
HIGH 7.1
CVE-2025-10918
Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary…
Endpoint Manager
2024+
HIGH 7.2
CVE-2025-10242EPSS 21%
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad…
Endpoint Manager Mobile
12.4.0.4 / 12.5.0.4+
HIGH 7.2
CVE-2025-10243EPSS 21%
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad…
Endpoint Manager Mobile
12.4.0.4 / 12.5.0.4+
HIGH 7.2
CVE-2025-10985EPSS 21%
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad…
Endpoint Manager Mobile
12.4.0.4 / 12.5.0.4+
MEDIUM 5.5
CVE-2025-10986
Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin pr…
Endpoint Manager Mobile
12.4.0.4 / 12.5.0.4+