Vulnerability index

Browse CVEs

467 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2026-14903 Path traversal in Ivanti  Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary files outside the web root. Xtraction 2026.2.1+ Fix from $1,6002026-07-14 MEDIUM 6.1 CVE-2026-14902 An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users to arbitrary external URLs. Xtraction 2026.2.1+ Fix from $1,6002026-07-14 CRITICAL 10.0 CVE-2026-10520 KEVEPSS 100% An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achie… Standalone Sentry 10.5.2 / 10.6.2+ Fix from $2,3002026-06-09 CRITICAL 9.8 CVE-2026-10523EPSS 52% An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated at… Standalone Sentry 10.5.2 / 10.6.2+ Fix from $2,3002026-06-09 HIGH 8.8 CVE-2026-8992 An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arb… Secure Access Client after 22.7 Fix from $1,9502026-05-22 HIGH 8.8 CVE-2026-8111 SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code exe… Endpoint Manager after 2022 Fix from $1,9502026-05-12 CRITICAL 9.6 CVE-2026-8043 External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write ar… Xtraction 2026.2+ Fix from $2,3002026-05-12 HIGH 7.8 CVE-2026-8110 Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate th… Endpoint Manager after 2022 Fix from $1,9502026-05-12 HIGH 7.2 CVE-2026-8051 OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve … Virtual Traffic Manager after 22.8 Fix from $1,9502026-05-12 HIGH 7.0 CVE-2026-7432 A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM Secure Access Client after 22.7 Fix from $1,9502026-05-12 MEDIUM 6.5 CVE-2026-8109 An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak acce… Endpoint Manager after 2022 Fix from $1,6002026-05-12 CRITICAL 9.1 CVE-2026-7821 Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a … Endpoint Manager Mobile 12.6.1.1+ Fix from $2,3002026-05-07 HIGH 7.2 CVE-2026-6973 KEVEPSS 34% An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative… Endpoint Manager Mobile 12.6.1.1+ Fix from $1,9502026-05-07 CRITICAL 9.8 CVE-2026-5788 An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitra… Endpoint Manager Mobile 12.6.1.1+ Fix from $2,3002026-05-07 CRITICAL 9.1 CVE-2026-5787 An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impers… Endpoint Manager Mobile 12.6.1.1+ Fix from $2,3002026-05-07 HIGH 8.8 CVE-2026-5786EPSS 6% An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to ga… Endpoint Manager Mobile 12.6.1.1+ Fix from $1,9502026-05-07 HIGH 7.8 CVE-2026-3483 An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges. Desktop \& Server Management 2026.1.1+ Fix from $1,9502026-03-10 HIGH 7.5 CVE-2026-1603 KEVEPSS 81% An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credenti… Endpoint Manager 2024+ Fix from $1,9502026-02-10 MEDIUM 6.5 CVE-2026-1602 SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. Endpoint Manager 2024+ Fix from $1,6002026-02-10 CRITICAL 9.8 CVE-2026-1281 KEVEPSS 82% A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. Endpoint Manager Mobile after 12.5.0.0 Fix from $2,3002026-01-29 CRITICAL 9.8 CVE-2026-1340 KEVEPSS 86% A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. Endpoint Manager Mobile after 12.7.0.0 Fix from $2,3002026-01-29 HIGH 8.0 CVE-2025-13661 Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of th… Endpoint Manager 2024+ Fix from $1,9502025-12-09 HIGH 7.8 CVE-2025-13662 Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a… Endpoint Manager 2024+ Fix from $1,9502025-12-09 HIGH 8.8 CVE-2025-13659 Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated atta… Endpoint Manager 2024+ Fix from $1,9502025-12-09 MEDIUM 6.1 CVE-2025-10573EPSS 33% Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the c… Endpoint Manager 2024+ Fix from $1,6002025-12-09 HIGH 7.1 CVE-2025-10918 Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary… Endpoint Manager 2024+ Fix from $1,9502025-11-11 HIGH 7.2 CVE-2025-10242EPSS 21% OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad… Endpoint Manager Mobile 12.4.0.4 / 12.5.0.4+ Fix from $1,9502025-10-14 HIGH 7.2 CVE-2025-10243EPSS 21% OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad… Endpoint Manager Mobile 12.4.0.4 / 12.5.0.4+ Fix from $1,9502025-10-14 HIGH 7.2 CVE-2025-10985EPSS 21% OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with ad… Endpoint Manager Mobile 12.4.0.4 / 12.5.0.4+ Fix from $1,9502025-10-14 MEDIUM 5.5 CVE-2025-10986 Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin pr… Endpoint Manager Mobile 12.4.0.4 / 12.5.0.4+ Fix from $1,6002025-10-14