Vulnerability index

Browse CVEs

35 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Standalone Sentry CRITICAL 10.0
CVE-2026-10520 KEVEPSS 100%

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achie…

Fix: 10.5.2 / 10.6.2+
Fix from $2,300 2026-06-09
Endpoint Manager Mobile HIGH 7.2
CVE-2026-6973 KEVEPSS 34%

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative…

Fix: 12.6.1.1+
Fix from $1,950 2026-05-07
Endpoint Manager HIGH 7.5
CVE-2026-1603 KEVEPSS 81%

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credenti…

Fix: 2024+
Fix from $1,950 2026-02-10
Endpoint Manager Mobile CRITICAL 9.8
CVE-2026-1281 KEVEPSS 82%

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Fix: after 12.5.0.0
Fix from $2,300 2026-01-29
Endpoint Manager Mobile CRITICAL 9.8
CVE-2026-1340 KEVEPSS 86%

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Fix: after 12.7.0.0
Fix from $2,300 2026-01-29
Endpoint Manager Mobile HIGH 8.8
CVE-2025-4428 KEVEPSS 86%

Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers t…

Fix: 11.12.0.5 / 12.3.0.2+
Fix from $1,950 2025-05-13
Endpoint Manager Mobile HIGH 7.5
CVE-2025-4427 KEVEPSS 100%

An authentication bypass in the API component of Ivanti Endpoint Manager Mobile 12.5.0.0 and prior allows attackers to access protected resources wit…

Fix: 11.12.0.5 / 12.3.0.2+
Fix from $1,950 2025-05-13
Connect Secure CRITICAL 9.8
CVE-2025-22457 KEVEPSS 100%

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways…

Fix: 22.7 / 22.8+
Fix from $2,300 2025-04-03
Endpoint Manager HIGH 7.5
CVE-2024-13159 KEVEPSS 100%

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthen…

Fix: 2022+
Fix from $1,950 2025-01-14
Endpoint Manager HIGH 7.5
CVE-2024-13160 KEVEPSS 91%

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthen…

Fix: 2022+
Fix from $1,950 2025-01-14
Endpoint Manager HIGH 7.5
CVE-2024-13161 KEVEPSS 90%

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthen…

Fix: 2022+
Fix from $1,950 2025-01-14
Connect Secure CRITICAL 9.0
CVE-2025-0282 KEVEPSS 100%

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for …

Mitigation only
Fix from $2,300 2025-01-08
Endpoint Manager Cloud Services Appliance HIGH 7.2
CVE-2024-9379 KEVEPSS 43%

SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitra…

Fix: 5.0.2+
Fix from $1,950 2024-10-08
Endpoint Manager Cloud Services Appliance HIGH 7.2
CVE-2024-9380 KEVEPSS 63%

An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin p…

Fix: 5.0.2+
Fix from $1,950 2024-10-08
Endpoint Manager Cloud Services Appliance CRITICAL 9.1
CVE-2024-8963 KEVEPSS 99%

Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.

Mitigation only
Fix from $2,300 2024-09-19
Cloud Services Appliance HIGH 7.2
CVE-2024-8190 KEVEPSS 89%

An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to …

Mitigation only
Fix from $1,950 2024-09-10
Virtual Traffic Manager CRITICAL 9.8
CVE-2024-7593 KEVEPSS 100%

Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated attacker t…

Patch available
Fix from $2,300 2024-08-13
Endpoint Manager HIGH 8.8
CVE-2024-29824 KEVEPSS 100%

An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network…

Fix: 2022+
Fix from $1,950 2024-05-31
Connect Secure HIGH 8.2
CVE-2024-21893 KEVEPSS 100%

A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivant…

Mitigation only
Fix from $1,950 2024-01-31
Connect Secure CRITICAL 9.1
CVE-2024-21887 KEVEPSS 100%

A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticate…

Mitigation only
Fix from $2,300 2024-01-12
Connect Secure HIGH 8.2
CVE-2023-46805 KEVEPSS 100%

An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restr…

Mitigation only
Fix from $1,950 2024-01-12
Mobileiron Sentry CRITICAL 9.8
CVE-2023-38035 KEVEPSS 100%

A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentica…

Fix: after 9.18.0
Fix from $2,300 2023-08-21
Endpoint Manager Mobile CRITICAL 9.8
CVE-2023-35082 KEVEPSS 100%

An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of t…

Fix: 11.11.0+
Fix from $2,300 2023-08-15
Endpoint Manager Mobile HIGH 7.2
CVE-2023-35081 KEVEPSS 64%

A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated admini…

Fix: 11.8.1.2 / 11.9.1.2+
Fix from $1,950 2023-08-03
Endpoint Manager Mobile CRITICAL 9.8
CVE-2023-35078 KEVEPSS 100%

An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application wi…

Fix: 11.8.1.1 / 11.9.1.1+
Fix from $2,300 2023-07-25
Endpoint Manager Cloud Services Appliance CRITICAL 9.8
CVE-2021-44529 KEVEPSS 99%

A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited…

Fix: after 4.5
Fix from $2,300 2021-12-08
Connect Secure HIGH 8.8
CVE-2021-22894 KEVEPSS 41%

A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as th…

Mitigation only
Fix from $1,950 2021-05-27
Connect Secure HIGH 8.8
CVE-2021-22899 KEVEPSS 23%

A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execut…

Mitigation only
Fix from $1,950 2021-05-27
Connect Secure HIGH 7.2
CVE-2021-22900 KEVEPSS 14%

A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to pe…

Fix: after 9.1
Fix from $1,950 2021-05-27
Connect Secure CRITICAL 10.0
CVE-2021-22893 KEVEPSS 47%

Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pul…

Mitigation only
Fix from $2,300 2021-04-23