Search: "ivanti"

379 CVEs found

CVE-2026-1340
9.8 CRITICAL

A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

Published: 2026-01-29
Products: 1
Vendors:
ivanti
CVE-2026-1602
6.5 MEDIUM

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Published: 2026-02-10
Products: 8
Vendors:
ivanti

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

Published: 2026-02-10
Products: 8
Vendors:
ivanti

An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate their privileges.

Published: 2026-03-10
Products: 1
Vendors:
ivanti

An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.

Published: 2026-05-07
Products: 3
Vendors:
ivanti

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-s...

Published: 2026-05-07
Products: 3
Vendors:
ivanti

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

Published: 2026-05-07
Products: 3
Vendors:
ivanti

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

Published: 2026-05-07
Products: 3
Vendors:
ivanti

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled ...

Published: 2026-05-07
Products: 3
Vendors:
ivanti
CVE-2026-7431
4.4 MEDIUM

An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a sha...

Published: 2026-05-12
Products: 8
Vendors:
ivanti microsoft

A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM

Published: 2026-05-12
Products: 8
Vendors:
ivanti microsoft
CVE-2026-8043
9.6 CRITICAL

External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read sensitive files and write arbitrary HTML files to a web directory, leading to i...

Published: 2026-05-12
Products: 1
Vendors:
ivanti

OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.

Published: 2026-05-12
Products: 4
Vendors:
ivanti

SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.

Published: 2026-05-12
Products: 9
Vendors:
ivanti

An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code.

Published: 2026-05-22
Products: 8
Vendors:
ivanti microsoft

An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access.

Published: 2026-06-01
Products: 0
CVE-2026-10520
10.0 CRITICAL

An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution

Published: 2026-06-09
Products: 3
Vendors:
ivanti
CVE-2026-10523
9.9 CRITICAL

An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated attacker to create arbitrary administrative accounts ...

Published: 2026-06-09
Products: 0

An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root

Published: 2026-06-09
Products: 0