VYPR

Endpoint Manager

by Ivanti

CVEs (124)

  • CVE-2020-13770HigNov 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Several services are accessing named pipes in Ivanti Endpoint Manager through 2020.1.1 with default or overly permissive security attributes; as these services run as user ‘NT AUTHORITY\SYSTEM’, the issue can be used to escalate privileges from a local standard or service…

  • CVE-2026-18127HigAug 11, 2026
    risk 0.50cvss 7.7epss 0.00

    External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage.

  • CVE-2024-34783HigSep 12, 2024
    risk 0.50cvss 7.2epss 0.43

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-32848HigSep 12, 2024
    risk 0.50cvss 7.2epss 0.43

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2026-18125HigAug 11, 2026
    risk 0.49cvss 7.5epss 0.01

    An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service.

  • CVE-2024-13170HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.03

    An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-13168HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.03

    An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-13167HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.03

    An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-13166HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-13165HigJan 14, 2025
    risk 0.49cvss 7.5epss 0.03

    An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.

  • CVE-2024-50326HigNov 12, 2024
    risk 0.49cvss 7.2epss 0.26

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-34785HigSep 12, 2024
    risk 0.49cvss 7.2epss 0.25

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-34779HigSep 12, 2024
    risk 0.49cvss 7.2epss 0.24

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-32845HigSep 12, 2024
    risk 0.49cvss 7.2epss 0.24

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-32840HigSep 12, 2024
    risk 0.49cvss 7.2epss 0.25

    An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2023-38343HigSep 21, 2023
    risk 0.49cvss 7.5epss 0.01

    An XXE (XML external entity injection) vulnerability exists in the CSEP component of Ivanti Endpoint Manager before 2022 SU4. External entity references are enabled in the XML parser configuration. Exploitation of this vulnerability can lead to file disclosure or Server Side…

  • CVE-2023-35077HigJul 21, 2023
    risk 0.49cvss 7.5epss 0.02

    An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update to Ivanti AV Product version 7.9.1.285 or above.

  • CVE-2024-50324HigNov 12, 2024
    risk 0.48cvss 7.2epss 0.18

    Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2025-7037HigJul 8, 2025
    risk 0.47cvss 7.2epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database

  • CVE-2025-22461HigApr 8, 2025
    risk 0.47cvss 7.2epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privileges to achieve code execution.

Page 4 of 7