VYPR

Endpoint Manager Mobile

by Ivanti

CVEs (98)

  • CVE-2023-35082CriKEVAug 15, 2023
    risk 0.90cvss 9.8epss 1.00

    An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced earlier.

  • CVE-2023-35078CriKEVJul 25, 2023
    risk 0.90cvss 9.8epss 1.00

    An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.

  • CVE-2026-1340CriKEVJan 29, 2026
    risk 0.85cvss 9.8epss 0.84

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

  • CVE-2026-1281CriKEVJan 29, 2026
    risk 0.85cvss 9.8epss 0.82

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

  • CVE-2024-13159CriKEVJan 14, 2025
    risk 0.84cvss 9.8epss 1.00

    Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

  • CVE-2024-13161CriKEVJan 14, 2025
    risk 0.83cvss 9.8epss 0.90

    Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

  • CVE-2024-13160CriKEVJan 14, 2025
    risk 0.83cvss 9.8epss 0.91

    Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

  • CVE-2026-1603HigKEVFeb 10, 2026
    risk 0.74cvss 8.6epss 0.81

    An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

  • CVE-2025-4428HigKEVMay 13, 2025
    risk 0.68cvss 7.2epss 0.85

    Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.

  • CVE-2023-28324CriJul 1, 2023
    risk 0.68cvss 9.8epss 0.13

    A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.

  • CVE-2024-50330CriNov 12, 2024
    risk 0.67cvss 9.8epss 0.41

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code execution.

  • CVE-2025-10573CriDec 9, 2025
    risk 0.65cvss 9.6epss 0.34

    Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required.

  • CVE-2024-10811CriJan 14, 2025
    risk 0.64cvss 9.8epss 0.04

    Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.

  • CVE-2024-36130CriAug 7, 2024
    risk 0.64cvss 9.8epss 0.02

    An insufficient authorization vulnerability in web component of EPMM prior to 12.1.0.1 allows an unauthorized attacker within the network to execute arbitrary commands on the underlying operating system of the appliance.

  • CVE-2023-39335CriNov 15, 2023
    risk 0.64cvss 9.8epss 0.02

    A security vulnerability has been identified in EPMM Versions 11.10, 11.9 and 11.8 and older allowing an unauthenticated threat actor to impersonate any existing user during the device enrollment process. This issue poses a significant security risk, as it enables unauthorized…

  • CVE-2023-35084CriOct 18, 2023
    risk 0.64cvss 9.8epss 0.03

    Unsafe Deserialization of User Input could lead to Execution of Unauthorized Operations in Ivanti Endpoint Manager 2022 su3 and all previous versions, which could allow an attacker to execute commands remotely.

  • CVE-2023-35081HigKEVAug 3, 2023
    risk 0.64cvss 7.2epss 0.64

    A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.

  • CVE-2023-28323CriJul 1, 2023
    risk 0.64cvss 9.8epss 0.03

    A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities to escalate privileges on the machine…

  • CVE-2026-6973HigKEVMay 7, 2026
    risk 0.62cvss 7.2epss 0.34

    An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

  • CVE-2025-9712HigSep 9, 2025
    risk 0.59cvss 8.8epss 0.21

    Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

Page 1 of 5