VYPR

Endpoint Manager Mobile

by Ivanti

CVEs (98)

  • CVE-2025-6770HigJul 8, 2025
    risk 0.48cvss 7.2epss 0.13

    OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution

  • CVE-2024-50324HigNov 12, 2024
    risk 0.48cvss 7.2epss 0.18

    Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2026-10727HigJun 9, 2026
    risk 0.47cvss 7.2epss 0.14

    An OS command injection vulnerability in Ivanti EPMM before 12.9.0.1, 12.8.0.3 and 12.7.0.2 versions allows a remote authenticated attacker to execute arbitrary commands as root

  • CVE-2025-7037HigJul 8, 2025
    risk 0.47cvss 7.2epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database

  • CVE-2025-22461HigApr 8, 2025
    risk 0.47cvss 7.2epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privileges to achieve code execution.

  • CVE-2024-13158HigJan 14, 2025
    risk 0.47cvss 7.2epss 0.03

    An unbounded resource search path in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-50328HigNov 12, 2024
    risk 0.47cvss 7.2epss 0.02

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2024-50327HigNov 12, 2024
    risk 0.47cvss 7.2epss 0.01

    SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.

  • CVE-2026-5788HigMay 7, 2026
    risk 0.46cvss 7.0epss 0.01

    An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

  • CVE-2025-13661HigDec 9, 2025
    risk 0.46cvss 7.1epss 0.01

    Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required.

  • CVE-2025-10918HigNov 11, 2025
    risk 0.46cvss 7.1epss 0.00

    Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk

  • CVE-2024-10256HigDec 10, 2024
    risk 0.46cvss 7.1epss 0.00

    Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.

  • CVE-2024-8441MedSep 10, 2024
    risk 0.44cvss 6.7epss 0.00

    An uncontrolled search path in the agent of Ivanti EPM before 2022 SU6, or the 2024 September update allows a local authenticated attacker with admin privileges to escalate their privileges to SYSTEM.

  • CVE-2024-22026MedMay 22, 2024
    risk 0.44cvss 6.7epss 0.01

    A local privilege escalation vulnerability in EPMM before 12.1.0.0 allows an authenticated local user to bypass shell restriction and execute arbitrary commands on the appliance.

  • CVE-2023-46807MedMay 22, 2024
    risk 0.44cvss 6.7epss 0.01

    An SQL Injection vulnerability in web component of EPMM before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database.

  • CVE-2023-46806MedMay 22, 2024
    risk 0.44cvss 6.7epss 0.01

    An SQL Injection vulnerability in a web component of EPMM versions before 12.1.0.0 allows an authenticated user with appropriate privilege to access or modify data in the underlying database.

  • CVE-2026-1602MedFeb 10, 2026
    risk 0.42cvss 6.5epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

  • CVE-2025-62392MedOct 13, 2025
    risk 0.42cvss 6.5epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

  • CVE-2025-62391MedOct 13, 2025
    risk 0.42cvss 6.5epss 0.01

    SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

  • CVE-2025-62390MedOct 13, 2025
    risk 0.42cvss 6.5epss 0.02

    SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

Page 4 of 5