ivanti records
504 published records for vendor ivanti.
Researcher profile
- Entered KEV
- 35 · 6.9%
- Weaponized
- 39 · 7.7%
- Pre-auth RCE
- 45
- With a fix record
- 12.5%
- Median publish → KEV
- 27 days
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')67
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')42
- CWE-787 Out-of-bounds Write27
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')21
- CWE-502 Deserialization of Untrusted Data19
- CWE-434 Unrestricted Upload of File with Dangerous Type19
The weakness classes this vendor ships most often: where to look.
CWEAll records
504 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2019-11510Weaponized | In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attackivanti · connect secure · CWE-22 | Critical10.0 | KEV | 100.0% | May 8, 2019 |
100Now | CVE-2026-10520Weaponized | An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated userivanti · standalone sentry · CWE-78 | Critical10.0 | KEV | 99.9% | Jun 9, 2026 |
99Now | CVE-2024-7593Weaponized | Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated aivanti · virtual traffic manager · CWE-287 | Critical9.8 | KEV | 100.0% | Aug 13, 2024 |
99Now | CVE-2023-35078Weaponized | An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appliivanti · endpoint manager mobile · CWE-287 | Critical9.8 | KEV | 100.0% | Jul 25, 2023 |
99Now | CVE-2023-35082Weaponized | An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resouivanti · endpoint manager mobile · CWE-287 | Critical9.8 | KEV | 100.0% | Aug 15, 2023 |
99Now | CVE-2025-22457Weaponized | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTAivanti · connect secure · CWE-121 | Critical9.8 | KEV | 100.0% | Apr 3, 2025 |
99Now | CVE-2023-38035Weaponized | A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass aivanti · mobileiron sentry · CWE-863 | Critical9.8 | KEV | 100.0% | Aug 21, 2023 |
99Now | CVE-2021-44529Weaponized | A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code witivanti · endpoint manager cloud services appliance · CWE-94 | Critical9.8 | KEV | 99.1% | Dec 8, 2021 |
99Now | CVE-2026-1281Weaponized | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.ivanti · endpoint manager mobile · CWE-94 | Critical9.8 | KEV | 98.7% | Jan 29, 2026 |
99Now | CVE-2026-1340Weaponized | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.ivanti · endpoint manager mobile · CWE-94 | Critical9.8 | KEV | 98.6% | Jan 29, 2026 |
96Now | CVE-2024-21887Weaponized | A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an autivanti · connect secure · CWE-77 | Critical9.1 | KEV | 100.0% | Jan 12, 2024 |
96Now | CVE-2025-0282Weaponized | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neuivanti · connect secure · CWE-121 | Critical9.0 | KEV | 100.0% | Jan 8, 2025 |
96Now | CVE-2024-8963Weaponized | Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.ivanti · endpoint manager cloud services appliance · CWE-22 | Critical9.1 | KEV | 98.6% | Sep 19, 2024 |
95Now | CVE-2024-29824Weaponized | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the samivanti · endpoint manager · CWE-89 | High8.8 | KEV | 99.9% | May 31, 2024 |
92Now | CVE-2024-21893Weaponized | A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) ivanti · connect secure · CWE-918 | High8.2 | KEV | 100.0% | Jan 31, 2024 |
92Now | CVE-2023-46805Weaponized | An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to accivanti · connect secure · CWE-287 | High8.2 | KEV | 100.0% | Jan 12, 2024 |
91Now | CVE-2025-4428Weaponized | Remote Code Executionivanti · endpoint manager mobile · CWE-94 | High8.8 | KEV | 86.5% | May 13, 2025 |
90Now | CVE-2024-13159Weaponized | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remoteivanti · endpoint manager · CWE-36 | High7.5 | KEV | 100.0% | Jan 14, 2025 |
90Now | CVE-2025-4427Weaponized | Authentication Bypassivanti · endpoint manager mobile · CWE-288 | High7.5 | KEV | 99.9% | May 13, 2025 |
88Now | CVE-2019-11539Weaponized | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 anivanti · connect secure · CWE-78 | High7.2 | KEV | 98.5% | Apr 25, 2019 |
87Now | CVE-2020-8260Weaponized | A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code eivanti · connect secure · CWE-434 | High7.2 | KEV | 96.5% | Oct 28, 2020 |
87Now | CVE-2024-13160Weaponized | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remoteivanti · endpoint manager · CWE-36 | High7.5 | KEV | 91.2% | Jan 14, 2025 |
87Now | CVE-2024-13161Weaponized | Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remoteivanti · endpoint manager · CWE-36 | High7.5 | KEV | 90.1% | Jan 14, 2025 |
86Now | CVE-2026-1603Weaponized | An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific storedivanti · endpoint manager · CWE-288 | High7.5 | KEV | 87.6% | Feb 10, 2026 |
85Now | CVE-2020-8243Weaponized | A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template toivanti · connect secure · CWE-94 | High7.2 | KEV | 90.8% | Sep 30, 2020 |
- CVE-2019-11510100Now
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attack
CriticalCVSS 10.0KEVWeaponizedEPSS 100%ivanti · connect secureMay 8, 2019
- CVE-2026-10520100Now
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user
CriticalCVSS 10.0KEVWeaponizedEPSS 100%ivanti · standalone sentryJun 9, 2026
- CVE-2024-759399Now
Incorrect implementation of an authentication algorithm in Ivanti vTM other than versions 22.2R1 or 22.7R2 allows a remote unauthenticated a
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ivanti · virtual traffic managerAug 13, 2024
- CVE-2023-3507899Now
An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the appli
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ivanti · endpoint manager mobileJul 25, 2023
- CVE-2023-3508299Now
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resou
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ivanti · endpoint manager mobileAug 15, 2023
- CVE-2025-2245799Now
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ivanti · connect secureApr 3, 2025
- CVE-2023-3803599Now
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass a
CriticalCVSS 9.8KEVWeaponizedEPSS 100%ivanti · mobileiron sentryAug 21, 2023
- CVE-2021-4452999Now
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code wit
CriticalCVSS 9.8KEVWeaponizedEPSS 99%ivanti · endpoint manager cloud services applianceDec 8, 2021
- CVE-2026-128199Now
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%ivanti · endpoint manager mobileJan 29, 2026
- CVE-2026-134099Now
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%ivanti · endpoint manager mobileJan 29, 2026
- CVE-2024-2188796Now
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an aut
CriticalCVSS 9.1KEVWeaponizedEPSS 100%ivanti · connect secureJan 12, 2024
- CVE-2025-028296Now
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neu
CriticalCVSS 9.0KEVWeaponizedEPSS 100%ivanti · connect secureJan 8, 2025
- CVE-2024-896396Now
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
CriticalCVSS 9.1KEVWeaponizedEPSS 99%ivanti · endpoint manager cloud services applianceSep 19, 2024
- CVE-2024-2982495Now
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the sam
HighCVSS 8.8KEVWeaponizedEPSS 100%ivanti · endpoint managerMay 31, 2024
- CVE-2024-2189392Now
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x)
HighCVSS 8.2KEVWeaponizedEPSS 100%ivanti · connect secureJan 31, 2024
- CVE-2023-4680592Now
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to acc
HighCVSS 8.2KEVWeaponizedEPSS 100%ivanti · connect secureJan 12, 2024
- CVE-2025-442891Now
Remote Code Execution
HighCVSS 8.8KEVWeaponizedEPSS 87%ivanti · endpoint manager mobileMay 13, 2025
- CVE-2024-1315990Now
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote
HighCVSS 7.5KEVWeaponizedEPSS 100%ivanti · endpoint managerJan 14, 2025
- CVE-2025-442790Now
Authentication Bypass
HighCVSS 7.5KEVWeaponizedEPSS 100%ivanti · endpoint manager mobileMay 13, 2025
- CVE-2019-1153988Now
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 an
HighCVSS 7.2KEVWeaponizedEPSS 99%ivanti · connect secureApr 25, 2019
- CVE-2020-826087Now
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code e
HighCVSS 7.2KEVWeaponizedEPSS 96%ivanti · connect secureOct 28, 2020
- CVE-2024-1316087Now
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote
HighCVSS 7.5KEVWeaponizedEPSS 91%ivanti · endpoint managerJan 14, 2025
- CVE-2024-1316187Now
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote
HighCVSS 7.5KEVWeaponizedEPSS 90%ivanti · endpoint managerJan 14, 2025
- CVE-2026-160386Now
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored
HighCVSS 7.5KEVWeaponizedEPSS 88%ivanti · endpoint managerFeb 10, 2026
- CVE-2020-824385Now
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to
HighCVSS 7.2KEVWeaponizedEPSS 91%ivanti · connect secureSep 30, 2020