ivanti

496 tracked vulnerabilities.

CVE-2025-22455 HIGH
Ivanti Workspace Control <10.19.0.0 - Privilege Escalation
Jun 10, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-4428 HIGH KEV
Ivanti EPMM Authentication Bypass for Expression Language Remote Code Execution
May 13, 2025
CVSS 7.2
EPSS 0.38
CVE-2025-4427 MEDIUM KEVNUCLEI
Ivanti Endpoint Manager Mobile <= 12.5.0.0 - Unauthenticated Authentication Bypass via API
May 13, 2025
CVSS 5.3
EPSS 0.91
CVE-2025-22462 CRITICAL
Ivanti Neurons for ITSM < 2023.4, 2024.2, 2024.3 - Unauthenticated Authentication Bypass
May 13, 2025
CVSS 9.8
EPSS 0.07
CVE-2025-22460 HIGH
Ivanti Cloud Services App <5.0.5 - Privilege Escalation
May 13, 2025
CVSS 7.8
EPSS 0.00
CVE-2025-43716 MEDIUM
Ivanti LANDesk Management Gateway <4.2-1.9 - Path Traversal
Apr 23, 2025
CVSS 5.8
EPSS 0.00
CVE-2025-22466 HIGH
Ivanti Endpoint Manager < 2024 SU1 and < 2022 SU7 - Unauthenticated Reflected Cross-Site Scripting
Apr 08, 2025
CVSS 8.2
EPSS 0.00
CVE-2025-22465 MEDIUM
Ivanti Endpoint Manager < 2024 SU1 and < 2022 SU7 - Unauthenticated Reflected Cross-Site Scripting
Apr 08, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-22464 MEDIUM
Ivanti Endpoint Manager <2024 SU1, <2022 SU7 - Memory Corruption
Apr 08, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-22461 HIGH
Ivanti Endpoint Manager < 2024 SU1 and < 2022 SU7 - Authenticated SQL Injection
Apr 08, 2025
CVSS 7.2
EPSS 0.01
CVE-2025-22459 MEDIUM
Ivanti Endpoint Manager <2024 SU1, <2022 SU7 - Info Disclosure
Apr 08, 2025
CVSS 4.8
EPSS 0.00
CVE-2025-22458 HIGH
Ivanti Endpoint Manager < 2024 SU1 and < 2022 SU7 - Authenticated DLL Hijacking
Apr 08, 2025
CVSS 7.8
EPSS 0.00
CVE-2025-22457 CRITICAL KEVNUCLEI
Ivanti Connect Secure Unauthenticated Remote Code Execution via Stack-based Buffer Overflow
Apr 03, 2025
CVSS 9.0
EPSS 0.59
CVE-2025-22454 HIGH
Ivanti Secure Access Client < 22.7R4 - Authenticated Privilege Escalation via Insufficiently Restrictive Permissions
Mar 11, 2025
CVSS 7.8
EPSS 0.00
CVE-2025-22467 CRITICAL
Ivanti Connect Secure < 22.7R2.6 - Authenticated Remote Code Execution via Stack-based Buffer Overflow
Feb 11, 2025
CVSS 9.9
EPSS 0.44
CVE-2025-0283 HIGH
Ivanti Connect Secure <22.7R2.5 - Privilege Escalation
Jan 08, 2025
CVSS 7.0
EPSS 0.42
CVE-2025-0282 CRITICAL KEVNUCLEI
Ivanti Connect Secure <22.7R2.5 - RCE
Jan 08, 2025
CVSS 9.0
EPSS 0.94
CVE-2024-38648 MEDIUM
Ivanti DSM <2024.2 - Info Disclosure
Jul 12, 2025
CVSS 5.7
EPSS 0.00
CVE-2024-38657 MEDIUM
Ivanti Connect/Ivanti Policy <22.7R2.4/<22.7R1.3 - Path Traversal
Feb 21, 2025
CVSS 4.9
EPSS 0.01
CVE-2024-47908 CRITICAL
Ivanti Cloud Services Appliance < 5.0.5 - Authenticated Remote Code Execution via Admin Web Console
Feb 11, 2025
CVSS 9.1
EPSS 0.54
CVE-2024-13843 MEDIUM
Ivanti Connect Secure < 22.7R2.6 & Policy Secure < 22.7R1.3 - Sensitive Data Exposure via Cleartext Storage
Feb 11, 2025
CVSS 6.0
EPSS 0.00
CVE-2024-13842 MEDIUM
Ivanti Connect/Ivanti Policy <22.7R2.3/<22.7R1.3 - Info Disclosure
Feb 11, 2025
CVSS 6.0
EPSS 0.00
CVE-2024-13830 MEDIUM
Ivanti Connect Secure < 22.7R2.6 and Policy Secure < 22.7R1.3 - Unauthenticated Reflected Cross-Site Scripting
Feb 11, 2025
CVSS 6.1
EPSS 0.00
CVE-2024-13813 HIGH
Ivanti Secure Access Client < 22.8 - Authenticated Arbitrary File Deletion
Feb 11, 2025
CVSS 7.1
EPSS 0.00
CVE-2024-12058 MEDIUM
Ivanti Connect/Ivanti Policy <22.7R2.6/<22.7R1.3 - Path Traversal
Feb 11, 2025
CVSS 6.8
EPSS 0.01