Ivanti
22 known vulnerabilities
Top Products
Path traversal in Ivanti Xtraction before version 2026.2.1 allows a remote authenticated attacker to read arbitrary fil
An open redirect in Ivanti Xtraction before version 2026.2.1 allows a remote unauthenticated attacker to redirect users
An Authentication Bypass vulnerability (CWE-288) in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allow
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote
An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenti
SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attack
Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenti
An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authen
OS command injection in Ivanti Virtual Traffic Manager before version 22.9r4 allows a remote authenticated attacker with
External control of a file name in Ivanti Xtraction before version 2026.2 allows a remote authenticated attacker to read
A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges
An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local a
Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthen
An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authentic
An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticat
An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unaut
An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote
An exposed dangerous method in Ivanti DSM before version 2026.1.1 allows a local authenticated attacker to escalate thei
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrar
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
Frequently Asked Questions
How many CVEs affect Ivanti?
Ivanti has 22 CVE records in our database, including 5 critical and 13 high severity vulnerabilities. 5 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Ivanti vulnerabilities?
Ivanti has 5 critical severity (CVSS 9.0+) and 13 high severity (CVSS 7.0-8.9) vulnerabilities. 5 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Ivanti vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Ivanti products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Ivanti Vulnerabilities
CyberStrike scans your infrastructure for Ivanti vulnerabilities and provides real-time remediation guidance.
Get Started