📦

endpoint_manager

Vendor: ivanti

Actively Exploited 5 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 52 Remote Access
Total CVEs 203 Total Indexed
Avg. EPSS 14.28% Exploit Prob.
Latest CVE CVE-2026-8111 May 12

Security Vulnerability Index

Page 3 / 21
6.5 CVSS

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

EPSS: 0.34%
8.8 CVSS

Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

EPSS: 3.50%
7.8 CVSS

Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges.

EPSS: 0.18%
8.8 CVSS

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

EPSS: 2.58%
8.8 CVSS

Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.

EPSS: 2.80%
7.2 CVSS

SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database

EPSS: 0.67%
8.4 CVSS

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.

EPSS: 0.09%
8.4 CVSS

Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.

EPSS: 0.09%
8.2 CVSS

Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.

EPSS: 0.23%
6.1 CVSS

Reflected XSS in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to execute arbitrary javascript in a victim's browser. Unlikely user interaction is required.

EPSS: 0.21%