📦

endpoint_manager

Vendor: ivanti

Actively Exploited 5 CISA KEV List
PoC / Exploits 4 Code Available
Total RCEs 52 Remote Access
Total CVEs 203 Total Indexed
Avg. EPSS 14.28% Exploit Prob.
Latest CVE CVE-2026-8111 May 12

Security Vulnerability Index

Page 4 / 21
6.1 CVSS

An untrusted pointer dereference vulnerability in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an attacker with local access to write arbitrary data into memory causing a denial-of-service condition.

EPSS: 0.23%
7.2 CVSS

SQL injection in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote authenticated attacker with admin privileges to achieve code execution.

EPSS: 1.18%
4.8 CVSS

Improper certificate validation in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows a remote unauthenticated attacker to intercept limited traffic between clients and servers.

EPSS: 0.29%
7.8 CVSS

DLL hijacking in Ivanti Endpoint Manager before version 2024 SU1 or before version 2022 SU7 allows an authenticated attacker to escalate to System.

EPSS: 0.16%
7.8 CVSS

Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.

EPSS: 0.70%
7.8 CVSS

Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.

EPSS: 35.89%
7.5 CVSS

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.

EPSS: 1.53%
7.8 CVSS

An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.

EPSS: 0.17%
7.5 CVSS

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.

EPSS: 1.53%
7.5 CVSS

An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.

EPSS: 1.53%