Skip to main content

Vendor/product archive

ivanti / endpoint_manager CVEs

Beta · best-effort

116 CVEs tagged to ivanti / endpoint_manager13 Critical, 78 High, 25 Medium, 0 Low, 0 Unrated.

CVE-2024-37376

Published Nov 13, 2024

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34787

Published Nov 13, 2024

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code executi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34784

Published Nov 13, 2024

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34782

Published Nov 13, 2024

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34781

Published Nov 13, 2024

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-34780

Published Nov 13, 2024

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32847

Published Nov 13, 2024

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32844

Published Nov 13, 2024

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32841

Published Nov 13, 2024

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-32839

Published Nov 13, 2024

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50330

Published Nov 12, 2024

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-50329

Published Nov 12, 2024

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote unauthenticated attacker to achieve remote code…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50328

Published Nov 12, 2024

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50327

Published Nov 12, 2024

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50326

Published Nov 12, 2024

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50324

Published Nov 12, 2024

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50323

Published Nov 12, 2024

SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code executio…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-50322

Published Nov 12, 2024

Path traversal in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a local unauthenticated attacker to achieve code executi…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37397

Published Sep 12, 2024

An External XML Entity (XXE) vulnerability in the provisioning web service of Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote unauthenticated attacker to…

CVSS 8.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-34785

Published Sep 12, 2024

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execut…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-34783

Published Sep 12, 2024

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execut…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-34779

Published Sep 12, 2024

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execut…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-32848

Published Sep 12, 2024

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execut…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-32846

Published Sep 12, 2024

An unspecified SQL injection in Ivanti EPM before 2022 SU6, or the 2024 September update allows a remote authenticated attacker with admin privileges to achieve remote code execut…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort
Showing 51-75 of 116 CVEsPage 3 of 5