📦 Endpoint Manager

by Ivanti

🔍 What is Endpoint Manager?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-10573

CRITICAL CVSS 9.6 Dec 9, 2025

This stored cross-site scripting (XSS) vulnerability in Ivanti Endpoint Manager allows unauthenticated remote attackers to inject malicious JavaScript that executes when administrators view compromise...

CVE-2024-13159

CRITICAL CVSS 9.8 Jan 14, 2025

CVE-2024-13159 is an absolute path traversal vulnerability in Ivanti Endpoint Manager (EPM) that allows remote unauthenticated attackers to access sensitive files on the server. This affects Ivanti EP...

CVE-2024-13161

CRITICAL CVSS 9.8 Jan 14, 2025

This vulnerability allows remote unauthenticated attackers to perform absolute path traversal attacks on Ivanti Endpoint Manager (EPM) systems, potentially leaking sensitive information like credentia...

CVE-2024-10811

CRITICAL CVSS 9.8 Jan 14, 2025

This vulnerability allows remote unauthenticated attackers to perform absolute path traversal attacks on Ivanti Endpoint Manager (EPM) systems, potentially leaking sensitive information like credentia...

CVE-2024-50330

CRITICAL CVSS 9.8 Nov 12, 2024

This critical SQL injection vulnerability in Ivanti Endpoint Manager allows remote unauthenticated attackers to execute arbitrary SQL commands, potentially leading to remote code execution. All organi...

CVE-2024-29847

CRITICAL CVSS 9.8 Sep 12, 2024

This critical vulnerability allows remote unauthenticated attackers to execute arbitrary code on Ivanti EPM systems by exploiting insecure deserialization in the agent portal. Organizations using Ivan...

CVE-2023-35084

CRITICAL CVSS 9.8 Oct 18, 2023

CVE-2023-35084 is a critical remote code execution vulnerability in Ivanti Endpoint Manager (formerly LANDesk Management Suite) caused by unsafe deserialization of untrusted data. Attackers can exploi...

CVE-2023-28324

CRITICAL CVSS 9.8 Jul 1, 2023

CVE-2023-28324 is an improper input validation vulnerability in Ivanti Endpoint Manager that could allow attackers to escalate privileges or execute arbitrary code. This affects Ivanti Endpoint Manage...

CVE-2020-13774

CRITICAL CVSS 9.9 Nov 12, 2020

This vulnerability allows authenticated attackers to upload malicious ASPX files to Ivanti Endpoint Manager servers, leading to remote code execution. Attackers can gain full control of affected syste...

CVE-2026-1603

HIGH CVSS 8.6 Feb 10, 2026

An authentication bypass vulnerability in Ivanti Endpoint Manager allows remote unauthenticated attackers to access stored credential data. This affects all Ivanti Endpoint Manager installations befor...

CVE-2025-13661

HIGH CVSS 7.1 Dec 9, 2025

CVE-2025-13661 is a path traversal vulnerability in Ivanti Endpoint Manager that allows authenticated remote attackers to write arbitrary files outside intended directories. This affects Ivanti Endpoi...

CVE-2025-13662

HIGH CVSS 7.8 Dec 9, 2025

CVE-2025-13662 is a critical vulnerability in Ivanti Endpoint Manager's patch management component that allows remote unauthenticated attackers to execute arbitrary code by exploiting improper cryptog...

CVE-2025-13659

HIGH CVSS 8.8 Dec 9, 2025

This vulnerability in Ivanti Endpoint Manager allows remote, unauthenticated attackers to write arbitrary files to the server, which could lead to remote code execution. User interaction is required f...

CVE-2025-10918

HIGH CVSS 7.1 Nov 11, 2025

This vulnerability allows local authenticated attackers to write arbitrary files anywhere on disk due to insecure default permissions in Ivanti Endpoint Manager agent. It affects organizations using I...

CVE-2025-9713

HIGH CVSS 8.8 Oct 13, 2025

CVE-2025-9713 is a path traversal vulnerability in Ivanti Endpoint Manager (EPM) that allows remote unauthenticated attackers to achieve remote code execution when user interaction occurs. This affect...

CVE-2025-11622

HIGH CVSS 7.8 Oct 13, 2025

This vulnerability allows a local authenticated attacker to exploit insecure deserialization in Ivanti Endpoint Manager to escalate their privileges. Attackers with existing local access can gain high...

CVE-2025-9712

HIGH CVSS 8.8 Sep 9, 2025

This vulnerability allows remote unauthenticated attackers to execute arbitrary code on Ivanti Endpoint Manager systems by exploiting insufficient filename validation. User interaction is required for...

CVE-2025-6996

HIGH CVSS 8.4 Jul 8, 2025

This vulnerability in Ivanti Endpoint Manager allows a local authenticated attacker to decrypt other users' passwords due to improper encryption implementation. It affects Ivanti EPM versions before 2...

CVE-2024-13172

HIGH CVSS 7.8 Jan 14, 2025

This vulnerability allows remote unauthenticated attackers to execute arbitrary code on Ivanti Endpoint Manager (EPM) systems by exploiting improper signature verification. Attackers can achieve remot...

CVE-2024-13168

HIGH CVSS 7.5 Jan 14, 2025

An out-of-bounds write vulnerability in Ivanti Endpoint Manager (EPM) allows remote unauthenticated attackers to cause denial of service by crashing the service. This affects Ivanti EPM 2024 versions ...

CVE-2024-13169

HIGH CVSS 7.8 Jan 14, 2025

This vulnerability allows a local authenticated attacker to perform an out-of-bounds read in Ivanti Endpoint Manager (EPM), potentially leading to privilege escalation. It affects Ivanti EPM 2024 and ...

CVE-2024-13170

HIGH CVSS 7.5 Jan 14, 2025

This vulnerability allows remote unauthenticated attackers to cause denial of service through an out-of-bounds write in Ivanti EPM. It affects Ivanti EPM 2024 versions before the January-2025 security...

CVE-2024-13171

HIGH CVSS 7.8 Jan 14, 2025

This vulnerability allows remote unauthenticated attackers to execute arbitrary code on Ivanti Endpoint Manager (EPM) systems by exploiting insufficient filename validation. Attackers can achieve remo...

CVE-2024-13163

HIGH CVSS 7.8 Jan 14, 2025

This vulnerability allows remote unauthenticated attackers to execute arbitrary code on Ivanti Endpoint Manager (EPM) systems through deserialization of untrusted data. Attackers can achieve remote co...

CVE-2024-13164

HIGH CVSS 7.8 Jan 14, 2025

An uninitialized resource vulnerability in Ivanti Endpoint Manager (EPM) allows local authenticated attackers to escalate privileges. This affects Ivanti EPM 2024 and 2022 SU6 versions before the Janu...

CVE-2024-13165

HIGH CVSS 7.5 Jan 14, 2025

An out-of-bounds write vulnerability in Ivanti Endpoint Manager (EPM) allows remote unauthenticated attackers to cause denial of service by crashing the service. This affects Ivanti EPM 2024 and 2022 ...

CVE-2024-13166

HIGH CVSS 7.5 Jan 14, 2025

An out-of-bounds write vulnerability in Ivanti Endpoint Manager (EPM) allows remote unauthenticated attackers to cause denial of service by crashing the service. This affects Ivanti EPM 2024 and 2022 ...

CVE-2024-13167

HIGH CVSS 7.5 Jan 14, 2025

An out-of-bounds write vulnerability in Ivanti Endpoint Manager (EPM) allows remote unauthenticated attackers to cause denial of service by crashing the service. This affects Ivanti EPM 2024 versions ...

CVE-2024-13158

HIGH CVSS 7.2 Jan 14, 2025

This vulnerability allows remote authenticated attackers with admin privileges to execute arbitrary code on Ivanti EPM systems by exploiting an unbounded resource search path. It affects Ivanti EPM 20...

CVE-2024-34780

HIGH CVSS 7.2 Nov 13, 2024

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated administrators to execute arbitrary SQL commands, potentially leading to remote code execution. Organizations using Iva...

CVE-2024-34782

HIGH CVSS 7.2 Nov 13, 2024

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated administrators to execute arbitrary SQL commands, potentially leading to remote code execution. Organizations using Iva...

CVE-2024-34787

HIGH CVSS 7.8 Nov 13, 2024

This CVE describes a path traversal vulnerability in Ivanti Endpoint Manager that allows a local unauthenticated attacker to execute arbitrary code. User interaction is required for exploitation. Affe...

CVE-2024-32839

HIGH CVSS 7.2 Nov 13, 2024

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated administrators to execute arbitrary SQL commands, potentially leading to remote code execution. It affects Ivanti EPM v...

CVE-2024-32844

HIGH CVSS 7.2 Nov 13, 2024

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated administrators to execute arbitrary SQL commands, potentially leading to remote code execution. Organizations using Iva...

CVE-2024-50328

HIGH CVSS 7.2 Nov 12, 2024

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated administrators to execute arbitrary SQL commands, potentially leading to remote code execution. It affects Ivanti EPM v...

CVE-2024-50323

HIGH CVSS 7.8 Nov 12, 2024

This CVE describes a SQL injection vulnerability in Ivanti Endpoint Manager that allows a local unauthenticated attacker to execute arbitrary code. User interaction is required for exploitation. Organ...

CVE-2024-50326

HIGH CVSS 7.2 Nov 12, 2024

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated administrators to execute arbitrary SQL commands, potentially leading to remote code execution. Organizations using Iva...

CVE-2024-32848

HIGH CVSS 7.2 Sep 12, 2024

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated administrators to execute arbitrary SQL commands, potentially leading to remote code execution. It affects Ivanti EPM v...

CVE-2024-34783

HIGH CVSS 7.2 Sep 12, 2024

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated administrators to execute arbitrary SQL commands, potentially leading to remote code execution. It affects Ivanti EPM v...

CVE-2024-37397

HIGH CVSS 8.2 Sep 12, 2024

An unauthenticated attacker can exploit an XML External Entity (XXE) vulnerability in Ivanti EPM's provisioning web service to read sensitive files, including API secrets. This affects Ivanti EPM vers...

CVE-2024-32842

HIGH CVSS 7.2 Sep 12, 2024

This is an SQL injection vulnerability in Ivanti Endpoint Manager (EPM) that allows authenticated administrators to execute arbitrary SQL commands, potentially leading to remote code execution. It aff...

CVE-2024-32845

HIGH CVSS 7.2 Sep 12, 2024

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated administrators to execute arbitrary SQL commands, potentially leading to remote code execution. It affects Ivanti EPM v...

CVE-2024-29830

HIGH CVSS 8.0 May 31, 2024

This SQL injection vulnerability in Ivanti EPM Core server allows authenticated attackers on the same network to execute arbitrary SQL commands, potentially leading to remote code execution. It affect...

CVE-2024-29824

HIGH CVSS 8.8 May 31, 2024

An unauthenticated SQL injection vulnerability in Ivanti EPM Core server allows attackers on the same network to execute arbitrary code. This affects Ivanti EPM 2022 SU5 and earlier versions. Attacker...

CVE-2024-29826

HIGH CVSS 8.8 May 31, 2024

An unauthenticated SQL injection vulnerability in Ivanti EPM Core server allows attackers on the same network to execute arbitrary code. This affects Ivanti EPM 2022 SU5 and earlier versions, potentia...

CVE-2024-29828

HIGH CVSS 8.0 May 31, 2024

An authenticated SQL injection vulnerability in Ivanti EPM Core server allows attackers on the same network to execute arbitrary code. This affects Ivanti EPM 2022 SU5 and earlier versions. Attackers ...

CVE-2024-22058

HIGH CVSS 7.8 May 31, 2024

This vulnerability allows a low-privilege local user with the Ivanti EPM Agent installed to exploit a buffer overflow and execute arbitrary code with elevated system permissions. It affects Ivanti End...

CVE-2024-29822

HIGH CVSS 8.8 May 31, 2024

An unauthenticated SQL injection vulnerability in Ivanti EPM Core server allows attackers on the same network to execute arbitrary code. This affects Ivanti EPM 2022 SU5 and earlier versions. Attacker...

CVE-2023-38343

HIGH CVSS 7.5 Sep 21, 2023

This XXE vulnerability in Ivanti Endpoint Manager's CSEP component allows attackers to read arbitrary files or perform SSRF attacks by exploiting improperly configured XML parsing. It affects Ivanti E...

CVE-2026-1602

MEDIUM CVSS 6.5 Feb 10, 2026

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated attackers to read arbitrary data from the database. It affects all Ivanti EPM installations before version 2024 SU5. At...

CVE-2025-62388

MEDIUM CVSS 6.5 Oct 13, 2025

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated attackers to read arbitrary database data. Organizations using Ivanti EPM versions before 2024 SU5 are affected. The vu...

CVE-2025-62389

MEDIUM CVSS 6.5 Oct 13, 2025

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated attackers to read arbitrary data from the database. Organizations using Ivanti EPM versions before 2024 SU5 are affecte...

CVE-2025-62390

MEDIUM CVSS 6.5 Oct 13, 2025

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated attackers to read arbitrary database data. Organizations using Ivanti EPM versions before 2024 SU5 are affected. The at...

CVE-2025-62391

MEDIUM CVSS 6.5 Oct 13, 2025

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated attackers to read arbitrary data from the database. Organizations using Ivanti EPM versions before 2024 SU5 are affecte...

CVE-2025-62392

MEDIUM CVSS 6.5 Oct 13, 2025

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated attackers to read arbitrary data from the database. Organizations using Ivanti EPM versions before 2024 SU5 are affecte...

CVE-2025-62383

MEDIUM CVSS 6.5 Oct 13, 2025

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated attackers to read arbitrary database data. Organizations using Ivanti EPM versions before 2024 SU5 are affected, potent...

CVE-2025-62384

MEDIUM CVSS 6.5 Oct 13, 2025

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated attackers to read arbitrary database data. Organizations using Ivanti EPM versions before 2024 SU5 are affected. Attack...

CVE-2025-62385

MEDIUM CVSS 6.5 Oct 13, 2025

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated attackers to read arbitrary database data. Organizations using Ivanti EPM versions before 2024 SU5 are affected. The at...

CVE-2025-62386

MEDIUM CVSS 6.5 Oct 13, 2025

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated attackers to read arbitrary data from the database. Organizations using Ivanti EPM versions before 2024 SU5 are affecte...

CVE-2025-62387

MEDIUM CVSS 6.5 Oct 13, 2025

This SQL injection vulnerability in Ivanti Endpoint Manager allows authenticated attackers to read arbitrary data from the database. Organizations using Ivanti EPM versions before 2024 SU5 are affecte...

CVE-2024-8320

MEDIUM CVSS 5.3 Sep 10, 2024

This vulnerability allows remote unauthenticated attackers to spoof the Network Isolation status of managed devices in Ivanti EPM. Attackers can make vulnerable systems appear isolated when they are n...

CVE-2024-8322

MEDIUM CVSS 4.3 Sep 10, 2024

This vulnerability allows remote authenticated attackers to bypass authentication controls in Ivanti Endpoint Manager (EPM) and access restricted functionality. It affects Ivanti EPM versions before 2...