Vulnerabilities > Ivanti > Endpoint Manager > 2021.1.1

DATE CVE VULNERABILITY TITLE RISK
2025-01-14 CVE-2024-13159 Unspecified vulnerability in Ivanti Endpoint Manager 2021.1.1/2022/2024
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
network
low complexity
ivanti
7.5
2025-01-14 CVE-2024-13160 Unspecified vulnerability in Ivanti Endpoint Manager 2021.1.1/2022/2024
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
network
low complexity
ivanti
7.5
2025-01-14 CVE-2024-13161 Unspecified vulnerability in Ivanti Endpoint Manager 2021.1.1/2022/2024
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensitive information.
network
low complexity
ivanti
7.5
2024-11-13 CVE-2024-32839 Unspecified vulnerability in Ivanti Endpoint Manager
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti
7.2
2024-11-13 CVE-2024-32841 Unspecified vulnerability in Ivanti Endpoint Manager
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti
7.2
2024-11-13 CVE-2024-32847 Unspecified vulnerability in Ivanti Endpoint Manager
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti
7.2
2024-11-13 CVE-2024-34780 Unspecified vulnerability in Ivanti Endpoint Manager
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti
7.2
2024-11-13 CVE-2024-34781 Unspecified vulnerability in Ivanti Endpoint Manager
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti
7.2
2024-11-13 CVE-2024-34782 Unspecified vulnerability in Ivanti Endpoint Manager
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti
7.2
2024-11-13 CVE-2024-34784 Unspecified vulnerability in Ivanti Endpoint Manager
SQL injection in Ivanti Endpoint Manager before 2024 November Security Update or 2022 SU6 November Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution.
network
low complexity
ivanti
7.2