Ivanti

Operational audit scripts and mitigation intelligence for 209 known Ivanti vulnerabilities.

CVSS 10

CVE-2024-11639

Target: Ivanti Cloud Services Application - Admin Web Console

CVSS 9.9

CVE-2023-46808

Target: Ivanti Neurons for ITSM - File Upload Component

CVSS 9.9

CVE-2025-22467

Target: Ivanti Connect Secure - Connect Secure

CVSS 9.8

CVE-2026-1281

Actively Exploited

Target: Ivanti Endpoint Manager Mobile - EPMM

CVSS 9.8

CVE-2026-1340

Target: Ivanti Endpoint Manager - Mobile

CVSS 9.8

CVE-2023-35082

Actively Exploited

Target: Ivanti EPMM - MobileIron Core

CVSS 9.8

CVE-2023-32567

Target: Ivanti Avalanche - decodeToMap

CVSS 9.8

CVE-2023-28324

Target: Ivanti Endpoint Manager - Core

CVSS 9.8

CVE-2023-38035

Actively Exploited

Target: Ivanti MobileIron Sentry - MICS Admin Portal

CVSS 9.8

CVE-2024-29204

Target: Ivanti Avalanche - WLAvalancheService

CVSS 9.8

CVE-2024-10811

Target: Ivanti EPM - Endpoint Manager

CVSS 9.8

CVE-2024-13160

Actively Exploited

Target: Ivanti EPM - Endpoint Manager

CVSS 9.8

CVE-2024-50330

Target: Ivanti Endpoint Manager - Core

CVSS 9.8

CVE-2024-24996

Target: Ivanti Avalanche - WLInfoRailService

CVSS 9.8

CVE-2024-22061

Target: Ivanti Avalanche - WLInfoRailService

CVSS 9.8

CVE-2025-22462

Target: Ivanti Neurons for ITSM - Authentication Module

CVSS 9.8

CVE-2024-29847

Target: Ivanti EPM - Agent Portal

CVSS 9.8

CVE-2023-38036

Target: Ivanti Avalanche - Manager

CVSS 9.8

CVE-2024-13159

Actively Exploited

Target: Ivanti EPM - Endpoint Manager

CVSS 9.8

CVE-2023-35078

Actively Exploited

Target: Ivanti EPMM - API

CVSS 9.8

CVE-2023-35084

Target: Ivanti Endpoint Manager - Core Server

CVSS 9.8

CVE-2024-21894

Target: Ivanti Connect Secure - IPSec component

CVSS 9.8

CVE-2024-13161

Actively Exploited

Target: Ivanti EPM - Endpoint Manager

CVSS 9.8

CVE-2024-7593

Actively Exploited

Target: Ivanti vTM - Admin Panel

CVSS 9.6

CVE-2024-7569

Target: Ivanti Neurons for ITSM - ITSM Component

CVSS 9.6

CVE-2025-10573

Target: Ivanti Endpoint Manager - Web UI

CVSS 9.4

CVE-2024-8963

Actively Exploited

Target: Ivanti CSA - Cloud Services Appliance

CVSS 9.1

CVE-2024-11634

Target: Ivanti Connect Secure - Web UI

CVSS 9.1

CVE-2024-11007

Target: Ivanti Connect Secure - Web UI

CVSS 9.1

CVE-2024-38652

Target: Ivanti Avalanche - Skin Management

CVSS 9.1

CVE-2024-11773

Target: Ivanti CSA - Admin Web Console

CVSS 9.1

CVE-2024-11005

Target: Ivanti Connect Secure - Web UI

CVSS 9.1

CVE-2024-11006

Target: Ivanti Connect Secure - Web UI

CVSS 9.1

CVE-2024-11772

Target: Ivanti CSA - Admin Web Console

CVSS 9.1

CVE-2024-11633

Target: Ivanti Connect Secure - Admin Interface

CVSS 9.1

CVE-2024-47908

Target: Ivanti Cloud Services Application - Admin Web Console

CVSS 9.1

CVE-2024-10644

Target: Ivanti Connect Secure - Web Interface

CVSS 9.1

CVE-2024-21887

Actively Exploited

Target: Ivanti Connect Secure - Web Components

CVSS 9.1

CVE-2024-38656

Target: Ivanti Connect Secure - Web Interface

CVSS 9

CVE-2025-22457

Actively Exploited

Target: Ivanti Connect Secure - Gateway

CVSS 9

CVE-2025-0282

Actively Exploited

Target: Ivanti Connect Secure - Gateway

CVSS 8.9

CVE-2025-55145

Target: Ivanti Connect Secure - Gateway

CVSS 8.8

CVE-2025-13659

Target: Ivanti Endpoint Manager - Server

CVSS 8.8

CVE-2024-37404

Target: Ivanti Connect Secure - Admin Portal

CVSS 8.8

CVE-2025-55142

Target: Ivanti Connect Secure - Authentication Module

CVSS 8.8

CVE-2024-44103

Target: Ivanti Workspace Control - Management Console

CVSS 8.8

CVE-2024-21888

Target: Ivanti Connect Secure - Web Component

CVSS 8.8

CVE-2025-9713

Target: Ivanti Endpoint Manager - EPM

CVSS 8.8

CVE-2025-9712

Target: Ivanti Endpoint Manager - Endpoint Manager

CVSS 8.8

CVE-2024-44104

Target: Ivanti Workspace Control - Management Console

CVSS 8.8

CVE-2025-55141

Target: Ivanti Connect Secure - Authentication Module

CVSS 8.8

CVE-2025-5353

Target: Ivanti Workspace Control - Core

CVSS 8.8

CVE-2025-22455

Target: Ivanti Workspace Control - Core

CVSS 8.8

CVE-2024-29827

Target: Ivanti EPM - Core server

CVSS 8.8

CVE-2024-29826

Target: Ivanti EPM - Core server

CVSS 8.8

CVE-2024-9420

Target: Ivanti Connect Secure - Ivanti Policy Secure

CVSS 8.8

CVE-2024-29825

Target: Ivanti EPM - Core server

CVSS 8.8

CVE-2024-29824

Actively Exploited

Target: Ivanti EPM - Core Server

CVSS 8.8

CVE-2024-23534

Target: Ivanti Avalanche - Web Component

CVSS 8.8

CVE-2024-23535

Target: Ivanti Avalanche - Web Component

CVSS 8.8

CVE-2024-24992

Target: Ivanti Avalanche - Web Component

CVSS 8.8

CVE-2024-29822

Target: Ivanti EPM - Core server

CVSS 8.8

CVE-2024-7612

Target: Ivanti EPMM - Endpoint Manager

CVSS 8.8

CVE-2025-55147

Target: Ivanti Connect Secure - Web UI

CVSS 8.8

CVE-2024-44106

Target: Ivanti Workspace Control - Management Console

CVSS 8.8

CVE-2024-24994

Target: Ivanti Avalanche - Web Component

CVSS 8.8

CVE-2024-8540

Target: Ivanti Sentry - Application Components

CVSS 8.8

CVE-2025-9872

Target: Ivanti Endpoint Manager - Endpoint Manager

CVSS 8.8

CVE-2024-24997

Target: Ivanti Avalanche - Web Component

CVSS 8.8

CVE-2024-24998

Target: Ivanti Avalanche - Web Component

CVSS 8.8

CVE-2024-24999

Target: Ivanti Avalanche - Web Component

CVSS 8.8

CVE-2024-25000

Target: Ivanti Avalanche - Web Component

CVSS 8.8

CVE-2024-27975

Target: Ivanti Avalanche - WLAvalancheService

CVSS 8.8

CVE-2024-27976

Target: Ivanti Avalanche - Web Component

CVSS 8.8

CVE-2024-29823

Target: Ivanti EPM - Core server

CVSS 8.8

CVE-2024-50329

Target: Ivanti Endpoint Manager - Core

CVSS 8.8

CVE-2024-44107

Target: Ivanti Workspace Control - Management Console

CVSS 8.6

CVE-2026-1603

Actively Exploited

Target: Ivanti Endpoint Manager - Core

CVSS 8.4

CVE-2025-6995

Target: Ivanti Endpoint Manager - Agent

CVSS 8.4

CVE-2025-6996

Target: Ivanti Endpoint Manager - Agent

CVSS 8.3

CVE-2024-7570

Target: Ivanti Neurons for ITSM - ITSM Component

CVSS 8.3

CVE-2024-22024

Target: Ivanti Connect Secure - SAML Component

CVSS 8.2

CVE-2024-37397

Target: Ivanti EPM - Provisioning Web Service

CVSS 8.2

CVE-2024-44105

Target: Ivanti Workspace Control - Management Console

CVSS 8.2

CVE-2024-21893

Actively Exploited

Target: Ivanti Connect Secure - SAML Component

CVSS 8.2

CVE-2024-22053

Target: Ivanti Connect Secure - IPSec component

CVSS 8.2

CVE-2025-22466

Target: Ivanti Endpoint Manager - Web UI

CVSS 8.1

CVE-2024-27977

Target: Ivanti Avalanche - Web Component

CVSS 8

CVE-2024-29846

Target: Ivanti EPM - Core server

CVSS 8

CVE-2024-37381

Target: Ivanti EPM - Core Server

CVSS 8

CVE-2024-29830

Target: Ivanti EPM - Core server

CVSS 8

CVE-2024-29829

Target: Ivanti EPM - Core server

CVSS 8

CVE-2024-29828

Target: Ivanti EPM - Core server

CVSS 7.8

CVE-2025-22454

Target: Ivanti Secure Access Client

CVSS 7.8

CVE-2024-39709

Target: Ivanti Connect Secure - Ivanti Policy Secure

CVSS 7.8

CVE-2024-47906

Target: Ivanti Connect Secure - Ivanti Policy Secure

CVSS 7.8

CVE-2024-50322

Target: Ivanti Endpoint Manager - Core

CVSS 7.8

CVE-2024-50323

Target: Ivanti Endpoint Manager - Core

CVSS 7.8

CVE-2024-37398

Target: Ivanti Secure Access Client

CVSS 7.8

CVE-2024-34787

Target: Ivanti Endpoint Manager - Core

CVSS 7.8

CVE-2024-7571

Target: Ivanti Secure Access Client

CVSS 7.8

CVE-2026-3483

Target: Ivanti DSM

CVSS 7.8

CVE-2024-13172

Target: Ivanti EPM - Core

CVSS 7.8

CVE-2025-11622

Target: Ivanti Endpoint Manager - Core

CVSS 7.8

CVE-2024-13171

Target: Ivanti EPM - Core

CVSS 7.8

CVE-2024-13169

Target: Ivanti EPM - Core

CVSS 7.8

CVE-2024-13164

Target: Ivanti EPM - Core

CVSS 7.8

CVE-2024-13163

Target: Ivanti EPM - Core

CVSS 7.8

CVE-2025-13662

Target: Ivanti Endpoint Manager - Patch Management Component

CVSS 7.8

CVE-2024-9167

Target: Ivanti Velocity - License Server

CVSS 7.8

CVE-2025-22458

Target: Ivanti Endpoint Manager - Core

CVSS 7.8

CVE-2025-22460

Target: Ivanti Cloud Services - Application

CVSS 7.8

CVE-2024-8012

Target: Ivanti Workspace Control - Message Broker Service

CVSS 7.8

CVE-2024-10630

Target: Ivanti Application Control - Engine

CVSS 7.8

CVE-2024-8191

Target: Ivanti EPM - Management Console

CVSS 7.8

CVE-2024-9845

Target: Ivanti Automation

CVSS 7.8

CVE-2024-8496

Target: Ivanti Workspace Control - Core

CVSS 7.8

CVE-2024-11598

Target: Ivanti Application Control

CVSS 7.8

CVE-2024-11597

Target: Ivanti Performance Manager - Core

CVSS 7.8

CVE-2024-10251

Target: Ivanti Security Controls - Security Controls

CVSS 7.6

CVE-2025-55148

Target: Ivanti Connect Secure - Admin Interface

CVSS 7.5

CVE-2024-23529

Target: Ivanti Avalanche - WLAvalancheService

CVSS 7.5

CVE-2024-47008

Target: Ivanti Avalanche - Server

CVSS 7.5

CVE-2025-5456

Target: Ivanti Connect Secure - Gateway

CVSS 7.5

CVE-2025-5462

Target: Ivanti Connect Secure - Gateway

CVSS 7.5

CVE-2024-23526

Target: Ivanti Avalanche - WLAvalancheService

CVSS 7.5

CVE-2024-23528

Target: Ivanti Avalanche - WLAvalancheService

CVSS 7.5

CVE-2024-22052

Target: Ivanti Connect Secure - IPSec

CVSS 7.5

CVE-2024-23530

Target: Ivanti Avalanche - WLAvalancheService

CVSS 7.5

CVE-2024-23531

Target: Ivanti Avalanche - WLInfoRailService

CVSS 7.5

CVE-2024-23532

Target: Ivanti Avalanche - WLAvalancheService

CVSS 7.5

CVE-2024-24993

Target: Ivanti Avalanche - Web Component

CVSS 7.5

CVE-2024-24995

Target: Ivanti Avalanche - Web Component

CVSS 7.5

CVE-2024-23527

Target: Ivanti Avalanche - WLAvalancheService

CVSS 7.5

CVE-2024-36136

Target: Ivanti Avalanche - WLInfoRailService

CVSS 7.5

CVE-2024-37399

Target: Ivanti Avalanche - WLAvalancheService

CVSS 7.5

CVE-2024-38653

Target: Ivanti Avalanche - SmartDeviceServer

CVSS 7.5

CVE-2024-47011

Target: Ivanti Avalanche - Management Server

CVSS 7.5

CVE-2024-47007

Target: Ivanti Avalanche - WLAvalancheService

CVSS 7.5

CVE-2024-38649

Target: Ivanti Connect Secure - IPsec

CVSS 7.5

CVE-2024-47907

Target: Ivanti Connect Secure - IPsec

CVSS 7.5

CVE-2024-50317

Target: Ivanti Avalanche - Core Service

CVSS 7.5

CVE-2024-50318

Target: Ivanti Avalanche - Core Service

CVSS 7.5

CVE-2024-50319

Target: Ivanti Avalanche - Core Service

CVSS 7.5

CVE-2024-50320

Target: Ivanti Avalanche - Server

CVSS 7.5

CVE-2024-50321

Target: Ivanti Avalanche - Core Service

CVSS 7.5

CVE-2024-50331

Target: Ivanti Avalanche - Core Service

CVSS 7.5

CVE-2024-8495

Target: Ivanti Connect Secure - Ivanti Policy Secure

CVSS 7.5

CVE-2024-13180

Target: Ivanti Avalanche - Web Interface

CVSS 7.5

CVE-2024-13165

Target: Ivanti EPM - Core

CVSS 7.5

CVE-2024-13166

Target: Ivanti EPM - Core

CVSS 7.5

CVE-2024-13167

Target: Ivanti EPM - Core

CVSS 7.5

CVE-2024-13168

Target: Ivanti EPM - Core

CVSS 7.5

CVE-2024-13170

Target: Ivanti EPM - Core

CVSS 7.3

CVE-2024-13179

Target: Ivanti Avalanche - Web Interface

CVSS 7.3

CVE-2024-47009

Target: Ivanti Avalanche - Web Interface

CVSS 7.3

CVE-2024-13181

Target: Ivanti Avalanche - Web Interface

CVSS 7.3

CVE-2025-22463

Target: Ivanti Workspace Control - Core

CVSS 7.3

CVE-2024-9842

Target: Ivanti Secure Access Client

CVSS 7.3

CVE-2024-47010

Target: Ivanti Avalanche - Web Interface

CVSS 7.2

CVE-2024-50327

Target: Ivanti Endpoint Manager - Core

CVSS 7.2

CVE-2024-37376

Target: Ivanti Endpoint Manager - Core

CVSS 7.2

CVE-2024-50326

Target: Ivanti Endpoint Manager - Core

CVSS 7.2

CVE-2024-50324

Target: Ivanti Endpoint Manager - Core

CVSS 7.2

CVE-2024-9381

Target: Ivanti CSA - Cloud Services Appliance

CVSS 7.2

CVE-2024-9380

Actively Exploited

Target: Ivanti CSA - Admin Web Console

CVSS 7.2

CVE-2024-34785

Target: Ivanti EPM - Core

CVSS 7.2

CVE-2024-34783

Target: Ivanti EPM - Core

CVSS 7.2

CVE-2024-34779

Target: Ivanti EPM - Core

CVSS 7.2

CVE-2024-32848

Target: Ivanti EPM - Core

CVSS 7.2

CVE-2024-32846

Target: Ivanti EPM - Core

CVSS 7.2

CVE-2024-32845

Target: Ivanti EPM - Core

CVSS 7.2

CVE-2024-32843

Target: Ivanti EPM - Core

CVSS 7.2

CVE-2024-32842

Target: Ivanti EPM - Core

CVSS 7.2

CVE-2024-32840

Target: Ivanti EPM - Core

CVSS 7.2

CVE-2024-8190

Actively Exploited

Target: Ivanti Cloud Services Appliance - Cloud Services Appliance

CVSS 7.2

CVE-2024-37373

Target: Ivanti Avalanche - Central Filestore

CVSS 7.2

CVE-2025-6770

Target: Ivanti Endpoint Manager Mobile - EPMM

CVSS 7.2

CVE-2024-13158

Target: Ivanti EPM - Core

CVSS 7.2

CVE-2024-29848

Target: Ivanti Avalanche - Web Component

CVSS 7.2

CVE-2024-32844

Target: Ivanti Endpoint Manager - Core

CVSS 7.2

CVE-2024-34780

Target: Ivanti Endpoint Manager - Core

CVSS 7.2

CVE-2024-38655

Target: Ivanti Connect Secure - Admin Interface

CVSS 7.2

CVE-2024-34781

Target: Ivanti Endpoint Manager - Core

CVSS 7.2

CVE-2024-34782

Target: Ivanti Endpoint Manager - Core

CVSS 7.2

CVE-2024-34784

Target: Ivanti Endpoint Manager - Core

CVSS 7.2

CVE-2025-10242

Target: Ivanti EPMM - Admin Panel

CVSS 7.2

CVE-2025-8297

Target: Ivanti Avalanche - Management Console

CVSS 7.2

CVE-2025-8296

Target: Ivanti Avalanche - Management Console

CVSS 7.2

CVE-2025-6771

Target: Ivanti Endpoint Manager Mobile - EPMM

CVSS 7.2

CVE-2025-7037

Target: Ivanti Endpoint Manager - Database

CVSS 7.2

CVE-2024-50328

Target: Ivanti Endpoint Manager - Core

CVSS 7.2

CVE-2024-32839

Target: Ivanti Endpoint Manager - Core

CVSS 7.2

CVE-2024-32841

Target: Ivanti Endpoint Manager - Core

CVSS 7.2

CVE-2024-32847

Target: Ivanti Endpoint Manager - Core

CVSS 7.2

CVE-2024-13162

Target: Ivanti EPM - Core

CVSS 7.2

CVE-2025-10985

Target: Ivanti EPMM - Admin Panel

CVSS 7.2

CVE-2025-4428

Actively Exploited

Target: Ivanti Endpoint Manager - API component

CVSS 7.2

CVE-2025-22461

Target: Ivanti Endpoint Manager - Web Interface

CVSS 7.2

CVE-2025-10243

Target: Ivanti EPMM - Admin Panel

CVSS 7.1

CVE-2024-13813

Target: Ivanti Secure Access Client

CVSS 7.1

CVE-2024-27984

Target: Ivanti Avalanche - Web Component

CVSS 7.1

CVE-2025-13661

Target: Ivanti Endpoint Manager - Core

CVSS 7.1

CVE-2024-8539

Target: Ivanti Secure Access Client

CVSS 7.1

CVE-2024-9844

Target: Ivanti Connect Secure - Secure Application Manager

CVSS 7.1

CVE-2025-10918

Target: Ivanti Endpoint Manager - Agent

CVSS 7.1

CVE-2024-10256

Target: Ivanti Patch SDK

CVSS 7.1

CVE-2024-7572

Target: Ivanti DSM - Management Server

CVSS 7

CVE-2025-0283

Target: Ivanti Connect Secure - Gateway