Latest CVE Feed
-
7.8
HIGHCVE-2024-10630
A race condition in Ivanti Application Control Engine before version 10.14.4.0 allows a local authenticated attacker to bypass the application blocking functionality.... Read more
- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Race Condition
-
7.8
HIGHCVE-2024-13172
Improper signature verification in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication
-
7.8
HIGHCVE-2024-13171
Insufficient filename validation in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authentication
-
7.5
HIGHCVE-2024-13170
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2024-13169
An out-of-bounds read in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
7.5
HIGHCVE-2024-13168
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
7.8
HIGHCVE-2024-13164
An uninitialized resource in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a local authenticated attacker to escalate their privileges.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Authorization
-
7.8
HIGHCVE-2024-13163
Deserialization of untrusted data in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to achieve remote code execution. Local user interaction is required.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
-
7.5
HIGHCVE-2024-13165
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-13166
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
7.5
HIGHCVE-2024-13167
An out-of-bounds write in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to cause a denial of service.... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Denial of Service
-
7.2
HIGHCVE-2024-13162
SQL injection in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote authenticated attacker with admin privileges to achieve remote code execution. This CVE addresses incomplete fixes from CVE-... Read more
Affected Products : endpoint_manager- Published: Jan. 14, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-6770
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2 allows a remote authenticated attacker with high privileges to achieve remote code execution... Read more
Affected Products : endpoint_manager_mobile- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2025-6771
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution... Read more
Affected Products : endpoint_manager_mobile- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2025-6970
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 7.0.3 due to insufficient escaping on the user supplied parameter ... Read more
Affected Products : events_manager- Published: Jul. 09, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection
-
6.1
MEDIUMCVE-2025-6975
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘calendar_header’ parameter in all versions up to, and including, 7.0.3 due to insufficient input sanitization and out... Read more
Affected Products : events_manager- Published: Jul. 09, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
6.4
MEDIUMCVE-2025-6976
The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcodes in all versions up to, and including, 7.0.3 due to insufficient input sanitization and output escapi... Read more
Affected Products : events_manager- Published: Jul. 09, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cross-Site Scripting
-
8.4
HIGHCVE-2025-6995
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.... Read more
Affected Products : endpoint_manager- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cryptography
-
8.4
HIGHCVE-2025-6996
Improper use of encryption in the agent of Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a local authenticated attacker to decrypt other users’ passwords.... Read more
Affected Products : endpoint_manager- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Cryptography
-
7.2
HIGHCVE-2025-7037
SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database... Read more
Affected Products : endpoint_manager- Published: Jul. 08, 2025
- Modified: Jul. 11, 2025
- Vuln Type: Injection