Endpoint Manager

Vendor:

First CVE: Dec 11, 2017 · Active for 8 years

116
Total CVEs
More Total CVEs than 99% of tracked products
14.5
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 64% of tracked products
4.3%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Endpoint Manager over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 11, 2017
8 years ago
Most Recent CVE
May 12, 2026
77 days ago

CVE Severity & Scoring

Endpoint Manager116 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local23 (19.8%)
Network81 (69.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network12 (10.3%)
Attack Complexity
Low115 (99.1%)
High1 (0.9%)
Unknown0 (0.0%)
User Interaction
None97 (83.6%)
Unknown0 (0.0%)
Required19 (16.4%)
Privileges Required
Low39 (33.6%)
High28 (24.1%)
None49 (42.2%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (116 CVEs).

116 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
May 31, 20248.898YESYES
An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.
Feb 10, 20267.597YESYES
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensit
Jan 14, 20257.597YESYES
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensit
Jan 14, 20257.596YESYES
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote unauthenticated attacker to leak sensit
Jan 14, 20257.596YESYES
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
May 31, 20248.879NONO
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
May 31, 20248.879NONO
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
May 31, 20248.879NONO
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
May 31, 20248.868NONO
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the same network to execute arbitrary code.
May 31, 20248.865NONO

Exploit Exposure

Signals from CVEs in this product scope (116 CVEs).

CISA KEV
5 CVEs
4.3% of CVEs· 98th percentile
Metasploit
2 CVEs
1.7% of CVEs· 97th percentile
Nuclei
5 CVEs
4.3% of CVEs· 97th percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (116 CVEs).

Media Mentions

Signals from CVEs in this product scope (116 CVEs).

Top CNAs Publishing CVEs For Endpoint Manager

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2024847.39.3%44
2022797.720.0%44
2021.1.116.70.3%00
2021.119.82.6%00
2020.119.94.8%00
2019.119.94.8%00
2018.319.84.3%00
2018.119.84.3%00
2017.329.33.4%00
2017.118.82.4%00
2016.418.82.4%00