Products › IT administration and security
IT administration and security
Monitoring, ITSM and asset management
Monitoring, ticketing, inventory, software deployment and mobile device management (MDM) tools.
For example: Ivanti EPMM, ManageEngine, SolarWinds, Nagios.
-
18 vulnerabilities added in the last 12 months
-
78 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 9, 2025 to Oct 8, 2025 | 0 |
| Oct 9, 2025 to Nov 7, 2025 | 3 |
| Nov 8, 2025 to Dec 7, 2025 | 0 |
| Dec 8, 2025 to Jan 6, 2026 | 0 |
| Jan 7, 2026 to Feb 5, 2026 | 3 |
| Feb 6, 2026 to Mar 7, 2026 | 3 |
| Mar 8, 2026 to Apr 6, 2026 | 4 |
| Apr 7, 2026 to May 6, 2026 | 3 |
| May 7, 2026 to Jun 5, 2026 | 1 |
| Jun 6, 2026 to Jul 5, 2026 | 1 |
| Jul 6, 2026 to Aug 4, 2026 | 0 |
| Aug 5, 2026 to Sep 3, 2026 | 0 |
| Sep 4, 2026 to Oct 3, 2026 (in progress) | 0 |
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Cacti 1 vulnerability
- Cisco 2 vulnerabilities
- EyesOfNetwork 2 vulnerabilities
- Fortinet 3 vulnerabilities · 2 in the last 12 months
- Grafana Labs 2 vulnerabilities · 1 in the last 12 months
- HPE 3 vulnerabilities · 1 in the last 12 months
- Ivanti 21 vulnerabilities · 5 in the last 12 months
- ManageEngine (Zoho) 6 vulnerabilities
- Microsoft 1 vulnerability · 1 in the last 12 months
- Motex 1 vulnerability · 1 in the last 12 months
- Nagios 4 vulnerabilities
- Omnissa (ex-VMware EUC) 1 vulnerability · 1 in the last 12 months
- OpenText (Micro Focus) 1 vulnerability
- Paessler 2 vulnerabilities
- Progress 2 vulnerabilities
- Quest 2 vulnerabilities · 1 in the last 12 months
- rConfig 1 vulnerability
- SaltStack 3 vulnerabilities
- ScienceLogic 1 vulnerability
- ServiceNow 2 vulnerabilities
- SKYSEA 1 vulnerability · 1 in the last 12 months
- SolarWinds 7 vulnerabilities · 3 in the last 12 months
- SysAid 3 vulnerabilities
- Teclib 1 vulnerability
- VMware (Broadcom) 3 vulnerabilities · 1 in the last 12 months
- Zabbix 2 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Remote monitoring and management (RMM) 20 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
- Rank 1
Ivanti SentryCVE-2026-10520
Ivanti Sentry OS Command Injection Vulnerability
CVSS severity 10.0critical
Added Jun 11, 2026
- Rank 2
Quest KACE Systems Management Appliance (SMA)CVE-2025-32975
Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
CVSS severity 10.0critical
Added Apr 20, 2026
- Rank 3
Fortinet FortiClient EMSCVE-2026-21643
Fortinet FortiClient EMS SQL Injection Vulnerability
CVSS severity 9.8critical
Added Apr 13, 2026
- Rank 4
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2026-1340
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CVSS severity 9.8critical
Added Apr 8, 2026
- Rank 5
Fortinet FortiClient EMSCVE-2026-35616
Fortinet FortiClient EMS Improper Access Control Vulnerability
CVSS severity 9.8critical
Added Apr 6, 2026
- Rank 6
SolarWinds Web Help DeskCVE-2025-26399
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
Ransomware
CVSS severity 9.8critical
Added Mar 9, 2026
- Rank 7
Microsoft Configuration ManagerCVE-2024-43468
Microsoft Configuration Manager SQL Injection Vulnerability
CVE from 2024, added in 2026
CVSS severity 9.8critical
Added Feb 12, 2026
- Rank 8
SolarWinds Web Help DeskCVE-2025-40536
SolarWinds Web Help Desk Security Control Bypass Vulnerability
CVSS severity 9.8critical
Added Feb 12, 2026
- Rank 9
SolarWinds Web Help DeskCVE-2025-40551
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
CVSS severity 9.8critical
Added Feb 3, 2026
- Rank 10
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2026-1281
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CVSS severity 9.8critical
Added Jan 29, 2026
Show 64 more vulnerabilities
- Rank 11
HPE OneViewCVE-2025-37164
Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability
CVSS severity 9.8critical
Added Jan 7, 2026
- Rank 12
Motex LANSCOPE Endpoint ManagerCVE-2025-61932
Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability
CVSS severity 9.8critical
Added Oct 22, 2025
- Rank 13
SKYSEA Client ViewCVE-2016-7836
SKYSEA Client View Improper Authentication Vulnerability
CVE from 2016, added in 2025
CVSS severity 9.8critical
Added Oct 14, 2025
- Rank 14
VMware (Broadcom) Aria Operations (ex-vRealize Operations)CVE-2026-22719
Broadcom VMware Aria Operations Command Injection Vulnerability
CVSS severity 8.1high
Added Mar 3, 2026
- Rank 15
Omnissa (ex-VMware EUC) Workspace ONE UEM (AirWatch)CVE-2021-22054
Omnissa Workspace ONE Server-Side Request Forgery
CVE from 2021, added in 2026
CVSS severity 7.5high
Added Mar 9, 2026
- Rank 16
Ivanti Endpoint Manager (EPM)CVE-2026-1603
Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
CVSS severity 7.5high
Added Mar 9, 2026
- Rank 17
Grafana Labs GrafanaCVE-2021-43798
Grafana Path Traversal Vulnerability
CVE from 2021, added in 2025
CVSS severity 7.5high
Added Oct 9, 2025
- Rank 18
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2026-6973
Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
CVSS severity 7.2high
Added May 7, 2026
- Rank 19
SysAid On-PremCVE-2025-2776
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
CVSS severity 9.8critical
Added Jul 22, 2025
- Rank 20
Cisco Smart Licensing UtilityCVE-2024-20439
Cisco Smart Licensing Utility Static Credential Vulnerability
CVSS severity 9.8critical
Added Mar 31, 2025
- Rank 21
Progress WhatsUp GoldCVE-2024-4885
Progress WhatsUp Gold Path Traversal Vulnerability
CVSS severity 9.8critical
Added Mar 3, 2025
- Rank 22
Paessler PRTG Network MonitorCVE-2018-19410
Paessler PRTG Network Monitor Local File Inclusion Vulnerability
CVE from 2018, added in 2025
CVSS severity 9.8critical
Added Feb 4, 2025
- Rank 23
ScienceLogic SL1CVE-2024-9537
ScienceLogic SL1 Unspecified Vulnerability
CVSS severity 9.8critical
Added Oct 21, 2024
- Rank 24
Progress WhatsUp GoldCVE-2024-6670
Progress WhatsUp Gold SQL Injection Vulnerability
Ransomware
CVSS severity 9.8critical
Added Sep 16, 2024
- Rank 25
SolarWinds Web Help DeskCVE-2024-28986
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
CVSS severity 9.8critical
Added Aug 15, 2024
- Rank 26
ServiceNow Now PlatformCVE-2024-4879
ServiceNow Improper Input Validation Vulnerability
CVSS severity 9.8critical
Added Jul 29, 2024
- Rank 27
ServiceNow Now PlatformCVE-2024-5217
ServiceNow Incomplete List of Disallowed Inputs Vulnerability
CVSS severity 9.8critical
Added Jul 29, 2024
- Rank 28
Ivanti Cloud Services Appliance (CSA)CVE-2021-44529
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
RansomwareCVE from 2021, added in 2024
CVSS severity 9.8critical
Added Mar 25, 2024
- Rank 29
Fortinet FortiClient EMSCVE-2023-48788
Fortinet FortiClient EMS SQL Injection Vulnerability
Ransomware
CVSS severity 9.8critical
Added Mar 25, 2024
- Rank 30
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2023-35082
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jan 18, 2024
- Rank 31
SysAid On-PremCVE-2023-47246
SysAid Server Path Traversal Vulnerability
Ransomware
CVSS severity 9.8critical
Added Nov 13, 2023
- Rank 32
Ivanti SentryCVE-2023-38035
Ivanti Sentry Authentication Bypass Vulnerability
Ransomware
CVSS severity 9.8critical
Added Aug 22, 2023
- Rank 33
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2023-35078
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jul 25, 2023
- Rank 34
VMware (Broadcom) Aria Operations for Networks (ex-vRealize Network Insight)CVE-2023-20887
Vmware Aria Operations for Networks Command Injection Vulnerability
CVSS severity 9.8critical
Added Jun 22, 2023
- Rank 35
Teclib GLPICVE-2022-35914
Teclib GLPI Remote Code Execution Vulnerability
CVSS severity 9.8critical
Added Mar 7, 2023
- Rank 36
CactiCVE-2022-46169
Cacti Command Injection Vulnerability
CVSS severity 9.8critical
Added Feb 16, 2023
- Rank 37
ManageEngine (Zoho) Multiple productsCVE-2022-47966
Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
Ransomware
CVSS severity 9.8critical
Added Jan 23, 2023
- Rank 38
HPE Network Node Manager (OpenView NNM)CVE-2005-2773
HP OpenView Network Node Manager Remote Code Execution Vulnerability
CVE from 2005, added in 2022
CVSS severity 9.8critical
Added Mar 25, 2022
- Rank 39
HPE ProCurve Manager (PCM, PCM+, IDM)CVE-2013-4810
HP Multiple Products Remote Code Execution Vulnerability
CVE from 2013, added in 2022
CVSS severity 9.8critical
Added Mar 25, 2022
- Rank 40
Quest KACE Systems Management Appliance (SMA)CVE-2018-11138
Quest KACE System Management Appliance Remote Command Execution Vulnerability
RansomwareCVE from 2018, added in 2022
CVSS severity 9.8critical
Added Mar 25, 2022
- Rank 41
Zabbix FrontendCVE-2022-23131
Zabbix Frontend Authentication Bypass Vulnerability
CVSS severity 9.8critical
Added Feb 22, 2022
- Rank 42
ManageEngine (Zoho) Endpoint Central (ex-Desktop Central)CVE-2021-44515
Zoho Desktop Central Authentication Bypass Vulnerability
CVSS severity 9.8critical
Added Dec 10, 2021
- Rank 43
ManageEngine (Zoho) ServiceDesk PlusCVE-2021-37415
Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability
CVSS severity 9.8critical
Added Dec 1, 2021
- Rank 44
ManageEngine (Zoho) ServiceDesk PlusCVE-2021-44077
Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability
CVSS severity 9.8critical
Added Dec 1, 2021
- Rank 45
SolarWinds Orion PlatformCVE-2020-10148
SolarWinds Orion Authentication Bypass Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 46
ManageEngine (Zoho) Endpoint Central (ex-Desktop Central)CVE-2020-10189
Zoho ManageEngine Desktop Central File Upload Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 47
SaltStack SaltCVE-2020-11651
SaltStack Salt Authentication Bypass Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 48
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2020-15505
Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 49
SaltStack SaltCVE-2020-16846
SaltStack Salt Shell Injection Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 50
EyesOfNetworkCVE-2020-8657
EyesOfNetwork Use of Hard-Coded Credentials Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 51
OpenText (Micro Focus) Operations Bridge Reporter (OBR)CVE-2021-22502
Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability
CVSS severity 9.8critical
Added Nov 3, 2021
- Rank 52
SolarWinds Web Help DeskCVE-2024-28987
SolarWinds Web Help Desk Hardcoded Credential Vulnerability
CVSS severity 9.1critical
Added Oct 15, 2024
- Rank 53
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2025-4428
Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
CVSS severity 8.8high
Added May 19, 2025
- Rank 54
Ivanti Endpoint Manager (EPM)CVE-2024-29824
Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability
CVSS severity 8.8high
Added Oct 2, 2024
- Rank 55
Nagios XICVE-2021-25296
Nagios XI OS Command Injection
CVSS severity 8.8high
Added Jan 18, 2022
- Rank 56
Nagios XICVE-2021-25297
Nagios XI OS Command Injection
CVSS severity 8.8high
Added Jan 18, 2022
- Rank 57
Nagios XICVE-2021-25298
Nagios XI OS Command Injection
CVSS severity 8.8high
Added Jan 18, 2022
- Rank 58
Nagios XICVE-2019-15949
Nagios XI Remote Code Execution Vulnerability
CVE from 2019, added in 2021
CVSS severity 8.8high
Added Nov 3, 2021
- Rank 59
rConfigCVE-2020-10221
rConfig OS Command Injection Vulnerability
CVSS severity 8.8high
Added Nov 3, 2021
- Rank 60
SolarWinds Virtualization ManagerCVE-2016-3643
SolarWinds Virtualization Manager Privilege Escalation Vulnerability
CVE from 2016, added in 2021
CVSS severity 7.8high
Added Nov 3, 2021
- Rank 61
EyesOfNetworkCVE-2020-8655
EyesOfNetwork Improper Privilege Management Vulnerability
CVSS severity 7.8high
Added Nov 3, 2021
- Rank 62
SysAid On-PremCVE-2025-2775
SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
CVSS severity 7.5high
Added Jul 22, 2025
- Rank 63
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2025-4427
Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability
CVSS severity 7.5high
Added May 19, 2025
- Rank 64
Ivanti Endpoint Manager (EPM)CVE-2024-13159
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
CVSS severity 7.5high
Added Mar 10, 2025
- Rank 65
Ivanti Endpoint Manager (EPM)CVE-2024-13160
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
CVSS severity 7.5high
Added Mar 10, 2025
- Rank 66
Ivanti Endpoint Manager (EPM)CVE-2024-13161
Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
CVSS severity 7.5high
Added Mar 10, 2025
- Rank 67
Cisco Prime Data Center Network Manager (DCNM)CVE-2015-0666
Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability
CVE from 2015, added in 2022
CVSS severity 7.5high
Added Mar 25, 2022
- Rank 68
VMware (Broadcom) Aria Operations (ex-vRealize Operations)CVE-2021-21975
VMware Server Side Request Forgery in vRealize Operations Manager API
Ransomware
CVSS severity 7.5high
Added Jan 18, 2022
- Rank 69
Grafana Labs GrafanaCVE-2021-39226
Grafana Authentication Bypass Vulnerability
CVSS severity 7.3high
Added Aug 25, 2022
- Rank 70
Paessler PRTG Network MonitorCVE-2018-9276
Paessler PRTG Network Monitor OS Command Injection Vulnerability
CVE from 2018, added in 2025
CVSS severity 7.2high
Added Feb 4, 2025
- Rank 71
Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)CVE-2023-35081
Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability
CVSS severity 7.2high
Added Jul 31, 2023
- Rank 72
ManageEngine (Zoho) ServiceDesk PlusCVE-2019-8394
Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
CVE from 2019, added in 2021
CVSS severity 6.5medium
Added Nov 3, 2021
- Rank 73
SaltStack SaltCVE-2020-11652
SaltStack Salt Path Traversal Vulnerability
CVSS severity 6.5medium
Added Nov 3, 2021
- Rank 74
Zabbix FrontendCVE-2022-23134
Zabbix Frontend Improper Access Control Vulnerability
CVSS severity 5.3medium
Added Feb 22, 2022
Filed under another category
These 2 vulnerabilities also concern this type of product, but are counted in their main category. My radar finds them when you follow this category.
Microsoft WindowsCVE-2025-59287
Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
CVSS severity 9.8critical
Added Oct 24, 2025
VMware (Broadcom) VMware ToolsCVE-2025-41244
Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
CVSS severity 7.8high
Added Oct 30, 2025
End of life: remove
These products are no longer supported: no patch is coming. Remove them or isolate them from the network.
Ivanti Cloud Services Appliance (CSA)CVE-2024-9379
Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability
End of life
CVSS severity 7.2high
Added Oct 9, 2024
Ivanti Cloud Services Appliance (CSA)CVE-2024-9380
Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability
End of life
CVSS severity 7.2high
Added Oct 9, 2024
Ivanti Cloud Services Appliance (CSA)CVE-2024-8963
Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability
End of life
CVSS severity 9.1critical
Added Sep 19, 2024
Ivanti Cloud Services Appliance (CSA)CVE-2024-8190
Ivanti Cloud Services Appliance OS Command Injection Vulnerability
End of life
CVSS severity 7.2high
Added Sep 13, 2024
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.