Products › IT administration and security
IT administration and security
Monitoring, ITSM and asset management
Monitoring, ticketing, inventory, software deployment and mobile device management (MDM) tools.
For example: Ivanti EPMM, ManageEngine, SolarWinds, Nagios.
-
18 vulnerabilities added in the last 12 months
-
78 exploited vulnerabilities in the catalog, in total
-
0 added in the last 30 days
Pace of additions
| Period | Vulnerabilities added |
|---|---|
| Sep 4, 2025 to Oct 3, 2025 | 0 |
| Oct 4, 2025 to Nov 2, 2025 | 3 |
| Nov 3, 2025 to Dec 2, 2025 | 0 |
| Dec 3, 2025 to Jan 1, 2026 | 0 |
| Jan 2, 2026 to Jan 31, 2026 | 2 |
| Feb 1, 2026 to Mar 2, 2026 | 3 |
| Mar 3, 2026 to Apr 1, 2026 | 4 |
| Apr 2, 2026 to May 1, 2026 | 4 |
| May 2, 2026 to May 31, 2026 | 1 |
| Jun 1, 2026 to Jun 30, 2026 | 1 |
| Jul 1, 2026 to Jul 30, 2026 | 0 |
| Jul 31, 2026 to Aug 29, 2026 | 0 |
| Aug 30, 2026 to Sep 28, 2026 (in progress) | 0 |
Affected brands
In alphabetical order, with their number of vulnerabilities in this category.
- Cacti 1 vulnerability
- Cisco 2 vulnerabilities
- EyesOfNetwork 2 vulnerabilities
- Fortinet 3 vulnerabilities · 2 in the last 12 months
- Grafana Labs 2 vulnerabilities · 1 in the last 12 months
- HPE 3 vulnerabilities · 1 in the last 12 months
- Ivanti 21 vulnerabilities · 5 in the last 12 months
- ManageEngine (Zoho) 6 vulnerabilities
- Microsoft 1 vulnerability · 1 in the last 12 months
- Motex 1 vulnerability · 1 in the last 12 months
- Nagios 4 vulnerabilities
- Omnissa (ex-VMware EUC) 1 vulnerability · 1 in the last 12 months
- OpenText (Micro Focus) 1 vulnerability
- Paessler 2 vulnerabilities
- Progress 2 vulnerabilities
- Quest 2 vulnerabilities · 1 in the last 12 months
- rConfig 1 vulnerability
- SaltStack 3 vulnerabilities
- ScienceLogic 1 vulnerability
- ServiceNow 2 vulnerabilities
- SKYSEA 1 vulnerability · 1 in the last 12 months
- SolarWinds 7 vulnerabilities · 3 in the last 12 months
- SysAid 3 vulnerabilities
- Teclib 1 vulnerability
- VMware (Broadcom) 3 vulnerabilities · 1 in the last 12 months
- Zabbix 2 vulnerabilities
A high count also reflects how widely a product is deployed and how much attackers care about it: it is not a security rating.
See also
- Remote monitoring and management (RMM) 20 vulnerabilities
Patch first
In the order of the main list (Patch first): recent additions first, then the most severe. The number is the rank within this category.
Rank 1Ivanti Sentry
CVE-2026-10520Ivanti Sentry OS Command Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jun 11, 2026
- CISA deadline
- 3 days
- CVSS severity
- 10.0 (critical)
Rank 2Quest KACE Systems Management Appliance (SMA)
CVE-2025-32975Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 20, 2026
- CISA deadline
- 14 days
- CVSS severity
- 10.0 (critical)
Rank 3Fortinet FortiClient EMS
CVE-2026-21643Fortinet FortiClient EMS SQL Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 13, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 4Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2026-1340Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 8, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 5Fortinet FortiClient EMS
CVE-2026-35616Fortinet FortiClient EMS Improper Access Control Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Apr 6, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 6SolarWinds Web Help Desk
CVE-2025-26399Ransomware
SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Mar 9, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 7Microsoft Configuration Manager
CVE-2024-43468CVE from 2024, added in 2026
Microsoft Configuration Manager SQL Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Feb 12, 2026
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 8SolarWinds Web Help Desk
CVE-2025-40536SolarWinds Web Help Desk Security Control Bypass Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Feb 12, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 9SolarWinds Web Help Desk
CVE-2025-40551SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Feb 3, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Rank 10Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2026-1281Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jan 29, 2026
- CISA deadline
- 3 days
- CVSS severity
- 9.8 (critical)
Show 64 more vulnerabilities
Rank 11HPE OneView
CVE-2025-37164Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Jan 7, 2026
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 12Motex LANSCOPE Endpoint Manager
CVE-2025-61932Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 22, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 13SKYSEA Client View
CVE-2016-7836CVE from 2016, added in 2025
SKYSEA Client View Improper Authentication Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 14, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 14VMware (Broadcom) Aria Operations (ex-vRealize Operations)
CVE-2026-22719Broadcom VMware Aria Operations Command Injection Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Mar 3, 2026
- CISA deadline
- 21 days
- CVSS severity
- 8.1 (high)
Rank 15Omnissa (ex-VMware EUC) Workspace ONE UEM (AirWatch)
CVE-2021-22054CVE from 2021, added in 2026
Omnissa Workspace ONE Server-Side Request Forgery
Added in the last 12 months: ranked by severity.
- Added
- Mar 9, 2026
- CISA deadline
- 14 days
- CVSS severity
- 7.5 (high)
Rank 16Ivanti Endpoint Manager (EPM)
CVE-2026-1603Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Mar 9, 2026
- CISA deadline
- 14 days
- CVSS severity
- 7.5 (high)
Rank 17Grafana Labs Grafana
CVE-2021-43798CVE from 2021, added in 2025
Grafana Path Traversal Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 9, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 18Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2026-6973Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- May 7, 2026
- CISA deadline
- 3 days
- CVSS severity
- 7.2 (high)
Rank 19SysAid On-Prem
CVE-2025-2776SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 22, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 20Cisco Smart Licensing Utility
CVE-2024-20439Cisco Smart Licensing Utility Static Credential Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 31, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 21Progress WhatsUp Gold
CVE-2024-4885Progress WhatsUp Gold Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 3, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 22Paessler PRTG Network Monitor
CVE-2018-19410CVE from 2018, added in 2025
Paessler PRTG Network Monitor Local File Inclusion Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 4, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 23ScienceLogic SL1
CVE-2024-9537ScienceLogic SL1 Unspecified Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 21, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 24Progress WhatsUp Gold
CVE-2024-6670Ransomware
Progress WhatsUp Gold SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Sep 16, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 25SolarWinds Web Help Desk
CVE-2024-28986SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 15, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 26ServiceNow Now Platform
CVE-2024-4879ServiceNow Improper Input Validation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 29, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 27ServiceNow Now Platform
CVE-2024-5217ServiceNow Incomplete List of Disallowed Inputs Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 29, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 28Ivanti Cloud Services Appliance (CSA)
CVE-2021-44529RansomwareCVE from 2021, added in 2024
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 29Fortinet FortiClient EMS
CVE-2023-48788Ransomware
Fortinet FortiClient EMS SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 30Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2023-35082Ransomware
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 18, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 31SysAid On-Prem
CVE-2023-47246Ransomware
SysAid Server Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 13, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 32Ivanti Sentry
CVE-2023-38035Ransomware
Ivanti Sentry Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 22, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 33Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2023-35078Ransomware
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 25, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 34VMware (Broadcom) Aria Operations for Networks (ex-vRealize Network Insight)
CVE-2023-20887Vmware Aria Operations for Networks Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jun 22, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 35Teclib GLPI
CVE-2022-35914Teclib GLPI Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 7, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 36Cacti
CVE-2022-46169Cacti Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 16, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 37ManageEngine (Zoho) Multiple products
CVE-2022-47966Ransomware
Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jan 23, 2023
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 38HPE Network Node Manager (OpenView NNM)
CVE-2005-2773CVE from 2005, added in 2022
HP OpenView Network Node Manager Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 39HPE ProCurve Manager (PCM, PCM+, IDM)
CVE-2013-4810CVE from 2013, added in 2022
HP Multiple Products Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 40Quest KACE Systems Management Appliance (SMA)
CVE-2018-11138RansomwareCVE from 2018, added in 2022
Quest KACE System Management Appliance Remote Command Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
Rank 41Zabbix Frontend
CVE-2022-23131Zabbix Frontend Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 22, 2022
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 42ManageEngine (Zoho) Endpoint Central (ex-Desktop Central)
CVE-2021-44515Zoho Desktop Central Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 10, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 43ManageEngine (Zoho) ServiceDesk Plus
CVE-2021-37415Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 1, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 44ManageEngine (Zoho) ServiceDesk Plus
CVE-2021-44077Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Dec 1, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 45SolarWinds Orion Platform
CVE-2020-10148SolarWinds Orion Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 46ManageEngine (Zoho) Endpoint Central (ex-Desktop Central)
CVE-2020-10189Zoho ManageEngine Desktop Central File Upload Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 47SaltStack Salt
CVE-2020-11651SaltStack Salt Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 48Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2020-15505Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 49SaltStack Salt
CVE-2020-16846SaltStack Salt Shell Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 50EyesOfNetwork
CVE-2020-8657EyesOfNetwork Use of Hard-Coded Credentials Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 9.8 (critical)
Rank 51OpenText (Micro Focus) Operations Bridge Reporter (OBR)
CVE-2021-22502Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 14 days
- CVSS severity
- 9.8 (critical)
Rank 52SolarWinds Web Help Desk
CVE-2024-28987SolarWinds Web Help Desk Hardcoded Credential Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 15, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Rank 53Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2025-4428Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 19, 2025
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 54Ivanti Endpoint Manager (EPM)
CVE-2024-29824Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Oct 2, 2024
- CISA deadline
- 21 days
- CVSS severity
- 8.8 (high)
Rank 55Nagios XI
CVE-2021-25296Nagios XI OS Command Injection
Added more than a year ago: ranked by severity.
- Added
- Jan 18, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.8 (high)
Rank 56Nagios XI
CVE-2021-25297Nagios XI OS Command Injection
Added more than a year ago: ranked by severity.
- Added
- Jan 18, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.8 (high)
Rank 57Nagios XI
CVE-2021-25298Nagios XI OS Command Injection
Added more than a year ago: ranked by severity.
- Added
- Jan 18, 2022
- CISA deadline
- 14 days
- CVSS severity
- 8.8 (high)
Rank 58Nagios XI
CVE-2019-15949CVE from 2019, added in 2021
Nagios XI Remote Code Execution Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.8 (high)
Rank 59rConfig
CVE-2020-10221rConfig OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 8.8 (high)
Rank 60SolarWinds Virtualization Manager
CVE-2016-3643CVE from 2016, added in 2021
SolarWinds Virtualization Manager Privilege Escalation Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.8 (high)
Rank 61EyesOfNetwork
CVE-2020-8655EyesOfNetwork Improper Privilege Management Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 7.8 (high)
Rank 62SysAid On-Prem
CVE-2025-2775SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 22, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 63Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2025-4427Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- May 19, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 64Ivanti Endpoint Manager (EPM)
CVE-2024-13159Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 10, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 65Ivanti Endpoint Manager (EPM)
CVE-2024-13160Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 10, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 66Ivanti Endpoint Manager (EPM)
CVE-2024-13161Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 10, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 67Cisco Prime Data Center Network Manager (DCNM)
CVE-2015-0666CVE from 2015, added in 2022
Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Mar 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.5 (high)
Rank 68VMware (Broadcom) Aria Operations (ex-vRealize Operations)
CVE-2021-21975Ransomware
VMware Server Side Request Forgery in vRealize Operations Manager API
Added more than a year ago: ranked by severity.
- Added
- Jan 18, 2022
- CISA deadline
- 14 days
- CVSS severity
- 7.5 (high)
Rank 69Grafana Labs Grafana
CVE-2021-39226Grafana Authentication Bypass Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Aug 25, 2022
- CISA deadline
- 21 days
- CVSS severity
- 7.3 (high)
Rank 70Paessler PRTG Network Monitor
CVE-2018-9276CVE from 2018, added in 2025
Paessler PRTG Network Monitor OS Command Injection Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 4, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 71Ivanti Endpoint Manager Mobile (EPMM, ex-MobileIron)
CVE-2023-35081Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Jul 31, 2023
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Rank 72ManageEngine (Zoho) ServiceDesk Plus
CVE-2019-8394CVE from 2019, added in 2021
Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 6.5 (medium)
Rank 73SaltStack Salt
CVE-2020-11652SaltStack Salt Path Traversal Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Nov 3, 2021
- CISA deadline
- 181 days
- CVSS severity
- 6.5 (medium)
Rank 74Zabbix Frontend
CVE-2022-23134Zabbix Frontend Improper Access Control Vulnerability
Added more than a year ago: ranked by severity.
- Added
- Feb 22, 2022
- CISA deadline
- 14 days
- CVSS severity
- 5.3 (medium)
Filed under another category
These 2 vulnerabilities also concern this type of product, but are counted in their main category. My radar finds them when you follow this category.
Microsoft Windows
CVE-2025-59287Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 24, 2025
- CISA deadline
- 21 days
- CVSS severity
- 9.8 (critical)
VMware (Broadcom) VMware Tools
CVE-2025-41244Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability
Added in the last 12 months: ranked by severity.
- Added
- Oct 30, 2025
- CISA deadline
- 21 days
- CVSS severity
- 7.8 (high)
End of life: remove
These products are no longer supported: no patch is coming. Remove them or isolate them from the network.
Ivanti Cloud Services Appliance (CSA)
CVE-2024-9379End of life
Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Oct 9, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Ivanti Cloud Services Appliance (CSA)
CVE-2024-9380End of life
Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Oct 9, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Ivanti Cloud Services Appliance (CSA)
CVE-2024-8963End of life
Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Sep 19, 2024
- CISA deadline
- 21 days
- CVSS severity
- 9.1 (critical)
Ivanti Cloud Services Appliance (CSA)
CVE-2024-8190End of life
Ivanti Cloud Services Appliance OS Command Injection Vulnerability
End-of-life product: no patch is coming; remove or isolate it.
- Added
- Sep 13, 2024
- CISA deadline
- 21 days
- CVSS severity
- 7.2 (high)
Follow and verify
Get new vulnerabilities in this category: RSS feed (add it to Outlook, Teams, Slack or your feed reader).
Indicative classification, based on the vendor and product names given by CISA. How products are classified.