Ivanti Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for Ivanti products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

30

In CISA KEV

26

Beyond CISA KEV

4

Sensor Observed

3

Virtual Patch Available

1

Ivanti KEVs Added by Year

Loading...

30 Ivanti KEVs added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2025-0282

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons...

Confirmed In CISA 08 Jan 2025
CVE-2024-13159

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote...

Confirmed In CISA 10 Mar 2025
CVE-2024-13160

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote...

Confirmed In CISA 10 Mar 2025
CVE-2024-13161

Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Update allows a remote...

Confirmed In CISA 10 Mar 2025
CVE-2025-22457

A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA...

Confirmed In CISA 04 Apr 2025

Common Vulnerability Classes (CWE)

  • CWE-287 — Improper Authentication 4
  • CWE-94 — Improper Control of Generation of Code ('Code Injection') 4
  • CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 4
  • CWE-36 — Absolute Path Traversal 3
  • CWE-288 — Authentication Bypass Using an Alternate Path or Channel 2
  • CWE-121 — Stack-based Buffer Overflow 2
  • CWE-611 — Improper Restriction of XML External Entity Reference 2
  • CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 2

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology