CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “ivanti”

124 vulnerabilities found for “ivanti”

Page 1 of 7

CVE-2025-22463
HIGH7.3

A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment password.

ivanti / workspace_control
Local
Published Jun 10, 2025
Page 1 of 7
CVE-2025-5353
HIGH8.8

A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials.

ivanti / workspace_control
Local
Published Jun 10, 2025
CVE-2025-22455
HIGH8.8

A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentials.

ivanti / workspace_control
Local
Published Jun 10, 2025
CVE-2024-8496
HIGH7.8

Under specific circumstances, insecure permissions in Ivanti Workspace Control before version 10.18.40.0 allows a local authenticated attacker to achieve local privilege escalation.

ivanti / workspace_control
Local
Published Dec 11, 2024
CVE-2024-44103
HIGH8.8

DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

ivanti / workspace_control
Local
Published Sep 10, 2024
CVE-2024-44106
HIGH8.8

Insufficient server-side controls in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

ivanti / workspace_control
Local
Published Sep 10, 2024
CVE-2024-8012
HIGH7.8

An authentication bypass weakness in the message broker service of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

ivanti / workspace_control
Local
Published Sep 10, 2024
CVE-2024-44105
HIGH8.2

Cleartext transmission of sensitive information in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to obtain OS credentials.

ivanti / workspace_control
Local
Published Sep 10, 2024
CVE-2024-44104
HIGH8.8

An incorrectly implemented authentication scheme that is subjected to a spoofing attack in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges.

ivanti / workspace_control
Local
Published Sep 10, 2024
CVE-2024-44107
HIGH8.8

DLL hijacking in the management console of Ivanti Workspace Control before version 2025.2 (10.19.0.0) allows a local authenticated attacker to escalate their privileges and achieve arbitrary code execution.

ivanti / workspace_control
Local
Published Sep 10, 2024
CVE-2022-21823
MEDIUM5.5

A insecure storage of sensitive information vulnerability exists in Ivanti Workspace Control <2021.2 (10.7.30.0) that could allow an attacker with locally authenticated low privileges to obtain key information due to an unspecified attack vector.

ivanti / workspace_control
Local
Published Jan 10, 2022
CVE-2019-19138
HIGH7.5

Ivanti Workspace Control before 10.4.50.0 allows attackers to degrade integrity.

ivanti / workspace_control
Network
Published Dec 15, 2021
CVE-2021-36235
HIGH7.8

An issue was discovered in Ivanti Workspace Control before 10.6.30.0. A locally authenticated user with low privileges can bypass File and Folder Security by leveraging an unspecified attack vector. As a result, the attacker can start applications with elevated privileges.

ivanti / workspace_control
Local
Published Sep 1, 2021
CVE-2019-17066
HIGH7.8

In Ivanti WorkSpace Control before 10.4.40.0, a user can elevate rights on the system by hijacking certain user registries. This is possible because pwrgrid.exe first checks the Current User registry hives (HKCU) when starting an application with elevated rights.

ivanti / workspace_control
Local
Published May 18, 2020
CVE-2019-19675
HIGH7.8

In Ivanti Workspace Control before 10.3.180.0. a locally authenticated user with low privileges can bypass Managed Application Security by leveraging an unspecified attack vector in Workspace Preferences, when it is enabled. As a result, the attacker can start applications that should be blocked.

ivanti / workspace_control
Local
Published Dec 17, 2019
CVE-2019-10885
HIGH7.8

An issue was discovered in Ivanti Workspace Control before 10.3.90.0. Local authenticated users with low privileges in a Workspace Control managed session can bypass Workspace Control security features configured for this session by resetting the session context.

ivanti / workspace_control
Local
Published Apr 5, 2019
CVE-2018-15591
HIGH7.8

An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can bypass Application Whitelisting restrictions to execute arbitrary code by leveraging multiple unspecified attack vectors.

ivanti / workspace_control
Local
Published Oct 15, 2018
CVE-2018-15592
HIGH7.8

An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can execute processes with elevated privileges via an unspecified attack vector.

ivanti / workspace_control
Local
Published Oct 15, 2018
CVE-2018-15590
MEDIUM5.5

An issue was discovered in Ivanti Workspace Control before 10.3.0.0 and RES One Workspace, when file and folder security are configured. A local authenticated user can bypass file and folder security restriction by leveraging an unspecified attack vector.

ivanti / workspace_control
Local
Published Oct 15, 2018
CVE-2018-15593
HIGH7.8

An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can decrypt the encrypted datastore or relay server password by leveraging an unspecified attack vector.

ivanti / workspace_control
Local
Published Oct 15, 2018