CVEs (130)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature |
A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room. |
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow...Show more |
2Ivanti Pulsesecure4Connect Secure Policy SecurePulse Connect Secure+1 moreNov 21, 2024 Oct 28, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface. |
2Ivanti Pulsesecure4Connect Secure Policy SecurePulse Connect Secure+1 moreNov 21, 2024 Oct 28, 2020 N/A· v4 4.3 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection. |
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction. |
2Ivanti Pulsesecure4Connect Secure Policy SecurePulse Connect Secure+1 moreNov 21, 2024 Oct 27, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks vi...Show more |
2Ivanti Pulsesecure2Connect Secure Pulse Connect SecureNov 21, 2024 Sep 30, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerabilit...Show more |
1Ivanti 2Connect Secure Policy SecureDec 18, 2025 Sep 30, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution. |
2Ivanti Pulsesecure4Connect Secure Policy SecurePulse Connect Secure+1 moreNov 21, 2024 Sep 30, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Scripting (XSS). |
2Ivanti Pulsesecure4Connect Secure Policy SecurePulse Connect Secure+1 moreNov 21, 2024 Jul 30, 2020 N/A· v4 6.8 MEDIUM· v3 4.0 MEDIUM· v2 A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated attacker via the administrator web interface to perform an arbitrary file reading vulnerability through Meeting. |
2Ivanti Pulsesecure4Connect Secure Policy SecurePulse Connect Secure+1 moreNov 21, 2024 Jul 30, 2020 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbitrary files via the administrator web interface. |
2Ivanti Pulsesecure4Connect Secure Policy SecurePulse Connect Secure+1 moreNov 21, 2024 Jul 30, 2020 N/A· v4 6.5 MEDIUM· v3 5.5 MEDIUM· v2 A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the administrator web which can cause DOS. |
2Ivanti Pulsesecure4Connect Secure Policy SecurePulse Connect Secure+1 moreNov 21, 2024 Jul 30, 2020 N/A· v4 7.2 HIGH· v3 4.0 MEDIUM· v2 An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full administrator. |
2Ivanti Pulsesecure3Connect Secure Policy SecurePulse Policy SecureOct 30, 2025 Jul 30, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface. |
2Ivanti Pulsesecure4Connect Secure Policy SecurePulse Connect Secure+1 moreNov 21, 2024 Jul 30, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used for Citrix ICA. |
2Ivanti Pulsesecure4Connect Secure Policy SecurePulse Connect Secure+1 moreNov 21, 2024 Jul 30, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to find meeting details, if they know the Meeting ID. |
2Ivanti Pulsesecure4Connect Secure Policy SecurePulse Connect Secure+1 moreNov 21, 2024 Jul 30, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP. |
2Ivanti Pulsesecure4Connect Secure Policy SecurePulse Connect Secure+1 moreNov 21, 2024 Jul 30, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page. |
2Ivanti Pulsesecure4Connect Secure Policy SecurePulse Connect Secure+1 moreNov 21, 2024 Jul 27, 2020 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a...Show more |