Vulnerability index

Browse CVEs

61 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dsm Netinst CRITICAL 9.8
CVE-2020-13793

Unsafe storage of AD credentials in Ivanti DSM netinst 5.1 due to a static, hard-coded encryption key.

Mitigation only
Fix from $2,300 2020-08-06
Avalanche CRITICAL 9.8
CVE-2020-12442

Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250.

Mitigation only
Fix from $2,300 2020-04-28
Connect Secure CRITICAL 9.8
CVE-2018-20810

Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8…

Mitigation only
Fix from $2,300 2019-06-28
Connect Secure CRITICAL 9.8
CVE-2018-20813

An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2.

Mitigation only
Fix from $2,300 2019-06-28
Connect Secure HIGH 7.5
CVE-2018-20809

A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and Pulse Policy Secure 5.4RX bef…

Mitigation only
Fix from $1,950 2019-06-28
Connect Secure MEDIUM 6.1
CVE-2018-20814

An XSS issue was found with Psaldownload.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.3R2 before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before…

Mitigation only
Fix from $1,600 2019-06-28
Connect Secure MEDIUM 5.3
CVE-2018-20811

A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12.

No fix yet
Fix from $1,600 2019-06-28
Connect Secure MEDIUM 6.1
CVE-2018-20807

An XSS issue has been found in welcome.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1.x before 8.1R12, 8.2.x before 8.2R9, and 8.3.x before 8.3R3…

Mitigation only
Fix from $1,600 2019-06-28
Connect Secure MEDIUM 6.1
CVE-2018-20808

An XSS issue has been found with rd.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R3 due to improper header sanitization. This is not appl…

Mitigation only
Fix from $1,600 2019-06-28
Landesk Management Suite CRITICAL 9.8
CVE-2019-12377EPSS 6%

A vulnerable upl/async_upload.asp web API endpoint in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 allows…

No fix yet
Fix from $2,300 2019-06-03
Landesk Management Suite MEDIUM 6.3
CVE-2019-12375

Open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to remote information disclosur…

Mitigation only
Fix from $1,600 2019-06-03
Landesk Management Suite CRITICAL 9.0
CVE-2019-12373

Improper access control and open directories in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 may lead to …

Mitigation only
Fix from $2,300 2019-06-03
Connect Secure HIGH 8.8
CVE-2019-11509EPSS 8%

In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policy Secure (…

Mitigation only
Fix from $1,950 2019-06-03
Landesk Management Suite HIGH 8.1
CVE-2019-12374

A SQL Injection vulnerability exists in Ivanti LANDESK Management Suite (LDMS, aka Endpoint Manager) 10.0.1.168 Service Update 5 due to improper user…

No fix yet
Fix from $1,950 2019-06-03
Connect Secure CRITICAL 9.8
CVE-2019-11540EPSS 8%

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5…

No fix yet
Fix from $2,300 2019-04-26
Connect Secure HIGH 7.7
CVE-2019-11538EPSS 7%

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1, an NFS pro…

No fix yet
Fix from $1,950 2019-04-26
Connect Secure HIGH 7.5
CVE-2019-11541

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication w…

Mitigation only
Fix from $1,950 2019-04-26
Connect Secure HIGH 7.2
CVE-2019-11539 KEVEPSS 99%

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse P…

Mitigation only
Fix from $1,950 2019-04-26
Connect Secure HIGH 7.2
CVE-2019-11542EPSS 66%

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse P…

No fix yet
Fix from $1,950 2019-04-26
Connect Secure MEDIUM 6.1
CVE-2019-11543

XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1 …

Mitigation only
Fix from $1,600 2019-04-26
Connect Secure CRITICAL 9.8
CVE-2018-6320

A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Poli…

Mitigation only
Fix from $2,300 2018-09-06
Connect Secure MEDIUM 6.1
CVE-2018-14366

download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and …

Mitigation only
Fix from $1,600 2018-09-06
Endpoint Manager HIGH 8.8
CVE-2017-11463

In Ivanti Service Desk (formerly LANDESK Management Suite) versions between 2016.3 and 2017.3, an Unrestricted Direct Object Reference leads to refer…

Mitigation only
Fix from $1,950 2017-12-11
Connect Secure HIGH 8.8
CVE-2017-11455

diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8, and 5.1R…

Mitigation only
Fix from $1,950 2017-08-29
Connect Secure MEDIUM 5.3
CVE-2016-4792

Pulse Connect Secure (PCS) 8.2 before 8.2r1 allows remote attackers to disclose sign in pages via unspecified vectors.

No fix yet
Fix from $1,600 2016-05-26
Connect Secure HIGH 8.6
CVE-2016-4791

The administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r9, and 7.4 before 7.4r13.4 allows …

Mitigation only
Fix from $1,950 2016-05-26
Connect Secure MEDIUM 5.5
CVE-2016-4790

Cross-site scripting (XSS) vulnerability in the administrative user interface in Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 b…

Mitigation only
Fix from $1,600 2016-05-26
Connect Secure MEDIUM 6.1
CVE-2016-4789

Cross-site scripting (XSS) vulnerability in the system configuration section in the administrative user interface in Pulse Connect Secure (PCS) 8.2 b…

Mitigation only
Fix from $1,600 2016-05-26
Connect Secure MEDIUM 5.8
CVE-2016-4788

Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read an unspecifi…

Mitigation only
Fix from $1,600 2016-05-26
Connect Secure CRITICAL 10.0
CVE-2016-4787

Pulse Connect Secure (PCS) 8.2 before 8.2r1, 8.1 before 8.1r2, 8.0 before 8.0r10, and 7.4 before 7.4r13.4 allow remote attackers to read sensitive sy…

Mitigation only
Fix from $2,300 2016-05-26