Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.5
CVE-2025-9559
Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only …
Pega Platform
23.1.5+
MEDIUM 5.4
CVE-2025-8681
Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component. Requires a high privileged user wi…
Pega Platform
23.1.5 / 24.1.3+
MEDIUM 6.1
CVE-2025-2160
Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup
Pega Platform
8.5.5 / 23.1.4+
MEDIUM 6.1
CVE-2025-2161
Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup
Pega Platform
8.5.5 / 23.1.4+
MEDIUM 5.4
CVE-2024-12211
Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile.
Pega Platform
23.1.4 / 24.1.2+
CRITICAL 9.8
CVE-2024-10094
Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code
Infinity
8.1.9 / 8.2.8+
HIGH 7.7
CVE-2023-50168
Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation.
Pega Platform
8.8.5+
MEDIUM 6.1
CVE-2023-50167
Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content.
Pega Platform
8.8.5+
HIGH 8.6
CVE-2023-50165
Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents.
Platform
after 23.1.0
MEDIUM 6.1
CVE-2023-50166
Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
Platform
after 8.8.3
MEDIUM 6.1
CVE-2023-32087
Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation
Platform
8.7.5 / 8.8.3+
MEDIUM 6.1
CVE-2023-32088
Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation
Platform
8.7.5 / 8.8.3+
MEDIUM 6.1
CVE-2023-32089
Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description
Platform
after 8.8.2
CRITICAL 9.8
CVE-2023-32090
Pega platform clients who are using versions 6.1 through 7.3.1 may be
utilizing default credentials
Pega Platform
after 7.3.1
CRITICAL 9.8
CVE-2023-28094
Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.
Pega Platform
after 8.8.3
MEDIUM 6.1
CVE-2023-26465
Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue.
Pega Platform
after 8.8.1
MEDIUM 5.4
CVE-2023-26467
A man in the middle can redirect traffic to a malicious server in a compromised configuration.
Synchronization Engine
3.1.30+
HIGH 7.8
CVE-2023-26466
A user with non-Admin access can change a configuration file on the client to modify the Server URL.
Synchronization Engine
3.1.30+
MEDIUM 6.5
CVE-2023-28093
A user with a compromised configuration can start an unsigned binary as a service.
Synchronization Engine
3.1.30+
MEDIUM 6.1
CVE-2022-35654
Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter.
Pega Platform
after 8.7.3
MEDIUM 6.1
CVE-2022-35655
Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting.
Pega Platform
after 8.7.3
CRITICAL 9.8
CVE-2022-24083
Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
Infinity
after 8.7.2
CRITICAL 9.8
CVE-2022-24082EPSS 12%
If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is no…
Infinity
8.7.3+
HIGH 7.8
CVE-2021-27654
Forgotten password reset functionality for local accounts can be used to bypass local authentication checks.
Infinity
after 8.6.1
CRITICAL 9.8
CVE-2021-27651EPSS 54%
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication chec…
Infinity
after 8.5.2
CRITICAL 9.8
CVE-2020-15390
pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo.
Pega Platform
No fix yet
MEDIUM 6.1
CVE-2020-23957
Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSett…
Pega Platform
after 8.4.2
MEDIUM 6.1
CVE-2020-24353
Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header.
Pega Platform
8.4+
CRITICAL 9.8
CVE-2019-16374
Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four c…
Platform
after 8.2.1
HIGH 8.9
CVE-2020-8775
Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags.
Platform
8.2.6+