Vulnerability index

Browse CVEs

35 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-9559 Pega Platform versions 8.7.5 to Infinity 24.2.2 are affected by a Insecure Direct Object Reference issue in a user interface component that can only … Pega Platform 23.1.5+ Fix from $1,6002025-10-16 MEDIUM 5.4 CVE-2025-8681 Pega Platform versions 7.1.0 to Infinity 24.2.2 are affected by a Stored XSS issue in a user interface component.  Requires a high privileged user wi… Pega Platform 23.1.5 / 24.1.3+ Fix from $1,6002025-09-10 MEDIUM 6.1 CVE-2025-2160 Pega Platform versions 8.4.3 to Infinity 24.2.1 are affected by an XSS issue with Mashup Pega Platform 8.5.5 / 23.1.4+ Fix from $1,6002025-04-14 MEDIUM 6.1 CVE-2025-2161 Pega Platform versions 7.2.1 to Infinity 24.2.1 are affected by an XSS issue with Mashup Pega Platform 8.5.5 / 23.1.4+ Fix from $1,6002025-04-14 MEDIUM 5.4 CVE-2024-12211 Pega Platform versions 8.1 to Infinity 24.2.0 are affected by an Stored XSS issue with profile. Pega Platform 23.1.4 / 24.1.2+ Fix from $1,6002025-01-13 CRITICAL 9.8 CVE-2024-10094 Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code Infinity 8.1.9 / 8.2.8+ Fix from $2,3002024-11-20 HIGH 7.7 CVE-2023-50168 Pega Platform from 6.x to 8.8.4 is affected by an XXE issue with PDF Generation. Pega Platform 8.8.5+ Fix from $1,9502024-03-14 MEDIUM 6.1 CVE-2023-50167 Pega Platform from 7.1.7 to 23.1.1 is affected by an XSS issue with editing/rendering user html content. Pega Platform 8.8.5+ Fix from $1,6002024-03-06 HIGH 8.6 CVE-2023-50165 Pega Platform versions 8.2.1 to Infinity 23.1.0 are affected by an Generated PDF issue that could expose file contents. Platform after 23.1.0 Fix from $1,9502024-01-31 MEDIUM 6.1 CVE-2023-50166 Pega Platform from 8.5.4 to 8.8.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. Platform after 8.8.3 Fix from $1,6002024-01-31 MEDIUM 6.1 CVE-2023-32087 Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with task creation Platform 8.7.5 / 8.8.3+ Fix from $1,6002023-10-18 MEDIUM 6.1 CVE-2023-32088 Pega Platform versions 8.1 to Infinity 23.1.0 are affected by an XSS issue with ad-hoc case creation Platform 8.7.5 / 8.8.3+ Fix from $1,6002023-10-18 MEDIUM 6.1 CVE-2023-32089 Pega Platform versions 8.1 to 8.8.2 are affected by an XSS issue with Pin description Platform after 8.8.2 Fix from $1,6002023-10-18 CRITICAL 9.8 CVE-2023-32090 Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials Pega Platform after 7.3.1 Fix from $2,3002023-08-07 CRITICAL 9.8 CVE-2023-28094 Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials. Pega Platform after 8.8.3 Fix from $2,3002023-06-22 MEDIUM 6.1 CVE-2023-26465 Pega Platform versions 7.2 to 8.8.1 are affected by an XSS issue. Pega Platform after 8.8.1 Fix from $1,6002023-06-09 MEDIUM 5.4 CVE-2023-26467 A man in the middle can redirect traffic to a malicious server in a compromised configuration. Synchronization Engine 3.1.30+ Fix from $1,6002023-04-10 HIGH 7.8 CVE-2023-26466 A user with non-Admin access can change a configuration file on the client to modify the Server URL. Synchronization Engine 3.1.30+ Fix from $1,9502023-04-10 MEDIUM 6.5 CVE-2023-28093 A user with a compromised configuration can start an unsigned binary as a service. Synchronization Engine 3.1.30+ Fix from $1,6002023-04-10 MEDIUM 6.1 CVE-2022-35654 Pega Platform from 8.5.4 to 8.7.3 is affected by an XSS issue with an unauthenticated user and the redirect parameter. Pega Platform after 8.7.3 Fix from $1,6002022-08-22 MEDIUM 6.1 CVE-2022-35655 Pega Platform from 7.3 to 8.7.3 is affected by an XSS issue due to a misconfiguration of a datapage setting. Pega Platform after 8.7.3 Fix from $1,6002022-08-22 CRITICAL 9.8 CVE-2022-24083 Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks. Infinity after 8.7.2 Fix from $2,3002022-07-25 CRITICAL 9.8 CVE-2022-24082EPSS 12% If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is no… Infinity 8.7.3+ Fix from $2,3002022-07-19 HIGH 7.8 CVE-2021-27654 Forgotten password reset functionality for local accounts can be used to bypass local authentication checks. Infinity after 8.6.1 Fix from $1,9502022-01-28 CRITICAL 9.8 CVE-2021-27651EPSS 54% In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication chec… Infinity after 8.5.2 Fix from $2,3002021-04-29 CRITICAL 9.8 CVE-2020-15390 pyActivity in Pega Platform 8.4.0.237 has a security misconfiguration that leads to an improper access control vulnerability via =GetWebInfo. Pega Platform No fix yet Fix from $2,3002021-04-12 MEDIUM 6.1 CVE-2020-23957 Pega Platform through 8.4.x is affected by Cross Site Scripting (XSS) via the ConnectionID parameter, as demonstrated by a pyActivity=Data-TRACERSett… Pega Platform after 8.4.2 Fix from $1,6002020-12-15 MEDIUM 6.1 CVE-2020-24353 Pega Platform before 8.4.0 has a XSS issue via stream rule parameters used in the request header. Pega Platform 8.4+ Fix from $1,6002020-11-09 CRITICAL 9.8 CVE-2019-16374 Pega Platform 8.2.1 allows LDAP injection because a username can contain a * character and can be of unlimited length. An attacker can specify four c… Platform after 8.2.1 Fix from $2,3002020-08-13 HIGH 8.9 CVE-2020-8775 Pega Platform before version 8.2.6 is affected by a Stored Cross-Site Scripting (XSS) vulnerability in the comment tags. Platform 8.2.6+ Fix from $1,9502020-04-29