Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Virtual Traffic Manager HIGH 7.5
CVE-2021-31922

An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request throug…

Fix: after 19.1
Fix from $1,950 2021-05-14
Pulse Secure Desktop Client MEDIUM 5.4
CVE-2020-8263

A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) t…

Fix: 9.1+
Fix from $1,600 2020-10-28
Pulse Secure Desktop Client CRITICAL 9.8
CVE-2020-8239

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires S…

Fix: 9.1+
Fix from $2,300 2020-10-28
Pulse Secure Desktop Client HIGH 8.8
CVE-2020-8254

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a malicious server…

Fix: 9.1+
Fix from $1,950 2020-10-28
Pulse Secure Desktop Client HIGH 7.8
CVE-2020-8240

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Emb…

Fix: 9.1+
Fix from $1,950 2020-10-28
Pulse Secure Desktop Client HIGH 7.8
CVE-2020-8248

A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.

Fix: 9.1+
Fix from $1,950 2020-10-28
Pulse Secure Desktop Client HIGH 7.8
CVE-2020-8249

A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to perform buffer overflow.

Fix: 9.1+
Fix from $1,950 2020-10-28
Pulse Secure Desktop Client HIGH 7.8
CVE-2020-8250

A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.

Fix: 9.1+
Fix from $1,950 2020-10-28
Pulse Secure Desktop Client HIGH 7.5
CVE-2020-8241

A vulnerability in the Pulse Secure Desktop Client < 9.1R9 could allow the attacker to perform a MITM Attack if end users are convinced to connect to…

Fix: 9.1+
Fix from $1,950 2020-10-28
Pulse Secure Desktop Client HIGH 7.0
CVE-2020-13162

A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which…

No fix yet
Fix from $1,950 2020-06-16
Pulse Connect Secure CRITICAL 9.1
CVE-2020-11580

An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris …

Fix: after 2020-04-06
Fix from $2,300 2020-04-06
Pulse Connect Secure HIGH 8.8
CVE-2020-11582

An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris …

Fix: after 2020-04-06
Fix from $1,950 2020-04-06
Pulse Connect Secure HIGH 8.1
CVE-2020-11581EPSS 10%

An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris …

Fix: after 2020-04-06
Fix from $1,950 2020-04-06
Pulse Secure Desktop Client HIGH 7.5
CVE-2018-20812

An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse S…

Mitigation only
Fix from $1,950 2019-06-28
Secure Access Series Ssl Vpn Sa 4000 HIGH 8.8
CVE-2018-20193

Certain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by Pulse Secure, LLC) allow pri…

No fix yet
Fix from $1,950 2018-12-21
Virtual Traffic Manager MEDIUM 5.4
CVE-2018-20306

A stored cross-site scripting (XSS) vulnerability in the web administration user interface of Pulse Secure Virtual Traffic Manager may allow a remote…

Fix: 9.9r2 / 10.4r1+
Fix from $1,600 2018-12-20
Pulse Secure Desktop Client MEDIUM 5.5
CVE-2018-11002

Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure Permissions.

No fix yet
Fix from $1,600 2018-11-29
Pulse Secure Desktop MEDIUM 6.8
CVE-2018-7572

Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can allow attackers to bypass Windo…

Mitigation only
Fix from $1,600 2018-09-12
Pulse Secure Desktop Client MEDIUM 6.8
CVE-2018-16261

In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust.

Mitigation only
Fix from $1,600 2018-09-06
Pulse Secure Desktop Client HIGH 7.8
CVE-2018-15865

The Pulse Secure Desktop (macOS) has a Privilege Escalation Vulnerability.

No fix yet
Fix from $1,950 2018-09-06
Pulse Secure Desktop Client MEDIUM 5.5
CVE-2018-15749

The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Format String Vulnerability.

Mitigation only
Fix from $1,600 2018-09-06
Pulse Secure Desktop Client MEDIUM 5.3
CVE-2018-15726

The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Privilege Escalation Vulnerability.

No fix yet
Fix from $1,600 2018-09-06
Pulse Connect Secure MEDIUM 5.5
CVE-2018-9849

Pulse Secure Pulse Connect Secure 8.1.x before 8.1R14, 8.2.x before 8.2R11, and 8.3.x before 8.3R5 do not properly process nested XML entities, which…

Fix: 8.1r14 / 8.2r11+
Fix from $1,600 2018-05-10
Desktop Linux Client MEDIUM 6.5
CVE-2018-6374

The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL C…

Fix: 5.2r9.2 / 5.3r4.2+
Fix from $1,600 2018-01-31
Pulse Connect Secure CRITICAL 9.8
CVE-2018-5299

A stack-based Buffer Overflow Vulnerability exists in the web server in Pulse Secure Pulse Connect Secure (PCS) before 8.3R4 and Pulse Policy Secure …

Fix: after 8.3r3
Fix from $2,300 2018-01-16
Pulse One On Premise HIGH 7.5
CVE-2017-14935

Pulse Secure Pulse One On-Premise 2.0.1649 and below does not properly validate requests, which allows remote users to query and obtain sensitive inf…

Patch available
Fix from $1,950 2017-09-30
Pulse Connect Secure HIGH 8.8
CVE-2017-11193

Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands such as ping, ping6, traceroute,…

Mitigation only
Fix from $1,950 2017-07-12
Pulse Connect Secure HIGH 8.8
CVE-2017-11196

Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF tokens, thus allowing an attac…

Mitigation only
Fix from $1,950 2017-07-12
Pulse Connect Secure MEDIUM 6.1
CVE-2017-11194

Pulse Connect Secure 8.3R1 has Reflected XSS in adminservercacertdetails.cgi. In the admin panel, the certid parameter of adminservercacertdetails.cg…

Mitigation only
Fix from $1,600 2017-07-12
Pulse Connect Secure MEDIUM 6.1
CVE-2017-11195

Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains…

Mitigation only
Fix from $1,600 2017-07-12