Vulnerability index

Browse CVEs

32 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2021-31922 An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request throug… Virtual Traffic Manager after 19.1 Fix from $1,9502021-05-14 MEDIUM 5.4 CVE-2020-8263 A vulnerability in the authenticated user web interface of Pulse Connect Secure < 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) t… Pulse Secure Desktop Client 9.1+ Fix from $1,6002020-10-28 CRITICAL 9.8 CVE-2020-8239 A vulnerability in the Pulse Secure Desktop Client < 9.1R9 is vulnerable to the client registry privilege escalation attack. This fix also requires S… Pulse Secure Desktop Client 9.1+ Fix from $2,3002020-10-28 HIGH 8.8 CVE-2020-8254 A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a malicious server… Pulse Secure Desktop Client 9.1+ Fix from $1,9502020-10-28 HIGH 7.8 CVE-2020-8240 A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Emb… Pulse Secure Desktop Client 9.1+ Fix from $1,9502020-10-28 HIGH 7.8 CVE-2020-8248 A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege. Pulse Secure Desktop Client 9.1+ Fix from $1,9502020-10-28 HIGH 7.8 CVE-2020-8249 A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to perform buffer overflow. Pulse Secure Desktop Client 9.1+ Fix from $1,9502020-10-28 HIGH 7.8 CVE-2020-8250 A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege. Pulse Secure Desktop Client 9.1+ Fix from $1,9502020-10-28 HIGH 7.5 CVE-2020-8241 A vulnerability in the Pulse Secure Desktop Client < 9.1R9 could allow the attacker to perform a MITM Attack if end users are convinced to connect to… Pulse Secure Desktop Client 9.1+ Fix from $1,9502020-10-28 HIGH 7.0 CVE-2020-13162 A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which… Pulse Secure Desktop Client No fix yet Fix from $1,9502020-06-16 CRITICAL 9.1 CVE-2020-11580 An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris … Pulse Connect Secure after 2020-04-06 Fix from $2,3002020-04-06 HIGH 8.8 CVE-2020-11582 An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris … Pulse Connect Secure after 2020-04-06 Fix from $1,9502020-04-06 HIGH 8.1 CVE-2020-11581EPSS 10% An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris … Pulse Connect Secure after 2020-04-06 Fix from $1,9502020-04-06 HIGH 7.5 CVE-2018-20812 An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse S… Pulse Secure Desktop Client Mitigation only Fix from $1,9502019-06-28 HIGH 8.8 CVE-2018-20193 Certain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by Pulse Secure, LLC) allow pri… Secure Access Series Ssl Vpn Sa 4000 No fix yet Fix from $1,9502018-12-21 MEDIUM 5.4 CVE-2018-20306 A stored cross-site scripting (XSS) vulnerability in the web administration user interface of Pulse Secure Virtual Traffic Manager may allow a remote… Virtual Traffic Manager 9.9r2 / 10.4r1+ Fix from $1,6002018-12-20 MEDIUM 5.5 CVE-2018-11002 Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure Permissions. Pulse Secure Desktop Client No fix yet Fix from $1,6002018-11-29 MEDIUM 6.8 CVE-2018-7572 Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can allow attackers to bypass Windo… Pulse Secure Desktop Mitigation only Fix from $1,6002018-09-12 MEDIUM 6.8 CVE-2018-16261 In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust. Pulse Secure Desktop Client Mitigation only Fix from $1,6002018-09-06 HIGH 7.8 CVE-2018-15865 The Pulse Secure Desktop (macOS) has a Privilege Escalation Vulnerability. Pulse Secure Desktop Client No fix yet Fix from $1,9502018-09-06 MEDIUM 5.5 CVE-2018-15749 The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Format String Vulnerability. Pulse Secure Desktop Client Mitigation only Fix from $1,6002018-09-06 MEDIUM 5.3 CVE-2018-15726 The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Privilege Escalation Vulnerability. Pulse Secure Desktop Client No fix yet Fix from $1,6002018-09-06 MEDIUM 5.5 CVE-2018-9849 Pulse Secure Pulse Connect Secure 8.1.x before 8.1R14, 8.2.x before 8.2R11, and 8.3.x before 8.3R5 do not properly process nested XML entities, which… Pulse Connect Secure 8.1r14 / 8.2r11+ Fix from $1,6002018-05-10 MEDIUM 6.5 CVE-2018-6374 The GUI component (aka PulseUI) in Pulse Secure Desktop Linux clients before PULSE5.2R9.2 and 5.3.x before PULSE5.3R4.2 does not perform strict SSL C… Desktop Linux Client 5.2r9.2 / 5.3r4.2+ Fix from $1,6002018-01-31 CRITICAL 9.8 CVE-2018-5299 A stack-based Buffer Overflow Vulnerability exists in the web server in Pulse Secure Pulse Connect Secure (PCS) before 8.3R4 and Pulse Policy Secure … Pulse Connect Secure after 8.3r3 Fix from $2,3002018-01-16 HIGH 7.5 CVE-2017-14935 Pulse Secure Pulse One On-Premise 2.0.1649 and below does not properly validate requests, which allows remote users to query and obtain sensitive inf… Pulse One On Premise Patch available Fix from $1,9502017-09-30 HIGH 8.8 CVE-2017-11193 Pulse Connect Secure 8.3R1 has CSRF in diag.cgi. In the panel, the diag.cgi file is responsible for running commands such as ping, ping6, traceroute,… Pulse Connect Secure Mitigation only Fix from $1,9502017-07-12 HIGH 8.8 CVE-2017-11196 Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF tokens, thus allowing an attac… Pulse Connect Secure Mitigation only Fix from $1,9502017-07-12 MEDIUM 6.1 CVE-2017-11194 Pulse Connect Secure 8.3R1 has Reflected XSS in adminservercacertdetails.cgi. In the admin panel, the certid parameter of adminservercacertdetails.cg… Pulse Connect Secure Mitigation only Fix from $1,6002017-07-12 MEDIUM 6.1 CVE-2017-11195 Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains… Pulse Connect Secure Mitigation only Fix from $1,6002017-07-12