CVE Tools

Pulsesecure

59 CVEs tracked since 2016. Since Mar 2016, 5 of them reached CISA KEV.

Pulsesecure CVEs per month

Mar 2016 to Aug 2021. Point at a month, or focus the strip and use the arrow keys.
Pulsesecure CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2016-0320
2016-0410
2016-0560
2016-06null or fewer
2016-07null or fewer
2016-08null or fewer
2016-09null or fewer
2016-10null or fewer
2016-11null or fewer
2016-12null or fewer
2017-01null or fewer
2017-02null or fewer
2017-03null or fewer
2017-04null or fewer
2017-05null or fewer
2017-06null or fewer
2017-0740
2017-08null or fewer
2017-09null or fewer
2017-10null or fewer
2017-11null or fewer
2017-12null or fewer
2018-0130
2018-02null or fewer
2018-03null or fewer
2018-04null or fewer
2018-05null or fewer
2018-06null or fewer
2018-07null or fewer
2018-0830
2018-0980
2018-10null or fewer
2018-11null or fewer
2018-1230
2019-01null or fewer
2019-02null or fewer
2019-03null or fewer
2019-04null or fewer
2019-0521
2019-06null or fewer
2019-07null or fewer
2019-08null or fewer
2019-09null or fewer
2019-10null or fewer
2019-11null or fewer
2019-12null or fewer
2020-01null or fewer
2020-02null or fewer
2020-03null or fewer
2020-04null or fewer
2020-05null or fewer
2020-06null or fewer
2020-07null or fewer
2020-08null or fewer
2020-0931
2020-10141
2020-11null or fewer
2020-12null or fewer
2021-01null or fewer
2021-02null or fewer
2021-03null or fewer
2021-04null or fewer
2021-0542
2021-06null or fewer
2021-07null or fewer
2021-0860

Products

The products that kept showing up in Pulsesecure's monthly top three, with their CVEs summed over those months.

  1. Pulse Connect Secure3711 months
  2. Pulse Secure Desktop Client142 months
  3. Pulse Policy Secure94 months
  4. Virtual Traffic Manager32 months
  5. Client21 month
  6. Steel Belted Radius21 month
  7. Desktop Linux Client11 month
  8. Secure Access Series SSL VPN Sa-400011 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Pulsesecure.

  1. CVE-2022-21826Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leave...5.4
  2. CVE-2021-44720In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targe...7.2
  3. CVE-2021-22965A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device.7.5
  4. CVE-2021-22937A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface.7.2
  5. CVE-2021-22936A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter.6.1
  6. CVE-2021-22935A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter.7.2
  7. CVE-2021-22934A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or compromised Pulse Connect Secure device in a load-balanced configuration to perform a buffer over...7.2
  8. CVE-2021-22938A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter in the administrator web console.7.2
  9. CVE-2021-22933A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request.6.5
  10. CVE-2021-22900A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted arc...7.2
  11. CVE-2021-22899A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature8.8
  12. CVE-2021-22894A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.8.8
  13. CVE-2021-22908A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. A...8.8
  14. CVE-2021-31922An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolv...7.5
  15. CVE-2021-22893Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connec...10.0

The record

Peak rank
#38 in Oct 2020
Busiest month shown
Oct 2020, 14 CVEs
Months with a KEV entry
4 since Mar 2016
Monthly snapshots
13 since 2016
Pulsesecure's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store