Pulsesecure
59 CVEs tracked since 2016. Since Mar 2016, 5 of them reached CISA KEV.
Pulsesecure CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2016-03 | 2 | 0 |
| 2016-04 | 1 | 0 |
| 2016-05 | 6 | 0 |
| 2016-06 | null or fewer | |
| 2016-07 | null or fewer | |
| 2016-08 | null or fewer | |
| 2016-09 | null or fewer | |
| 2016-10 | null or fewer | |
| 2016-11 | null or fewer | |
| 2016-12 | null or fewer | |
| 2017-01 | null or fewer | |
| 2017-02 | null or fewer | |
| 2017-03 | null or fewer | |
| 2017-04 | null or fewer | |
| 2017-05 | null or fewer | |
| 2017-06 | null or fewer | |
| 2017-07 | 4 | 0 |
| 2017-08 | null or fewer | |
| 2017-09 | null or fewer | |
| 2017-10 | null or fewer | |
| 2017-11 | null or fewer | |
| 2017-12 | null or fewer | |
| 2018-01 | 3 | 0 |
| 2018-02 | null or fewer | |
| 2018-03 | null or fewer | |
| 2018-04 | null or fewer | |
| 2018-05 | null or fewer | |
| 2018-06 | null or fewer | |
| 2018-07 | null or fewer | |
| 2018-08 | 3 | 0 |
| 2018-09 | 8 | 0 |
| 2018-10 | null or fewer | |
| 2018-11 | null or fewer | |
| 2018-12 | 3 | 0 |
| 2019-01 | null or fewer | |
| 2019-02 | null or fewer | |
| 2019-03 | null or fewer | |
| 2019-04 | null or fewer | |
| 2019-05 | 2 | 1 |
| 2019-06 | null or fewer | |
| 2019-07 | null or fewer | |
| 2019-08 | null or fewer | |
| 2019-09 | null or fewer | |
| 2019-10 | null or fewer | |
| 2019-11 | null or fewer | |
| 2019-12 | null or fewer | |
| 2020-01 | null or fewer | |
| 2020-02 | null or fewer | |
| 2020-03 | null or fewer | |
| 2020-04 | null or fewer | |
| 2020-05 | null or fewer | |
| 2020-06 | null or fewer | |
| 2020-07 | null or fewer | |
| 2020-08 | null or fewer | |
| 2020-09 | 3 | 1 |
| 2020-10 | 14 | 1 |
| 2020-11 | null or fewer | |
| 2020-12 | null or fewer | |
| 2021-01 | null or fewer | |
| 2021-02 | null or fewer | |
| 2021-03 | null or fewer | |
| 2021-04 | null or fewer | |
| 2021-05 | 4 | 2 |
| 2021-06 | null or fewer | |
| 2021-07 | null or fewer | |
| 2021-08 | 6 | 0 |
Products
The products that kept showing up in Pulsesecure's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Pulsesecure.
- CVE-2022-21826Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leave...5.4
- CVE-2021-44720In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targe...7.2
- CVE-2021-22965A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device.7.5
- CVE-2021-22937A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface.7.2
- CVE-2021-22936A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter.6.1
- CVE-2021-22935A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter.7.2
- CVE-2021-22934A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator or compromised Pulse Connect Secure device in a load-balanced configuration to perform a buffer over...7.2
- CVE-2021-22938A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform command injection via an unsanitized web parameter in the administrator web console.7.2
- CVE-2021-22933A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform an arbitrary file delete via a maliciously crafted web request.6.5
- CVE-2021-22900A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted arc...7.2
- CVE-2021-22899A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code execution via Windows Resource Profiles Feature8.8
- CVE-2021-22894A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.8.8
- CVE-2021-22908A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. A...8.8
- CVE-2021-31922An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header. This vulnerability is resolv...7.5
- CVE-2021-22893Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connec...10.0
The record
- Peak rank
- #38 in Oct 2020
- Busiest month shown
- Oct 2020, 14 CVEs
- Months with a KEV entry
- 4 since Mar 2016
- Monthly snapshots
- 13 since 2016