Pulsesecure

    Dashboard / Vendors

    Products: 19
    Vulnerabilities: 93
    Known Exploited: 1
    8
    Critical Level Threats
    45
    High Level Threats
    37
    Medium Level Threats
    3
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2022-21826

    Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length header and leaves the POST body on the TCP/TLS socket. This body ends up prefixing the next HTTP request sent down that connection, this means when someone loads website attacker may be able to make browser issue a POST to the application, enabling XSS.

    Last Modified: Nov 21, 2024
    Published: Sep 30, 2022

    CVE-2021-44720

    In Ivanti Pulse Secure Pulse Connect Secure (PCS) before 9.1R12, the administrator password is stored in the HTML source code of the "Maintenance > Push Configuration > Targets > Target Name" targets.cgi screen. A read-only administrative user can escalate to a read-write administrative role.

    Last Modified: Nov 21, 2024
    Published: Aug 11, 2022

    CVE-2021-22965

    A vulnerability in Pulse Connect Secure before 9.1R12.1 could allow an unauthenticated administrator to causes a denial of service when a malformed request is sent to the device.

    Last Modified: Nov 21, 2024
    Published: Nov 19, 2021

    CVE-2021-22937

    A vulnerability in Pulse Connect Secure before 9.1R12 could allow an authenticated administrator to perform a file write via a maliciously crafted archive uploaded in the administrator web interface.

    Last Modified: Nov 21, 2024
    Published: Aug 16, 2021

    CVE-2021-22936

    A vulnerability in Pulse Connect Secure before 9.1R12 could allow a threat actor to perform a cross-site script attack against an authenticated administrator via an unsanitized web parameter.

    Last Modified: Nov 21, 2024
    Published: Aug 16, 2021
    Items Per Page
    Pulsesecure Vulnerabilities & Security CVEs | CVE-DB