Vulnerabilities > Ivanti > Connect Secure > 7.1

DATE CVE VULNERABILITY TITLE RISK
2020-10-28 CVE-2020-8260 Unrestricted Upload of File with Dangerous Type vulnerability in Ivanti Connect Secure
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.
network
low complexity
ivanti CWE-434
7.2
2020-09-30 CVE-2020-8243 Code Injection vulnerability in Ivanti Connect Secure and Policy Secure
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
network
low complexity
ivanti CWE-94
7.2
2020-07-30 CVE-2020-8218 Code Injection vulnerability in multiple products
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
network
low complexity
ivanti pulsesecure CWE-94
7.2
2019-05-08 CVE-2019-11508 Path Traversal vulnerability in multiple products
In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) can exploit Directory Traversal to execute arbitrary code on the appliance.
network
low complexity
pulsesecure ivanti CWE-22
7.2