Vulnerabilities > Pulsesecure > High

DATE CVE VULNERABILITY TITLE RISK
2021-05-14 CVE-2021-31922 HTTP Request Smuggling vulnerability in Pulsesecure Virtual Traffic Manager
An HTTP Request Smuggling vulnerability in Pulse Secure Virtual Traffic Manager before 21.1 could allow an attacker to smuggle an HTTP request through an HTTP/2 Header.
network
low complexity
pulsesecure CWE-444
7.5
2020-10-28 CVE-2020-8260 Unrestricted Upload of File with Dangerous Type vulnerability in Pulsesecure Pulse Secure Desktop Client 9.1
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.
network
low complexity
pulsesecure CWE-434
7.2
2020-10-28 CVE-2020-8254 Path Traversal vulnerability in Pulsesecure Pulse Secure Desktop Client
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 has Remote Code Execution (RCE) if users can be convinced to connect to a malicious server.
network
low complexity
pulsesecure CWE-22
8.8
2020-10-28 CVE-2020-8250 Unspecified vulnerability in Pulsesecure Pulse Secure Desktop Client 9.1
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.
local
low complexity
pulsesecure
7.8
2020-10-28 CVE-2020-8249 Classic Buffer Overflow vulnerability in Pulsesecure Pulse Secure Desktop Client 9.1
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to perform buffer overflow.
local
low complexity
pulsesecure CWE-120
7.8
2020-10-28 CVE-2020-8248 Unspecified vulnerability in Pulsesecure Pulse Secure Desktop Client 9.1
A vulnerability in the Pulse Secure Desktop Client (Linux) < 9.1R9 could allow local attackers to escalate privilege.
local
low complexity
pulsesecure
7.8
2020-10-28 CVE-2020-8241 Unspecified vulnerability in Pulsesecure Pulse Secure Desktop Client 9.1
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 could allow the attacker to perform a MITM Attack if end users are convinced to connect to a malicious server.
network
high complexity
pulsesecure
7.5
2020-10-28 CVE-2020-8240 Unspecified vulnerability in Pulsesecure Pulse Secure Desktop Client
A vulnerability in the Pulse Secure Desktop Client < 9.1R9 allows a restricted user on an endpoint machine can use system-level privileges if the Embedded Browser is configured with Credential Provider.
local
low complexity
pulsesecure
7.8
2020-10-27 CVE-2020-15352 XXE vulnerability in multiple products
An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
network
low complexity
pulsesecure ivanti CWE-611
7.2
2020-09-30 CVE-2020-8243 Code Injection vulnerability in multiple products
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
network
low complexity
pulsesecure ivanti CWE-94
7.2