Vulnerabilities > Purevpn

DATE CVE VULNERABILITY TITLE RISK
2024-08-25 CVE-2023-48957 Unspecified vulnerability in Purevpn 2.0.2
PureVPN Linux client 2.0.2-Productions fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and be sent directly to the ISP or default DNS servers.
network
low complexity
purevpn
5.3
2018-10-26 CVE-2018-18656 Insufficiently Protected Credentials vulnerability in Purevpn
The PureVPN client before 6.1.0 for Windows stores Login Credentials (username and password) in cleartext.
local
low complexity
purevpn CWE-522
7.8
2018-04-18 CVE-2018-10204 Incorrect Permission Assignment for Critical Resource vulnerability in Purevpn 6.0.1
PureVPN 6.0.1 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "sevpnclient" service.
network
low complexity
purevpn CWE-732
8.8
2018-02-26 CVE-2018-7484 Untrusted Search Path vulnerability in Purevpn 5.19.4.0
An issue was discovered in PureVPN through 5.19.4.0 on Windows.
local
low complexity
purevpn CWE-426
7.8
2018-02-07 CVE-2018-6822 Unspecified vulnerability in Purevpn
In PureVPN 6.0.1 on macOS, HelperTool LaunchDaemon implements an unprotected XPC service that can be abused to execute system commands as root.
network
low complexity
purevpn
critical
9.8