Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 8.3% | — | Ivanti Connect SecurePulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure | 26/4/2019 | 17/6/2026 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthenticated, remote attacker can conduct a session hijacking attack. | |
| Analizada | Alta (7.2) | 99% | ⚠ Explotación activa💥 Exploit | Ivanti Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure | 26/4/2019 | 17/6/2026 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows… | |
| Modificada | Crítica (9.8) | 4.1% | — | Ivanti Connect SecurePulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure | 6/9/2018 | 17/6/2026 | A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an http(s) Host header received from the browser is trusted without validation. | |
| Modificada | Media (6.1) | 1.5% | — | Ivanti Connect SecurePulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure | 6/9/2018 | 17/6/2026 | download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability. | |
| Modificada | Crítica (9.8) | 3.1% | — | Pulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure | 16/1/2018 | 17/6/2026 | A stack-based Buffer Overflow Vulnerability exists in the web server in Pulse Secure Pulse Connect Secure (PCS) before 8.3R4 and Pulse Policy Secure (PPS) before 5.4R4, leading to memory corruption and possibly remote code execution. | |
| Modificada | Alta (8.8) | 1.3% | — | Ivanti Connect SecurePulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure | 29/8/2017 | 17/6/2026 | diag.cgi in Pulse Connect Secure 8.2R1 through 8.2R5, 8.1R1 through 8.1R10 and Pulse Policy Secure 5.3R1 through 5.3R5, 5.2R1 through 5.2R8, and 5.1R1 through 5.1R10 allow remote attackers to hijack the authentication of administrators for requests to start tcpdump, related to the lack of anti-CSRF tokens. |