Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

210 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)2.3%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated attacker via the administrator web interface to perform an arbitrary file reading vulnerability through Meeting.
ModificadaMedia (4.9)2.3%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbitrary files via the administrator web interface.
ModificadaMedia (6.5)2.5%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the administrator web which can cause DOS.
ModificadaAlta (7.2)2.2%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full administrator.
AnalizadaAlta (7.2)32%⚠ Explotación activa💥 PoCIvanti Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
ModificadaMedia (5.4)1.4%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used for Citrix ICA.
ModificadaMedia (4.3)2.3%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to find meeting details, if they know the Meeting ID.
ModificadaAlta (8.1)3.0%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP.
ModificadaMedia (6.1)1.8%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page.
ModificadaMedia (4.6)0.77%—Pulsesecure Pulse Connect SecurePulsesecure Pulse Secure Desktop Client28/7/202017/6/2026
An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite.
ModificadaMedia (5.5)0.48%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure27/7/202017/6/2026
An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved.…
ModificadaAlta (7)0.79%💥 PoCPulsesecure Pulse Secure Desktop ClientPulsesecure Pulse Secure Installer Service16/6/202017/6/2026
A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT AUTHORITY/SYSTEM) allows unprivileged users to run a Microsoft Installer executable with elevated privileges.
ModificadaBaja (3.3)0.33%—PulseaudioCanonical Ubuntu Linux15/5/202017/6/2026
—
ModificadaAlta (8.8)0.88%—Pulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure6/4/202017/6/2026
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, launches a TCP server that accepts local connections on a random port. This can be reached by local HTTP clients, because…
ModificadaAlta (8.1)9.8%—Pulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure6/4/202017/6/2026
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-middle attacker to perform OS command injection attacks (against a client) via shell metacharacters to…
ModificadaCrítica (9.1)1.1%—Pulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure6/4/202017/6/2026
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate.
ModificadaAlta (8.8)5.6%💥 ExploitImpulseadventure Jpegsnoop6/2/202016/6/2026
A vulnerability exists in JPEGsnoop 1.5.2 due to an unspecified issue in JPEG file handling, which could let a malicious user execute arbitrary code
ModificadaMedia (6.5)0.19%—Philips Veradius Unity FirmwarePhilips Pulsera FirmwarePhilips Endura Firmware20/12/201917/6/2026
An issue was found in Philips Veradius Unity, Pulsera, and Endura Dual WAN Router, Veradius Unity (718132) with wireless option (shipped between 2016-August 2018), Veradius Unity (718132) with ViewForum option (shipped between 2016-August 2018), Pulsera (718095) and Endura (718075) with wireless option (shipped…
ModificadaMedia (6.1)0.65%—Ideagen Q-pulse22/11/201917/6/2026
Cross-site scripting (XSS) vulnerability in ui/common/managedlistdialog.aspx in Gael Q-Pulse 0.6 and earlier.
ModificadaMedia (6.1)1.6%—Ivanti Connect SecurePulsesecure Pulse Policy Secure28/6/201917/6/2026
An XSS issue was found with Psaldownload.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.3R2 before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX or PPS 5.2RX.
ModificadaAlta (7.5)1.1%—Pulsesecure Pulse Secure Desktop Client28/6/201917/6/2026
An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below. This is applicable only to dual-stack (IPv4/IPv6) endpoints.
ModificadaCrítica (9.8)1.8%—Ivanti Connect SecurePulsesecure Pulse Policy Secure28/6/201917/6/2026
Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices.
ModificadaAlta (7.5)2.7%—Ivanti Connect SecurePulsesecure Pulse Policy Secure28/6/201917/6/2026
A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and Pulse Policy Secure 5.4RX before 5.4R5. This is not applicable to PCS 8.1RX.
ModificadaAlta (7.5)95%—Linux KernelF5 Big-ip Advanced Firewall ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Application Acceleration Manager+2019/6/201917/6/2026
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182,…
ModificadaAlta (7.5)99%💥 PoCLinux KernelF5 Big-ip Advanced Firewall ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Application Acceleration Manager+2019/6/201917/6/2026
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127,…