Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
222 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 3.0% | — | Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure | 30/7/2020 | 17/6/2026 | An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP. | |
| Modificada | Media (6.1) | 1.8% | — | Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure | 30/7/2020 | 17/6/2026 | A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page. | |
| Modificada | Media (4.6) | 0.77% | — | Pulsesecure Pulse Connect SecurePulsesecure Pulse Secure Desktop Client | 28/7/2020 | 17/6/2026 | An issue was discovered in Pulse Secure Pulse Connect Secure before 9.1R8. An authenticated attacker can access the admin page console via the end-user web interface because of a rewrite. | |
| Modificada | Media (5.5) | 0.48% | — | Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure | 27/7/2020 | 17/6/2026 | An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved.… | |
| Modificada | Alta (8.8) | 0.88% | — | Pulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure | 6/4/2020 | 17/6/2026 | An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, launches a TCP server that accepts local connections on a random port. This can be reached by local HTTP clients, because… | |
| Modificada | Alta (8.1) | 9.8% | — | Pulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure | 6/4/2020 | 17/6/2026 | An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-middle attacker to perform OS command injection attacks (against a client) via shell metacharacters to… | |
| Modificada | Crítica (9.1) | 1.1% | — | Pulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure | 6/4/2020 | 17/6/2026 | An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate. | |
| Analizada | Media (6.5) | 28% | ⚠ Explotación activa💥 Exploit | Cisco Anyconnect Secure Mobility Client | 19/2/2020 | 12/8/2026 | A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could… | |
| Modificada | Media (6.1) | 1.6% | — | Ivanti Connect SecurePulsesecure Pulse Policy Secure | 28/6/2019 | 17/6/2026 | An XSS issue was found with Psaldownload.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.3R2 before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX or PPS 5.2RX. | |
| Modificada | Crítica (9.8) | 3.1% | — | Ivanti Connect Secure | 28/6/2019 | 17/6/2026 | An input validation issue has been found with login_meeting.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2. | |
| Modificada | Media (5.3) | 2.1% | — | Ivanti Connect Secure | 28/6/2019 | 17/6/2026 | A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12. | |
| Modificada | Crítica (9.8) | 1.8% | — | Ivanti Connect SecurePulsesecure Pulse Policy Secure | 28/6/2019 | 17/6/2026 | Session data between cluster nodes during cluster synchronization is not properly encrypted in Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.4RX before 5.4R2. This is not applicable to PCS 8.1RX, PPS 5.2RX, or stand-alone devices. | |
| Modificada | Alta (7.5) | 2.7% | — | Ivanti Connect SecurePulsesecure Pulse Policy Secure | 28/6/2019 | 17/6/2026 | A crafted message can cause the web server to crash with Pulse Secure Pulse Connect Secure (PCS) 8.3RX before 8.3R5 and Pulse Policy Secure 5.4RX before 5.4R5. This is not applicable to PCS 8.1RX. | |
| Modificada | Media (6.1) | 1.6% | — | Ivanti Connect Secure | 28/6/2019 | 17/6/2026 | An XSS issue has been found with rd.cgi in Pulse Secure Pulse Connect Secure 8.3RX before 8.3R3 due to improper header sanitization. This is not applicable to 8.1RX. | |
| Modificada | Media (6.1) | 1.6% | — | Ivanti Connect Secure | 28/6/2019 | 17/6/2026 | An XSS issue has been found in welcome.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1.x before 8.1R12, 8.2.x before 8.2R9, and 8.3.x before 8.3R3 due to one of the URL parameters not being sanitized properly. | |
| Modificada | Alta (7.5) | 95% | — | Linux KernelF5 Big-ip Advanced Firewall ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Application Acceleration Manager+20 | 19/6/2019 | 17/6/2026 | Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgment (SACK) sequences. A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182,… | |
| Modificada | Alta (7.5) | 99% | 💥 PoC | Linux KernelF5 Big-ip Advanced Firewall ManagerF5 Big-ip Access Policy ManagerF5 Big-ip Application Acceleration Manager+20 | 19/6/2019 | 17/6/2026 | Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs). A remote attacker could use this to cause a denial of service. This has been fixed in stable kernel releases 4.4.182, 4.9.182, 4.14.127,… | |
| Modificada | Alta (8.8) | 7.7% | — | Ivanti Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure | 3/6/2019 | 17/6/2026 | In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policy Secure (PPS) before 5.1R15.1, 5.2 before 5.2R12.1, 5.3 before 5.3R15.1, 5.4 before 5.4R7.1, and 9.0 before 9.0R3.2, an authenticated attacker (via the admin web interface) can… | |
| Modificada | Alta (7.5) | 1.6% | — | Cisco Anyconnect Secure Mobility Client | 16/5/2019 | 17/6/2026 | A vulnerability in the HostScan component of Cisco AnyConnect Secure Mobility Client for Linux could allow an unauthenticated, remote attacker to read sensitive information on an affected system. The vulnerability exists because the affected software performs improper bounds checks. An attacker could exploit this… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Connect Secure | 8/5/2019 | 17/6/2026 | In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can send a specially crafted URI to perform an arbitrary file reading vulnerability . | |
| Modificada | Alta (7.2) | 15% | — | Ivanti Connect SecurePulsesecure Pulse Connect Secure | 8/5/2019 | 17/6/2026 | In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) can exploit Directory Traversal to execute arbitrary code on the appliance. | |
| Modificada | Media (6.1) | 4.1% | 💥 Exploit | Ivanti Connect Secure | 8/5/2019 | 17/6/2026 | In Pulse Secure Pulse Connect Secure (PCS) 8.3.x before 8.3R7.1 and 9.0.x before 9.0R3, an XSS issue has been found on the Application Launcher page. | |
| Modificada | Media (6.1) | 3.1% | — | Ivanti Connect SecurePulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure | 26/4/2019 | 17/6/2026 | XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, and 5.2RX before 5.2R12.1. | |
| Modificada | Alta (7.2) | 66% | — | Ivanti Connect SecurePulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure | 26/4/2019 | 17/6/2026 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via… | |
| Modificada | Alta (7.5) | 4.0% | — | Ivanti Connect SecurePulsesecure Pulse Connect Secure | 26/4/2019 | 17/6/2026 | In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks. |