Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

210 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)7.7%—Ivanti Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure3/6/201917/6/2026
In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4 and Pulse Policy Secure (PPS) before 5.1R15.1, 5.2 before 5.2R12.1, 5.3 before 5.3R15.1, 5.4 before 5.4R7.1, and 9.0 before 9.0R3.2, an authenticated attacker (via the admin web interface) can…
ModificadaAlta (7.2)15%—Ivanti Connect SecurePulsesecure Pulse Connect Secure8/5/201917/6/2026
In Pulse Secure Pulse Connect Secure (PCS) before 8.1R15.1, 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an authenticated attacker (via the admin web interface) can exploit Directory Traversal to execute arbitrary code on the appliance.
ModificadaMedia (6.1)3.1%—Ivanti Connect SecurePulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure26/4/201917/6/2026
XSS exists in the admin web console in Pulse Secure Pulse Connect Secure (PCS) 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, and 5.2RX before 5.2R12.1.
ModificadaAlta (7.2)66%—Ivanti Connect SecurePulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure26/4/201917/6/2026
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, an authenticated attacker (via…
ModificadaAlta (7.5)4.0%—Ivanti Connect SecurePulsesecure Pulse Connect Secure26/4/201917/6/2026
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, and 8.2RX before 8.2R12.1, users using SAML authentication with the Reuse Existing NC (Pulse) Session option may see authentication leaks.
ModificadaCrítica (9.8)7.7%—Ivanti Connect SecurePulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure26/4/201917/6/2026
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthenticated, remote attacker can conduct a session hijacking attack.
AnalizadaAlta (7.2)99%⚠ Explotación activa💥 ExploitIvanti Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure26/4/201917/6/2026
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows…
ModificadaAlta (8.1)2.8%—Ivanti Connect SecurePulsesecure Pulse Connect SecurePulsesecure Pulse Secure Desktop Client12/4/201917/6/2026
In Pulse Secure Pulse Desktop Client and Network Connect, an attacker could access session tokens to replay and spoof sessions, and as a result, gain unauthorized access as an end user, a related issue to CVE-2019-1573. (The endpoint would need to be already compromised for exploitation to succeed.) This affects Pulse…
ModificadaAlta (8.8)1.3%—Pulsesecure Secure Access Series SSL VPN Sa-400021/12/201817/6/2026
Certain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by Pulse Secure, LLC) allow privilege escalation, as demonstrated by Secure Access SSL VPN SA-4000 5.1R5 (build 9627) 4.2 Release (build 7631). This occurs because appropriate controls are not…
ModificadaMedia (4.3)0.83%—Pulsesecure Virtual Traffic Manager20/12/201817/6/2026
Pulse Secure Virtual Traffic Manager 9.9 versions prior to 9.9r2 and 10.4r1 allow a remote authenticated user to obtain sensitive historical activity information by leveraging incorrect permission validation.
ModificadaMedia (5.4)0.54%—Pulsesecure Virtual Traffic Manager20/12/201817/6/2026
A stored cross-site scripting (XSS) vulnerability in the web administration user interface of Pulse Secure Virtual Traffic Manager may allow a remote authenticated attacker to inject web script or HTML via a crafted website and steal sensitive data and credentials. Affected releases are Pulse Secure Virtual Traffic…
ModificadaMedia (5.5)0.90%—Pulsesecure Pulse Secure Desktop Client29/11/201817/6/2026
Pulse Secure Desktop Client 5.3 up to and including R6.0 build 1769 on Windows has Insecure Permissions.
ModificadaAlta (8.6)16%—Artifex GhostscriptDebian LinuxCanonical Ubuntu LinuxArtifex GPL Ghostscript+719/10/201817/6/2026
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.
ModificadaMedia (6.8)0.36%—Pulsesecure Pulse Secure Desktop12/9/201817/6/2026
Pulse Secure Client 9.0R1 and 5.3RX before 5.3R5, when configured to authenticate VPN users during Windows Logon, can allow attackers to bypass Windows authentication and execute commands on the system with the privileges of Pulse Secure Client. The attacker must interrupt the client's network connectivity, and…
ModificadaCrítica (9.8)4.1%—Ivanti Connect SecurePulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure6/9/201817/6/2026
A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an http(s) Host header received from the browser is trusted without validation.
ModificadaMedia (6.8)0.20%—Pulsesecure Pulse Secure Desktop Client6/9/201817/6/2026
In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust.
ModificadaAlta (7.8)0.32%—Pulsesecure Pulse Secure Desktop Client6/9/201817/6/2026
The Pulse Secure Desktop (macOS) has a Privilege Escalation Vulnerability.
ModificadaMedia (5.5)0.32%—Pulsesecure Pulse Secure Desktop Client6/9/201817/6/2026
The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Format String Vulnerability.
ModificadaMedia (5.3)0.33%—Pulsesecure Pulse Secure Desktop Client6/9/201817/6/2026
The Pulse Secure Desktop (macOS) 5.3RX before 5.3R5 and 9.0R1 has a Privilege Escalation Vulnerability.
ModificadaMedia (6.1)1.5%—Ivanti Connect SecurePulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure6/9/201817/6/2026
download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.
ModificadaAlta (7.8)1.5%—Artifex GhostscriptCanonical Ubuntu LinuxDebian LinuxArtifex GPL Ghostscript+15/9/201817/6/2026
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the setcolor function to crash the interpreter or possibly have unspecified other impact.
ModificadaAlta (7.8)3.0%—Debian LinuxCanonical Ubuntu LinuxArtifex GhostscriptArtifex GPL Ghostscript+728/8/201817/6/2026
In Artifex Ghostscript 9.23 before 2018-08-24, attackers able to supply crafted PostScript could use uninitialized memory access in the aesdecode operator to crash the interpreter or potentially execute code.
ModificadaAlta (7.8)3.0%—Debian LinuxCanonical Ubuntu LinuxArtifex GhostscriptRedhat Enterprise Linux Desktop+527/8/201817/6/2026
In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use a type confusion in the LockDistillerParams parameter to crash the interpreter or execute code.
ModificadaAlta (7.8)3.0%—Debian LinuxCanonical Ubuntu LinuxArtifex GhostscriptArtifex GPL Ghostscript+727/8/201817/6/2026
In Artifex Ghostscript 9.23 before 2018-08-24, a type confusion using the .shfill operator could be used by attackers able to supply crafted PostScript files to crash the interpreter or potentially execute code.
ModificadaAlta (8.1)2.6%—GE MDS Pulsenet4/6/201817/6/2026
Directory traversal may lead to files being exfiltrated or deleted on the GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior host platform.
Orbitaley — Vulnerabilidades