CVEInsight.
TrendingZero-DayExploreBrowseSearchSaved
CVEInsight.

Free vulnerability intelligence for developers, security teams, and researchers. Data sourced from public databases for informational purposes only.

Explore

HomeTrendingZero-Day WatchAttack TypesBrowse CVEsSearch

Legal

Privacy PolicyTerms of ServiceData Disclaimer

© 2026CVEInsight. For informational use only — not a substitute for professional security advice.

CVE data sourced from NVD / NIST & public disclosures.

Search Vulnerabilities

 Software

Searching vulnerabilities affecting “pulsesecure”

77 vulnerabilities found for “pulsesecure”

Page 1 of 4

CVE-2020-8261
MEDIUM4.3

A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection.

ivanti / connect_secure+17
Network
Published Oct 28, 2020
Page 1 of 4
CVE-2020-8262
MEDIUM6.1

A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface.

ivanti / connect_secure+17
Network
Published Oct 28, 2020
CVE-2020-15352
HIGH7.2

An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

ivanti / connect_secure+26
Network
Published Oct 27, 2020
CVE-2020-8238
MEDIUM6.1

A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Scripting (XSS).

ivanti / connect_secure+27
Network
Published Sep 30, 2020
CVE-2020-8222
MEDIUM6.8

A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated attacker via the administrator web interface to perform an arbitrary file reading vulnerability through Meeting.

ivanti / connect_secure+23
Network
Published Jul 30, 2020
CVE-2020-8218
HIGH7.2

A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.

ivanti / connect_secure+23
Network
Published Jul 30, 2020
CVE-2020-8217
MEDIUM5.4

A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used for Citrix ICA.

ivanti / connect_secure+23
Network
Published Jul 30, 2020
CVE-2020-8206
HIGH8.1

An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP.

ivanti / connect_secure+23
Network
Published Jul 30, 2020
CVE-2020-8219
HIGH7.2

An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full administrator.

ivanti / connect_secure+23
Network
Published Jul 30, 2020
CVE-2020-8221
MEDIUM4.9

A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbitrary files via the administrator web interface.

ivanti / connect_secure+23
Network
Published Jul 30, 2020
CVE-2020-8204
MEDIUM6.1

A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page.

ivanti / connect_secure+23
Network
Published Jul 30, 2020
CVE-2020-8216
MEDIUM4.3

An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to find meeting details, if they know the Meeting ID.

ivanti / connect_secure+23
Network
Published Jul 30, 2020
CVE-2020-8220
MEDIUM6.5

A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the administrator web which can cause DOS.

ivanti / connect_secure+23
Network
Published Jul 30, 2020
CVE-2020-12880
MEDIUM5.5

An issue was discovered in Pulse Policy Secure (PPS) and Pulse Connect Secure (PCS) Virtual Appliance before 9.1R8. By manipulating a certain kernel boot parameter, it can be tricked into dropping into a root shell in a pre-install phase where the entire source code of the appliance is available and can be retrieved. (The source code is otherwise inaccessible because the appliance has its hard disks encrypted, and no root shell is available during normal operation.)

ivanti / connect_secure+22
Local
Published Jul 27, 2020
CVE-2020-13162
HIGH7.0

A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT AUTHORITY/SYSTEM) allows unprivileged users to run a Microsoft Installer executable with elevated privileges.

pulsesecure / pulse_secure_desktop_client+31
Local
Published Jun 16, 2020
CVE-2019-11539
HIGH7.2

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2, 5.4RX before 5.4R7.1, 5.3RX before 5.3R12.1, 5.2RX before 5.2R12.1, and 5.1RX before 5.1R15.1, the admin web interface allows an authenticated attacker to inject and execute commands.

ivanti / connect_secure+137
Network
Published Apr 26, 2019
CVE-2019-11540
CRITICAL9.8

In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4 and 8.3RX before 8.3R7.1 and Pulse Policy Secure version 9.0RX before 9.0R3.2 and 5.4RX before 5.4R7.1, an unauthenticated, remote attacker can conduct a session hijacking attack.

ivanti / connect_secure+25
Network
Published Apr 26, 2019
CVE-2018-6320
CRITICAL9.8

A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an http(s) Host header received from the browser is trusted without validation.

ivanti / connect_secure+17
Network
Published Sep 6, 2018
CVE-2018-14366
MEDIUM6.1

download.cgi in Pulse Secure Pulse Connect Secure 8.1RX before 8.1R13 and 8.3RX before 8.3R4 and Pulse Policy Secure through 5.2RX before 5.2R10 and 5.4RX before 5.4R4 have an Open Redirect Vulnerability.

ivanti / connect_secure+22
Network
Published Sep 6, 2018
CVE-2018-5299
CRITICAL9.8

A stack-based Buffer Overflow Vulnerability exists in the web server in Pulse Secure Pulse Connect Secure (PCS) before 8.3R4 and Pulse Policy Secure (PPS) before 5.4R4, leading to memory corruption and possibly remote code execution.

pulsesecure / pulse_connect_secure+1
Network
Published Jan 16, 2018