Pulse Secure Known Exploited Vulnerabilities
Evidence-backed KEV intelligence for Pulse Secure products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.
Total KEVs
9
In CISA KEV
9
Beyond CISA KEV
0
Sensor Observed
0
Virtual Patch Available
0
Pulse Secure KEVs Added by Year
9 Pulse Secure KEVs added all time (primary attestation date).
Attested CVEs
| CVE | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2019-11539
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse... |
Pulse Connect Secure | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2019-11510
In Pulse Secure Pulse Connect Secure (PCS) 8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4, an unauthenticated remote attacker can... |
Pulse Connect Secure | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-22899
A command injection vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to perform remote code... |
Pulse Connect Secure | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-8260
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code... |
Pulse Connect Secure / Pulse Policy Secure | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-22894
A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as... |
Pulse Connect Secure | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-22900
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to... |
Pulse Secure Secure | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-8243
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to... |
Pulse Connect Secre | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2021-22893
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and... |
Pulse Connect Secure | Confirmed | In CISA | 03 Nov 2021 |
|
CVE-2020-8218
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code... |
Pulse Connect Secure | Confirmed | In CISA | 07 Mar 2022 |
Common Vulnerability Classes (CWE)
- CWE-94 — Improper Control of Generation of Code ('Code Injection') 4
- CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') 1
- CWE-287 — Improper Authentication 1
- CWE-434 — Unrestricted Upload of File with Dangerous Type 1
- CWE-77 — Improper Neutralization of Special Elements used in a Command ('Command Injection') 1
- CWE-78 — Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') 1
Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology