CVE-2020-8256
- EPSS 2.71%
- Published 30.09.2020 18:15:29
- Last modified 21.11.2024 05:38:36
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.
CVE-2020-8238
- EPSS 0.17%
- Published 30.09.2020 18:15:28
- Last modified 21.11.2024 05:38:34
A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Scripting (XSS).
CVE-2020-8221
- EPSS 2.86%
- Published 30.07.2020 13:15:12
- Last modified 21.11.2024 05:38:31
A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbitrary files via the administrator web interface.
CVE-2020-8222
- EPSS 0.86%
- Published 30.07.2020 13:15:12
- Last modified 21.11.2024 05:38:32
A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated attacker via the administrator web interface to perform an arbitrary file reading vulnerability through Meeting.
CVE-2020-8204
- EPSS 0.17%
- Published 30.07.2020 13:15:11
- Last modified 21.11.2024 05:38:29
A cross site scripting (XSS) vulnerability exists in Pulse Connect Secure <9.1R5 on the PSAL Page.
CVE-2020-8206
- EPSS 1.52%
- Published 30.07.2020 13:15:11
- Last modified 21.11.2024 05:38:30
An improper authentication vulnerability exists in Pulse Connect Secure <9.1RB that allows an attacker with a users primary credentials to bypass the Google TOTP.
CVE-2020-8216
- EPSS 2.17%
- Published 30.07.2020 13:15:11
- Last modified 21.11.2024 05:38:31
An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to find meeting details, if they know the Meeting ID.
CVE-2020-8217
- EPSS 0.14%
- Published 30.07.2020 13:15:11
- Last modified 21.11.2024 05:38:31
A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used for Citrix ICA.
CVE-2020-8218
- EPSS 91.07%
- Published 30.07.2020 13:15:11
- Last modified 30.07.2025 18:59:52
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
CVE-2020-8219
- EPSS 1.73%
- Published 30.07.2020 13:15:11
- Last modified 21.11.2024 05:38:31
An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full administrator.