Known vulnerabilities in Ivanti Policy Secure (formerly Pulse Policy Secure) - page 2

Vendor: Ivanti
Software CPE: cpe:2.3:a:ivanti:pulse_policy_secure:*:*:*:*:*:*:*:*
Total vulnerabilities: 89
Public exploits: 10
Known exploited (KEV): 9
Highest CVSSv4 Score: 9.4

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Ivanti Policy Secure (formerly Pulse Policy Secure) Ivanti Policy Secure (formerly Pulse Policy Secure) is affected by 89 known vulnerabilities: 5 critical, 5 high, 31 medium, 48 low Critical High Medium Low

Vulnerabilities (89)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU106969 - Stack-based buffer overflow
CVE-2025-22457
CWE-121 Critical
Available
Exploited
22.7R1.5 03.04.2025 SB20250403123
SB20250403124
SB20250403125
#VU103945 - Cleartext Storage of Sensitive Information
CVE-2024-13843
CWE-312 Low
No
No
22.7R1.3 13.02.2025 SB2025021312
#VU103944 - Use of Hard-coded Cryptographic Key
CVE-2024-13842
CWE-321 Low
No
No
22.7R1.3 13.02.2025 SB2025021311
#VU103943 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-13830
CWE-79 Low
No
No
22.7R1.3 13.02.2025 SB2025021312
#VU103942 - External Control of File Name or Path
CVE-2024-12058
CWE-73 Low
No
No
22.7R1.3 13.02.2025 SB2025021312
#VU103941 - Improper Control of Generation of Code ('Code Injection')
CVE-2024-10644
CWE-94 Low
No
No
22.7R1.3 13.02.2025 SB2025021310
#VU103939 - External Control of File Name or Path
CVE-2024-38657
CWE-73 Low
No
No
22.7R1.3 13.02.2025 SB2025021310
#VU102474 - Stack-based buffer overflow
CVE-2025-0283
CWE-121 Low
No
No
22.7R1.3 08.01.2025 SB2025010871
SB2025010872
SB2025010873
#VU102473 - Stack-based buffer overflow
CVE-2025-0282
CWE-121 Critical
Available
Exploited
22.7R1.3 08.01.2025 SB2025010871
SB2025010872
SB2025010873
#VU101677 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-11634
CWE-78 Low
No
No
22.7R1.2 11.12.2024 SB2024121176
#VU100485 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2024-11004
CWE-79 Low
No
No
22.7R1.2 14.11.2024 SB2024111422
#VU100484 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-11005
CWE-78 Medium
No
No
22.7R1.2 14.11.2024 SB2024111422
#VU100483 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-11006
CWE-78 Medium
No
No
22.7R1.2 14.11.2024 SB2024111422
#VU100482 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2024-11007
CWE-78 Medium
No
No
22.7R1.2 14.11.2024 SB2024111422
#VU100481 - Argument Injection or Modification
CVE-2024-39712
CWE-88 Low
No
No
22.7R1.2 14.11.2024 SB2024111422
#VU100480 - Argument Injection or Modification
CVE-2024-39711
CWE-88 Low
No
No
22.7R1.2 14.11.2024 SB2024111422
#VU100479 - Argument Injection or Modification
CVE-2024-39710
CWE-88 Low
No
No
22.7R1.2 14.11.2024 SB2024111422
#VU100477 - Incorrect Default Permissions
CVE-2024-39709
CWE-276 Low
No
No
22.7R1.2 14.11.2024 SB2024111422
#VU100476 - Argument Injection or Modification
CVE-2024-38656
CWE-88 Low
No
No
22.7R1.2 14.11.2024 SB2024111422
#VU100467 - Use After Free
CVE-2024-9420
CWE-416 Medium
No
No
22.7R1.2 14.11.2024 SB2024111422


Showing elements 21 - 40 out of 89