Pegasystems Inc.

First CVE: Apr 1, 2021Active for: 5 years
44
CVEs Published
More CVEs Published than 54% of tracked CNAs
7.3
Avg CVEs / Year
More Avg CVEs / Year than 44% of tracked CNAs
6.4
Avg CVSS Score
Higher Avg CVSS Score than 21% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Pegasystems Inc. as a CNA, 84.1% affect products that Pegasystems Inc. develops as a vendor.

84.1%
15.9%
Self-reported: 37Third-party: 7

Of all the CVEs published that affect products developed by Pegasystems Inc., 74.0% are self-published by Pegasystems Inc. as a CNA.

74.0%
26.0%
Self-published: 37Published by other CNAs: 13

Trends Over Time

The number and severity of CVEs published by Pegasystems Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 1, 2021
5 years ago
Most Recent CVE
Jul 15, 2026
8 days ago

Top CVEs

All CVEs published by Pegasystems Inc. as a CNA, regardless of affected vendor or product.

44 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In versions 8.2.1 through 8.5.2 of Pega Infinity, the password reset functionality for local accounts can be used to bypass local authentication checks.
Apr 29, 20219.870NOYES
If an on-premise installation of the Pega Platform is configured with the port for the JMX interface exposed to the Internet and port filtering is not properly configured, then it
Jul 19, 20229.850NOYES
Password authentication bypass vulnerability for local accounts can be used to bypass local authentication checks.
Jul 25, 20229.831NONO
Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs
Jun 23, 20267.129NONO
An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version
Mar 23, 20269.027NONO
Pega Platform versions 6.x to Infinity 24.1.1 are affected by an issue with Improper Control of Generation of Code
Nov 20, 20249.826NONO
Pega platform clients who are using versions 6.1 through 7.3.1 may be utilizing default credentials
Aug 7, 20239.826NONO
Pega platform clients who are using versions 7.4 through 8.8.x and have upgraded from a version prior to 8.x may be utilizing default credentials.
Jun 22, 20239.826NONO
A user with non-Admin access can change a configuration file on the client to modify the Server URL.
Apr 10, 20237.825NONO
Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user wit
Jul 15, 20264.824NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA44 CVEs
Severity distribution among all CVEs352,101 CVEs
LowMediumHighCritical
Attack Vector
Local2 (4.5%)
Network42 (95.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low43 (97.7%)
High1 (2.3%)
Unknown0 (0.0%)
User Interaction
None18 (40.9%)
Unknown0 (0.0%)
Required22 (50.0%)
Privileges Required
Low9 (20.5%)
High13 (29.5%)
None22 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (44 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
2.3% of CVEs· 86th percentile
ExploitDB
1 CVE
2.3% of CVEs· 90th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Pegasystems Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Pegasystems Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs