Policy Secure

Vendor:

First CVE: Apr 26, 2019 · Active for 7 years

77
Total CVEs
More Total CVEs than 99% of tracked products
15.4
Avg CVEs / Year
Higher CVE frequency than 98% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 42% of tracked products
10.4%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Policy Secure over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 26, 2019
7 years ago
Most Recent CVE
Sep 9, 2025
322 days ago

CVE Severity & Scoring

Policy Secure77 CVEs
All CVEs353,173 CVEs
LowMediumHighCritical
Attack Vector
Local8 (10.4%)
Network69 (89.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low74 (96.1%)
High3 (3.9%)
Unknown0 (0.0%)
User Interaction
None66 (85.7%)
Unknown0 (0.0%)
Required11 (14.3%)
Privileges Required
Low18 (23.4%)
High33 (42.9%)
None26 (33.8%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (77 CVEs).

77 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows
Apr 3, 20259.899YESYES
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.
Jan 8, 20259.098YESYES
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an att
Jan 31, 20248.298YESYES
A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send special
Jan 12, 20249.198YESYES
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing co
Jan 12, 20248.298YESYES
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX befo
Apr 26, 20197.297YESYES
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
Sep 30, 20207.293YESNO
An XML external entity or XXE vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x), Ivanti Policy Secure (9.x, 22.x) and ZTA gateways which allows an attacker t
Feb 13, 20248.385NOYES
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker
Oct 18, 20248.878NOYES
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
Jul 30, 20207.277YESNO

Exploit Exposure

Signals from CVEs in this product scope (77 CVEs).

CISA KEV
8 CVEs
10.4% of CVEs· 98th percentile
Metasploit
6 CVEs
7.8% of CVEs· 97th percentile
Nuclei
6 CVEs
7.8% of CVEs· 97th percentile
ExploitDB
2 CVEs
2.6% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (77 CVEs).

Media Mentions

Signals from CVEs in this product scope (77 CVEs).

Top CNAs Publishing CVEs For Policy Secure

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
9.1267.332.2%53
9.0108.040.9%44
22.7486.65.6%23
22.697.846.3%33
22.598.364.6%34
22.488.474.4%33
22.388.366.9%33
22.2108.257.7%33
22.1108.257.7%33