Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pulsesecure

First CVE: Mar 1, 2016Active for: 10 yearsTotal CVEs: 93
62.2
VTI Score
TOP TARGET

Pulsesecure's vulnerability footprint is anchored in a focused set of remote-access and network security appliances—Pulse Connect Secure, Pulse Policy Secure, and its desktop client products—that serve as gateways and enforcement points for enterprise access control, giving vulnerabilities in this portfolio outsized impact on defended perimeters. The recurring weakness classes, including cross-site scripting, path traversal, buffer overflows, and sensitive information exposure, reflect the input-handling and access-control demands of gateway and policy-enforcement appliances. A meaningful share of the vendor's disclosures reach serious severity; the exposure pattern suggests that defenders should treat this vendor's advisories as high-priority, particularly for internet-reachable instances and VPN concentrators. Defenders should maintain close tracking of Pulsesecure release schedules and apply patches to remote-access appliances with urgency, as compromise of these products can grant attackers deep network reach; live exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.

FAUCET AI Generated
93
Total CVEs
More Total CVEs than 99% of tracked vendors
0.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
3.2%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Pulsesecure over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 1, 2016
10 years ago
Most Recent CVE
Sep 30, 2022
1,393 days ago

Products(19 total)

Top CVEs

Signals from CVEs in this vendor scope (93 CVEs).

93 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-11539HIGH
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX befo
Apr 26, 20197.297YESYES
CVE-2019-11477HIGH
Jonathan Looney discovered that the TCP_SKB_CB(skb)->tcp_gso_segs value was subject to an integer overflow in the Linux kernel when handling TCP Selective Acknowledgments (SACKs).
Jun 19, 20197.578NONO
CVE-2020-8218HIGH
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
Jul 30, 20207.277YESNO
CVE-2019-11478HIGH
Jonathan Looney discovered that the TCP retransmission queue implementation in tcp_fragment in the Linux kernel could be fragmented when handling certain TCP Selective Acknowledgme
Jun 19, 20197.576NONO
CVE-2016-0800MEDIUM
The SSLv2 protocol, as used in OpenSSL before 1.0.1s and 1.0.2 before 1.0.2g and other products, requires a server to send a ServerVerify message before establishing that a client
Mar 1, 20165.975NOYES
CVE-2021-22900HIGH
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a malici
May 27, 20217.270YESNO
CVE-2021-22908HIGH
A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as
May 27, 20218.866NONO
CVE-2019-11542HIGH
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1RX before 8.1R15.1 and Pulse Policy Secure version 9.0RX befo
Apr 26, 20197.260NONO
CVE-2016-0799CRITICAL
The fmtstr function in crypto/bio/b_print.c in OpenSSL 1.0.1 before 1.0.1s and 1.0.2 before 1.0.2g improperly calculates string lengths, which allows remote attackers to cause a de
Mar 3, 20169.849NONO
CVE-2022-21826MEDIUM
Pulse Secure version 9.115 and below may be susceptible to client-side http request smuggling, When the application receives a POST request, it ignores the request's Content-Length
Sep 30, 20225.435NONO
View all 93 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products93 CVEs
40%
49%
9%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local19 (20.4%)
Network71 (76.3%)
Unknown0 (0.0%)
Physical2 (2.2%)
Adjacent Network1 (1.1%)
Attack Complexity
Low87 (93.5%)
High6 (6.5%)
Unknown0 (0.0%)
User Interaction
None64 (68.8%)
Unknown0 (0.0%)
Required29 (31.2%)
Privileges Required
Low22 (23.7%)
High21 (22.6%)
None50 (53.8%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (93 CVEs).

CISA KEV
3 CVEs
3.2% of CVEs· 99th percentile
Metasploit
3 CVEs
3.2% of CVEs· 98th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
1.1% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pulsesecure.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pulsesecure — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pulsesecure's Products

View all 4 CNAs →

Top CWEs