{"resultsPerPage":4,"startIndex":0,"totalResults":4,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-08T05:31:12.094","vulnerabilities":[{"cve":{"id":"CVE-2018-10204","sourceIdentifier":"cve@mitre.org","published":"2018-04-18T21:29:00.343","lastModified":"2026-06-17T01:33:40.400","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"PureVPN 6.0.1 for Windows suffers from a SYSTEM privilege escalation vulnerability in its \"sevpnclient\" service. When configured to use the OpenVPN protocol, the \"sevpnclient\" service executes \"openvpn.exe\" using the OpenVPN config file located at %PROGRAMDATA%\\purevpn\\config\\config.ovpn. This file allows \"Write\" permissions to users in the \"Everyone\" group. An authenticated attacker may modify this file to specify a dynamic library plugin that should run for every new VPN connection attempt. This plugin will execute code in the context of the SYSTEM account."},{"lang":"es","value":"PureVPN 6.0.1 para Windows sufre de una vulnerabilidad de escalado de privilegios SYSTEM a través del servicio \"sevpnclient\". Cuando se configura para emplear el protocolo OpenVPN, el servicio \"sevpnclient\" ejecuta \"openvpn.exe\" empleando el archivo de configuración de OpenVPN ubicado en %PROGRAMDATA%\\purevpn\\config\\config.ovpn. Este archivo otorga los permisos \"Write\" a los usuarios en el grupo \"Everyone\". Un atacante autenticado puede modificar este archivo para especificar un plugin de biblioteca dinámica que debería ejecutarse para cada nuevo intento de conexión de VPN. Este plugin ejecutará código en el contexto de la cuenta SYSTEM."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV30":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.0","vectorString":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":8.8,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","baseScore":9.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":8.0,"impactScore":10.0,"acInsufInfo":true,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-732"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:purevpn:purevpn:6.0.1:*:*:*:*:windows:*:*","matchCriteriaId":"B8E8F6FD-57D8-4600-98B8-9F9E3658C63B"}]}]}],"references":[{"url":"https://github.com/VerSprite/research/blob/master/advisories/VS-2018-021.md","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://github.com/VerSprite/research/blob/master/advisories/VS-2018-021.md","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]}]}},{"cve":{"id":"CVE-2023-48957","sourceIdentifier":"cve@mitre.org","published":"2024-08-25T17:15:03.553","lastModified":"2026-06-17T06:35:11.547","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"PureVPN Linux client 2.0.2-Productions fails to properly handle DNS queries, allowing them to bypass the VPN tunnel and be sent directly to the ISP or default DNS servers."},{"lang":"es","value":"El cliente PureVPN Linux 2.0.2-Productions no maneja adecuadamente las consultas DNS, lo que les permite omitir el túnel VPN y enviarse directamente al ISP o a los servidores DNS predeterminados."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"purevpn","product":"purevpn","defaultStatus":"unknown","cpes":["cpe:2.3:a:purevpn:purevpn:*:*:*:*:*:macos:*:*"],"versions":[{"version":"2.0.2","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":5.3,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-08-26T16:51:13.933235Z","id":"CVE-2023-48957","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","description":[{"lang":"en","value":"CWE-200"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:purevpn:purevpn:2.0.2:*:*:*:*:linux:*:*","matchCriteriaId":"7D6E5CC1-C133-4168-89D3-C6907F279ED6"}]}]}],"references":[{"url":"https://latesthackingnews.com/2023/11/13/multiple-vulnerabilities-found-in-purevpn-one-remains-unpatched/","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.rafaybaloch.com/2023/11/Multiple%20Critical-Vulnerabilities-in-PureVPN.html?m=1","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]}]}},{"cve":{"id":"CVE-2025-59691","sourceIdentifier":"cve@mitre.org","published":"2025-09-18T23:15:34.310","lastModified":"2026-06-17T09:46:31.850","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"PureVPN client applications on Linux through September 2025 allow IPv6 traffic to leak outside the VPN tunnel upon network events such as Wi-Fi reconnect or system resume. In the CLI client, the VPN auto-reconnects and claims to be connected, but IPv6 traffic is no longer routed or blocked. In the GUI client, the IPv6 connection remains functional after disconnection until the user clicks Reconnect. In both cases, the real IPv6 address is exposed to external services, violating user privacy and defeating the advertised IPv6 leak protection. This affects CLI 2.0.1 and GUI 2.10.0."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"PureVPN","product":"PureVPN","defaultStatus":"unknown","versions":[{"version":"CLI 2.0.1","versionType":"custom","status":"affected"},{"version":"GUI 2.10.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-19T13:08:42.717940Z","id":"CVE-2025-59691","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@mitre.org","type":"Secondary","description":[{"lang":"en","value":"CWE-669"}]}],"references":[{"url":"https://anagogistis.com/posts/purevpn-ipv6-leak/","source":"cve@mitre.org"}]}},{"cve":{"id":"CVE-2025-59692","sourceIdentifier":"cve@mitre.org","published":"2025-09-18T23:15:34.517","lastModified":"2026-06-17T09:46:31.967","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"PureVPN client applications on Linux through September 2025 mishandle firewalling. They flush the system's existing iptables rules and apply default ACCEPT policies when connecting to a VPN server. This removes firewall rules that may have been configured manually or by other software (e.g., UFW, container engines, or system security policies). Upon VPN disconnect, the original firewall state is not restored. As a result, the system may become unintentionally exposed to network traffic that was previously blocked. This affects CLI 2.0.1 and GUI 2.10.0."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"PureVPN","product":"PureVPN","defaultStatus":"unknown","versions":[{"version":"CLI 2.0.1","versionType":"custom","status":"affected"},{"version":"GUI 2.10.0","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-09-19T13:08:24.214138Z","id":"CVE-2025-59692","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@mitre.org","type":"Secondary","description":[{"lang":"en","value":"CWE-669"}]}],"references":[{"url":"https://anagogistis.com/posts/purevpn-ipv6-leak/","source":"cve@mitre.org"}]}}]}