Proofpoint
proofpoint
44 CVEs • 9 products
Products (9)
Click to collapseToggle
Products (9)
Click to collapse
CVEs (44)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Proofpoint 1Insider Threat Management Server Jun 17, 2026 Nov 3, 2025 2.3 LOW· v4 5.4 MEDIUM· v3 N/A· v2 Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform agent unregistration when the number of r...Show more |
Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy by sending a malicious S/MIME a...Show more |
Proofpoint Enterprise Protection contains a vulnerability in the email delivery agent that allows an unauthenticated attacker to inject improperly encoded HTML into the email body of a message through the email subject....Show more |
Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can send a specially crafted email with HTML in the subject which triggers XSS when viewing quarantined mes...Show more |
1Proofpoint 1Insider Threat Management Jun 17, 2026 Sep 13, 2023 N/A· v4 4.2 MEDIUM· v3 N/A· v2 An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacker to change the server's configuration of any already-registered agent so that the agent sends all f...Show more |
1Proofpoint 1Insider Threat Management Jun 17, 2026 Sep 13, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascript with...Show more |
1Proofpoint 1Insider Threat Management Jun 17, 2026 Sep 13, 2023 N/A· v4 4.8 MEDIUM· v3 N/A· v2 A reflected cross-site scripting vulnerability in the UpdateInstalledSoftware endpoint of the Insider Threat Management (ITM) Server's web console could be used by an authenticated administrator to run arbitrary javascri...Show more |
1Proofpoint 1Insider Threat Management Jun 17, 2026 Sep 13, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a man-in-the-middle position between the a...Show more |
1Proofpoint 1Insider Threat Management Server Jun 17, 2026 Jun 27, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14...Show more |
1Proofpoint 1Insider Threat Management Server Jun 17, 2026 Jun 27, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to obtain sensitive information. Successful exploitatio...Show more |
1Proofpoint 1Insider Threat Management Server Jun 17, 2026 Jun 27, 2023 N/A· v4 4.6 MEDIUM· v3 N/A· v2 A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an atta...Show more |
1Proofpoint 1Insider Threat Management Jun 17, 2026 Jun 27, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring. All versions prior to 7.14.3 are affected. Agents for MacOS and Linux and...Show more |
1Proofpoint 1Threat Response Auto Pull Jun 17, 2026 Jun 14, 2023 N/A· v4 6.8 MEDIUM· v3 N/A· v2 An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to obtain credentials to integrated se...Show more |
1Proofpoint 1Threat Response Auto Pull Jun 17, 2026 Jun 14, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 A stored cross-site scripting vulnerability in the Sources UI in Proofpoint Threat Response/ Threat Response Auto Pull (PTR/TRAP) could allow an authenticated administrator on an adjacent network to replace the image fil...Show more |
The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webser...Show more |
The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'.
This affects all versions 8.20.0 and below.
|
Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versions 8.19.0 and below.
|
The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute commands beyond their allowed scope. This affects all versions 8.19.0 an...Show more |
1Proofpoint 1Enterprise Protection Jun 17, 2026 Dec 6, 2022 N/A· v4 9.6 CRITICAL· v3 N/A· v2 The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within the user interface....Show more |
Proofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control. |