Sophos
sophos
168 CVEs • 73 products
Products (73)
Click to collapseToggle
Products (73)
Click to collapse
CVEs (168)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901. |
1Sophos 1Unified Threat Management Jun 17, 2026 Jul 29, 2021 N/A· v4 4.8 MEDIUM· v3 3.5 LOW· v2 Stored XSS can execute as administrator in quarantined email detail view in Sophos UTM before version 9.706. |
In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administrator privileges. |
A malicious website could execute code remotely in Sophos Connect Client before version 2.1. |
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements remotely. |
1Sophos 1Unified Threat Management Jun 17, 2026 Sep 25, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11 |
Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to remotely execute arbitrary code. |
1Sophos 1Xg Firewall Firmware Jun 17, 2026 Jul 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run arbitrary code remotely. The fix is built into the re-release of XG Firew...Show more |
1Sophos 1Xg Firewall Firmware Jun 17, 2026 Jun 29, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access. Hotfix HF062020.1 was published for all firewalls running v17.x. |
1Sophos 1Sophos Secure Email Jun 17, 2026 Jun 22, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation. |
A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary code remotely. |
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April 2020. This affected devices configured with either the administration...Show more |
1Sophos 2Anti Virus For Sophos Central Anti Virus For Sophos HomeJun 17, 2026 Apr 17, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation. |
Sophos HitmanPro.Alert before build 861 allows local elevation of privilege. |
1Sophos 6Cloud Optix Endpoint ProtectionIntercept X Endpoint+3 moreJun 17, 2026 Feb 24, 2020 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix, Mobile, Intercept X Endpoint, Intercept X for Server, and Secure Web...Show more |
A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbitrary commands via the Web Admin and SSL VPN consoles. |
A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attackers to execute arbitrary OS commands via shell metachracters in the "X-Fo...Show more |
A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary OS commands via shell metacharacters in the "dbName" POST...Show more |
SQL injection vulnerability in AccountStatus.jsp in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute arbitrary SQL commands via the "username" GET parameter. |
2Ncp E Sophos2Ipsec Client Ncp Secure Entry ClientNov 21, 2024 Apr 9, 2019 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com). The affected client software, "Sophos IPSec Client" 11.04 is a rebranded version of NCP "Secure Entry Client" 10.11...Show more |