Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.4
CVE-2025-8558
Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on a…
Insider Threat Management Server
7.17.2+
MEDIUM 5.3
CVE-2024-10635
Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to byp…
Enterprise Protection
Mitigation only
MEDIUM 5.4
CVE-2023-5770
Proofpoint Enterprise Protection contains a vulnerability in the email delivery agent that allows an unauthenticated attacker to inject improperly en…
Enterprise Protection
Mitigation only
MEDIUM 6.1
CVE-2023-5771
Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can send a specially crafted email w…
Enterprise Protection
8.18.6+
HIGH 7.5
CVE-2023-4801
An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an a…
Insider Threat Management
7.14.3.69+
MEDIUM 6.5
CVE-2023-36000
A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an a…
Insider Threat Management Server
7.14.3+
MEDIUM 5.5
CVE-2023-2818
An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring. Al…
Insider Threat Management
7.14.3+
MEDIUM 6.8
CVE-2023-2820
An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an…
Threat Response Auto Pull
5.10.0+
CRITICAL 9.8
CVE-2023-0090
The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code throug…
Enterprise Protection
8.13.22 / 8.18.4+
HIGH 8.8
CVE-2023-0089
The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through '…
Enterprise Protection
8.13.22 / 8.18.4+
HIGH 7.8
CVE-2022-46334
Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permi…
Enterprise Protection
after 8.19.0
CRITICAL 9.6
CVE-2022-46332
The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an ano…
Enterprise Protection
after 8.19.0
HIGH 7.2
CVE-2022-46333
The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute co…
Enterprise Protection
after 8.19.0
HIGH 7.8
CVE-2022-25294
Proofpoint Insider Threat Management Agent for Windows relies on an inherently dangerous function that could enable an unprivileged local Windows use…
Insider Threat Management
7.12.1+
CRITICAL 9.8
CVE-2021-40842
Proofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console. The vulnerability exists due to improper input…
Insider Threat Management Server
7.11.2+
HIGH 7.3
CVE-2021-40843
Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An attacker with write access to the…
Insider Threat Management Server
7.11.2+
HIGH 7.5
CVE-2021-34814
Proofpoint Spam Engine before 8.12.0-2106240000 has a Security Control Bypass.
Spam Engine
8.12.0-2106240000+
HIGH 7.5
CVE-2021-39304
Proofpoint Enterprise Protection before 8.12.0-2108090000 allows security control bypass.
Enterprise Protection
8.12.0-2108090000+
MEDIUM 6.3
CVE-2020-14009
Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to deliver an email message with a mal…
Enterprise Protection
8.13.16 / 8.16.4+
HIGH 8.1
CVE-2021-27900
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several pages in the Web Console. Th…
Insider Threat Management
7.9.3 / 7.10.3+
HIGH 7.4
CVE-2021-27899
The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validation of the ITM Server's certif…
Insider Threat Management
7.9.3 / 7.10.3+
HIGH 7.2
CVE-2021-22158
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) injection in the Web Console. …
Insider Threat Management
7.9.3 / 7.10.3+
MEDIUM 6.1
CVE-2021-22157
Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.11.1 allows stored XSS.
Insider Threat Management
7.9.3 / 7.10.3+
HIGH 7.8
CVE-2021-22159
Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Management (formerly ObserveIT) Agent …
Insider Threat Management
7.4.3 / 7.5.4+
CRITICAL 9.8
CVE-2020-10655
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's Wri…
Insider Threat Management Server
7.9.1+
CRITICAL 9.8
CVE-2020-10656
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's Wri…
Insider Threat Management Server
7.9.1+
CRITICAL 9.8
CVE-2020-10658
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application server's Wri…
Insider Threat Management Server
7.9.1+
HIGH 8.8
CVE-2020-8884
rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated users to e…
Insider Threat Management
7.4.2 / 7.5.3+
HIGH 7.2
CVE-2020-10657
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM web console's ImportAler…
Insider Threat Management Server
7.9.1+
HIGH 8.8
CVE-2019-19680
A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of PPS through 8.9.22 and 8.14.2 …
Enterprise Protection
after 8.14.2