Vulnerability index

Browse CVEs

124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Ssl Vpn Client MEDIUM 6.0
CVE-2021-36809

A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial o…

Mitigation only
Fix from $1,600 2022-03-08
Unified Threat Management Up2date HIGH 8.8
CVE-2021-36807

An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.

Fix: 9.708+
Fix from $1,950 2021-11-26
Sophos Secure Workspace HIGH 7.0
CVE-2021-36808

A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.

Fix: 9.7.3115+
Fix from $1,950 2021-10-30
Hitmanpro.alert MEDIUM 6.7
CVE-2021-25270

A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.

Fix: 901+
Fix from $1,600 2021-10-08
Hitmanpro MEDIUM 6.0
CVE-2021-25271

A local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318.

Fix: 318+
Fix from $1,600 2021-10-08
Home MEDIUM 6.7
CVE-2021-25264

In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administrator privileges.

Fix: after 10.0.3
Fix from $1,600 2021-05-17
Connect HIGH 8.8
CVE-2021-25265

A malicious website could execute code remotely in Sophos Connect Client before version 2.1.

Fix: 2.1+
Fix from $1,950 2021-03-22
Cyberoamos CRITICAL 9.8
CVE-2020-29574 KEV

An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements…

Fix: after 2020-12-04
Fix from $2,300 2020-12-11
Unified Threat Management CRITICAL 9.8
CVE-2020-25223 KEVEPSS 97%

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11

Fix: 9.511 / 9.607+
Fix from $2,300 2020-09-25
Xg Firewall Firmware HIGH 8.8
CVE-2020-17352

Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to r…

Patch available
Fix from $1,950 2020-08-07
Xg Firewall Firmware CRITICAL 9.8
CVE-2020-15504

A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run ar…

Fix: after 17.5
Fix from $2,300 2020-07-10
Xg Firewall Firmware CRITICAL 9.8
CVE-2020-15069 KEVEPSS 11%

Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access.…

Fix: 17.5+
Fix from $2,300 2020-06-29
Sophos Secure Email MEDIUM 5.9
CVE-2020-14980

The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.

Fix: after 3.9.4
Fix from $1,600 2020-06-22
Sfos CRITICAL 9.8
CVE-2020-11503

A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary …

Fix: 17.5+
Fix from $2,300 2020-06-18
Sfos CRITICAL 9.8
CVE-2020-12271 KEVEPSS 42%

A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April…

Mitigation only
Fix from $2,300 2020-04-27
Anti Virus For Sophos Central HIGH 8.8
CVE-2020-10947

Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.

Fix: 2.2.6 / 9.9.6+
Fix from $1,950 2020-04-17
Hitmanpro.alert HIGH 7.8
CVE-2020-9540

Sophos HitmanPro.Alert before build 861 allows local elevation of privilege.

Fix: 861+
Fix from $1,950 2020-03-02
Cloud Optix HIGH 7.8
CVE-2020-9363

The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix…

Fix: 2020-01-14+
Fix from $1,950 2020-02-24
Cyberoamos CRITICAL 9.8
CVE-2019-17059EPSS 7%

A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbit…

Fix: 10.6.6+
Fix from $2,300 2019-10-11
Sfos HIGH 8.8
CVE-2018-16117EPSS 44%

A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to exec…

Fix: after 17.0
Fix from $1,950 2019-06-20
Sfos HIGH 8.1
CVE-2018-16118

A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attacker…

Fix: after 16.0
Fix from $1,950 2019-06-20
Sfos HIGH 8.8
CVE-2018-16116

SQL injection vulnerability in AccountStatus.jsp in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute ar…

Mitigation only
Fix from $1,950 2019-06-20
Hitmanpro.alert HIGH 7.8
CVE-2018-3971

An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially craf…

No fix yet
Fix from $1,950 2018-10-25
Hitmanpro.alert MEDIUM 5.5
CVE-2018-3970

An exploitable memory disclosure vulnerability exists in the 0x222000 IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially cr…

No fix yet
Fix from $1,600 2018-10-25
Safeguard Easy Device Encryption Client HIGH 7.8
CVE-2018-6857

Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Esca…

Patch available
Fix from $1,950 2018-07-09
Safeguard Easy Device Encryption Client HIGH 7.8
CVE-2018-6851

Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Esca…

Patch available
Fix from $1,950 2018-07-09
Safeguard Easy Device Encryption Client HIGH 7.8
CVE-2018-6852

Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Esca…

Patch available
Fix from $1,950 2018-07-09
Safeguard Easy Device Encryption Client HIGH 7.8
CVE-2018-6853

Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Esca…

Patch available
Fix from $1,950 2018-07-09
Safeguard Easy Device Encryption Client HIGH 7.8
CVE-2018-6854

Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Esca…

Patch available
Fix from $1,950 2018-07-09
Safeguard Easy Device Encryption Client HIGH 7.8
CVE-2018-6855

Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Esca…

Patch available
Fix from $1,950 2018-07-09