Vulnerability index

Browse CVEs

124 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2025-6704EPSS 8% An arbitrary file writing vulnerability in the Secure PDF eXchange (SPX) feature of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to… Firewall Firmware 21.0.2+ Fix from $2,3002025-07-21 CRITICAL 9.8 CVE-2025-7624EPSS 7% An SQL injection vulnerability in the legacy (transparent) SMTP proxy of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to remote cod… Firewall Firmware 21.0.2+ Fix from $2,3002025-07-21 HIGH 8.8 CVE-2025-7382 A command injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR2 (21.0.2) can lead to adjacent attackers achieving pre-a… Firewall Firmware 21.0.2+ Fix from $1,9502025-07-21 HIGH 8.1 CVE-2024-13974EPSS 7% A business logic vulnerability in the Up2Date component of Sophos Firewall older than version 21.0 MR1 (20.0.1) can lead to attackers controlling the… Firewall Firmware 21.0.1+ Fix from $1,9502025-07-21 HIGH 7.2 CVE-2024-13973EPSS 8% A post-auth SQL injection vulnerability in WebAdmin of Sophos Firewall versions older than 21.0 MR1 (21.0.1) can potentially lead to administrators a… Firewall Firmware 21.0.1+ Fix from $1,9502025-07-21 HIGH 7.8 CVE-2024-13861 A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10 allows local users arbitra… Taegis Endpoint Agent 1.3.10+ Fix from $1,9502025-04-11 CRITICAL 9.8 CVE-2024-12727 A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the … Firewall Firmware 21.0.1+ Fix from $2,3002024-12-19 CRITICAL 9.8 CVE-2024-12728 A weak credentials vulnerability potentially allows privileged system access via SSH to Sophos Firewall older than version 20.0 MR3 (20.0.3). Firewall Firmware 20.0.3+ Fix from $2,3002024-12-19 HIGH 8.8 CVE-2024-12729 A post-auth code injection vulnerability in the User Portal allows authenticated users to execute code remotely in Sophos Firewall older than version… Firewall Firmware 21.0.1+ Fix from $1,9502024-12-19 MEDIUM 6.1 CVE-2021-36806 A reflected XSS vulnerability allows an open redirect when the victim clicks a malicious link to an error page on Sophos Email Appliance older th… Email Appliance 4.5.3.4+ Fix from $1,6002023-11-30 HIGH 7.5 CVE-2023-5552 A password disclosure vulnerability in the Secure PDF eXchange (SPX) feature allows attackers with full email access to decrypt PDFs in Sophos Firewa… Firewall after 19.5.3 Fix from $1,9502023-10-18 MEDIUM 6.1 CVE-2023-33335 Cross Site Scripting (XSS) in Sophos Sophos iView (The EOL was December 31st 2020) in grpname parameter that allows arbitrary script to be executed. Iview Mitigation only Fix from $1,6002023-07-05 CRITICAL 9.8 CVE-2023-1671 KEVEPSS 100% A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10.4 allows execution of arbitr… Web Appliance 4.3.10.4+ Fix from $2,3002023-04-04 HIGH 7.2 CVE-2022-4934 A post-auth command injection vulnerability in the exception wizard of Sophos Web Appliance older than version 4.3.10.4 allows administrators to exec… Web Appliance 4.3.10.4+ Fix from $1,9502023-04-04 MEDIUM 5.4 CVE-2020-36692 A reflected XSS via POST vulnerability in report scheduler of Sophos Web Appliance versions older than 4.3.10.4 allows execution of JavaScript code i… Web Appliance 4.3.10.4+ Fix from $1,6002023-04-04 MEDIUM 6.1 CVE-2022-4901 Multiple stored XSS vulnerabilities in Sophos Connect versions older than 2.2.90 allow Javascript code to run in the local UI via a malicious VPN con… Connect 2.2.90+ Fix from $1,6002023-03-01 MEDIUM 5.5 CVE-2022-48310 An information disclosure vulnerability allows sensitive key material to be included in technical support archives in Sophos Connect versions older t… Connect 2.2.90+ Fix from $1,6002023-03-01 HIGH 8.8 CVE-2022-3713 A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 G… Xg Firewall Firmware after 19.0 Fix from $1,9502022-12-01 HIGH 8.4 CVE-2022-3709 A stored XSS vulnerability allows admin to super-admin privilege escalation in the Webadmin import group wizard of Sophos Firewall releases older tha… Xg Firewall Firmware after 19.0 Fix from $1,9502022-12-01 HIGH 7.2 CVE-2022-3226 An OS command injection vulnerability allows admins to execute code via SSL VPN configuration uploads in Sophos Firewall releases older than version … Xg Firewall Firmware after 19.0 Fix from $1,9502022-12-01 HIGH 7.2 CVE-2022-3696 A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA. Xg Firewall Firmware after 19.0 Fix from $1,9502022-12-01 CRITICAL 9.8 CVE-2022-3980EPSS 8% An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premise… Mobile 9.7.5+ Fix from $2,3002022-11-16 CRITICAL 9.8 CVE-2022-3236 KEVEPSS 99% A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and olde… Firewall after 19.0.1 Fix from $2,3002022-09-23 HIGH 7.2 CVE-2022-1807 Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and… Firewall 18.5+ Fix from $1,9502022-09-07 HIGH 8.4 CVE-2021-25267 Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 19.0 GA. Firewall Firmware 19.0+ Fix from $1,9502022-05-05 HIGH 8.4 CVE-2021-25268 Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 … Firewall Firmware 19.0+ Fix from $1,9502022-05-05 MEDIUM 5.3 CVE-2022-0331 An information disclosure vulnerability in Webadmin allows an unauthenticated remote attacker to read the device serial number in Sophos Firewall ver… Sfos after 18.5.2 Fix from $1,6002022-03-29 CRITICAL 9.8 CVE-2022-1040 KEVEPSS 100% An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 … Sfos after 18.5.3 Fix from $2,3002022-03-25 HIGH 8.8 CVE-2022-0386 A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version… Unified Threat Management 9.710+ Fix from $1,9502022-03-22 HIGH 7.8 CVE-2022-0652 Confd log files contain local users', including root’s, SHA512crypt password hashes with insecure access permissions. This allows a local attacker to… Unified Threat Management 9.710+ Fix from $1,9502022-03-22