Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.0
CVE-2021-36809
A local attacker can overwrite arbitrary files on the system with VPN client logs using administrator privileges, potentially resulting in a denial o…
Ssl Vpn Client
Mitigation only
HIGH 8.8
CVE-2021-36807
An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.
Unified Threat Management Up2date
9.708+
HIGH 7.0
CVE-2021-36808
A local attacker could bypass the app password using a race condition in Sophos Secure Workspace for Android before version 9.7.3115.
Sophos Secure Workspace
9.7.3115+
MEDIUM 6.7
CVE-2021-25270
A local attacker could execute arbitrary code with administrator privileges in HitmanPro.Alert before version Build 901.
Hitmanpro.alert
901+
MEDIUM 6.0
CVE-2021-25271
A local attacker could read or write arbitrary files with administrator privileges in HitmanPro before version Build 318.
Hitmanpro
318+
MEDIUM 6.7
CVE-2021-25264
In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administrator privileges.
Home
after 10.0.3
HIGH 8.8
CVE-2021-25265
A malicious website could execute code remotely in Sophos Connect Client before version 2.1.
Connect
2.1+
CRITICAL 9.8
CVE-2020-29574 KEV
An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attackers to execute arbitrary SQL statements…
Cyberoamos
after 2020-12-04
CRITICAL 9.8
CVE-2020-25223 KEVEPSS 97%
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
Unified Threat Management
9.511 / 9.607+
HIGH 8.8
CVE-2020-17352
Two OS command injection vulnerabilities in the User Portal of Sophos XG Firewall through 2020-08-05 potentially allow an authenticated attacker to r…
Xg Firewall Firmware
Patch available
CRITICAL 9.8
CVE-2020-15504
A SQL injection vulnerability in the user and admin web interfaces of Sophos XG Firewall v18.0 MR1 and older potentially allows an attacker to run ar…
Xg Firewall Firmware
after 17.5
CRITICAL 9.8
CVE-2020-15069 KEVEPSS 11%
Sophos XG Firewall 17.x through v17.5 MR12 allows a Buffer Overflow and remote code execution via the HTTP/S Bookmarks feature for clientless access.…
Xg Firewall Firmware
17.5+
MEDIUM 5.9
CVE-2020-14980
The Sophos Secure Email application through 3.9.4 for Android has Missing SSL Certificate Validation.
Sophos Secure Email
after 3.9.4
CRITICAL 9.8
CVE-2020-11503
A heap-based buffer overflow in the awarrensmtp component of Sophos XG Firewall v17.5 MR11 and older potentially allows an attacker to run arbitrary …
Sfos
17.5+
CRITICAL 9.8
CVE-2020-12271 KEVEPSS 42%
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild in April…
Sfos
Mitigation only
HIGH 8.8
CVE-2020-10947
Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.
Anti Virus For Sophos Central
2.2.6 / 9.9.6+
HIGH 7.8
CVE-2020-9540
Sophos HitmanPro.Alert before build 861 allows local elevation of privilege.
Hitmanpro.alert
861+
HIGH 7.8
CVE-2020-9363
The Sophos AV parsing engine before 2020-01-14 allows virus-detection bypass via a crafted ZIP archive. This affects Endpoint Protection, Cloud Optix…
Cloud Optix
2020-01-14+
CRITICAL 9.8
CVE-2019-17059EPSS 7%
A shell injection vulnerability on the Sophos Cyberoam firewall appliance with CyberoamOS before 10.6.6 MR-6 allows remote attackers to execute arbit…
Cyberoamos
10.6.6+
HIGH 8.8
CVE-2018-16117EPSS 44%
A shell escape vulnerability in /webconsole/Controller in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to exec…
Sfos
after 17.0
HIGH 8.1
CVE-2018-16118
A shell escape vulnerability in /webconsole/APIController in the API Configuration component of Sophos XG firewall 17.0.8 MR-8 allows remote attacker…
Sfos
after 16.0
HIGH 8.8
CVE-2018-16116
SQL injection vulnerability in AccountStatus.jsp in Admin Portal of Sophos XG firewall 17.0.8 MR-8 allow remote authenticated attackers to execute ar…
Sfos
Mitigation only
HIGH 7.8
CVE-2018-3971
An exploitable arbitrary write vulnerability exists in the 0x2222CC IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially craf…
Hitmanpro.alert
No fix yet
MEDIUM 5.5
CVE-2018-3970
An exploitable memory disclosure vulnerability exists in the 0x222000 IOCTL handler functionality of Sophos HitmanPro.Alert 3.7.6.744. A specially cr…
Hitmanpro.alert
No fix yet
HIGH 7.8
CVE-2018-6857
Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Esca…
Safeguard Easy Device Encryption Client
Patch available
HIGH 7.8
CVE-2018-6851
Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Esca…
Safeguard Easy Device Encryption Client
Patch available
HIGH 7.8
CVE-2018-6852
Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Esca…
Safeguard Easy Device Encryption Client
Patch available
HIGH 7.8
CVE-2018-6853
Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Esca…
Safeguard Easy Device Encryption Client
Patch available
HIGH 7.8
CVE-2018-6854
Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Esca…
Safeguard Easy Device Encryption Client
Patch available
HIGH 7.8
CVE-2018-6855
Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Esca…
Safeguard Easy Device Encryption Client
Patch available