checkpoint records
135 published records for vendor checkpoint.
Researcher profile
- Entered KEV
- 7 · 5.2%
- Weaponized
- 7 · 5.2%
- Pre-auth RCE
- 12
- With a fix record
- 4.4%
- Median publish → KEV
- 2 days
Recurring classes
- CWE-264 Permissions, Privileges, and Access Controls6
- CWE-65 Windows Hard Link5
- CWE-732 Incorrect Permission Assignment for Critical Resource5
- CWE-59 Improper Link Resolution Before File Access ('Link Following')5
- CWE-114 Process Control5
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
The weakness classes this vendor ships most often: where to look.
CWEAll records
135 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
99Now | CVE-2014-6271Weaponized | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attacgnu · bash · CWE-78 | Critical9.8 | KEV | 100.0% | Sep 24, 2014 |
99Now | CVE-2014-7169Weaponized | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variablgnu · bash · CWE-78 | Critical9.8 | KEV | 99.9% | Sep 24, 2014 |
94Now | CVE-2024-24919Weaponized | Information disclosurecheckpoint · quantum spark firmware · CWE-200 | High8.6 | KEV | 100.0% | May 28, 2024 |
90Now | CVE-2026-16232Weaponized | Authentication Bypass in the SmartConsole Login Process Using an Application Tokencheckpoint · multi-domain security management · CWE-287 | Critical9.3 | KEV | 78.0% | Jul 22, 2026 |
75This week | CVE-2026-93616Weaponized | Directory Traversal and File upload allows execution of arbitrary script on the Management Servercheckpoint · multi-domain security management · CWE-22 | Critical9.8 | KEV | 19.7% | Sep 22, 2026 |
71This week | CVE-2026-85102Weaponized | Improper Certificate Validation in Quantum Security Gatewaycheckpoint · gaia embedded · CWE-295 | Critical9.8 | KEV | 7.5% | Sep 9, 2026 |
69This week | CVE-2026-50751Weaponized | User Authentication Bypass in VPN Remote Access and Mobile Accesscheckpoint · gaia os · CWE-287 | Critical9.3 | KEV | 6.3% | Jun 8, 2026 |
43Plan | CVE-2004-0039No exploit | Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Checcheckpoint · firewall-1 | Critical10.0 | — | 9.3% | Mar 3, 2004 |
42Plan | CVE-2021-3449Proof of concept | NULL pointer deref in signature_algorithms processingopenssl · openssl · CWE-476 | Medium5.9 | — | 63.5% | Mar 25, 2021 |
42Plan | CVE-2004-0040No exploit | Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 42checkpoint · firewall-1 | Critical10.0 | — | 7.6% | Mar 3, 2004 |
42Plan | CVE-2009-1227Proof of concept | NOTE: this issue has been disputed by the vendor.checkpoint · firewall-1 pki web service · CWE-119 | Critical10.0 | — | 7.2% | Apr 2, 2009 |
41Plan | CVE-2004-0469No exploit | Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-41checkpoint · firewall-1 | Critical10.0 | — | 5.0% | Jul 7, 2004 |
40Plan | CVE-2013-7350No exploit | Multiple unspecified vulnerabilities in Check Point Security Gateway 80 R71.x before R71.45 (730159141) and R75.20.x before R75.20.4 and 600checkpoint · security gateway | Critical10.0 | — | 1.4% | Apr 1, 2014 |
39Monitor | CVE-2019-8459No exploit | Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the pacheckpoint · jumbo hotfix for endpoint security server · CWE-428 | Critical9.8 | — | 1.2% | Jun 20, 2019 |
39Monitor | CVE-2025-3831No exploit | Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.checkpoint · harmony sase · CWE-200 | Critical9.8 | — | 0.4% | Aug 12, 2025 |
38Monitor | CVE-2011-1827No exploit | Multiple unspecified vulnerabilities in Check Point SSL Network Extender (SNX), SecureWorkSpace, and Endpoint Security On-Demand, as distribcheckpoint · connectra ngx | Critical9.3 | — | 4.5% | Oct 4, 2011 |
38Monitor | CVE-2007-3489No exploit | Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33checkpoint · vpn-1 utm edge | Critical9.3 | — | 3.3% | Jun 29, 2007 |
36Monitor | CVE-2021-30358No exploit | Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from othcheckpoint · mobile access portal agent · CWE-78 | High7.2 | — | 27.5% | Oct 19, 2021 |
35Monitor | CVE-2002-1623No exploit | The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initiacheckpoint · vpn-1 firewall-1 | Medium5.0 | — | 48.6% | Dec 31, 2002 |
35Monitor | CVE-2022-23745No exploit | A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS).checkpoint · capsule workspace · CWE-1218 | High7.5 | — | 16.5% | Jul 18, 2022 |
35Monitor | CVE-2020-6013No exploit | ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute cocheckpoint · zonealarm extreme security · CWE-65 | High8.8 | — | 1.6% | Jul 6, 2020 |
35Monitor | CVE-2022-41604No exploit | Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges.checkpoint · zonealarm · CWE-269 | High8.8 | — | 0.6% | Sep 27, 2022 |
34Monitor | CVE-2023-28130No exploit | Local user may lead to privilege escalation using Gaia Portal hostnames page.checkpoint · gaia portal · CWE-20 | High7.2 | — | 20.9% | Jul 26, 2023 |
33Monitor | CVE-2004-0079No exploit | The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (openssl · openssl · CWE-476 | High7.5 | — | 9.5% | Nov 23, 2004 |
33Monitor | CVE-2023-28133No exploit | Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration filecheckpoint · endpoint security · CWE-732 | High7.8 | — | 5.7% | Jul 23, 2023 |
- CVE-2014-627199Now
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attac
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2014-716999Now
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variabl
CriticalCVSS 9.8KEVWeaponizedEPSS 100%gnu · bashSep 24, 2014
- CVE-2024-2491994Now
Information disclosure
HighCVSS 8.6KEVWeaponizedEPSS 100%checkpoint · quantum spark firmwareMay 28, 2024
- CVE-2026-1623290Now
Authentication Bypass in the SmartConsole Login Process Using an Application Token
CriticalCVSS 9.3KEVWeaponizedEPSS 78%checkpoint · multi-domain security managementJul 22, 2026
- CVE-2026-9361675This week
Directory Traversal and File upload allows execution of arbitrary script on the Management Server
CriticalCVSS 9.8KEVWeaponizedEPSS 20%checkpoint · multi-domain security managementSep 22, 2026
- CVE-2026-8510271This week
Improper Certificate Validation in Quantum Security Gateway
CriticalCVSS 9.8KEVWeaponizedEPSS 8%checkpoint · gaia embeddedSep 9, 2026
- CVE-2026-5075169This week
User Authentication Bypass in VPN Remote Access and Mobile Access
CriticalCVSS 9.3KEVWeaponizedEPSS 6%checkpoint · gaia osJun 8, 2026
- CVE-2004-003943Plan
Multiple format string vulnerabilities in HTTP Application Intelligence (AI) component in Check Point Firewall-1 NG-AI R55 and R54, and Chec
CriticalCVSS 10.0No exploitEPSS 9%checkpoint · firewall-1Mar 3, 2004
- CVE-2021-344942Plan
NULL pointer deref in signature_algorithms processing
MediumCVSS 5.9Proof of conceptEPSS 64%openssl · opensslMar 25, 2021
- CVE-2004-004042Plan
Stack-based buffer overflow in Check Point VPN-1 Server 4.1 through 4.1 SP6 and Check Point SecuRemote/SecureClient 4.1 through 4.1 build 42
CriticalCVSS 10.0No exploitEPSS 8%checkpoint · firewall-1Mar 3, 2004
- CVE-2009-122742Plan
NOTE: this issue has been disputed by the vendor.
CriticalCVSS 10.0Proof of conceptEPSS 7%checkpoint · firewall-1 pki web serviceApr 2, 2009
- CVE-2004-046941Plan
Buffer overflow in the ISAKMP functionality for Check Point VPN-1 and FireWall-1 NG products, before VPN-1/FireWall-1 R55 HFA-03, R54 HFA-41
CriticalCVSS 10.0No exploitEPSS 5%checkpoint · firewall-1Jul 7, 2004
- CVE-2013-735040Plan
Multiple unspecified vulnerabilities in Check Point Security Gateway 80 R71.x before R71.45 (730159141) and R75.20.x before R75.20.4 and 600
CriticalCVSS 10.0No exploitEPSS 1%checkpoint · security gatewayApr 1, 2014
- CVE-2019-845939Monitor
Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the pa
CriticalCVSS 9.8No exploitEPSS 1%checkpoint · jumbo hotfix for endpoint security serverJun 20, 2019
- CVE-2025-383139Monitor
Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.
CriticalCVSS 9.8No exploitEPSS 0%checkpoint · harmony saseAug 12, 2025
- CVE-2011-182738Monitor
Multiple unspecified vulnerabilities in Check Point SSL Network Extender (SNX), SecureWorkSpace, and Endpoint Security On-Demand, as distrib
CriticalCVSS 9.3No exploitEPSS 5%checkpoint · connectra ngxOct 4, 2011
- CVE-2007-348938Monitor
Cross-site request forgery (CSRF) vulnerability in pop/WizU.html in the management interface in Check Point VPN-1 Edge X Embedded NGX 7.0.33
CriticalCVSS 9.3No exploitEPSS 3%checkpoint · vpn-1 utm edgeJun 29, 2007
- CVE-2021-3035836Monitor
Mobile Access Portal Native Applications who's path is defined by the administrator with environment variables may run applications from oth
HighCVSS 7.2No exploitEPSS 27%checkpoint · mobile access portal agentOct 19, 2021
- CVE-2002-162335Monitor
The design of the Internet Key Exchange (IKE) protocol, when using Aggressive Mode for shared secret authentication, does not encrypt initia
MediumCVSS 5.0No exploitEPSS 49%checkpoint · vpn-1 firewall-1Dec 31, 2002
- CVE-2022-2374535Monitor
A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS).
HighCVSS 7.5No exploitEPSS 16%checkpoint · capsule workspaceJul 18, 2022
- CVE-2020-601335Monitor
ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute co
HighCVSS 8.8No exploitEPSS 2%checkpoint · zonealarm extreme securityJul 6, 2020
- CVE-2022-4160435Monitor
Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges.
HighCVSS 8.8No exploitEPSS 1%checkpoint · zonealarmSep 27, 2022
- CVE-2023-2813034Monitor
Local user may lead to privilege escalation using Gaia Portal hostnames page.
HighCVSS 7.2No exploitEPSS 21%checkpoint · gaia portalJul 26, 2023
- CVE-2004-007933Monitor
The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (
HighCVSS 7.5No exploitEPSS 10%openssl · opensslNov 23, 2004
- CVE-2023-2813333Monitor
Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file
HighCVSS 7.8No exploitEPSS 6%checkpoint · endpoint securityJul 23, 2023