Proofpoint records
45 published records for vendor proofpoint.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 7
- With a fix record
- 40%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-502 Deserialization of Untrusted Data6
- CWE-862 Missing Authorization4
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')2
- CWE-754 Improper Check for Unusual or Exceptional Conditions2
- CWE-295 Improper Certificate Validation2
The weakness classes this vendor ships most often: where to look.
CWEAll records
45 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2020-10658No exploit | The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application serproofpoint · insider threat management server · CWE-502 | Critical9.8 | — | 2.7% | Jan 6, 2021 |
40Plan | CVE-2020-10655No exploit | The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application serproofpoint · insider threat management server · CWE-502 | Critical9.8 | — | 2.6% | Jan 6, 2021 |
40Plan | CVE-2020-10656No exploit | The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application serproofpoint · insider threat management server · CWE-502 | Critical9.8 | — | 2.6% | Jan 6, 2021 |
39Monitor | CVE-2021-40842No exploit | Proofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console.proofpoint · insider threat management server · CWE-89 | Critical9.8 | — | 1.0% | Oct 13, 2021 |
39Monitor | CVE-2023-0090Proof of concept | Proofpoint Enterprise Protection webservices unauthenticated RCEproofpoint · enterprise protection · CWE-95 | Critical9.8 | — | 0.7% | Mar 7, 2023 |
38Monitor | CVE-2022-46332No exploit | Proofpoint Enterprise Protection (PPS/PoD) XSS in "Attachment Names"proofpoint · enterprise protection · CWE-79 | Critical9.6 | — | 0.6% | Dec 6, 2022 |
36Monitor | CVE-2020-8884No exploit | rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated uproofpoint · insider threat management · CWE-502 | High8.8 | — | 4.1% | Jan 6, 2021 |
35Monitor | CVE-2019-19680No exploit | A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of PPS through 8.9.22 anproofpoint · enterprise protection | High8.8 | — | 1.1% | Jan 13, 2020 |
35Monitor | CVE-2023-0089Proof of concept | Proofpoint Enterprise Protection webutils authenticated RCEproofpoint · enterprise protection · CWE-95 | High8.8 | — | 0.7% | Mar 7, 2023 |
33Monitor | CVE-2021-27900No exploit | The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several pages in the Web Coproofpoint · insider threat management · CWE-862 | High8.1 | — | 2.5% | Apr 6, 2021 |
31Monitor | CVE-2011-1904No exploit | An unspecified function in the web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protectiproofpoint · messaging security gateway · CWE-78 | High7.5 | — | 2.4% | May 5, 2011 |
31Monitor | CVE-2011-1901No exploit | The mail-filter web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3proofpoint · messaging security gateway · CWE-287 | High7.5 | — | 2.0% | May 5, 2011 |
31Monitor | CVE-2021-22159No exploit | Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Management (formerly ObserveIproofpoint · insider threat management · CWE-306 | High7.8 | — | 0.3% | Jan 26, 2021 |
31Monitor | CVE-2022-25294No exploit | Proofpoint Insider Threat Management Agent for Windows relies on an inherently dangerous function that could enable an unprivileged local Wiproofpoint · insider threat management | High7.8 | — | 0.3% | Mar 10, 2022 |
31Monitor | CVE-2022-46334No exploit | Proofpoint Enterprise Protection Local Privilege Escalationproofpoint · enterprise protection · CWE-269 | High7.8 | — | 0.2% | Dec 21, 2022 |
30Monitor | CVE-2011-1903No exploit | SQL injection vulnerability in an unspecified function in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoinproofpoint · messaging security gateway · CWE-89 | High7.5 | — | 1.3% | May 5, 2011 |
30Monitor | CVE-2021-34814No exploit | Proofpoint Spam Engine before 8.12.0-2106240000 has a Security Control Bypass.proofpoint · spam engine | High7.5 | — | 1.0% | Oct 13, 2021 |
30Monitor | CVE-2021-39304No exploit | Proofpoint Enterprise Protection before 8.12.0-2108090000 allows security control bypass.proofpoint · enterprise protection | High7.5 | — | 1.0% | Oct 13, 2021 |
30Monitor | CVE-2024-3676No exploit | The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unproofpoint · enterprise protection · CWE-20 | High7.5 | — | 0.4% | May 14, 2024 |
30Monitor | CVE-2023-4801No exploit | ITM MacOS Agent Improper Certificate Validationproofpoint · insider threat management · CWE-295 | High7.5 | — | 0.3% | Sep 13, 2023 |
29Monitor | CVE-2020-10657No exploit | The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM web console's Iproofpoint · insider threat management server · CWE-502 | High7.2 | — | 2.5% | Jan 6, 2021 |
29Monitor | CVE-2021-27899No exploit | The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validation of the ITM Serverproofpoint · insider threat management · CWE-295 | High7.4 | — | 0.6% | Apr 6, 2021 |
29Monitor | CVE-2021-40843No exploit | Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console.proofpoint · insider threat management server · CWE-502 | High7.3 | — | 0.5% | Oct 13, 2021 |
28Monitor | CVE-2022-46333No exploit | Proofpoint Enterprise Protection perl eval() arbitrary command executionproofpoint · enterprise protection · CWE-94 | High7.2 | — | 1.5% | Dec 6, 2022 |
28Monitor | CVE-2021-22158No exploit | The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) injection in the Web proofpoint · insider threat management · CWE-611 | High7.2 | — | 0.6% | Apr 6, 2021 |
- CVE-2020-1065840Plan
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application ser
CriticalCVSS 9.8No exploitEPSS 3%proofpoint · insider threat management serverJan 6, 2021
- CVE-2020-1065540Plan
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application ser
CriticalCVSS 9.8No exploitEPSS 3%proofpoint · insider threat management serverJan 6, 2021
- CVE-2020-1065640Plan
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM application ser
CriticalCVSS 9.8No exploitEPSS 3%proofpoint · insider threat management serverJan 6, 2021
- CVE-2021-4084239Monitor
Proofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console.
CriticalCVSS 9.8No exploitEPSS 1%proofpoint · insider threat management serverOct 13, 2021
- CVE-2023-009039Monitor
Proofpoint Enterprise Protection webservices unauthenticated RCE
CriticalCVSS 9.8Proof of conceptEPSS 1%proofpoint · enterprise protectionMar 7, 2023
- CVE-2022-4633238Monitor
Proofpoint Enterprise Protection (PPS/PoD) XSS in "Attachment Names"
CriticalCVSS 9.6No exploitEPSS 1%proofpoint · enterprise protectionDec 6, 2022
- CVE-2020-888436Monitor
rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows remote authenticated u
HighCVSS 8.8No exploitEPSS 4%proofpoint · insider threat managementJan 6, 2021
- CVE-2019-1968035Monitor
A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of PPS through 8.9.22 an
HighCVSS 8.8No exploitEPSS 1%proofpoint · enterprise protectionJan 13, 2020
- CVE-2023-008935Monitor
Proofpoint Enterprise Protection webutils authenticated RCE
HighCVSS 8.8Proof of conceptEPSS 1%proofpoint · enterprise protectionMar 7, 2023
- CVE-2021-2790033Monitor
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several pages in the Web Co
HighCVSS 8.1No exploitEPSS 2%proofpoint · insider threat managementApr 6, 2021
- CVE-2011-190431Monitor
An unspecified function in the web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protecti
HighCVSS 7.5No exploitEPSS 2%proofpoint · messaging security gatewayMay 5, 2011
- CVE-2011-190131Monitor
The mail-filter web interface in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoint Protection Server 5.5.3
HighCVSS 7.5No exploitEPSS 2%proofpoint · messaging security gatewayMay 5, 2011
- CVE-2021-2215931Monitor
Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Management (formerly ObserveI
HighCVSS 7.8No exploitEPSS 0%proofpoint · insider threat managementJan 26, 2021
- CVE-2022-2529431Monitor
Proofpoint Insider Threat Management Agent for Windows relies on an inherently dangerous function that could enable an unprivileged local Wi
HighCVSS 7.8No exploitEPSS 0%proofpoint · insider threat managementMar 10, 2022
- CVE-2022-4633431Monitor
Proofpoint Enterprise Protection Local Privilege Escalation
HighCVSS 7.8No exploitEPSS 0%proofpoint · enterprise protectionDec 21, 2022
- CVE-2011-190330Monitor
SQL injection vulnerability in an unspecified function in Proofpoint Messaging Security Gateway 6.2.0.263:6.2.0.237 and earlier in Proofpoin
HighCVSS 7.5No exploitEPSS 1%proofpoint · messaging security gatewayMay 5, 2011
- CVE-2021-3481430Monitor
Proofpoint Spam Engine before 8.12.0-2106240000 has a Security Control Bypass.
HighCVSS 7.5No exploitEPSS 1%proofpoint · spam engineOct 13, 2021
- CVE-2021-3930430Monitor
Proofpoint Enterprise Protection before 8.12.0-2108090000 allows security control bypass.
HighCVSS 7.5No exploitEPSS 1%proofpoint · enterprise protectionOct 13, 2021
- CVE-2024-367630Monitor
The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an un
HighCVSS 7.5No exploitEPSS 0%proofpoint · enterprise protectionMay 14, 2024
- CVE-2023-480130Monitor
ITM MacOS Agent Improper Certificate Validation
HighCVSS 7.5No exploitEPSS 0%proofpoint · insider threat managementSep 13, 2023
- CVE-2020-1065729Monitor
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the ITM web console's I
HighCVSS 7.2No exploitEPSS 3%proofpoint · insider threat management serverJan 6, 2021
- CVE-2021-2789929Monitor
The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validation of the ITM Server
HighCVSS 7.4No exploitEPSS 1%proofpoint · insider threat managementApr 6, 2021
- CVE-2021-4084329Monitor
Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console.
HighCVSS 7.3No exploitEPSS 0%proofpoint · insider threat management serverOct 13, 2021
- CVE-2022-4633328Monitor
Proofpoint Enterprise Protection perl eval() arbitrary command execution
HighCVSS 7.2No exploitEPSS 2%proofpoint · enterprise protectionDec 6, 2022
- CVE-2021-2215828Monitor
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) injection in the Web
HighCVSS 7.2No exploitEPSS 1%proofpoint · insider threat managementApr 6, 2021