Proofpoint
49 known vulnerabilities
Top Products
Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allo
Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthent
Proofpoint Enterprise Protection contains a vulnerability in the email delivery agent that allows an unauthenticated att
Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can sen
An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacke
A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) S
A reflected cross-site scripting vulnerability in the UpdateInstalledSoftware endpoint of the Insider Threat Management
An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used
A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an an
A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables
A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on
An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to
An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (
A stored cross-site scripting vulnerability in the Sources UI in Proofpoint Threat Response/ Threat Response Auto Pull (
The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user
The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to
Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privil
The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that e
The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vuln
Proofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control.
Proofpoint Insider Threat Management Agent for Windows relies on an inherently dangerous function that could enable an u
Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An atta
Proofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console. The vulnerability
Proofpoint Enterprise Protection before 8.12.0-2108090000 allows security control bypass.
Proofpoint Spam Engine before 8.12.0-2106240000 has a Security Control Bypass.
Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to delive
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several
The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validati
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) i
Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.11.1 allows stored XSS.
Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Managemen
rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows re
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the
The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the
An issue was discovered in Proofpoint Email Protection through 2019-09-08. By collecting scores from Proofpoint email he
A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of P
Frequently Asked Questions
How many CVEs affect Proofpoint?
Proofpoint has 49 CVE records in our database, including 6 critical and 21 high severity vulnerabilities.
What are the most severe Proofpoint vulnerabilities?
Proofpoint has 6 critical severity (CVSS 9.0+) and 21 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Proofpoint vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Proofpoint products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Proofpoint Vulnerabilities
CyberStrike scans your infrastructure for Proofpoint vulnerabilities and provides real-time remediation guidance.
Get Started