Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

Proofpoint

49 known vulnerabilities

6
CRITICAL
15
HIGH
16
MEDIUM
1
LOW

Top Products

enterprise protection 12 insider threat management 12 insider threat management server 10 threat response auto pull 2 spam engine 1 email protection 1
38 CVEs
5.4
CVE-2025-8558

Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allo

6.1
CVE-2024-10635

Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthent

5.3
CVE-2023-5770

Proofpoint Enterprise Protection contains a vulnerability in the email delivery agent that allows an unauthenticated att

6.1
CVE-2023-5771

Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can sen

6.4
CVE-2023-4828

An improper check for an exceptional condition in the Insider Threat Management (ITM) Server could be used by an attacke

4.8
CVE-2023-4803

A reflected cross-site scripting vulnerability in the WriteWindowTitle endpoint of the Insider Threat Management (ITM) S

4.8
CVE-2023-4802

A reflected cross-site scripting vulnerability in the UpdateInstalledSoftware endpoint of the Insider Threat Management

7.5
CVE-2023-4801

An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used

4.3
CVE-2023-36002

A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an an

6.5
CVE-2023-36000

A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables

4.6
CVE-2023-35998

A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on

5.5
CVE-2023-2818

An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to

6.1
CVE-2023-2820

An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (

4.3
CVE-2023-2819

A stored cross-site scripting vulnerability in the Sources UI in Proofpoint Threat Response/ Threat Response Auto Pull (

9.8
CVE-2023-0090

The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user

8.8
CVE-2023-0089

The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to

7.8
CVE-2022-46334

Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privil

7.2
CVE-2022-46333

The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that e

9.6
CVE-2022-46332

The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vuln

4.3
CVE-2021-31608

Proofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control.

7.8
CVE-2022-25294

Proofpoint Insider Threat Management Agent for Windows relies on an inherently dangerous function that could enable an u

7.3
CVE-2021-40843

Proofpoint Insider Threat Management Server contains an unsafe deserialization vulnerability in the Web Console. An atta

9.8
CVE-2021-40842

Proofpoint Insider Threat Management Server contains a SQL injection vulnerability in the Web Console. The vulnerability

7.5
CVE-2021-39304

Proofpoint Enterprise Protection before 8.12.0-2108090000 allows security control bypass.

7.5
CVE-2021-34814

Proofpoint Spam Engine before 8.12.0-2106240000 has a Security Control Bypass.

6.3
CVE-2020-14009

Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to delive

8.1
CVE-2021-27900

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is missing an authorization check on several

7.4
CVE-2021-27899

The Proofpoint Insider Threat Management Agents (formerly ObserveIT Agent) for MacOS and Linux perform improper validati

7.2
CVE-2021-22158

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) is vulnerable to XML external entity (XXE) i

6.1
CVE-2021-22157

Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.11.1 allows stored XSS.

7.8
CVE-2021-22159

Insider Threat Management Windows Agent Local Privilege Escalation Vulnerability The Proofpoint Insider Threat Managemen

8.8
CVE-2020-8884

rcdsvc in the Proofpoint Insider Threat Management Windows Agent (formerly ObserveIT Windows Agent) before 7.9 allows re

9.8
CVE-2020-10658

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the

7.2
CVE-2020-10657

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the

9.8
CVE-2020-10656

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the

9.8
CVE-2020-10655

The Proofpoint Insider Threat Management Server (formerly ObserveIT Server) before 7.9.1 contains a vulnerability in the

3.7
CVE-2019-20634

An issue was discovered in Proofpoint Email Protection through 2019-09-08. By collecting scores from Proofpoint email he

8.8
CVE-2019-19680

A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of P

Frequently Asked Questions

How many CVEs affect Proofpoint?

Proofpoint has 49 CVE records in our database, including 6 critical and 21 high severity vulnerabilities.

What are the most severe Proofpoint vulnerabilities?

Proofpoint has 6 critical severity (CVSS 9.0+) and 21 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.

How can I scan for Proofpoint vulnerabilities?

CyberStrike's AI-powered security agents automatically detect vulnerabilities in Proofpoint products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.

Detect Proofpoint Vulnerabilities

CyberStrike scans your infrastructure for Proofpoint vulnerabilities and provides real-time remediation guidance.

Get Started