Proofpoint
Proofpoint Enterprise Protection: vulnerabilidades y CVE
Proofpoint Enterprise Protection tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-10635 | Media (5.3) | 0.31% | — | 28 abr 2025 | Enterprise Protection contains an improper input validation vulnerability in attachment defense that allows an unauthenticated remote attacker to bypass attachment scanning security policy by sending a malicious S/MIME… |
| CVE-2025-0431 | Media (5.8) | 0.41% | — | 19 mar 2025 | Enterprise Protection contains a vulnerability in URL rewriting that allows an unauthenticated remote attacker to send an email which bypasses URL protections impacting the integrity of recipient's email. This occurs… |
| CVE-2024-3676 | Alta (7.5) | 0.36% | — | 14 may 2024 | The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a specially crafted HTTP request to create… |
| CVE-2024-0862 | Media (5) | 0.19% | — | 14 may 2024 | The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains a Server-Side Request Forgery vulnerability that allows an authenticated user to relay HTTP requests from the Protection server to… |
| CVE-2023-5770 | Media (5.4) | 0.34% | — | 9 ene 2024 | Proofpoint Enterprise Protection contains a vulnerability in the email delivery agent that allows an unauthenticated attacker to inject improperly encoded HTML into the email body of a message through the email subject.… |
| CVE-2023-5771 | Media (6.1) | 0.34% | — | 6 nov 2023 | Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can send a specially crafted email with HTML in the subject which triggers XSS when viewing quarantined… |
| CVE-2023-0090 | Crítica (9.8) | 0.74% | — | 8 mar 2023 | The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the… |
| CVE-2023-0089 | Alta (8.8) | 0.74% | — | 8 mar 2023 | The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'. This affects all versions 8.20.0 and below. |
| CVE-2022-46334 | Alta (7.8) | 0.17% | — | 21 dic 2022 | Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versions 8.19.0 and below. |
| CVE-2022-46333 | Alta (7.2) | 1.5% | — | 6 dic 2022 | The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute commands beyond their allowed scope. This affects all versions 8.19.0… |
| CVE-2022-46332 | Crítica (9.6) | 0.63% | — | 6 dic 2022 | The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain admin privileges within the user… |
| CVE-2021-31608 | Media (4.3) | 0.44% | — | 17 nov 2022 | Proofpoint Enterprise Protection before 18.8.0 allows a Bypass of a Security Control. |
| CVE-2021-39304 | Alta (7.5) | 1.0% | — | 13 oct 2021 | Proofpoint Enterprise Protection before 8.12.0-2108090000 allows security control bypass. |
| CVE-2020-14009 | Media (6.3) | 0.32% | — | 7 may 2021 | Proofpoint Enterprise Protection (PPS/PoD) before 8.16.4 contains a vulnerability that could allow an attacker to deliver an email message with a malicious attachment that bypasses scanning and file-blocking rules. The… |
| CVE-2019-19680 | Alta (8.8) | 1.1% | — | 13 ene 2020 | A file-extension filtering vulnerability in Proofpoint Enterprise Protection (PPS / PoD), in the unpatched versions of PPS through 8.9.22 and 8.14.2 respectively, allows attackers to bypass protection mechanisms… |