Known vulnerabilities in Gaia

Software: Gaia
Software CPE: cpe:2.3:h:check_point_software_technologies:gaia:*:*:*:*:*:*:*:*
Total vulnerabilities: 31
Public exploits: 6
Known exploited (KEV): 3
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Gaia Gaia is affected by 31 known vulnerabilities: 2 critical, 8 high, 16 medium, 5 low Critical High Medium Low

Vulnerabilities (31)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU140806 - Improper Authentication
CVE-2026-18574
CWE-287 High
No
No
R81.20 Take 161, R82.10 Take 40, R82 Take 122 03.08.2026 SB2026080387
#VU139241 - Improper Authentication
CVE-2026-16232
CWE-287 Critical
Available
Exploited
R81.20 Take 158, R82 Take 118, R82.10 Take 36 23.07.2026 SB2026072351
#VU139242 - Improper Access Control
CVE-2026-62144
CWE-284 High
No
No
R81.20 Take 158, R82 Take 118, R82.10 Take 36 23.07.2026 SB2026072351
#VU139243 - Improper Privilege Management
CVE-2026-62145
CWE-269 Low
No
No
R81.20 Take 158, R82 Take 118, R82.10 Take 36 23.07.2026 SB2026072351
#VU134144 - Improper Authentication
CVE-2026-50751
CWE-287 High
Available
Exploited
R81.20 Take 113.2, R81.20 Take 120.2, R81.20 Take 127.2, R81.20 Take 141.2, R82.10 Take 6.2, R82.10 Take 19.3, R82 Take 103.2 09.06.2026 SB2026060932
#VU134001 - Improper Certificate Validation
CVE-2026-50752
CWE-295 Medium
No
No
R81.20 Take 113.2, R81.20 Take 120.2, R81.20 Take 127.2, R81.20 Take 141.2, R82.10 Take 6.2, R82.10 Take 19.3, R82 Take 103.2 09.06.2026 SB2026060932
#VU132669 - Improper Access Control
CVE-2026-48136
CWE-284 Low
No
No
R81.20 Take 141, R82 Take 103, R82.10 Take 19 28.05.2026 SB20260528251
#VU132668 - Heap-based Buffer Overflow
CVE-2026-48135
CWE-122 High
No
No
R81.20 Take 141, R82 Take 103, R82.10 Take 19 28.05.2026 SB20260528251
#VU132667 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-48134
CWE-89 Low
No
No
R81.20 Take 141, R82 Take 103, R82.10 Take 19 28.05.2026 SB20260528251
#VU132666 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-48133
CWE-22 Medium
No
No
R81.20 Take 141, R82 Take 103, R82.10 Take 19 28.05.2026 SB20260528251
#VU132665 - Improper input validation
CVE-2026-48132
CWE-20 Medium
No
No
R81.20 Take 141, R82 Take 103, R82.10 Take 19 28.05.2026 SB20260528251
#VU132664 - Heap-based Buffer Overflow
CVE-2026-48131
CWE-122 Medium
No
No
R81.20 Take 141, R82 Take 103, R82.10 Take 19 28.05.2026 SB20260528251
#VU89894 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2024-24919
CWE-22 High
Available
Exploited
- 29.05.2024 SB2024052951
#VU81669 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2023-28130
CWE-78 Low
No
No
R80.40 Take 198, R81 Take 82, R81.10 Take 95, R81.20 Take 14 06.10.2023 SB2023100602
#VU71995 - Use After Free
CVE-2023-0215
CWE-416 Medium
No
No
R81.10 Take 95 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 209 more
#VU71993 - Information Exposure Through Timing Discrepancy
CVE-2022-4304
CWE-208 Medium
No
No
R81.10 Take 95 07.02.2023 SB2023020742
SB2023020748
SB2023020767
and 222 more
#VU71992 - Type confusion
CVE-2023-0286
CWE-843 High
No
No
R81.10 Take 95 07.02.2023 SB2023020742
SB2023020747
SB2023020748
and 223 more
#VU64922 - Missing Encryption of Sensitive Data
CVE-2022-2097
CWE-311 Low
No
No
R81.10 Take 95 05.07.2022 SB2022070509
SB2022070522
SB2022070531
and 112 more
#VU64559 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-2068
CWE-78 Medium
No
No
R81.10 Take 95 21.06.2022 SB2022062120
SB2022062125
SB2022062236
and 135 more
#VU62765 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2022-1292
CWE-78 Medium
Available
No
R81.10 Take 95 03.05.2022 SB2022050315
SB2022050436
SB2022050503
and 141 more


Showing elements 1 - 20 out of 31