Known vulnerabilities in Proofpoint Enterprise Protection

Vendor: Proofpoint
Software CPE: cpe:2.3:a:proofpoint:proofpoint_enterprise_protection:*:*:*:*:*:*:*:*
Total vulnerabilities: 11
Public exploits: 0
Known exploited (KEV): 0
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting Proofpoint Enterprise Protection Proofpoint Enterprise Protection is affected by 11 known vulnerabilities: 1 critical, 7 medium, 3 low Critical High Medium Low

Vulnerabilities (11)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU108032 - Protection Mechanism Failure
CVE-2024-10635
CWE-693 Medium
No
No
8.18.6 patch 5110, 8.20.6 patch 5134, 8.21.0 patch 5112 29.04.2025 SB2025042921
#VU105927 - Improper input validation
CVE-2025-0431
CWE-20 Medium
No
No
8.18.6 patch 5113, 8.20.6 patch 5114, 8.21.0 patch 5115 21.03.2025 SB2025032116
#VU89561 - Improper Access Control
CVE-2024-3676
CWE-284 Medium
No
No
8.18.6 patch 4868, 8.20.0 patch 4869, 8.20.2 patch 4870, 8.20.4 patch 4871, 8.21.0 patch 4872 15.05.2024 SB2024051529
#VU89560 - Server-Side Request Forgery (SSRF)
CVE-2024-0862
CWE-918 Medium
No
No
8.18.6 patch 4868, 8.20.0 patch 4869, 8.20.2 patch 4870, 8.20.4 patch 4871, 8.21.0 patch 4872 15.05.2024 SB2024051529
#VU85270 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-5770
CWE-79 Medium
No
No
8.18.6 patch 4804, 8.20.0 patch 4805, 8.20.2 patch 4809 10.01.2024 SB2024011034
#VU82794 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2023-5771
CWE-79 Medium
No
No
8.18.6 patch 4795, 8.20.0 patch 4796 07.11.2023 SB2023110701
#VU73184 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-0090
CWE-94 Critical
No
No
8.13.22 patch 4566, 8.18.6 patch 4580, 8.19.0 patch 4581, 8.20.0 patch 4570 08.03.2023 SB2023030853
#VU73183 - Improper Control of Generation of Code ('Code Injection')
CVE-2023-0089
CWE-94 Low
No
No
8.13.22 patch 4566, 8.18.6 patch 4580, 8.19.0 patch 4581, 8.20.0 patch 4570 08.03.2023 SB2023030853
#VU70534 - Permissions, Privileges, and Access Controls
CVE-2022-46334
CWE-264 Low
No
No
8.13.22 patch 4548, 8.18.6 patch 4549, 8.19.0 patch 4550 28.12.2022 SB2022122831
#VU70533 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2022-46332
CWE-79 Medium
No
No
8.13.22 patch 4543, 8.18.4 patch 4544, 8.18.6 patch 4545, 8.19.0 patch 4546 28.12.2022 SB2022122830
#VU70532 - Command injection
CVE-2022-46333
CWE-77 Low
No
No
8.13.22 patch 4543, 8.18.4 patch 4544, 8.18.6 patch 4545, 8.19.0 patch 4546 28.12.2022 SB2022122830