Check Point Software Ltd.

First CVE: Jan 11, 2017Active for: 10 years
111
CVEs Published
More CVEs Published than 71% of tracked CNAs
11.1
Avg CVEs / Year
More Avg CVEs / Year than 56% of tracked CNAs
7.7
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked CNAs
5.4%
In CISA KEV
Higher KEV Rate than 97% of tracked CNAs

Self-Reporting Analysis

Of all the CVEs published by Check Point Software Ltd. as a CNA, 43.2% affect products that Check Point Software Ltd. develops as a vendor.

43.2%
56.8%
Self-reported: 48Third-party: 63

Of all the CVEs published that affect products developed by Check Point Software Ltd., 36.1% are self-published by Check Point Software Ltd. as a CNA.

36.1%
63.9%
Self-published: 48Published by other CNAs: 85

Trends Over Time

The number and severity of CVEs published by Check Point Software Ltd. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 11, 2017
9 years ago
Most Recent CVE
Jul 22, 2026
2 days ago

Top CVEs

All CVEs published by Check Point Software Ltd. as a CNA, regardless of affected vendor or product.

111 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentica
Jun 8, 20269.398YESYES
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Sof
May 28, 20248.698YESYES
In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field i
Feb 5, 20197.898YESYES
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to au
Jul 22, 20269.182YESNO
TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tam
Mar 30, 20267.875YESNO
mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a m
Nov 17, 20227.869YESNO
LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection
Apr 30, 20208.867NOYES
The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arb
Jan 11, 20179.855NONO
In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFr
Dec 24, 20187.853NONO
In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free. A remote attacker may exploit
Jan 12, 20179.853NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA111 CVEs
Severity distribution among all CVEs352,231 CVEs
LowMediumHighCritical
Attack Vector
Local42 (37.8%)
Network65 (58.6%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network4 (3.6%)
Attack Complexity
Low100 (90.1%)
High11 (9.9%)
Unknown0 (0.0%)
User Interaction
None86 (77.5%)
Unknown0 (0.0%)
Required25 (22.5%)
Privileges Required
Low30 (27.0%)
High11 (9.9%)
None70 (63.1%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (111 CVEs).

CISA KEV
6 CVEs
5.4% of CVEs· 97th percentile
Metasploit
3 CVEs
2.7% of CVEs· 93rd percentile
Nuclei
2 CVEs
1.8% of CVEs· 85th percentile
ExploitDB
4 CVEs
3.6% of CVEs· 93rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Check Point Software Ltd. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Check Point Software Ltd. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs