Check Point Software Ltd.
Self-Reporting Analysis
Of all the CVEs published by Check Point Software Ltd. as a CNA, 43.2% affect products that Check Point Software Ltd. develops as a vendor.
Of all the CVEs published that affect products developed by Check Point Software Ltd., 36.1% are self-published by Check Point Software Ltd. as a CNA.
Trends Over Time
The number and severity of CVEs published by Check Point Software Ltd. over time
Top CVEs
All CVEs published by Check Point Software Ltd. as a CNA, regardless of affected vendor or product.
111 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-50751CRITICAL A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentica | Jun 8, 2026 | 9.3 | 98 | YES | YES |
CVE-2024-24919HIGH Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Sof | May 28, 2024 | 8.6 | 98 | YES | YES |
CVE-2018-20250HIGH In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field i | Feb 5, 2019 | 7.8 | 98 | YES | YES |
CVE-2026-16232CRITICAL An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to au | Jul 22, 2026 | 9.1 | 82 | YES | NO |
CVE-2026-3502HIGH TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tam | Mar 30, 2026 | 7.8 | 75 | YES | NO |
CVE-2022-23748HIGH mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a m | Nov 17, 2022 | 7.8 | 69 | YES | NO |
CVE-2020-6010HIGH LearnPress Wordpress plugin version prior and including 3.2.6.7 is vulnerable to SQL Injection | Apr 30, 2020 | 8.8 | 67 | NO | YES |
CVE-2016-7480CRITICAL The SplObjectStorage unserialize implementation in ext/spl/spl_observer.c in PHP before 7.0.12 does not verify that a key is an object, which allows remote attackers to execute arb | Jan 11, 2017 | 9.8 | 55 | NO | NO |
CVE-2018-20247HIGH In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFr | Dec 24, 2018 | 7.8 | 53 | NO | NO |
CVE-2016-7479CRITICAL In all versions of PHP 7, during the unserialization process, resizing the 'properties' hash table of a serialized object may lead to use-after-free. A remote attacker may exploit | Jan 12, 2017 | 9.8 | 53 | NO | NO |
CVE Severity & Scoring
Exploit Exposure
Signals from CVEs in this cna scope (111 CVEs).
Social Chatter
An overview of all social media posts that mention a CVE ID published by Check Point Software Ltd. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Check Point Software Ltd. as a CNA — matched by CVE ID, not by organization name.