Proofpoint Inc.
First CVE: Dec 6, 2022Active for: 4 years
22
CVEs Published
More CVEs Published than 42% of tracked CNAs
5.5
Avg CVEs / Year
More Avg CVEs / Year than 34% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Proofpoint Inc. as a CNA, 86.4% affect products that Proofpoint Inc. develops as a vendor.
86.4%
13.6%
Self-reported: 19Third-party: 3
Of all the CVEs published that affect products developed by Proofpoint Inc., 43.2% are self-published by Proofpoint Inc. as a CNA.
43.2%
56.8%
Self-published: 19Published by other CNAs: 25
Trends Over Time
The number and severity of CVEs published by Proofpoint Inc. over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2022
3 years ago
Most Recent CVE
Nov 3, 2025
262 days ago
Top CVEs
All CVEs published by Proofpoint Inc. as a CNA, regardless of affected vendor or product.
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-46332CRITICAL The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain adm | Dec 6, 2022 | 9.6 | 30 | NO | NO |
CVE-2023-0090CRITICAL The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitati | Mar 8, 2023 | 9.8 | 29 | NO | NO |
CVE-2023-0089HIGH
The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'.
This affects | Mar 8, 2023 | 8.8 | 25 | NO | NO |
CVE-2022-46334HIGH Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versio | Dec 21, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-46333HIGH The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute commands beyond their allowed sco | Dec 6, 2022 | 7.2 | 24 | NO | NO |
CVE-2023-4801HIGH An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a | Sep 13, 2023 | 7.5 | 22 | NO | NO |
CVE-2023-2820MEDIUM An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent networ | Jun 14, 2023 | 6.8 | 21 | NO | NO |
CVE-2025-8558MEDIUM Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform a | Nov 3, 2025 | 5.4 | 20 | NO | NO |
CVE-2024-3676HIGH The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a spe | May 14, 2024 | 7.5 | 20 | NO | NO |
CVE-2023-5771MEDIUM Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can send a specially crafted email with HTML in the subject which t | Nov 6, 2023 | 6.1 | 20 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA22 CVEs
68%
23%
9%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (9.1%)
Network13 (59.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network7 (31.8%)
Attack Complexity
Low19 (86.4%)
High3 (13.6%)
Unknown0 (0.0%)
User Interaction
None16 (72.7%)
Unknown0 (0.0%)
Required6 (27.3%)
Privileges Required
Low6 (27.3%)
High4 (18.2%)
None12 (54.5%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (22 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
An overview of all social media posts that mention a CVE ID published by Proofpoint Inc. as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Proofpoint Inc. as a CNA — matched by CVE ID, not by organization name.