Proofpoint Inc.

First CVE: Dec 6, 2022Active for: 4 years
22
CVEs Published
More CVEs Published than 42% of tracked CNAs
5.5
Avg CVEs / Year
More Avg CVEs / Year than 34% of tracked CNAs
6.2
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Proofpoint Inc. as a CNA, 86.4% affect products that Proofpoint Inc. develops as a vendor.

86.4%
13.6%
Self-reported: 19Third-party: 3

Of all the CVEs published that affect products developed by Proofpoint Inc., 43.2% are self-published by Proofpoint Inc. as a CNA.

43.2%
56.8%
Self-published: 19Published by other CNAs: 25

Trends Over Time

The number and severity of CVEs published by Proofpoint Inc. over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 6, 2022
3 years ago
Most Recent CVE
Nov 3, 2025
262 days ago

Top CVEs

All CVEs published by Proofpoint Inc. as a CNA, regardless of affected vendor or product.

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
The Admin Smart Search feature in Proofpoint Enterprise Protection (PPS/PoD) contains a stored cross-site scripting vulnerability that enables an anonymous email sender to gain adm
Dec 6, 20229.630NONO
The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitati
Mar 8, 20239.829NONO
The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'. This affects
Mar 8, 20238.825NONO
Proofpoint Enterprise Protection (PPS/PoD) contains a vulnerability which allows the pps user to escalate to root privileges due to unnecessary permissions. This affects all versio
Dec 21, 20227.825NONO
The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute commands beyond their allowed sco
Dec 6, 20227.224NONO
An improper certification validation vulnerability in the Insider Threat Management (ITM) Agent for MacOS could be used by an anonymous actor on an adjacent network to establish a
Sep 13, 20237.522NONO
An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent networ
Jun 14, 20236.821NONO
Insider Threat Management (ITM) Server versions prior to 7.17.2 contain an authentication bypass vulnerability that allows unauthenticated users on an adjacent network to perform a
Nov 3, 20255.420NONO
The Proofpoint Encryption endpoint of Proofpoint Enterprise Protection contains an Improper Input Validation vulnerability that allows an unauthenticated remote attacker with a spe
May 14, 20247.520NONO
Proofpoint Enterprise Protection contains a stored XSS vulnerability in the AdminUI. An unauthenticated attacker can send a specially crafted email with HTML in the subject which t
Nov 6, 20236.120NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA22 CVEs
Severity distribution among all CVEs352,101 CVEs
MediumHighCritical
Attack Vector
Local2 (9.1%)
Network13 (59.1%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network7 (31.8%)
Attack Complexity
Low19 (86.4%)
High3 (13.6%)
Unknown0 (0.0%)
User Interaction
None16 (72.7%)
Unknown0 (0.0%)
Required6 (27.3%)
Privileges Required
Low6 (27.3%)
High4 (18.2%)
None12 (54.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Proofpoint Inc. as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Proofpoint Inc. as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs