VYPR
Vendor

Checkpoint

Products
98
CVEs
152
Across products
203
Status
Private

Products

98
View all 98 products →

Recent CVEs

152
View all 152 CVEs →
  • CVE-2014-7169CriKEVSep 25, 2014
    risk 0.87cvss 9.8epss 1.00

    GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by…

  • CVE-2014-6271CriKEVSep 24, 2014
    risk 0.87cvss 9.8epss 1.00

    GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd,…

  • CVE-2024-24919HigKEVMay 28, 2024
    risk 0.85cvss 8.6epss 1.00

    Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.

  • CVE-2026-16232CriKEVJul 22, 2026
    risk 0.81cvss 9.8epss 0.73

    An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to…

  • CVE-2026-50751CriKEVJun 8, 2026
    risk 0.80cvss 9.3epss 0.83

    A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

  • CVE-2019-8459CriJun 20, 2019
    risk 0.64cvss 9.8epss 0.01

    Check Point Endpoint Security Client for Windows, with the VPN blade, before version E80.83, starts a process without using quotes in the path. This can cause loading of a previously placed executable with a name similar to the parts of the path, instead of the intended one.

  • CVE-2026-18574CriAug 3, 2026
    risk 0.61cvss epss 0.01

    An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management…

  • CVE-2022-41604HigSep 27, 2022
    risk 0.57cvss 8.8epss 0.01

    Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissions for the %PROGRAMDATA%\CheckPoint\ZoneAlarm\Data\Updates directory, and a self-protection driver bypass that allows creation of a…

  • CVE-2020-6013HigJul 6, 2020
    risk 0.57cvss 8.8epss 0.02

    ZoneAlarm Firewall and Antivirus products before version 15.8.109.18436 allow an attacker who already has access to the system to execute code at elevated privileges through a combination of file permission manipulation and exploitation of Windows CVE-2020-00896 on unpatched…

  • CVE-2019-8452HigApr 22, 2019
    risk 0.54cvss 7.8epss 0.01

    A hard-link created from log file archive of Check Point ZoneAlarm up to 15.4.062 or Check Point Endpoint Security client for Windows before E80.96 to any file on the system will get its permission changed so that all users can access that linked file. Doing this on files with…

  • CVE-2026-48132HigMay 26, 2026
    risk 0.53cvss 8.1epss 0.02

    The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary…

  • CVE-2026-48131HigMay 26, 2026
    risk 0.53cvss 8.1epss 0.03

    The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related…

  • CVE-2025-3831HigAug 12, 2025
    risk 0.53cvss 8.1epss 0.00

    Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties.

  • CVE-2021-30356HigApr 22, 2021
    risk 0.53cvss 8.1epss 0.01

    A denial of service vulnerability was reported in Check Point Identity Agent before R81.018.0000, which could allow low privileged users to overwrite protected system files.

  • CVE-2024-24914HigNov 7, 2024
    risk 0.52cvss 8.0epss 0.00

    Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.

  • CVE-2026-10847HigJun 11, 2026
    risk 0.51cvss 7.8epss 0.00

    A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process.…

  • CVE-2024-6233HigNov 22, 2024
    risk 0.51cvss 7.8epss 0.00

    Check Point ZoneAlarm Extreme Security Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Check Point ZoneAlarm Extreme Security. An attacker must first obtain the ability to…

  • CVE-2023-28134HigNov 12, 2023
    risk 0.51cvss 7.8epss 0.00

    Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

  • CVE-2023-28133HigJul 23, 2023
    risk 0.51cvss 7.8epss 0.06

    Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file

  • CVE-2022-23742HigMay 12, 2022
    risk 0.51cvss 7.8epss 0.04

    Check Point Endpoint Security Client for Windows versions earlier than E86.40 copy files for forensics reports from a directory with low privileges. An attacker can replace those files with malicious or linked content, such as exploiting CVE-2020-0896 on unpatched systems or…