Skip to main content

Vendor archive

checkpoint CVEs

Beta · best-effort

130 CVEs tagged to vendor checkpoint10 Critical, 61 High, 52 Medium, 7 Low, 0 Unrated.

CVE-2025-2028

Published Aug 6, 2025

Lack of TLS validation when downloading a CSV file including mapping from IPs to countries used ONLY for displaying country flags in logs

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-24914

Published Nov 7, 2024

Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available.

CVSS 8.0 · High

CVE-2024-24919

Published May 28, 2024

Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access So…

CVSS 8.6 · High
evidence mentions
21
Buzz score
72.5
KEV listed

CVE-2023-28134

Published Nov 12, 2023

Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute l…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23746

Published Nov 30, 2022

The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-41604

Published Sep 27, 2022

Check Point ZoneAlarm Extreme Security before 15.8.211.19229 allows local users to escalate privileges. This occurs because of weak permissions for the %PROGRAMDATA%\CheckPoint\Zo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23745

Published Jul 18, 2022

A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS). This could result in application crashing but could not be used to gather a…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2022-23743

Published May 11, 2022

Check Point ZoneAlarm before version 15.8.200.19118 allows a local actor to escalate privileges during the upgrade process. In addition, weak permissions in the ProgramData\CheckP…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort
Showing 1-25 of 130 CVEsPage 1 of 6