Skip to content
VulniPulse

Complete feed

Action required

Critical/high still unreviewed, or CISA KEV listed

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Critical9.8Sophos

Critical [CVE-2022-3980] Sophos Mobile: XML External Entity (XEE) vulnerability

An XML External Entity (XEE) vulnerability allows server-side request forgery (SSRF) and potential code execution in Sophos Mobile managed on-premises between versions 5.0.0 and 9.7.4.

CVE-2022-3980
Sophos Mobile / Connect
Nov 16, 2022
Critical9.8Sophos Exploited CISA KEV

Critical [CVE-2022-3236] Sophos Firewall: code injection vulnerability in the User Portal and Webadmin

A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.

CVE-2022-3236
Sophos Firewall (XGS/SFOS)
Sep 23, 2022
High7.2Sophos

High [CVE-2022-1807] Sophos Firewall: Multiple SQLi vulnerabilities in Webadmin

Multiple SQLi vulnerabilities in Webadmin allow for privilege escalation from admin to super-admin in Sophos Firewall older than version 18.5 MR4 and version 19.0 MR1.

CVE-2022-1807
Sophos Firewall (XGS/SFOS)
Sep 7, 2022
High8.4Sophos

High [CVE-2021-25268] Sophos Firewall: Multiple XSS vulnerabilities in Webadmin

Multiple XSS vulnerabilities in Webadmin allow for privilege escalation from MySophos admin to SFOS admin in Sophos Firewall older than version 19.0 GA.

CVE-2021-25268
Sophos Firewall (XGS/SFOS)
May 5, 2022
Critical9.8Sophos Exploited CISA KEV

Critical [CVE-2022-1040] Sophos Firewall: authentication bypass vulnerability in the User Portal and Webadmin

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

CVE-2022-1040
Sophos Firewall (XGS/SFOS)
Mar 25, 2022
High8.8Sophos

High [CVE-2022-0386] Sophos UTM: post-auth SQL injection vulnerability in the Mail Manager potentially

A post-auth SQL injection vulnerability in the Mail Manager potentially allows an authenticated attacker to execute code in Sophos UTM before version 9.710.

CVE-2022-0386
Sophos UTM
Mar 22, 2022
High8.8Sophos

High [CVE-2022-0366] authenticated and authorized agent user could potentially gain administrative access

An authenticated and authorized agent user could potentially gain administrative access via an SQLi vulnerability to Capsule8 Console between versions 4.6.0 and 4.9.1.

CVE-2022-0366
Unclassified
Feb 2, 2022
High8.8Sophos

High [CVE-2021-36807] authenticated user could potentially execute code

An authenticated user could potentially execute code via an SQLi vulnerability in the user portal of SG UTM before version 9.708 MR8.

CVE-2021-36807
Unclassified
Nov 26, 2021
High8.8Sophos

High [CVE-2021-25265] Sophos Connect: malicious website could execute code remotely in Sophos Connect Client before version 2.1.

A malicious website could execute code remotely in Sophos Connect Client before version 2.1.

CVE-2021-25265
Sophos Mobile / Connect
Mar 22, 2021