Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.
Assigner (CNA / source):[email protected] Remove this filter
| CVE | Description | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|
| CVE-2026-10847 | A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation could allow an attacker to gain elevated privileges on the affected Windows endpoint. | 7.8 | 0.12% | 2026-06-11 | 2026-06-17 |
| CVE-2026-50752 | A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN site-to-site connections that use certificate-based authentication. Successful exploitation could allow interception or modification of traffic traversing the VPN tunnel. | 7.4 | 4.86% | 2026-06-08 | 2026-06-17 |
| CVE-2026-50751 KEV | A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password. | 9.3 | 70.10% | 2026-06-08 | 2026-06-17 |
| CVE-2026-48133 | When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway. | 7.5 | 4.75% | 2026-05-26 | 2026-06-17 |
| CVE-2026-48132 | The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted or malformed packet can cause the VPN processing service to terminate unexpectedly, leading to denial of service (temporary interruption of VPN negotiations/traffic). | 8.1 | 2.14% | 2026-05-26 | 2026-06-17 |
| CVE-2026-48131 | The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This can cause the service to terminate unexpectedly, resulting in denial of service (temporary disruption of VPN-related functionality). | 8.1 | 2.66% | 2026-05-26 | 2026-06-17 |
| CVE-2026-3502 KEV | TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user. | 7.8 | 5.75% | 2026-03-30 | 2026-06-17 |
| CVE-2025-9142 | A local user can trigger Harmony SASE Windows client to write or delete files outside the intended certificate working directory. | 7.5 | 0.07% | 2026-01-14 | 2026-06-17 |
| CVE-2025-3831 | Log files uploaded during troubleshooting by the Harmony SASE agent may have been accessible to unauthorized parties. | 8.1 | 0.37% | 2025-08-12 | 2026-06-17 |
| CVE-2024-24914 | Authenticated Gaia users can inject code or commands by global variables through special HTTP requests. A Security fix that mitigates this vulnerability is available. | 8.0 | 0.40% | 2024-11-07 | 2026-06-17 |
| CVE-2024-24919 KEV | Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available. | 8.6 | 99.98% | 2024-05-28 | 2026-06-17 |
| CVE-2024-24910 | A local attacker can erscalate privileges on affected Check Point ZoneAlarm ExtremeSecurity NextGen, Identity Agent for Windows, and Identity Agent for Windows Terminal Server. To exploit this vulnerability, an attacker must first obtain the ability to execute local privileged code on the target system. | 7.3 | 0.15% | 2024-04-18 | 2026-06-17 |
| CVE-2023-28134 | Local attacker can escalate privileges on affected installations of Check Point Harmony Endpoint/ZoneAlarm Extreme Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | 7.8 | 0.24% | 2023-11-12 | 2026-06-17 |
| CVE-2023-28130 | Local user may lead to privilege escalation using Gaia Portal hostnames page. | 7.2 | 21.38% | 2023-07-26 | 2026-06-17 |
| CVE-2023-28133 | Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file | 7.8 | 5.70% | 2023-07-23 | 2026-06-17 |
| CVE-2023-28131 | A vulnerability in the expo.io framework allows an attacker to take over accounts and steal credentials on an application/website that configured the "Expo AuthSession Redirect Proxy" for social sign-in. This can be achieved once a victim clicks a malicious link. The link itself may be sent to the victim in various ways (including email, text message, an attacker-controlled website, etc). | 9.6 | 22.99% | 2023-04-24 | 2026-06-17 |
| CVE-2022-23746 | The IPsec VPN blade has a dedicated portal for downloading and connecting through SSL Network Extender (SNX). If the portal is configured for username/password authentication, it is vulnerable to a brute-force attack on usernames and passwords. | 7.5 | 0.59% | 2022-11-30 | 2026-06-17 |
| CVE-2022-23748 KEV | mDNSResponder.exe is vulnerable to DLL Sideloading attack. Executable improperly specifies how to load the DLL, from which folder and under what conditions. In these scenarios, a malicious attacker could be using the valid and legitimate executable to load malicious files. | 7.8 | 9.09% | 2022-11-17 | 2026-06-17 |
| CVE-2022-23747 | In Sony Xperia series 1, 5, and Pro, an out of bound memory access can occur due to lack of validation of the number of frames being passed during music playback. | 9.8 | 10.01% | 2022-08-17 | 2026-06-17 |
| CVE-2022-23745 | A potential memory corruption issue was found in Capsule Workspace Android app (running on GrapheneOS). This could result in application crashing but could not be used to gather any sensitive information. | 7.5 | 15.21% | 2022-07-18 | 2026-06-17 |