Known Vulnerabilities for Endpoint Protection by Sophos
Listed below are 3 of the newest known vulnerabilities associated with "Endpoint Protection" by "Sophos".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-64625 json | AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted... | Not Provided | 2026-07-20 | 2026-07-23 |
| CVE-2026-63098 json | TheHive through 4.1.24 contains an unauthenticated information disclosure vulnerability that allows unauthenticated attackers... | Not Provided | 2026-07-17 | 2026-07-17 |
| CVE-2026-61835 json | Directus is a real-time API and App dashboard for managing SQL database content. Prior to 12.0.0, the SSRF protection on Dire... | Not Provided | 2026-07-15 | 2026-07-21 |
| CVE-2026-60025 json | The Joomla extension Events Booking prior version 5.8.0 had an frontend file upload endpoint that lacked CSRF protection. | Not Provided | 2026-07-17 | 2026-07-20 |
| CVE-2026-58479 json | Sustainable Irrigation Platform (SIP) through version 5.2.16 contains a command injection vulnerability in the optional cli_c... | Not Provided | 2026-07-14 | 2026-07-14 |
| CVE-2026-57947 json | Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows ... | Not Provided | 2026-06-29 | 2026-07-14 |
| CVE-2026-56312 json | Capgo before 12.128.2 contains an improper validation vulnerability in the accept_invitation endpoint that creates user accou... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-50132 json | Budibase is an open-source low-code platform. Prior to 3.39.0, `GET /api/chat-links/:instance/:token/handoff` is a public end... | Not Provided | 2026-06-26 | 2026-06-29 |
| CVE-2026-49433 json | The DeepAI endpoint 'https://api.deepai.org/change_user_email' accepts POST requests without any CSRF protection. If an attac... | Not Provided | 2026-06-01 | 2026-06-01 |
| CVE-2026-48146 json | Budibase is an open-source low-code platform. Prior to 3.39.0, the OAuth2 token fetch function in packages/server/src/sdk/wor... | Not Provided | 2026-05-27 | 2026-05-28 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Sophos | Endpoint Protection | 10.7 |