Skip to main content
0-Doubt
NewsInvestorsQuestionnairesDeveloperHelp
AnonymousSign in
0-Doubt — neutral IT/Security research
BrowseResellersCertified analystsRFI/RFP questionnairesHow trust worksHelp & FAQAPI
  1. Home/
  2. FireEye/
  3. FireEye Endpoint Security APIs

FireEye Endpoint Security APIs

AI-generated from public sourcesAuto-generated by 0-Doubt from public vendor materials. Not verified by the vendor or an analyst. Check the freshness indicator.Lowest independence — unverified. A higher label means a more independent source — not a better product.How trust works →Secure coding rating: 0/100How this score is computedA product with no known CVEs starts at a neutral score and climbs the longer it goes without one; a product with known CVEs is penalized by severity instead. This one has 11 known CVEs (vendor-level match — see the CVE list below) and is tracked as ~39 days old in our catalog (a stand-in for real release date, which we don't track). The platform admin controls the formula's weights.

APIs for FireEye endpoint security management and monitoring operations

by FireEye · fireeye.dev · source ↗

Known CVEs (11)About this listSourced from the public NVD database, matched by vendor name. Shown here at the vendor level — we don't track per-product/version data, so a listed CVE may affect a different product from this vendor, not necessarily this one. “New” means published within the last 30 days. “Actively exploited” means CISA's Known Exploited Vulnerabilities (KEV) catalog confirms real-world exploitation, not just a theoretical severity score.

RSS ⇢
  • CVE-2025-0618 ↗MEDIUM 6.52025

    A malicious third party could invoke a persistent denial of service vulnerability in FireEye EDR agent by sending a specially-crafted tamper protection event to the HX service to trigger an exception.…

  • CVE-2024-0320 ↗MEDIUM 5.42024

    Cross-Site Scripting in FireEye Malware Analysis (AX) affecting version 9.0.3.936530. This vulnerability allows an attacker to send a specially crafted JavaScript payload in the application URL to ret…

  • CVE-2024-0319 ↗MEDIUM 5.42024

    Open Redirect vulnerability in FireEye HXTool affecting version 4.6, the exploitation of which could allow an attacker to redirect a legitimate user to a malicious page by changing the 'redirect_uri' …

  • CVE-2024-0318 ↗MEDIUM 5.42024

    Cross-Site Scripting in FireEye HXTool affecting version 4.6. This vulnerability allows an attacker to store a specially crafted JavaScript payload in the 'Profile Name' and 'Hostname/IP' parameters t…

  • CVE-2024-0317 ↗MEDIUM 5.42024

    Cross-Site Scripting in FireEye EX, affecting version 9.0.3.936727. Exploitation of this vulnerability allows an attacker to send a specially crafted JavaScript payload via the 'type' and 's_f_name' p…

  • CVE-2024-0316 ↗MEDIUM 6.82024

    Improper cleanup vulnerability in exceptions thrown in FireEye Endpoint Security, affecting version 5.2.0.958244. This vulnerability could allow an attacker to send multiple request packets to the con…

  • CVE-2024-0315 ↗MEDIUM 6.62024

    Remote file inclusion vulnerability in FireEye Central Management affecting version 9.1.1.956704. This vulnerability allows an attacker to upload a malicious PDF file to the system during the report c…

  • CVE-2024-0314 ↗MEDIUM 5.42024

    XSS vulnerability in FireEye Central Management affecting version 9.1.1.956704, which could allow an attacker to modify special HTML elements in the application and cause a reflected XSS, leading to a…

  • CVE-2021-28970 ↗MEDIUM 6.52021

    eMPS 9.0.1.923211 on the Central Management of FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the job_id parameter to the email search feature. Accordin…

  • CVE-2021-28969 ↗MEDIUM 6.52021

    eMPS 9.0.1.923211 on FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort_by parameter to the email search feature. According to the vendor, the issu…

  • CVE-2020-25034 ↗MEDIUM 6.52020

    eMPS prior to eMPS 9.0 FireEye EX 3500 devices allows remote authenticated users to conduct SQL injection attacks via the sort, sort_by, search{URL], or search[attachment] parameter to the email searc…

Materials

0

No datasheets, whitepapers, case studies, videos, or demos linked yet.

Other Endpoint Detection & Response products

see all →
  • 360 High-Risk Vulnerability Immunization Tool V2.0 · 360 Security Group (Qihoo 360)
  • AI EdgeLabs Host Platform Security · AI EdgeLabs
  • AVG AntiVirus FREE · AVG
  • AVG Antivirus Free for Mac · AVG
  • Abatis System · Abatis
  • Absolute Ransomware Response · Absolute
  • Absolute Resilience · Absolute
  • Absolute Resilience for Security · Absolute