Forcepoint records
27 published records for vendor forcepoint.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 18.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-284 Improper Access Control2
- CWE-863 Incorrect Authorization2
- CWE-250 Execution with Unnecessary Privileges2
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
The weakness classes this vendor ships most often: where to look.
CWEAll records
27 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2018-16530No exploit | A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a pforcepoint · email security · CWE-787 | Critical9.8 | — | 3.4% | Apr 9, 2019 |
40Plan | CVE-2019-6139No exploit | Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001.forcepoint · user id · CWE-434 | Critical9.8 | — | 2.4% | Feb 7, 2019 |
39Monitor | CVE-2018-16529No exploit | A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x.forcepoint · email security · CWE-640 | Critical9.8 | — | 1.6% | Mar 28, 2019 |
39Monitor | CVE-2019-6140No exploit | A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hybforcepoint · email security · CWE-284 | Critical9.8 | — | 1.4% | Apr 9, 2019 |
39Monitor | CVE-2022-1700No exploit | Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), wforcepoint · cloud security gateway · CWE-611 | Critical9.8 | — | 0.8% | Sep 12, 2022 |
39Monitor | CVE-2023-2080No exploit | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSGforcepoint · email security · CWE-89 | Critical9.8 | — | 0.5% | Jun 15, 2023 |
38Monitor | CVE-2023-6452No exploit | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction Vforcepoint · web security · CWE-79 | Critical9.6 | — | 0.4% | Aug 22, 2024 |
36Monitor | CVE-2019-6143No exploit | Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authenticforcepoint · next generation firewall · CWE-287 | Critical9.1 | — | 1.1% | Aug 20, 2019 |
34Monitor | CVE-2025-12694No exploit | Local Privilege Escalation in VPN Clientforcepoint · vpn client · CWE-250 | High8.5 | — | 0.1% | Jun 4, 2026 |
31Monitor | CVE-2025-14026No exploit | Vulnerable Python version used in Forcepoint One DLP Clientforcepoint · one data loss prevention · CWE-1104 | High7.8 | — | 0.2% | Jan 6, 2026 |
31Monitor | CVE-2023-1705No exploit | Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escalaforcepoint · one smartedge agent · CWE-862 | High7.8 | — | 0.2% | Jan 29, 2024 |
30Monitor | CVE-2020-6590No exploit | Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.forcepoint · data loss prevention · CWE-611 | High7.5 | — | 1.0% | Apr 8, 2021 |
30Monitor | CVE-2021-41530No exploit | Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP reflected amplification vulnerabilitforcepoint · next generation firewall | High7.5 | — | 0.9% | Oct 4, 2021 |
29Monitor | CVE-2025-12690No exploit | Local Privilege Escalation in NGFW Engineforcepoint · next generation firewall · CWE-250 | High7.3 | — | 0.1% | Mar 11, 2026 |
26Monitor | CVE-2019-6144No exploit | This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP andforcepoint · one endpoint · CWE-284 | Medium6.5 | — | 1.0% | Oct 23, 2019 |
26Monitor | CVE-2019-6145No exploit | Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability.forcepoint · vpn client · CWE-428 | Medium6.7 | — | 0.7% | Sep 20, 2019 |
25Monitor | CVE-2019-6146Proof of concept | It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection.forcepoint · web security · CWE-79 | Medium6.1 | — | 3.0% | Jan 22, 2020 |
24Monitor | CVE-2019-6142No exploit | It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3.forcepoint · email security · CWE-79 | Medium6.1 | — | 0.6% | Nov 5, 2019 |
24Monitor | CVE-2023-26290No exploit | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSGforcepoint · cloud security gateway · CWE-79 | Medium6.1 | — | 0.4% | Mar 29, 2023 |
24Monitor | CVE-2023-26291No exploit | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSGforcepoint · cloud security gateway · CWE-79 | Medium6.1 | — | 0.4% | Mar 29, 2023 |
24Monitor | CVE-2023-26292No exploit | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSGforcepoint · cloud security gateway · CWE-79 | Medium6.1 | — | 0.4% | Mar 29, 2023 |
24Monitor | CVE-2024-2166No exploit | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Mforcepoint · email security · CWE-79 | Medium6.1 | — | 0.3% | Sep 4, 2024 |
24Monitor | CVE-2022-27608No exploit | Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administforcepoint · one endpoint · CWE-863 | Medium6.0 | — | 0.2% | Apr 4, 2022 |
24Monitor | CVE-2022-27609No exploit | Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of serviforcepoint · one endpoint · CWE-863 | Medium6.0 | — | 0.2% | Apr 4, 2022 |
23Monitor | CVE-2004-0112No exploit | The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of openssl · openssl · CWE-125 | Medium5.0 | — | 10.4% | Nov 23, 2004 |
- CVE-2018-1653040Plan
A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a p
CriticalCVSS 9.8No exploitEPSS 3%forcepoint · email securityApr 9, 2019
- CVE-2019-613940Plan
Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001.
CriticalCVSS 9.8No exploitEPSS 2%forcepoint · user idFeb 7, 2019
- CVE-2018-1652939Monitor
A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x.
CriticalCVSS 9.8No exploitEPSS 2%forcepoint · email securityMar 28, 2019
- CVE-2019-614039Monitor
A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hyb
CriticalCVSS 9.8No exploitEPSS 1%forcepoint · email securityApr 9, 2019
- CVE-2022-170039Monitor
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), w
CriticalCVSS 9.8No exploitEPSS 1%forcepoint · cloud security gatewaySep 12, 2022
- CVE-2023-208039Monitor
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG
CriticalCVSS 9.8No exploitEPSS 1%forcepoint · email securityJun 15, 2023
- CVE-2023-645238Monitor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction V
CriticalCVSS 9.6No exploitEPSS 0%forcepoint · web securityAug 22, 2024
- CVE-2019-614336Monitor
Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentic
CriticalCVSS 9.1No exploitEPSS 1%forcepoint · next generation firewallAug 20, 2019
- CVE-2025-1269434Monitor
Local Privilege Escalation in VPN Client
HighCVSS 8.5No exploitEPSS 0%forcepoint · vpn clientJun 4, 2026
- CVE-2025-1402631Monitor
Vulnerable Python version used in Forcepoint One DLP Client
HighCVSS 7.8No exploitEPSS 0%forcepoint · one data loss preventionJan 6, 2026
- CVE-2023-170531Monitor
Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escala
HighCVSS 7.8No exploitEPSS 0%forcepoint · one smartedge agentJan 29, 2024
- CVE-2020-659030Monitor
Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.
HighCVSS 7.5No exploitEPSS 1%forcepoint · data loss preventionApr 8, 2021
- CVE-2021-4153030Monitor
Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP reflected amplification vulnerabilit
HighCVSS 7.5No exploitEPSS 1%forcepoint · next generation firewallOct 4, 2021
- CVE-2025-1269029Monitor
Local Privilege Escalation in NGFW Engine
HighCVSS 7.3No exploitEPSS 0%forcepoint · next generation firewallMar 11, 2026
- CVE-2019-614426Monitor
This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and
MediumCVSS 6.5No exploitEPSS 1%forcepoint · one endpointOct 23, 2019
- CVE-2019-614526Monitor
Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability.
MediumCVSS 6.7No exploitEPSS 1%forcepoint · vpn clientSep 20, 2019
- CVE-2019-614625Monitor
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection.
MediumCVSS 6.1Proof of conceptEPSS 3%forcepoint · web securityJan 22, 2020
- CVE-2019-614224Monitor
It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3.
MediumCVSS 6.1No exploitEPSS 1%forcepoint · email securityNov 5, 2019
- CVE-2023-2629024Monitor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG
MediumCVSS 6.1No exploitEPSS 0%forcepoint · cloud security gatewayMar 29, 2023
- CVE-2023-2629124Monitor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG
MediumCVSS 6.1No exploitEPSS 0%forcepoint · cloud security gatewayMar 29, 2023
- CVE-2023-2629224Monitor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG
MediumCVSS 6.1No exploitEPSS 0%forcepoint · cloud security gatewayMar 29, 2023
- CVE-2024-216624Monitor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time M
MediumCVSS 6.1No exploitEPSS 0%forcepoint · email securitySep 4, 2024
- CVE-2022-2760824Monitor
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administ
MediumCVSS 6.0No exploitEPSS 0%forcepoint · one endpointApr 4, 2022
- CVE-2022-2760924Monitor
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of servi
MediumCVSS 6.0No exploitEPSS 0%forcepoint · one endpointApr 4, 2022
- CVE-2004-011223Monitor
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of
MediumCVSS 5.0No exploitEPSS 10%openssl · opensslNov 23, 2004