Skip to content
Noroxi

Forcepoint records

27 published records for vendor forcepoint.

All records

27 records
  • A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a p

    CriticalCVSS 9.8No exploitEPSS 3%

    forcepoint · email securityApr 9, 2019

  • Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001.

    CriticalCVSS 9.8No exploitEPSS 2%

    forcepoint · user idFeb 7, 2019

  • A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x.

    CriticalCVSS 9.8No exploitEPSS 2%

    forcepoint · email securityMar 28, 2019

  • CVE-2019-6140
    39Monitor

    A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hyb

    CriticalCVSS 9.8No exploitEPSS 1%

    forcepoint · email securityApr 9, 2019

  • CVE-2022-1700
    39Monitor

    Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), w

    CriticalCVSS 9.8No exploitEPSS 1%

    forcepoint · cloud security gatewaySep 12, 2022

  • CVE-2023-2080
    39Monitor

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG

    CriticalCVSS 9.8No exploitEPSS 1%

    forcepoint · email securityJun 15, 2023

  • CVE-2023-6452
    38Monitor

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction V

    CriticalCVSS 9.6No exploitEPSS 0%

    forcepoint · web securityAug 22, 2024

  • CVE-2019-6143
    36Monitor

    Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentic

    CriticalCVSS 9.1No exploitEPSS 1%

    forcepoint · next generation firewallAug 20, 2019

  • Local Privilege Escalation in VPN Client

    HighCVSS 8.5No exploitEPSS 0%

    forcepoint · vpn clientJun 4, 2026

  • Vulnerable Python version used in Forcepoint One DLP Client

    HighCVSS 7.8No exploitEPSS 0%

    forcepoint · one data loss preventionJan 6, 2026

  • CVE-2023-1705
    31Monitor

    Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escala

    HighCVSS 7.8No exploitEPSS 0%

    forcepoint · one smartedge agentJan 29, 2024

  • CVE-2020-6590
    30Monitor

    Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.

    HighCVSS 7.5No exploitEPSS 1%

    forcepoint · data loss preventionApr 8, 2021

  • Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP reflected amplification vulnerabilit

    HighCVSS 7.5No exploitEPSS 1%

    forcepoint · next generation firewallOct 4, 2021

  • Local Privilege Escalation in NGFW Engine

    HighCVSS 7.3No exploitEPSS 0%

    forcepoint · next generation firewallMar 11, 2026

  • CVE-2019-6144
    26Monitor

    This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and

    MediumCVSS 6.5No exploitEPSS 1%

    forcepoint · one endpointOct 23, 2019

  • CVE-2019-6145
    26Monitor

    Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability.

    MediumCVSS 6.7No exploitEPSS 1%

    forcepoint · vpn clientSep 20, 2019

  • CVE-2019-6146
    25Monitor

    It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection.

    MediumCVSS 6.1Proof of conceptEPSS 3%

    forcepoint · web securityJan 22, 2020

  • CVE-2019-6142
    24Monitor

    It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3.

    MediumCVSS 6.1No exploitEPSS 1%

    forcepoint · email securityNov 5, 2019

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG

    MediumCVSS 6.1No exploitEPSS 0%

    forcepoint · cloud security gatewayMar 29, 2023

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG

    MediumCVSS 6.1No exploitEPSS 0%

    forcepoint · cloud security gatewayMar 29, 2023

  • Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG

    MediumCVSS 6.1No exploitEPSS 0%

    forcepoint · cloud security gatewayMar 29, 2023

  • CVE-2024-2166
    24Monitor

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time M

    MediumCVSS 6.1No exploitEPSS 0%

    forcepoint · email securitySep 4, 2024

  • Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administ

    MediumCVSS 6.0No exploitEPSS 0%

    forcepoint · one endpointApr 4, 2022

  • Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of servi

    MediumCVSS 6.0No exploitEPSS 0%

    forcepoint · one endpointApr 4, 2022

  • CVE-2004-0112
    23Monitor

    The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of

    MediumCVSS 5.0No exploitEPSS 10%

    openssl · opensslNov 23, 2004