Записи Forcepoint
27 опубликованных записей вендора forcepoint.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 18,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-284 Improper Access Control2
- CWE-863 Incorrect Authorization2
- CWE-250 Execution with Unnecessary Privileges2
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
27 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2018-16530Эксплойта нет | A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a pforcepoint · email security · CWE-787 | Критическая9,8 | — | 3,4 % | 9 апр. 2019 г. |
40В плане | CVE-2019-6139Эксплойта нет | Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001.forcepoint · user id · CWE-434 | Критическая9,8 | — | 2,4 % | 7 февр. 2019 г. |
39Наблюдать | CVE-2018-16529Эксплойта нет | A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x.forcepoint · email security · CWE-640 | Критическая9,8 | — | 1,6 % | 28 мар. 2019 г. |
39Наблюдать | CVE-2019-6140Эксплойта нет | A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hybforcepoint · email security · CWE-284 | Критическая9,8 | — | 1,4 % | 9 апр. 2019 г. |
39Наблюдать | CVE-2022-1700Эксплойта нет | Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), wforcepoint · cloud security gateway · CWE-611 | Критическая9,8 | — | 0,8 % | 12 сент. 2022 г. |
39Наблюдать | CVE-2023-2080Эксплойта нет | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSGforcepoint · email security · CWE-89 | Критическая9,8 | — | 0,5 % | 15 июн. 2023 г. |
38Наблюдать | CVE-2023-6452Эксплойта нет | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction Vforcepoint · web security · CWE-79 | Критическая9,6 | — | 0,4 % | 22 авг. 2024 г. |
36Наблюдать | CVE-2019-6143Эксплойта нет | Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authenticforcepoint · next generation firewall · CWE-287 | Критическая9,1 | — | 1,1 % | 20 авг. 2019 г. |
34Наблюдать | CVE-2025-12694Эксплойта нет | Local Privilege Escalation in VPN Clientforcepoint · vpn client · CWE-250 | Высокая8,5 | — | 0,1 % | 4 июн. 2026 г. |
31Наблюдать | CVE-2025-14026Эксплойта нет | Vulnerable Python version used in Forcepoint One DLP Clientforcepoint · one data loss prevention · CWE-1104 | Высокая7,8 | — | 0,2 % | 6 янв. 2026 г. |
31Наблюдать | CVE-2023-1705Эксплойта нет | Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escalaforcepoint · one smartedge agent · CWE-862 | Высокая7,8 | — | 0,2 % | 29 янв. 2024 г. |
30Наблюдать | CVE-2020-6590Эксплойта нет | Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.forcepoint · data loss prevention · CWE-611 | Высокая7,5 | — | 1,0 % | 8 апр. 2021 г. |
30Наблюдать | CVE-2021-41530Эксплойта нет | Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP reflected amplification vulnerabilitforcepoint · next generation firewall | Высокая7,5 | — | 0,9 % | 4 окт. 2021 г. |
29Наблюдать | CVE-2025-12690Эксплойта нет | Local Privilege Escalation in NGFW Engineforcepoint · next generation firewall · CWE-250 | Высокая7,3 | — | 0,1 % | 11 мар. 2026 г. |
26Наблюдать | CVE-2019-6144Эксплойта нет | This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP andforcepoint · one endpoint · CWE-284 | Средняя6,5 | — | 1,0 % | 23 окт. 2019 г. |
26Наблюдать | CVE-2019-6145Эксплойта нет | Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability.forcepoint · vpn client · CWE-428 | Средняя6,7 | — | 0,7 % | 20 сент. 2019 г. |
25Наблюдать | CVE-2019-6146Proof of concept | It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection.forcepoint · web security · CWE-79 | Средняя6,1 | — | 3,0 % | 22 янв. 2020 г. |
24Наблюдать | CVE-2019-6142Эксплойта нет | It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3.forcepoint · email security · CWE-79 | Средняя6,1 | — | 0,6 % | 5 нояб. 2019 г. |
24Наблюдать | CVE-2023-26290Эксплойта нет | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSGforcepoint · cloud security gateway · CWE-79 | Средняя6,1 | — | 0,4 % | 29 мар. 2023 г. |
24Наблюдать | CVE-2023-26291Эксплойта нет | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSGforcepoint · cloud security gateway · CWE-79 | Средняя6,1 | — | 0,4 % | 29 мар. 2023 г. |
24Наблюдать | CVE-2023-26292Эксплойта нет | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSGforcepoint · cloud security gateway · CWE-79 | Средняя6,1 | — | 0,4 % | 29 мар. 2023 г. |
24Наблюдать | CVE-2024-2166Эксплойта нет | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Mforcepoint · email security · CWE-79 | Средняя6,1 | — | 0,3 % | 4 сент. 2024 г. |
24Наблюдать | CVE-2022-27608Эксплойта нет | Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administforcepoint · one endpoint · CWE-863 | Средняя6,0 | — | 0,2 % | 4 апр. 2022 г. |
24Наблюдать | CVE-2022-27609Эксплойта нет | Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of serviforcepoint · one endpoint · CWE-863 | Средняя6,0 | — | 0,2 % | 4 апр. 2022 г. |
23Наблюдать | CVE-2004-0112Эксплойта нет | The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of openssl · openssl · CWE-125 | Средняя5,0 | — | 10,4 % | 23 нояб. 2004 г. |
- CVE-2018-1653040В плане
A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a p
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %forcepoint · email security9 апр. 2019 г.
- CVE-2019-613940В плане
Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %forcepoint · user id7 февр. 2019 г.
- CVE-2018-1652939Наблюдать
A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %forcepoint · email security28 мар. 2019 г.
- CVE-2019-614039Наблюдать
A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hyb
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %forcepoint · email security9 апр. 2019 г.
- CVE-2022-170039Наблюдать
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), w
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %forcepoint · cloud security gateway12 сент. 2022 г.
- CVE-2023-208039Наблюдать
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %forcepoint · email security15 июн. 2023 г.
- CVE-2023-645238Наблюдать
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction V
КритическаяCVSS 9,6Эксплойта нетEPSS 0 %forcepoint · web security22 авг. 2024 г.
- CVE-2019-614336Наблюдать
Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentic
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %forcepoint · next generation firewall20 авг. 2019 г.
- CVE-2025-1269434Наблюдать
Local Privilege Escalation in VPN Client
ВысокаяCVSS 8,5Эксплойта нетEPSS 0 %forcepoint · vpn client4 июн. 2026 г.
- CVE-2025-1402631Наблюдать
Vulnerable Python version used in Forcepoint One DLP Client
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %forcepoint · one data loss prevention6 янв. 2026 г.
- CVE-2023-170531Наблюдать
Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escala
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %forcepoint · one smartedge agent29 янв. 2024 г.
- CVE-2020-659030Наблюдать
Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %forcepoint · data loss prevention8 апр. 2021 г.
- CVE-2021-4153030Наблюдать
Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP reflected amplification vulnerabilit
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %forcepoint · next generation firewall4 окт. 2021 г.
- CVE-2025-1269029Наблюдать
Local Privilege Escalation in NGFW Engine
ВысокаяCVSS 7,3Эксплойта нетEPSS 0 %forcepoint · next generation firewall11 мар. 2026 г.
- CVE-2019-614426Наблюдать
This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and
СредняяCVSS 6,5Эксплойта нетEPSS 1 %forcepoint · one endpoint23 окт. 2019 г.
- CVE-2019-614526Наблюдать
Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability.
СредняяCVSS 6,7Эксплойта нетEPSS 1 %forcepoint · vpn client20 сент. 2019 г.
- CVE-2019-614625Наблюдать
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection.
СредняяCVSS 6,1Proof of conceptEPSS 3 %forcepoint · web security22 янв. 2020 г.
- CVE-2019-614224Наблюдать
It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %forcepoint · email security5 нояб. 2019 г.
- CVE-2023-2629024Наблюдать
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG
СредняяCVSS 6,1Эксплойта нетEPSS 0 %forcepoint · cloud security gateway29 мар. 2023 г.
- CVE-2023-2629124Наблюдать
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG
СредняяCVSS 6,1Эксплойта нетEPSS 0 %forcepoint · cloud security gateway29 мар. 2023 г.
- CVE-2023-2629224Наблюдать
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG
СредняяCVSS 6,1Эксплойта нетEPSS 0 %forcepoint · cloud security gateway29 мар. 2023 г.
- CVE-2024-216624Наблюдать
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time M
СредняяCVSS 6,1Эксплойта нетEPSS 0 %forcepoint · email security4 сент. 2024 г.
- CVE-2022-2760824Наблюдать
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administ
СредняяCVSS 6,0Эксплойта нетEPSS 0 %forcepoint · one endpoint4 апр. 2022 г.
- CVE-2022-2760924Наблюдать
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of servi
СредняяCVSS 6,0Эксплойта нетEPSS 0 %forcepoint · one endpoint4 апр. 2022 г.
- CVE-2004-011223Наблюдать
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of
СредняяCVSS 5,0Эксплойта нетEPSS 10 %openssl · openssl23 нояб. 2004 г.