İçeriğe atla
Noroxi

Forcepoint kayıtları

forcepoint üreticisine ait 27 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
2
Düzeltme kaydı olan
%18,5
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

27 kayıt
  • CVE-2018-16530
    40Planlayın

    A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a p

    KritikCVSS 9,8İstismar yokEPSS %3

    forcepoint · email security9 Nis 2019

  • CVE-2019-6139
    40Planlayın

    Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001.

    KritikCVSS 9,8İstismar yokEPSS %2

    forcepoint · user id7 Şub 2019

  • CVE-2018-16529
    39İzleyin

    A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x.

    KritikCVSS 9,8İstismar yokEPSS %2

    forcepoint · email security28 Mar 2019

  • CVE-2019-6140
    39İzleyin

    A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hyb

    KritikCVSS 9,8İstismar yokEPSS %1

    forcepoint · email security9 Nis 2019

  • CVE-2022-1700
    39İzleyin

    Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), w

    KritikCVSS 9,8İstismar yokEPSS %1

    forcepoint · cloud security gateway12 Eyl 2022

  • CVE-2023-2080
    39İzleyin

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG

    KritikCVSS 9,8İstismar yokEPSS %1

    forcepoint · email security15 Haz 2023

  • CVE-2023-6452
    38İzleyin

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction V

    KritikCVSS 9,6İstismar yokEPSS %0

    forcepoint · web security22 Ağu 2024

  • CVE-2019-6143
    36İzleyin

    Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentic

    KritikCVSS 9,1İstismar yokEPSS %1

    forcepoint · next generation firewall20 Ağu 2019

  • CVE-2025-12694
    34İzleyin

    Local Privilege Escalation in VPN Client

    YüksekCVSS 8,5İstismar yokEPSS %0

    forcepoint · vpn client4 Haz 2026

  • CVE-2025-14026
    31İzleyin

    Vulnerable Python version used in Forcepoint One DLP Client

    YüksekCVSS 7,8İstismar yokEPSS %0

    forcepoint · one data loss prevention6 Oca 2026

  • CVE-2023-1705
    31İzleyin

    Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escala

    YüksekCVSS 7,8İstismar yokEPSS %0

    forcepoint · one smartedge agent29 Oca 2024

  • CVE-2020-6590
    30İzleyin

    Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.

    YüksekCVSS 7,5İstismar yokEPSS %1

    forcepoint · data loss prevention8 Nis 2021

  • CVE-2021-41530
    30İzleyin

    Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP reflected amplification vulnerabilit

    YüksekCVSS 7,5İstismar yokEPSS %1

    forcepoint · next generation firewall4 Eki 2021

  • CVE-2025-12690
    29İzleyin

    Local Privilege Escalation in NGFW Engine

    YüksekCVSS 7,3İstismar yokEPSS %0

    forcepoint · next generation firewall11 Mar 2026

  • CVE-2019-6144
    26İzleyin

    This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and

    OrtaCVSS 6,5İstismar yokEPSS %1

    forcepoint · one endpoint23 Eki 2019

  • CVE-2019-6145
    26İzleyin

    Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability.

    OrtaCVSS 6,7İstismar yokEPSS %1

    forcepoint · vpn client20 Eyl 2019

  • CVE-2019-6146
    25İzleyin

    It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection.

    OrtaCVSS 6,1Kavram kanıtıEPSS %3

    forcepoint · web security22 Oca 2020

  • CVE-2019-6142
    24İzleyin

    It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3.

    OrtaCVSS 6,1İstismar yokEPSS %1

    forcepoint · email security5 Kas 2019

  • CVE-2023-26290
    24İzleyin

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG

    OrtaCVSS 6,1İstismar yokEPSS %0

    forcepoint · cloud security gateway29 Mar 2023

  • CVE-2023-26291
    24İzleyin

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG

    OrtaCVSS 6,1İstismar yokEPSS %0

    forcepoint · cloud security gateway29 Mar 2023

  • CVE-2023-26292
    24İzleyin

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG

    OrtaCVSS 6,1İstismar yokEPSS %0

    forcepoint · cloud security gateway29 Mar 2023

  • CVE-2024-2166
    24İzleyin

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time M

    OrtaCVSS 6,1İstismar yokEPSS %0

    forcepoint · email security4 Eyl 2024

  • CVE-2022-27608
    24İzleyin

    Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administ

    OrtaCVSS 6,0İstismar yokEPSS %0

    forcepoint · one endpoint4 Nis 2022

  • CVE-2022-27609
    24İzleyin

    Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of servi

    OrtaCVSS 6,0İstismar yokEPSS %0

    forcepoint · one endpoint4 Nis 2022

  • CVE-2004-0112
    23İzleyin

    The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of

    OrtaCVSS 5,0İstismar yokEPSS %10

    openssl · openssl23 Kas 2004