Forcepoint kayıtları
forcepoint üreticisine ait 27 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %18,5
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-611 Improper Restriction of XML External Entity Reference2
- CWE-284 Improper Access Control2
- CWE-863 Incorrect Authorization2
- CWE-250 Execution with Unnecessary Privileges2
- CWE-640 Weak Password Recovery Mechanism for Forgotten Password1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
27 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2018-16530İstismar yok | A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a pforcepoint · email security · CWE-787 | Kritik9,8 | — | %3,4 | 9 Nis 2019 |
40Planlayın | CVE-2019-6139İstismar yok | Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001.forcepoint · user id · CWE-434 | Kritik9,8 | — | %2,4 | 7 Şub 2019 |
39İzleyin | CVE-2018-16529İstismar yok | A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x.forcepoint · email security · CWE-640 | Kritik9,8 | — | %1,6 | 28 Mar 2019 |
39İzleyin | CVE-2019-6140İstismar yok | A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hybforcepoint · email security · CWE-284 | Kritik9,8 | — | %1,4 | 9 Nis 2019 |
39İzleyin | CVE-2022-1700İstismar yok | Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), wforcepoint · cloud security gateway · CWE-611 | Kritik9,8 | — | %0,8 | 12 Eyl 2022 |
39İzleyin | CVE-2023-2080İstismar yok | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSGforcepoint · email security · CWE-89 | Kritik9,8 | — | %0,5 | 15 Haz 2023 |
38İzleyin | CVE-2023-6452İstismar yok | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction Vforcepoint · web security · CWE-79 | Kritik9,6 | — | %0,4 | 22 Ağu 2024 |
36İzleyin | CVE-2019-6143İstismar yok | Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authenticforcepoint · next generation firewall · CWE-287 | Kritik9,1 | — | %1,1 | 20 Ağu 2019 |
34İzleyin | CVE-2025-12694İstismar yok | Local Privilege Escalation in VPN Clientforcepoint · vpn client · CWE-250 | Yüksek8,5 | — | %0,1 | 4 Haz 2026 |
31İzleyin | CVE-2025-14026İstismar yok | Vulnerable Python version used in Forcepoint One DLP Clientforcepoint · one data loss prevention · CWE-1104 | Yüksek7,8 | — | %0,2 | 6 Oca 2026 |
31İzleyin | CVE-2023-1705İstismar yok | Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escalaforcepoint · one smartedge agent · CWE-862 | Yüksek7,8 | — | %0,2 | 29 Oca 2024 |
30İzleyin | CVE-2020-6590İstismar yok | Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.forcepoint · data loss prevention · CWE-611 | Yüksek7,5 | — | %1,0 | 8 Nis 2021 |
30İzleyin | CVE-2021-41530İstismar yok | Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP reflected amplification vulnerabilitforcepoint · next generation firewall | Yüksek7,5 | — | %0,9 | 4 Eki 2021 |
29İzleyin | CVE-2025-12690İstismar yok | Local Privilege Escalation in NGFW Engineforcepoint · next generation firewall · CWE-250 | Yüksek7,3 | — | %0,1 | 11 Mar 2026 |
26İzleyin | CVE-2019-6144İstismar yok | This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP andforcepoint · one endpoint · CWE-284 | Orta6,5 | — | %1,0 | 23 Eki 2019 |
26İzleyin | CVE-2019-6145İstismar yok | Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability.forcepoint · vpn client · CWE-428 | Orta6,7 | — | %0,7 | 20 Eyl 2019 |
25İzleyin | CVE-2019-6146Kavram kanıtı | It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection.forcepoint · web security · CWE-79 | Orta6,1 | — | %3,0 | 22 Oca 2020 |
24İzleyin | CVE-2019-6142İstismar yok | It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3.forcepoint · email security · CWE-79 | Orta6,1 | — | %0,6 | 5 Kas 2019 |
24İzleyin | CVE-2023-26290İstismar yok | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSGforcepoint · cloud security gateway · CWE-79 | Orta6,1 | — | %0,4 | 29 Mar 2023 |
24İzleyin | CVE-2023-26291İstismar yok | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSGforcepoint · cloud security gateway · CWE-79 | Orta6,1 | — | %0,4 | 29 Mar 2023 |
24İzleyin | CVE-2023-26292İstismar yok | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSGforcepoint · cloud security gateway · CWE-79 | Orta6,1 | — | %0,4 | 29 Mar 2023 |
24İzleyin | CVE-2024-2166İstismar yok | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Mforcepoint · email security · CWE-79 | Orta6,1 | — | %0,3 | 4 Eyl 2024 |
24İzleyin | CVE-2022-27608İstismar yok | Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administforcepoint · one endpoint · CWE-863 | Orta6,0 | — | %0,2 | 4 Nis 2022 |
24İzleyin | CVE-2022-27609İstismar yok | Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of serviforcepoint · one endpoint · CWE-863 | Orta6,0 | — | %0,2 | 4 Nis 2022 |
23İzleyin | CVE-2004-0112İstismar yok | The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of openssl · openssl · CWE-125 | Orta5,0 | — | %10,4 | 23 Kas 2004 |
- CVE-2018-1653040Planlayın
A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a p
KritikCVSS 9,8İstismar yokEPSS %3forcepoint · email security9 Nis 2019
- CVE-2019-613940Planlayın
Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001.
KritikCVSS 9,8İstismar yokEPSS %2forcepoint · user id7 Şub 2019
- CVE-2018-1652939İzleyin
A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x.
KritikCVSS 9,8İstismar yokEPSS %2forcepoint · email security28 Mar 2019
- CVE-2019-614039İzleyin
A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hyb
KritikCVSS 9,8İstismar yokEPSS %1forcepoint · email security9 Nis 2019
- CVE-2022-170039İzleyin
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), w
KritikCVSS 9,8İstismar yokEPSS %1forcepoint · cloud security gateway12 Eyl 2022
- CVE-2023-208039İzleyin
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG
KritikCVSS 9,8İstismar yokEPSS %1forcepoint · email security15 Haz 2023
- CVE-2023-645238İzleyin
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction V
KritikCVSS 9,6İstismar yokEPSS %0forcepoint · web security22 Ağu 2024
- CVE-2019-614336İzleyin
Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentic
KritikCVSS 9,1İstismar yokEPSS %1forcepoint · next generation firewall20 Ağu 2019
- CVE-2025-1269434İzleyin
Local Privilege Escalation in VPN Client
YüksekCVSS 8,5İstismar yokEPSS %0forcepoint · vpn client4 Haz 2026
- CVE-2025-1402631İzleyin
Vulnerable Python version used in Forcepoint One DLP Client
YüksekCVSS 7,8İstismar yokEPSS %0forcepoint · one data loss prevention6 Oca 2026
- CVE-2023-170531İzleyin
Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escala
YüksekCVSS 7,8İstismar yokEPSS %0forcepoint · one smartedge agent29 Oca 2024
- CVE-2020-659030İzleyin
Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.
YüksekCVSS 7,5İstismar yokEPSS %1forcepoint · data loss prevention8 Nis 2021
- CVE-2021-4153030İzleyin
Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP reflected amplification vulnerabilit
YüksekCVSS 7,5İstismar yokEPSS %1forcepoint · next generation firewall4 Eki 2021
- CVE-2025-1269029İzleyin
Local Privilege Escalation in NGFW Engine
YüksekCVSS 7,3İstismar yokEPSS %0forcepoint · next generation firewall11 Mar 2026
- CVE-2019-614426İzleyin
This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and
OrtaCVSS 6,5İstismar yokEPSS %1forcepoint · one endpoint23 Eki 2019
- CVE-2019-614526İzleyin
Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability.
OrtaCVSS 6,7İstismar yokEPSS %1forcepoint · vpn client20 Eyl 2019
- CVE-2019-614625İzleyin
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection.
OrtaCVSS 6,1Kavram kanıtıEPSS %3forcepoint · web security22 Oca 2020
- CVE-2019-614224İzleyin
It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3.
OrtaCVSS 6,1İstismar yokEPSS %1forcepoint · email security5 Kas 2019
- CVE-2023-2629024İzleyin
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG
OrtaCVSS 6,1İstismar yokEPSS %0forcepoint · cloud security gateway29 Mar 2023
- CVE-2023-2629124İzleyin
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG
OrtaCVSS 6,1İstismar yokEPSS %0forcepoint · cloud security gateway29 Mar 2023
- CVE-2023-2629224İzleyin
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG
OrtaCVSS 6,1İstismar yokEPSS %0forcepoint · cloud security gateway29 Mar 2023
- CVE-2024-216624İzleyin
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time M
OrtaCVSS 6,1İstismar yokEPSS %0forcepoint · email security4 Eyl 2024
- CVE-2022-2760824İzleyin
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administ
OrtaCVSS 6,0İstismar yokEPSS %0forcepoint · one endpoint4 Nis 2022
- CVE-2022-2760924İzleyin
Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of servi
OrtaCVSS 6,0İstismar yokEPSS %0forcepoint · one endpoint4 Nis 2022
- CVE-2004-011223İzleyin
The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of
OrtaCVSS 5,0İstismar yokEPSS %10openssl · openssl23 Kas 2004