Vulnerability index

Browse CVEs

25 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Vpn Client HIGH 7.8
CVE-2025-12694

A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYST…

Fix: 6.11.3+
Fix from $1,950 2026-06-04
Web Security MEDIUM 6.1
CVE-2025-2274

Improper Neutralization of Input During Web Page Generation in Forcepoint Web Security (On-Prem) on Windows allows Stored XSS.This issue affects Web …

Fix: after 8.5.6
Fix from $1,600 2026-03-16
Next Generation Firewall HIGH 7.8
CVE-2025-12690

Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGFW Engine through 6.10.19, thr…

Fix: 6.10.20 / 7.1.11+
Fix from $1,950 2026-03-11
One Data Loss Prevention HIGH 7.8
CVE-2025-14026

Forcepoint One DLP Client, version 23.04.5642 (and possibly newer versions), includes a restricted version of Python 2.5.4 that prevents use of the c…

Mitigation only
Fix from $1,950 2026-01-06
Email Security MEDIUM 6.1
CVE-2024-2166

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Email Security (Real Time Monitor mo…

Fix: 8.5.5+
Fix from $1,600 2024-09-04
One Smartedge Agent HIGH 7.8
CVE-2023-1705

Missing Authorization vulnerability in Forcepoint F|One SmartEdge Agent on Windows (bgAutoinstaller service modules) allows Privilege Escalation, Fun…

Fix: 1.7.0.230330-554+
Fix from $1,950 2024-01-29
Email Security CRITICAL 9.8
CVE-2023-2080

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal …

Mitigation only
Fix from $2,300 2023-06-15
Cloud Security Gateway MEDIUM 6.1
CVE-2023-26290

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal …

Fix: 2023-03-29+
Fix from $1,600 2023-03-29
Cloud Security Gateway MEDIUM 6.1
CVE-2023-26291

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal …

Fix: 2023-03-29+
Fix from $1,600 2023-03-29
Cloud Security Gateway MEDIUM 6.1
CVE-2023-26292

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal …

Fix: 2023-03-29+
Fix from $1,600 2023-03-29
Cloud Security Gateway CRITICAL 9.8
CVE-2022-1700

Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is a…

Fix: 8.5.5 / 8.8.2+
Fix from $2,300 2022-09-12
One Endpoint MEDIUM 6.0
CVE-2022-27608

Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows is vulnerable to registry key tampering by users with Administrator pri…

Fix: 22.01+
Fix from $1,600 2022-04-04
One Endpoint MEDIUM 6.0
CVE-2022-27609

Forcepoint One Endpoint prior to version 22.01 installed on Microsoft Windows does not provide sufficient anti-tampering protection of services by us…

Fix: 22.01+
Fix from $1,600 2022-04-04
Next Generation Firewall HIGH 7.5
CVE-2021-41530

Forcepoint NGFW Engine versions 6.5.11 and earlier, 6.8.6 and earlier, and 6.10.0 are vulnerable to TCP reflected amplification vulnerability, if HTT…

Fix: after 6.8.6
Fix from $1,950 2021-10-04
Data Loss Prevention HIGH 7.5
CVE-2020-6590

Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.

Fix: 8.5.4 / 8.7.1+
Fix from $1,950 2021-04-08
Web Security MEDIUM 6.1
CVE-2019-6146

It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (M…

Fix: 8.5.4+
Fix from $1,600 2020-01-22
Next Generation Firewall Security Management Center MEDIUM 5.9
CVE-2019-6147

Forcepoint NGFW Security Management Center (SMC) versions lower than 6.5.12 or 6.7.1 have a rare issue that in specific circumstances can corrupt the…

Fix: 6.5.12 / 6.7.1+
Fix from $1,600 2019-12-23
Email Security MEDIUM 6.1
CVE-2019-6142

It has been reported that XSS is possible in Forcepoint Email Security, versions 8.5 and 8.5.3. It is strongly recommended that you apply the relevan…

Mitigation only
Fix from $1,600 2019-11-05
One Endpoint MEDIUM 6.5
CVE-2019-6144

This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint (versions 19.04 through 19.08) and bypass DLP and Web prot…

Fix: after 19.08
Fix from $1,600 2019-10-23
Vpn Client MEDIUM 6.7
CVE-2019-6145

Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables local privilege escalation to SY…

Fix: 6.6.1+
Fix from $1,600 2019-09-20
Next Generation Firewall CRITICAL 9.1
CVE-2019-6143

Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentication vul…

Fix: 6.4.7 / 6.5.4+
Fix from $2,300 2019-08-20
Email Security CRITICAL 9.8
CVE-2019-6140

A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hybrid regis…

Fix: after 8.5.3
Fix from $2,300 2019-04-09
Email Security CRITICAL 9.8
CVE-2018-16530

A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a process cr…

Mitigation only
Fix from $2,300 2019-04-09
Email Security CRITICAL 9.8
CVE-2018-16529

A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expirati…

Fix: after 8.5.3
Fix from $2,300 2019-03-28
User Id CRITICAL 9.8
CVE-2019-6139

Forcepoint User ID (FUID) server versions up to 1.2 have a remote arbitrary file upload vulnerability on TCP port 5001. Successful exploitation of th…

Fix: 1.3.0+
Fix from $2,300 2019-02-07