Forcepoint

First CVE: Feb 7, 2019Active for: 7 years
28
CVEs Published
More CVEs Published than 47% of tracked CNAs
3.5
Avg CVEs / Year
More Avg CVEs / Year than 25% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 66% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Self-Reporting Analysis

Of all the CVEs published by Forcepoint as a CNA, 96.4% affect products that Forcepoint develops as a vendor.

96.4%
Self-reported: 27Third-party: 1

Of all the CVEs published that affect products developed by Forcepoint, 93.1% are self-published by Forcepoint as a CNA.

93.1%
Self-published: 27Published by other CNAs: 2

Trends Over Time

The number and severity of CVEs published by Forcepoint over time

Volume of CVEsAvg CVSS Base Score
First CVE
Feb 7, 2019
7 years ago
Most Recent CVE
Jun 4, 2026
53 days ago

Top CVEs

All CVEs published by Forcepoint as a CNA, regardless of affected vendor or product.

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Clie
Jun 4, 20267.832NONO
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One
Sep 12, 20229.831NONO
It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S:
Jan 22, 20206.131NOYES
A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hybrid registration process is not complete
Apr 9, 20199.830NONO
A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a process creating a denial-of-service. Whi
Apr 9, 20199.830NONO
A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has
Mar 28, 20199.829NONO
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction Viewer) allows Stored XSS. The Forc
Aug 22, 20249.628NONO
Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentication vulnerability that potentially all
Aug 20, 20199.128NONO
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway,
Jun 15, 20239.827NONO
Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGFW Engine through 6.10.19, through 7.3.0, through 7.2.4, thro
Mar 11, 20267.826NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA28 CVEs
Severity distribution among all CVEs352,727 CVEs
MediumHighCritical
Attack Vector
Local7 (25.0%)
Network21 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (92.9%)
High2 (7.1%)
Unknown0 (0.0%)
User Interaction
None18 (64.3%)
Unknown0 (0.0%)
Required10 (35.7%)
Privileges Required
Low5 (17.9%)
High3 (10.7%)
None20 (71.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.6% of CVEs· 93rd percentile

Social Chatter

An overview of all social media posts that mention a CVE ID published by Forcepoint as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Forcepoint as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs