Forcepoint
First CVE: Feb 7, 2019Active for: 7 years
28
CVEs Published
More CVEs Published than 47% of tracked CNAs
3.5
Avg CVEs / Year
More Avg CVEs / Year than 25% of tracked CNAs
7.5
Avg CVSS Score
Higher Avg CVSS Score than 66% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%
Self-Reporting Analysis
Of all the CVEs published by Forcepoint as a CNA, 96.4% affect products that Forcepoint develops as a vendor.
96.4%
Self-reported: 27Third-party: 1
Of all the CVEs published that affect products developed by Forcepoint, 93.1% are self-published by Forcepoint as a CNA.
93.1%
Self-published: 27Published by other CNAs: 2
Trends Over Time
The number and severity of CVEs published by Forcepoint over time
Volume of CVEsAvg CVSS Base Score
First CVE
Feb 7, 2019
7 years ago
Most Recent CVE
Jun 4, 2026
53 days ago
Top CVEs
All CVEs published by Forcepoint as a CNA, regardless of affected vendor or product.
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-12694HIGH A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Clie | Jun 4, 2026 | 7.8 | 32 | NO | NO |
CVE-2022-1700CRITICAL Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One | Sep 12, 2022 | 9.8 | 31 | NO | NO |
CVE-2019-6146MEDIUM It has been reported that cross-site scripting (XSS) is possible in Forcepoint Web Security, version 8.x, via host header injection. CVSSv3.0: 5.3 (Medium) (/AV:N/AC:L/PR:N/UI:N/S: | Jan 22, 2020 | 6.1 | 31 | NO | YES |
CVE-2019-6140CRITICAL A configuration issue has been discovered in Forcepoint Email Security 8.4.x and 8.5.x: the product is left in a vulnerable state if the hybrid registration process is not complete | Apr 9, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-16530CRITICAL A stack-based buffer overflow in Forcepoint Email Security version 8.5 allows an attacker to craft malicious input and potentially crash a process creating a denial-of-service. Whi | Apr 9, 2019 | 9.8 | 30 | NO | NO |
CVE-2018-16529CRITICAL A password reset vulnerability has been discovered in Forcepoint Email Security 8.5.x. The password reset URL can be used after the intended expiration period or after the URL has | Mar 28, 2019 | 9.8 | 29 | NO | NO |
CVE-2023-6452CRITICAL Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Web Security (Transaction Viewer) allows Stored XSS.
The
Forc | Aug 22, 2024 | 9.6 | 28 | NO | NO |
CVE-2019-6143CRITICAL Forcepoint Next Generation Firewall (Forcepoint NGFW) 6.4.x before 6.4.7, 6.5.x before 6.5.4, and 6.6.x before 6.6.2 has a serious authentication vulnerability that potentially all | Aug 20, 2019 | 9.1 | 28 | NO | NO |
CVE-2023-2080CRITICAL Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, | Jun 15, 2023 | 9.8 | 27 | NO | NO |
CVE-2025-12690HIGH Execution with unnecessary privileges in Forcepoint NGFW Engine allows local privilege escalation.This issue affects NGFW Engine through 6.10.19, through 7.3.0, through 7.2.4, thro | Mar 11, 2026 | 7.8 | 26 | NO | NO |
CVE Severity & Scoring
Severity distribution of CVEs published by this CNA28 CVEs
50%
21%
29%
Severity distribution among all CVEs352,727 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local7 (25.0%)
Network21 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low26 (92.9%)
High2 (7.1%)
Unknown0 (0.0%)
User Interaction
None18 (64.3%)
Unknown0 (0.0%)
Required10 (35.7%)
Privileges Required
Low5 (17.9%)
High3 (10.7%)
None20 (71.4%)
Unknown0 (0.0%)
Exploit Exposure
Signals from CVEs in this cna scope (28 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
3.6% of CVEs· 93rd percentile
Social Chatter
An overview of all social media posts that mention a CVE ID published by Forcepoint as a CNA.
Media Mentions
Media articles that mention a CVE ID published by Forcepoint as a CNA — matched by CVE ID, not by organization name.