Data Loss Prevention
22 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Data Loss Prevention, a product in the security products space. Use it to gauge the current risk picture and drill into individual advisories.
Data Loss Prevention CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 1 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 22 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical2
- High7
- Medium13
Latest CVEs
The 15 most recently published vulnerabilities affecting Data Loss Prevention.
- CVE-2026-3991Elevation of Privileges in Symantec Data Loss Prevention Windows Endpoint7.8
- CVE-2024-23617Symantec Data Loss Prevention Buffer Overflow9.6
- CVE-2023-4814 A Privilege escalation vulnerability exists in Trellix Windows DLP endpoint for windows which can be abused to delete any file/folder for which the user does not have permission to. 7.1
- CVE-2023-0400 The protection bypass vulnerability in DLP for Windows 11.9.x is addressed in version 11.10.0. This allowed a local user to bypass DLP controls when uploading sensitive data from a mapped drive in...5.9
- CVE-2022-1700Improper Restriction of XML External Entity Reference ('XXE') vulnerability in the Policy Engine of Forcepoint Data Loss Prevention (DLP), which is also leveraged by Forcepoint One Endpoint (F1E), ...7.5
- CVE-2021-4088Blind SQL injection in DLP ePO extension8.4
- CVE-2021-31832Cross site scripting vulnerability in DLP Endpoint for Windows5.2
- CVE-2020-6590Forcepoint Web Security Content Gateway versions prior to 8.5.4 improperly process XML input, leading to information disclosure.7.5
- CVE-2020-7346Privilege escalation in McAfee DLP Endpoint for Windows7.8
- CVE-2020-7307DLP for Mac - Unprotected Storage of Credentials5.2
- CVE-2020-7306DLP for Mac - Unprotected Storage of Credentials5.2
- CVE-2020-7305DLP ePO extension - Privilege escalation6.7
- CVE-2020-7304DLP ePO extension - Cross-site request forgery7.6
- CVE-2020-7303DLP ePO extension - Cross-site scripting4.1
- CVE-2020-7302DLP ePO extension - Unrestricted Upload of File with Dangerous Type5.4
Product grouping is registry-driven, with AI assist and human review. How it works