Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortisiem HIGH 7.5
CVE-2026-59841

A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow a…

Fix: 7.4.2+
Fix from $1,950 2026-07-14
Fortiproxy MEDIUM 5.5
CVE-2026-59839

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0…

Fix: 1.7.3 / 7.4.10+
Fix from $1,600 2026-07-14
Forticlientems CRITICAL 9.8
CVE-2026-59836

A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.…

Fix: 7.4.6+
Fix from $2,300 2026-07-14
Fortisandbox HIGH 8.6
CVE-2026-59835

A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unau…

Fix: 4.4.9 / 5.0.3+
Fix from $1,950 2026-07-14
Fortiproxy MEDIUM 6.6
CVE-2026-59837

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM…

Fix: 1.8.3 / 7.4.2+
Fix from $1,600 2026-07-14
Fortiproxy MEDIUM 6.1
CVE-2026-23573

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.…

Fix: 1.8.1 / 7.2.10+
Fix from $1,600 2026-07-14
Fortiauthenticator HIGH 7.5
CVE-2025-53379

A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthe…

Fix: after 6.6.2
Fix from $1,950 2026-07-14
Fortiportal MEDIUM 6.5
CVE-2026-49938

A improper access control vulnerability in Fortinet FortiPortal 7.4.0 through 7.4.7, FortiPortal 7.2.0 through 7.2.8, FortiPortal 7.0 all versions ma…

Fix: 7.2.9 / 7.4.8+
Fix from $1,600 2026-06-09
Fortisandbox CRITICAL 9.8
CVE-2026-25089 KEVEPSS 74%

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0…

Fix: 4.4.9 / 5.0.6+
Fix from $2,300 2026-06-09
Fortios MEDIUM 6.7
CVE-2025-67862

An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, Forti…

Fix: 7.2.11 / 7.2.15+
Fix from $1,600 2026-06-09
Fortiauthenticator CRITICAL 9.8
CVE-2026-44277

A improper access control vulnerability in Fortinet FortiAuthenticator 8.0.2, FortiAuthenticator 8.0.0, FortiAuthenticator 6.6.0 through 6.6.8, Forti…

Fix: 6.5.7 / 6.6.9+
Fix from $2,300 2026-05-12
Forticlient MEDIUM 5.5
CVE-2026-44278

A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow…

Fix: 7.4.3+
Fix from $1,600 2026-05-12
Fortitoken Mobile MEDIUM 5.5
CVE-2026-44279

An improper export of android application components vulnerability in Fortinet FortiTokenAndroid 6.2 all versions, FortiTokenAndroid 6.1 all versions…

Mitigation only
Fix from $1,600 2026-05-12
Fortisandbox CRITICAL 9.8
CVE-2026-26083

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 throug…

Fix: 4.4.9 / 5.0.2+
Fix from $2,300 2026-05-12
Fortindr HIGH 8.8
CVE-2026-25088

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, Forti…

Fix: 7.4.10 / 7.6.3+
Fix from $1,950 2026-05-12
Fortideceptor MEDIUM 6.5
CVE-2026-25690

An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.0.0 through 6.0.2, Fo…

Fix: after 6.0.2
Fix from $1,600 2026-05-12
Fortiap MEDIUM 6.7
CVE-2025-53870

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiAP 7.6.0 through 7.6.2, …

Fix: 7.2.6 / 7.4.5+
Fix from $1,600 2026-05-12
Fortianalyzer MEDIUM 5.3
CVE-2025-67604

A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer…

Fix: 7.4.9 / 7.6.5+
Fix from $1,600 2026-05-12
Fortios HIGH 8.8
CVE-2025-53844

A out-of-bounds write vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11 allows attacke…

Fix: 7.2.12 / 7.4.9+
Fix from $1,950 2026-05-12
Fortimail HIGH 7.2
CVE-2025-53681

An improper neutralization of special elements used in an SQL Command ("SQL Injection&") vulnerability [CWE-89] vulnerability in Fortinet FortiMail 7…

Fix: 7.2.9 / 7.4.6+
Fix from $1,950 2026-05-12
Fortiap MEDIUM 6.7
CVE-2025-53680

An improper neutralization of special elements used in an OS command ("OS Command Injection") vulnerability [CWE-78] vulnerability in Fortinet FortiA…

Fix: 7.0.6 / 7.4.5+
Fix from $1,600 2026-05-12
Fortiweb HIGH 7.2
CVE-2026-40688EPSS 6%

An out-of-bounds write vulnerability [CWE-787] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 t…

Fix: 7.4.12 / 7.6.7+
Fix from $1,950 2026-04-14
Fortiddos F HIGH 8.8
CVE-2026-39815

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may …

Fix: 7.2.3+
Fix from $1,950 2026-04-14
Fortisandbox CRITICAL 9.8
CVE-2026-39813EPSS 23%

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to esc…

Fix: 4.4.9 / 5.0.6+
Fix from $2,300 2026-04-14
Forticlientems MEDIUM 6.7
CVE-2026-39809

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, …

Fix: 7.2.13 / 7.4.6+
Fix from $1,600 2026-04-14
Fortiweb MEDIUM 6.7
CVE-2026-39814

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiW…

Fix: 7.6.7 / 8.0.3+
Fix from $1,600 2026-04-14
Forticlientems MEDIUM 5.5
CVE-2026-39810

A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via d…

Fix: 7.4.6+
Fix from $1,600 2026-04-14
Fortisandbox CRITICAL 9.8
CVE-2026-39808 KEVEPSS 91%

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4…

Fix: after 4.4.9
Fix from $2,300 2026-04-14
Fortianalyzer Cloud HIGH 8.1
CVE-2026-22828

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a re…

Fix: 7.6.5+
Fix from $1,950 2026-04-14
Fortisoar HIGH 8.1
CVE-2026-23708

A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.…

Fix: 7.5.3 / 7.6.4+
Fix from $1,950 2026-04-14