Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortiwan CRITICAL 9.1
CVE-2021-26102EPSS 17%

A relative path traversal vulnerability (CWE-23) in FortiWAN version 4.5.7 and below, 4.4 all versions may allow a remote non-authenticated attacker …

Fix: 4.5.8+
Fix from $2,300 2024-12-19
Fortianalyzer CRITICAL 9.8
CVE-2021-32589EPSS 9%

A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, v…

Fix: 5.3.7 / 5.6.11+
Fix from $2,300 2024-12-19
Fortiwan HIGH 7.8
CVE-2021-26115

An OS command injection (CWE-78) vulnerability in FortiWAN version 4.5.7 and below Command Line Interface may allow a local, authenticated and unpriv…

Fix: 4.5.8+
Fix from $1,950 2024-12-19
Forticlient HIGH 7.8
CVE-2020-15934

An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow …

Fix: 6.2.8+
Fix from $1,950 2024-12-19
Fortios HIGH 8.8
CVE-2020-12820

Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5.6.12 and below may allow a remote attac…

Fix: 5.6.13 / 6.0.11+
Fix from $1,950 2024-12-19
Fortiwlc MEDIUM 6.5
CVE-2021-26093

An access of uninitialized pointer (CWE-824) vulnerability in FortiWLC versions 8.6.0, 8.5.3 and earlier may allow a local and authenticated attacker…

Fix: 8.6.3+
Fix from $1,600 2024-12-19
Fortios HIGH 7.5
CVE-2020-12819

A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate versions 5.6.12, 6.0.10, 6.2.4 and 6.4.1 …

Fix: 5.6.13 / 6.0.11+
Fix from $1,950 2024-12-19
Fortimanager HIGH 7.2
CVE-2024-48889

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, v…

Fix: 6.4.15 / 7.0.13+
Fix from $1,950 2024-12-18
Forticlient MEDIUM 5.0
CVE-2024-50570

A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.…

Fix: 7.0.14 / 7.2.7+
Fix from $1,600 2024-12-18
Fortiwlm CRITICAL 9.8
CVE-2023-34990EPSS 25%

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or co…

Fix: 8.5.5 / 8.6.6+
Fix from $2,300 2024-12-18
Forticlient HIGH 7.8
CVE-2024-47574

A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.1…

Fix: 7.0.13 / 7.2.5+
Fix from $1,950 2024-11-13
Forticlient MEDIUM 6.7
CVE-2024-40592

An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.…

Fix: 7.2.5+
Fix from $1,600 2024-11-12
Forticlient HIGH 8.8
CVE-2024-36513

A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all version…

Fix: 7.0.13 / 7.2.5+
Fix from $1,950 2024-11-12
Forticlient HIGH 7.8
CVE-2024-36507

A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker…

Fix: 7.0.13 / 7.2.5+
Fix from $1,950 2024-11-12
Fortianalyzer HIGH 7.3
CVE-2024-33505

A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, …

Fix: 7.2.6 / 7.2.7+
Fix from $1,950 2024-11-12
Fortianalyzer MEDIUM 6.7
CVE-2024-32118

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager…

Fix: 7.2.6 / 7.2.8+
Fix from $1,600 2024-11-12
Fortios CRITICAL 9.8
CVE-2024-26011

A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0…

Fix: 1.3.0 / 6.0.15+
Fix from $2,300 2024-11-12
Fortianalyzer MEDIUM 6.7
CVE-2024-31496

A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.…

Fix: 7.2.6 / 7.2.8+
Fix from $1,600 2024-11-12
Fortianalyzer MEDIUM 6.0
CVE-2024-32116

Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer versio…

Fix: 7.2.6 / 7.2.8+
Fix from $1,600 2024-11-12
Fortios HIGH 8.8
CVE-2023-50176

A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauth…

Fix: 7.0.14 / 7.2.8+
Fix from $1,950 2024-11-12
Fortianalyzer HIGH 8.8
CVE-2024-23666

A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 throug…

Fix: 6.4.15 / 7.0.13+
Fix from $1,950 2024-11-12
Fortiportal HIGH 8.1
CVE-2023-47543

An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticat…

Fix: 7.0.4+
Fix from $1,950 2024-11-12
Fortimanager CRITICAL 9.8
CVE-2024-47575 KEVEPSS 95%

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManage…

Fix: 6.2.13 / 6.4.15+
Fix from $2,300 2024-10-23
Fortianalyzer HIGH 7.2
CVE-2024-45330

A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate …

Fix: after 7.4.3
Fix from $1,950 2024-10-08
Fortisoar HIGH 7.5
CVE-2024-45327

An improper authorization vulnerability [CWE-285] in FortiSOAR version 7.4.0 through 7.4.3, 7.3.0 through 7.3.2, 7.2.0 through 7.2.2, 7.0.0 through 7…

Fix: 7.3.3 / 7.4.4+
Fix from $1,950 2024-09-11
Forticlient Enterprise Management Server HIGH 7.3
CVE-2024-33508

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 throug…

Fix: 7.0.13 / 7.2.5+
Fix from $1,950 2024-09-10
Forticlient HIGH 8.1
CVE-2024-31489

AAn improper certificate validation vulnerability [CWE-295] in FortiClientWindows 7.2.0 through 7.2.2, 7.0.0 through 7.0.11, FortiClientLinux 7.2.0,…

Fix: 7.0.12 / 7.2.3+
Fix from $1,950 2024-09-10
Fortisandbox MEDIUM 6.5
CVE-2024-31490

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through …

Fix: 4.2.7 / 4.4.5+
Fix from $1,600 2024-09-10
Fortianalyzer MEDIUM 6.5
CVE-2023-44254

An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version …

Fix: 7.2.5+
Fix from $1,600 2024-09-10
Forticlient Endpoint Management Server MEDIUM 6.0
CVE-2024-21753

A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiClientEMS versions 7.2.0 through 7.2.4, 7.0.0 throu…

Fix: after 7.2.4
Fix from $1,600 2024-09-10