Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Forticlient MEDIUM 5.9
CVE-2022-45856

An improper certificate validation vulnerability [CWE-295] in FortiClientWindows 6.4 all versions, 7.0.0 through 7.0.7, FortiClientMac 6.4 all versio…

Fix: 7.0.7 / 7.0.8+
Fix from $1,600 2024-09-10
Fortisoar CRITICAL 9.0
CVE-2023-26211

An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiSOAR 7.3.0 through 7.3.2 allows an authentic…

Fix: 7.3.3+
Fix from $2,300 2024-08-13
Fortianalyzer HIGH 7.8
CVE-2024-21757

A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, …

Fix: 7.0.11 / 7.2.5+
Fix from $1,950 2024-08-13
Fortios MEDIUM 5.5
CVE-2024-36505

An improper access control vulnerability [CWE-284] in FortiOS 7.4.0 through 7.4.3, 7.2.5 through 7.2.7, 7.0.12 through 7.0.14 and 6.4.x may allow an …

Fix: 7.0.15 / 7.2.8+
Fix from $1,600 2024-08-13
Fortiproxy HIGH 8.8
CVE-2022-45862

An insufficient session expiration vulnerability [CWE-613] vulnerability in FortiOS 7.2.5 and below, 7.0 all versions, 6.4 all versions; FortiProxy 7…

Fix: 1.4.0 / 7.2.2+
Fix from $1,950 2024-08-13
Fortiddos HIGH 7.8
CVE-2022-27486

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2…

Fix: 5.6.2 / 6.4.2+
Fix from $1,950 2024-08-13
Fortiaiops CRITICAL 9.8
CVE-2024-27782

Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an attacker to re-use stolen old s…

Mitigation only
Fix from $2,300 2024-07-09
Fortiaiops HIGH 8.8
CVE-2024-27783

Multiple cross-site request forgery (CSRF) weaknesses [CWE-352] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an unauthenticated remote attack…

Mitigation only
Fix from $1,950 2024-07-09
Fortiaiops MEDIUM 6.5
CVE-2024-27784

Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerability in Fortinet FortiAIOps 2.0.0 may allow an auth…

Mitigation only
Fix from $1,600 2024-07-09
Fortiaiops MEDIUM 6.5
CVE-2024-27785

An improper neutralization of formula elements in a CSV File [CWE-1236] vulnerability in Fortinet FortiAIOps 2.0.0 may allow a remote authenticated a…

Mitigation only
Fix from $1,600 2024-07-09
Fortiextender Firmware HIGH 8.8
CVE-2024-23663

An improper access control in Fortinet FortiExtender 4.1.1 - 4.1.9, 4.2.0 - 4.2.6, 5.3.2, 7.0.0 - 7.0.4, 7.2.0 - 7.2.4 and 7.4.0 - 7.4.2 allows an at…

Fix: after 7.4.2
Fix from $1,950 2024-07-09
Fortiadc HIGH 7.4
CVE-2023-50178

An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 all versio…

Fix: after 7.2.3
Fix from $1,950 2024-07-09
Fortiadc MEDIUM 6.5
CVE-2023-50181

An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticate…

Fix: 7.2.5 / 7.4.2+
Fix from $1,600 2024-07-09
Fortiadc MEDIUM 5.9
CVE-2023-50179

An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2 all versions, 7.1 all versions, 7.0 all versions may allow a remote…

Fix: 7.4.1+
Fix from $1,600 2024-07-09
Fortios HIGH 7.5
CVE-2024-26010

A stack-based buffer overflow in Fortinet FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiWeb, FortiAuthenticator, FortiSwitch…

Fix: 7.0.4 / 7.0.15+
Fix from $1,950 2024-06-11
Fortios HIGH 7.8
CVE-2024-23110

A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0…

Fix: 6.2.16 / 6.4.15+
Fix from $1,950 2024-06-11
Fortios HIGH 7.8
CVE-2023-46720

A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.…

Fix: 7.2.8 / 7.4.3+
Fix from $1,950 2024-06-11
Fortisoar HIGH 8.8
CVE-2023-23775

Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerabilities [CWE-89] in FortiSOAR 7.2.0 and before 7.…

Fix: 7.2.1+
Fix from $1,950 2024-06-11
Fortiwebmanager HIGH 8.8
CVE-2024-23669

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug…

Fix: 6.2.5 / 7.0.5+
Fix from $1,950 2024-06-05
Fortiwebmanager HIGH 8.8
CVE-2024-23667

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug…

Fix: 6.2.5 / 7.0.5+
Fix from $1,950 2024-06-03
Fortiwebmanager HIGH 8.8
CVE-2024-23668

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug…

Fix: 6.2.5 / 7.0.5+
Fix from $1,950 2024-06-03
Fortiwebmanager HIGH 8.8
CVE-2024-23670

An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, FortiWebManager 6.3.0, FortiWebManager 6.2.3 throug…

Fix: 6.2.5 / 7.0.5+
Fix from $1,950 2024-06-03
Fortiweb HIGH 8.8
CVE-2024-23665

Multiple improper authorization vulnerabilities [CWE-285] in FortiWeb version 7.4.2 and below, version 7.2.7 and below, version 7.0.10 and below, ver…

Fix: 7.2.8 / 7.4.3+
Fix from $1,950 2024-06-03
Fortiauthenticator MEDIUM 6.1
CVE-2024-23664

A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below …

Fix: 6.5.4+
Fix from $1,600 2024-06-03
Fortisoar MEDIUM 6.5
CVE-2024-31493

An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, …

Fix: 7.3.1+
Fix from $1,600 2024-06-03
Fortiportal MEDIUM 6.5
CVE-2023-48789

A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via…

Fix: 6.0.15+
Fix from $1,600 2024-06-03
Fortiweb MEDIUM 5.5
CVE-2024-23107

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiWeb version 7.4.0, version 7.2.4 and below, version 7.0…

Fix: 7.0.9 / 7.2.5+
Fix from $1,600 2024-06-03
Fortisandbox HIGH 8.8
CVE-2024-31491

A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6 allows…

Fix: 4.2.7 / 4.4.5+
Fix from $1,950 2024-05-14
Fortinac CRITICAL 9.0
CVE-2024-31488

An improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC version 9.4.0 through 9.4.4, 9.2.0 through 9.2.8, …

Fix: 7.2.4 / 9.4.5+
Fix from $2,300 2024-05-14
Fortios HIGH 7.5
CVE-2024-26007

An improper check or handling of exceptional conditions vulnerability [CWE-703] in Fortinet FortiOS version 7.4.1 allows an unauthenticated attacker …

Mitigation only
Fix from $1,950 2024-05-14