Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortiportal HIGH 7.5
CVE-2024-23105

A Use Of Less Trusted Source [CWE-348] vulnerability in Fortinet FortiPortal version 7.0.0 through 7.0.6 and version 7.2.0 through 7.2.1 allows an un…

Fix: after 7.0.6
Fix from $1,950 2024-05-14
Fortiadc MEDIUM 5.5
CVE-2023-50180

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, version 7.…

Fix: after 7.2.3
Fix from $1,600 2024-05-14
Fortios HIGH 7.2
CVE-2023-46714

A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.1 through 7.2.6 and version 7.4.0 through 7.4.1 allows a privil…

Fix: after 7.2.6
Fix from $1,950 2024-05-14
Fortiproxy MEDIUM 5.0
CVE-2023-45586

An insufficient verification of data authenticity vulnerability [CWE-345] in Fortinet FortiOS SSL-VPN tunnel mode version 7.4.0 through 7.4.1, versio…

Fix: 7.0.13 / 7.0.14+
Fix from $1,600 2024-05-14
Fortiproxy HIGH 7.2
CVE-2023-45583

A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS …

Fix: 7.0.3 / 7.0.12+
Fix from $1,950 2024-05-14
Fortios HIGH 7.2
CVE-2023-44247

A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 6.4 all versions may allow a privileged attacker to execute code or commands …

Fix: after 6.4.15
Fix from $1,950 2024-05-14
Fortivoice HIGH 7.1
CVE-2023-40720

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allo…

Fix: after 6.4.8
Fix from $1,950 2024-05-14
Fortiproxy MEDIUM 6.7
CVE-2023-36640

A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0 all versions, FortiOS …

Fix: after 7.2.4
Fix from $1,600 2024-05-14
Forticlient HIGH 7.6
CVE-2024-3661

DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redi…

Fix: 1.5.1.25 / 3.7.0.134+
Fix from $1,950 2024-05-06
Forticlient HIGH 7.8
CVE-2024-31492

An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may al…

Fix: 7.0.11 / 7.2.4+
Fix from $1,950 2024-04-10
Fortisandbox HIGH 8.8
CVE-2024-21756

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4…

Fix: 4.0.5 / 4.2.7+
Fix from $1,950 2024-04-09
Fortisandbox HIGH 8.1
CVE-2024-23671

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.3, FortiSan…

Fix: 4.0.5 / 4.2.7+
Fix from $1,950 2024-04-09
Fortios HIGH 7.5
CVE-2024-23662

An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2…

Fix: 7.2.6 / 7.4.2+
Fix from $1,950 2024-04-09
Fortisandbox MEDIUM 6.5
CVE-2024-31487

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSan…

Fix: 4.2.7 / 4.4.5+
Fix from $1,600 2024-04-09
Fortisandbox HIGH 8.8
CVE-2024-21755

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4…

Fix: 4.0.5 / 4.2.7+
Fix from $1,950 2024-04-09
Fortisandbox MEDIUM 6.7
CVE-2023-47541

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, FortiSa…

Fix: 4.2.7 / 4.4.3+
Fix from $1,600 2024-04-09
Fortimanager MEDIUM 6.7
CVE-2023-47542

A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below…

Fix: 7.0.11 / 7.2.5+
Fix from $1,600 2024-04-09
Fortios MEDIUM 6.7
CVE-2023-48784

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.1 and below, version 7.2.7 and below, 7.0 all versions, 6…

Fix: 7.0.16 / 7.2.8+
Fix from $1,600 2024-04-09
Fortiproxy HIGH 8.8
CVE-2023-41677

A insufficiently protected credentials in Fortinet FortiProxy 7.4.0, 7.2.0 through 7.2.6, 7.0.0 through 7.0.12, 2.0.0 through 2.0.13, 1.2.0 through 1…

Fix: 6.2.16 / 6.4.15+
Fix from $1,950 2024-04-09
Forticlient HIGH 8.8
CVE-2023-45590

An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4…

Fix: 7.0.11+
Fix from $1,950 2024-04-09
Fortisandbox MEDIUM 6.7
CVE-2023-47540

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.…

Fix: 4.2.7 / 4.4.3+
Fix from $1,600 2024-04-09
Fortiproxy CRITICAL 9.8
CVE-2023-42789

A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4.0…

Fix: after 7.2.6
Fix from $2,300 2024-03-12
Forticlient Enterprise Management Server CRITICAL 9.8
CVE-2023-48788 KEVEPSS 98%

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiC…

Fix: 7.0.11 / 7.2.3+
Fix from $2,300 2024-03-12
Fortios HIGH 8.8
CVE-2023-46717

An improper authentication vulnerability [CWE-287] in FortiOS versions 7.4.1 and below, versions 7.2.6 and below, and versions 7.0.12 and below when …

Fix: 7.0.13 / 7.2.7+
Fix from $1,950 2024-03-12
Forticlient Endpoint Management Server HIGH 8.8
CVE-2023-47534

A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 throu…

Fix: after 7.2.2
Fix from $1,950 2024-03-12
Fortiproxy HIGH 8.1
CVE-2023-42790

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, Forti…

Fix: after 7.4.1
Fix from $1,950 2024-03-12
Fortimanager CRITICAL 9.8
CVE-2023-36554

A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.…

Fix: after 7.2.3
Fix from $2,300 2024-03-12
Fortianalyzer MEDIUM 6.7
CVE-2023-41842

A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized …

Fix: 6.0.15 / 7.0.10+
Fix from $1,600 2024-03-12
Fortiproxy HIGH 8.8
CVE-2023-29181

A use of externally-controlled format string in Fortinet FortiOS 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.1…

Fix: 1.1.0 / 2.0.13+
Fix from $1,950 2024-02-22
Fortiproxy HIGH 7.5
CVE-2023-29180

A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, 6.2.0 through 6.2.14, 6.0.0 t…

Fix: 2.0.13 / 6.0.17+
Fix from $1,950 2024-02-22