Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortios MEDIUM 6.5
CVE-2023-29179

A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 thro…

Fix: 6.4.13 / 7.0.11+
Fix from $1,600 2024-02-22
Fortimanager HIGH 8.8
CVE-2023-42791

A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12 and 6.2.0 t…

Fix: 6.2.12 / 6.4.13+
Fix from $1,950 2024-02-20
Fortiproxy CRITICAL 9.8
CVE-2024-23113 KEVEPSS 62%

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy …

Fix: after 7.4.2
Fix from $2,300 2024-02-15
Forticlient Enterprise Management Server HIGH 7.2
CVE-2023-45581

An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site admi…

Fix: 7.0.10+
Fix from $1,950 2024-02-15
Fortinac MEDIUM 6.1
CVE-2023-26206

An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4.2, 9.2.0 - 9.2.8, 9.1.0 - 9.…

Fix: after 9.4.2
Fix from $1,600 2024-02-15
Fortianalyzer MEDIUM 5.0
CVE-2023-44253

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before…

Fix: after 7.2.3
Fix from $1,600 2024-02-15
Fortiproxy CRITICAL 9.8
CVE-2024-21762 KEVEPSS 84%

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 throug…

Fix: 2.0.14 / 6.0.18+
Fix from $2,300 2024-02-09
Fortisiem CRITICAL 9.8
CVE-2024-23109

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute u…

Fix: after 7.0.2
Fix from $2,300 2024-02-05
Fortisiem CRITICAL 9.8
CVE-2024-23108EPSS 78%

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute u…

Fix: after 7.0.2
Fix from $2,300 2024-02-05
Fortiproxy HIGH 8.8
CVE-2023-44250

An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy H…

Mitigation only
Fix from $1,950 2024-01-10
Fortiportal HIGH 8.8
CVE-2023-46712

A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to es…

Fix: after 7.2.1
Fix from $1,950 2024-01-10
Fortiportal MEDIUM 5.4
CVE-2023-48783EPSS 22%

An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, v…

Fix: 7.0.7 / 7.2.2+
Fix from $1,600 2024-01-10
Fortivoice MEDIUM 6.5
CVE-2023-37932

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and be…

Fix: 6.4.8+
Fix from $1,600 2024-01-10
Fortipam MEDIUM 6.5
CVE-2023-37934

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perf…

Fix: 1.1.0+
Fix from $1,600 2024-01-10
Fortiwan HIGH 8.8
CVE-2023-44251

** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in Fortinet Fo…

Mitigation only
Fix from $1,950 2023-12-13
Fortiwan HIGH 8.8
CVE-2023-44252

** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 …

Mitigation only
Fix from $1,950 2023-12-13
Fortiproxy MEDIUM 5.3
CVE-2023-47536

An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy versio…

Fix: after 7.2.3
Fix from $1,600 2023-12-13
Fortiportal HIGH 8.8
CVE-2023-48791

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7…

Fix: after 7.0.6
Fix from $1,950 2023-12-13
Fortiwlm HIGH 8.8
CVE-2023-48782

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows …

Fix: after 8.6.5
Fix from $1,950 2023-12-13
Fortiweb MEDIUM 5.3
CVE-2023-46713

An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may allow an at…

Fix: after 7.2.5
Fix from $1,600 2023-12-13
Fortisandbox MEDIUM 5.4
CVE-2023-45587

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, F…

Fix: after 4.2.5
Fix from $1,600 2023-12-13
Fortisandbox MEDIUM 5.4
CVE-2023-41844

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, Fo…

Fix: after 4.2.5
Fix from $1,600 2023-12-13
Fortios HIGH 8.8
CVE-2023-41678

A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute …

Mitigation only
Fix from $1,950 2023-12-13
Fortiadc MEDIUM 5.4
CVE-2023-41673

An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low privileged user to read or back…

Fix: after 7.0.5
Fix from $1,600 2023-12-13
Fortitester HIGH 7.8
CVE-2023-40716

An improper neutralization of special elements used in an OS command vulnerability [CWE-78]  in the command line interpreter of FortiTester 2.3.0 thr…

Mitigation only
Fix from $1,950 2023-12-13
Fortiproxy HIGH 8.8
CVE-2023-36639

A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0…

Fix: after 7.2.4
Fix from $1,950 2023-12-13
Fortiai HIGH 8.8
CVE-2022-27488

A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4…

Fix: after 7.0.4
Fix from $1,950 2023-12-13
Fortianalyzer MEDIUM 5.5
CVE-2023-40719

A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an attacker to…

Fix: after 7.2.3
Fix from $1,600 2023-11-14
Fortiadc MEDIUM 6.7
CVE-2023-29177

Multiple buffer copy without checking size of input ('classic buffer overflow') vulnerabilities [CWE-120] in FortiADC version 7.2.0 and before 7.1.2 …

Fix: after 7.1.2
Fix from $1,600 2023-11-14
Fortiadc CRITICAL 9.1
CVE-2023-25603

A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1…

Fix: after 6.3.4
Fix from $2,300 2023-11-14