Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Forticlient HIGH 7.1
CVE-2022-40681

A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to caus…

Fix: after 7.0.7
Fix from $1,950 2023-11-14
Fortimail HIGH 7.3
CVE-2023-45582

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through …

Fix: after 7.2.4
Fix from $1,950 2023-11-14
Fortiedr MEDIUM 5.5
CVE-2023-44248

An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow …

Fix: after 5.2.0.4549
Fix from $1,600 2023-11-14
Forticlient HIGH 7.8
CVE-2023-41840

A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL …

Mitigation only
Fix from $1,950 2023-11-14
Fortiwlm HIGH 7.5
CVE-2023-42783

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.2 through 8.4.0 and 8.3.2 through 8.3.0 an…

Fix: after 8.6.6
Fix from $1,950 2023-11-14
Fortisiem MEDIUM 6.5
CVE-2023-41676

An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with acces…

Fix: after 6.7.5
Fix from $1,600 2023-11-14
Fortiproxy MEDIUM 6.5
CVE-2023-36641

A numeric truncation error in Fortinet FortiProxy version 7.2.0 through 7.2.4, FortiProxy version 7.0.0 through 7.0.10, FortiProxy 2.0 all versions, …

Fix: after 7.2.5
Fix from $1,600 2023-11-14
Fortimail MEDIUM 5.4
CVE-2023-36633

An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker …

Fix: 7.0.6 / 7.2.3+
Fix from $1,600 2023-11-14
Fortisiem CRITICAL 9.8
CVE-2023-36553

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.…

Fix: after 5.1.3
Fix from $2,300 2023-11-14
Fortiwlm CRITICAL 9.8
CVE-2023-34991EPSS 29%

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 thr…

Fix: after 8.6.5
Fix from $2,300 2023-11-14
Forticlient MEDIUM 5.5
CVE-2023-33304

A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system pro…

Fix: after 7.0.9
Fix from $1,600 2023-11-14
Fortiproxy MEDIUM 6.7
CVE-2023-28002

An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 a…

Fix: after 7.2.7
Fix from $1,600 2023-11-14
Fortiadc HIGH 8.8
CVE-2023-26205

An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all ve…

Fix: after 7.0.5
Fix from $1,950 2023-11-14
Fortianalyzer MEDIUM 6.5
CVE-2023-44256

A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and Forti…

Fix: after 7.2.3
Fix from $1,600 2023-10-20
Fortisandbox HIGH 7.5
CVE-2023-41682

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox 4.2.1 thr…

Fix: after 4.2.5
Fix from $1,950 2023-10-13
Fortisandbox MEDIUM 6.1
CVE-2023-41680

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, Fo…

Fix: after 4.4.1
Fix from $1,600 2023-10-13
Fortisandbox MEDIUM 6.1
CVE-2023-41681

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, Fo…

Fix: after 4.4.1
Fix from $1,600 2023-10-13
Fortisandbox MEDIUM 6.1
CVE-2023-41836

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox 4.…

Fix: after 4.2.4
Fix from $1,600 2023-10-13
Fortisandbox MEDIUM 5.4
CVE-2023-41843

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, Fo…

Fix: after 4.4.1
Fix from $1,600 2023-10-13
Fortiedr HIGH 8.1
CVE-2023-33303

A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api r…

Fix: after 5.0.1
Fix from $1,950 2023-10-13
Fortianalyzer MEDIUM 6.5
CVE-2023-44249

An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer…

Fix: 7.2.4+
Fix from $1,600 2023-10-10
Fortiwlm CRITICAL 9.8
CVE-2023-36550

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5…

Fix: after 8.6.5
Fix from $2,300 2023-10-10
Fortimanager CRITICAL 9.6
CVE-2023-41679

An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.1…

Fix: after 7.0.7
Fix from $2,300 2023-10-10
Fortimail HIGH 8.8
CVE-2023-36556

An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allo…

Fix: after 7.0.5
Fix from $1,950 2023-10-10
Fortios HIGH 8.8
CVE-2023-41841

An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile t…

Fix: after 7.2.4
Fix from $1,950 2023-10-10
Fortios HIGH 7.5
CVE-2023-37935

A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker…

Fix: after 7.2.5
Fix from $1,950 2023-10-10
Fortios Ips Engine HIGH 7.5
CVE-2023-40718

A interpretation conflict in Fortinet IPS Engine versions 7.321, 7.166 and 6.158 allows attacker to evade IPS features via crafted TCP packets.

Fix: after 7.312
Fix from $1,950 2023-10-10
Fortianalyzer HIGH 7.1
CVE-2023-41838

An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow…

Fix: after 7.2.3
Fix from $1,950 2023-10-10
Fortianalyzer MEDIUM 6.7
CVE-2023-42788

An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer …

Fix: after 7.2.3
Fix from $1,600 2023-10-10
Fortianalyzer MEDIUM 6.5
CVE-2023-42787

A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer v…

Fix: after 7.2.3
Fix from $1,600 2023-10-10