Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortianalyzer MEDIUM 6.7
CVE-2021-43072

A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and below, version 6.4.7 and below, …

Fix: 2.0.9 / 6.2.11+
Fix from $1,600 2023-07-18
Fortios CRITICAL 9.8
CVE-2023-28001

An insufficient session expiration in Fortinet FortiOS 7.0.0 - 7.0.12 and 7.2.0 - 7.2.4 allows an attacker to execute unauthorized code or commands v…

Fix: after 7.2.4
Fix from $2,300 2023-07-11
Fortianalyzer MEDIUM 6.5
CVE-2023-25606

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management…

Fix: 6.4.12 / 7.2.2+
Fix from $1,600 2023-07-11
Fortiextender Firmware HIGH 7.5
CVE-2022-23447

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiExtender management interface 7.0.0…

Fix: 3.2.4 / 3.3.3+
Fix from $1,950 2023-07-11
Fortiweb HIGH 7.2
CVE-2023-23777

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb version 7.0.1 and be…

Fix: after 6.4.3
Fix from $1,950 2023-07-11
Fortinac CRITICAL 9.8
CVE-2023-33299EPSS 24%

A deserialization of untrusted data in Fortinet FortiNAC below 7.2.1, below 9.4.3, below 9.2.8 and all earlier versions of 8.x allows attacker to exe…

Fix: after 9.2.7
Fix from $2,300 2023-06-23
Fortiproxy MEDIUM 6.5
CVE-2023-33306

A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attac…

Fix: 6.4.13 / 7.0.10+
Fix from $1,600 2023-06-16
Fortiproxy MEDIUM 6.5
CVE-2023-33307

A null pointer dereference in Fortinet FortiOS before 7.2.5 and before 7.0.11, FortiProxy before 7.2.3 and before 7.0.9 allows attacker to denial of …

Fix: 7.0.11 / 7.2.5+
Fix from $1,600 2023-06-16
Fortiproxy MEDIUM 6.5
CVE-2023-33305

A loop with unreachable exit condition ('infinite loop') in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS version 7.0.0 through 7.0.10, Forti…

Fix: after 7.2.4
Fix from $1,600 2023-06-13
Fortisiem CRITICAL 9.8
CVE-2023-26204

A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 al…

Fix: after 6.7.5
Fix from $2,300 2023-06-13
Fortiproxy CRITICAL 9.8
CVE-2023-27997 KEVEPSS 86%

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version …

Fix: after 7.2.4
Fix from $2,300 2023-06-13
Fortiproxy HIGH 7.8
CVE-2022-43953

A use of externally-controlled format string in Fortinet FortiOS version 7.2.0 through 7.2.4, FortiOS all versions 7.0, FortiOS all versions 6.4, For…

Fix: after 7.2.4
Fix from $1,950 2023-06-13
Fortiproxy HIGH 7.8
CVE-2023-22639

A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.12, Fo…

Fix: after 7.2.3
Fix from $1,950 2023-06-13
Fortiadc HIGH 7.8
CVE-2023-26210

Multiple improper neutralization of special elements used in an os command ('OS Command Injection') vulnerabilties [CWE-78] vulnerability in Fortinet…

Fix: after 7.0.5
Fix from $1,950 2023-06-13
Fortiadc HIGH 7.8
CVE-2023-28000

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC CLI 7.1.0, 7.0.0 through 7.0.3, 6.2.0 through…

Fix: after 7.0.3
Fix from $1,950 2023-06-13
Fortisiem HIGH 7.5
CVE-2022-43949

A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform …

Fix: after 6.6.3
Fix from $1,950 2023-06-13
Fortinac HIGH 7.5
CVE-2023-22633

An improper permissions, privileges, and access controls vulnerability [CWE-264] in FortiNAC-F 7.2.0, FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.…

Fix: after 9.2.6
Fix from $1,950 2023-06-13
Fortianalyzer MEDIUM 6.5
CVE-2023-25609

A server-side request forgery (SSRF) vulnerability [CWE-918] in FortiManager and FortiAnalyzer GUI 7.2.0 through 7.2.1, 7.0.0 through 7.0.6, 6.4.8 th…

Fix: after 7.0.6
Fix from $1,600 2023-06-13
Fortiproxy MEDIUM 6.5
CVE-2023-26207

An insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.2.0 through 7.2.4 and FortiProxy 7.0.0 through 7.0.10. 7.2.0 …

Fix: after 7.2.4
Fix from $1,600 2023-06-13
Fortisiem HIGH 8.8
CVE-2022-42478

An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access to severa…

Fix: after 6.3.3
Fix from $1,950 2023-06-13
Fortinac HIGH 7.2
CVE-2022-39946

An access control vulnerability [CWE-284] in FortiNAC version 9.4.2 and below, version 9.2.7 and below, 9.1 all versions, 8.8 all versions, 8.7 all v…

Fix: after 9.2.8
Fix from $1,950 2023-06-13
Forticlient MEDIUM 5.5
CVE-2022-33877

An incorrect default permission [CWE-276] vulnerability in FortiClient (Windows) versions 7.0.0 through 7.0.6 and 6.4.0 through 6.4.8 and FortiConver…

Fix: after 7.0.6
Fix from $1,600 2023-06-13
Fortiadc HIGH 7.8
CVE-2023-27999

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 7.2.0, 7.1.0 through 7.1.1 may allow an authe…

Fix: 7.1.2+
Fix from $1,950 2023-05-03
Fortinac HIGH 7.8
CVE-2023-26203

A use of hard-coded credentials vulnerability [CWE-798] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all vers…

Fix: 9.4.3+
Fix from $1,950 2023-05-03
Fortiadc HIGH 7.1
CVE-2023-27993

A relative path traversal [CWE-23] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a privileged attacker to delete arbitrary directories f…

Fix: 7.1.2+
Fix from $1,950 2023-05-03
Fortinac CRITICAL 9.0
CVE-2023-22637

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiNAC-F version 7.2.0, FortiNAC …

Fix: 9.4.3+
Fix from $2,300 2023-05-03
Fortiproxy HIGH 8.8
CVE-2023-22640

A out-of-bounds write in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.10, FortiOS version 6.4.0 through 6.4.11, Fo…

Fix: 6.2.14 / 6.4.12+
Fix from $1,950 2023-05-03
Fortinac HIGH 7.5
CVE-2022-45860

A weak authentication vulnerability [CWE-1390] in FortiNAC-F version 7.2.0, FortiNAC version 9.4.2 and below, 9.2 all versions, 9.1 all versions, 8.8…

Fix: 9.4.2+
Fix from $1,950 2023-05-03
Fortinac HIGH 7.4
CVE-2022-45858

A use of a weak cryptographic algorithm vulnerability [CWE-327] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.0 all versions, 8.8.0 all versions,…

Fix: 9.1.0 / 9.2.6+
Fix from $1,950 2023-05-03
Fortisoar HIGH 8.8
CVE-2023-27995

A improper neutralization of special elements used in a template engine vulnerability in Fortinet FortiSOAR 7.3.0 through 7.3.1 allows an authenticat…

Fix: 7.3.2+
Fix from $1,950 2023-04-11