Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortianalyzer HIGH 8.1
CVE-2023-22642

An improper certificate validation vulnerability [CWE-295] in FortiAnalyzer and FortiManager 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4.8 through …

Fix: 6.4.11 / 7.0.6+
Fix from $1,950 2023-04-11
Forticlient HIGH 7.8
CVE-2023-22635

A download of code without Integrity check vulnerability [CWE-494] in FortiClientMac version 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions…

Fix: 7.0.8+
Fix from $1,950 2023-04-11
Fortiproxy MEDIUM 5.4
CVE-2023-22641

A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS v…

Fix: 6.4.13 / 7.0.9+
Fix from $1,600 2023-04-11
Fortiproxy CRITICAL 9.8
CVE-2022-41331

A missing authentication for critical function vulnerability [CWE-306] in FortiPresence infrastructure server before version 1.2.1 allows a remote, u…

Fix: 2.0.0+
Fix from $2,300 2023-04-11
Fortideceptor HIGH 8.8
CVE-2022-27487

A improper privilege management in Fortinet FortiSandbox version 4.2.0 through 4.2.2, 4.0.0 through 4.0.2 and before 3.2.3 and FortiDeceptor version …

Fix: 3.2.4 / 3.3.3+
Fix from $1,950 2023-04-11
Fortiproxy HIGH 8.8
CVE-2022-43947

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiOS version 7.2.0 through 7.2.3 and before 7.0.1…

Fix: 6.4.13 / 7.0.8+
Fix from $1,950 2023-04-11
Forticlient HIGH 8.1
CVE-2022-43946

Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (…

Fix: 7.0.8+
Fix from $1,950 2023-04-11
Fortiadc HIGH 7.8
CVE-2022-40679

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 5.x all versions, 6.0 all versions, 6.1 all v…

Fix: 5.7.0 / 6.1.5+
Fix from $1,950 2023-04-11
Forticlient HIGH 7.8
CVE-2022-40682

A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to exec…

Fix: 7.0.8+
Fix from $1,950 2023-04-11
Forticlient HIGH 7.8
CVE-2022-42470

A relative path traversal vulnerability in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an at…

Fix: 7.0.8+
Fix from $1,950 2023-04-11
Fortiadc HIGH 7.8
CVE-2022-43948

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.3, FortiA…

Fix: 6.2.6 / 7.0.4+
Fix from $1,950 2023-04-11
Fortinac HIGH 7.5
CVE-2022-43951

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and below, …

Fix: 7.2.0 / 9.4.2+
Fix from $1,950 2023-04-11
Fortisandbox MEDIUM 6.5
CVE-2022-27485

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-89] in Fortinet FortiSandbox version 4.2.0,…

Fix: 3.2.4 / 4.0.3+
Fix from $1,600 2023-04-11
Fortiauthenticator MEDIUM 6.1
CVE-2022-35850

An improper neutralization of script-related HTML tags in a web page vulnerability [CWE-80] in FortiAuthenticator versions 6.4.0 through 6.4.4, 6.3.0…

Fix: 6.3.4 / 6.4.7+
Fix from $1,600 2023-04-11
Fortiproxy MEDIUM 6.1
CVE-2022-41330

An improper neutralization of input during web page generation vulnerability ('Cross-site Scripting') [CWE-79] in Fortinet FortiOS version 7.2.0 thro…

Fix: 6.2.13 / 6.4.12+
Fix from $1,600 2023-04-11
Fortiweb MEDIUM 6.1
CVE-2022-43955

An improper neutralization of input during web page generation [CWE-79] in the FortiWeb web interface 7.0.0 through 7.0.3, 6.3.0 through 6.3.21, 6.4 …

Fix: 6.3.22 / 7.0.4+
Fix from $1,600 2023-04-11
Fortianalyzer MEDIUM 5.5
CVE-2022-42477

An improper input validation vulnerability [CWE-20] in FortiAnalyzer version 7.2.1 and below, version 7.0.6 and below, 6.4 all versions may allow an …

Fix: 7.0.7+
Fix from $1,600 2023-04-11
Fortiadc MEDIUM 5.4
CVE-2022-43952

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC version 7.1.1 and below, v…

Fix: 6.2.6 / 7.0.4+
Fix from $1,600 2023-04-11
Fortimail MEDIUM 5.3
CVE-2022-29056

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiMail version 6.4.0, version 6.2.0 through 6.2.4 …

Fix: 6.0.10 / 6.2.5+
Fix from $1,600 2023-03-09
Fortiauthenticator MEDIUM 5.3
CVE-2023-26208

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiAuthenticator 6.4.x and before allows a remote …

Fix: 6.5.0+
Fix from $1,600 2023-03-09
Fortideceptor MEDIUM 5.3
CVE-2023-26209

A improper restriction of excessive authentication attempts vulnerability [CWE-307] in Fortinet FortiDeceptor 3.1.x and before allows a remote unaut…

Fix: 3.2.0+
Fix from $1,600 2023-03-09
Fortiproxy HIGH 8.2
CVE-2022-42476

A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.11, FortiProxy v…

Fix: after 7.2.3
Fix from $1,950 2023-03-07
Fortirecorder Firmware HIGH 7.5
CVE-2022-41333EPSS 7%

An uncontrolled resource consumption vulnerability [CWE-400] in FortiRecorder version 6.4.3 and below, 6.0.11 and below login authentication mechanis…

Fix: after 6.4.3
Fix from $1,950 2023-03-07
Fortianalyzer HIGH 7.3
CVE-2023-25611

A improper neutralization of formula elements in a CSV file vulnerability in Fortinet FortiAnalyzer 6.4.0 - 6.4.9, 7.0.0 - 7.0.5, and 7.2.0 - 7.2.1 a…

Fix: 7.0.6 / 7.2.2+
Fix from $1,950 2023-03-07
Fortisoar HIGH 7.2
CVE-2023-25605

A improper access control vulnerability in Fortinet FortiSOAR 7.3.0 - 7.3.1 allows an attacker authenticated on the administrative interface to perfo…

Fix: 7.3.2+
Fix from $1,950 2023-03-07
Fortios HIGH 7.1
CVE-2022-41328 KEVEPSS 12%

A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2…

Fix: 6.2.14 / 6.4.12+
Fix from $1,950 2023-03-07
Fortiproxy MEDIUM 6.5
CVE-2022-45861

An access of uninitialized pointer vulnerability [CWE-824] in the SSL VPN portal of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 throu…

Fix: after 7.2.3
Fix from $1,600 2023-03-07
Fortinac MEDIUM 5.4
CVE-2022-40676

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.…

Fix: after 9.2.5
Fix from $1,600 2023-03-07
Fortiproxy MEDIUM 5.3
CVE-2022-41329

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 th…

Fix: after 7.2.3
Fix from $1,600 2023-03-07
Fortiweb HIGH 8.8
CVE-2022-39951

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiW…

Fix: after 7.0.2
Fix from $1,950 2023-03-07