Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortinac HIGH 7.8
CVE-2022-39953

A improper privilege management in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.6, FortiNAC version 9.1.0 throug…

Fix: after 9.2.6
Fix from $1,950 2023-03-07
Fortianalyzer MEDIUM 6.5
CVE-2022-27490

A exposure of sensitive information to an unauthorized actor in Fortinet FortiManager version 6.0.0 through 6.0.4, FortiAnalyzer version 6.0.0 throug…

Fix: after 7.0.4
Fix from $1,600 2023-03-07
Fortiweb MEDIUM 5.5
CVE-2022-22297

An incomplete filtering of one or more instances of special elements vulnerability [CWE-792] in the command line interpreter of FortiWeb version 6.4.…

Fix: after 6.4.3
Fix from $1,600 2023-03-07
Fortiweb HIGH 8.8
CVE-2023-23779

Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiWeb version 7.0.…

Fix: after 6.3.19
Fix from $1,950 2023-02-16
Fortiweb HIGH 8.8
CVE-2023-23780

A stack-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, Fortinet FortiWeb version 6.3.6 through 6.3.19, Fortinet FortiWeb 6.4…

Fix: 6.3.20 / 7.0.2+
Fix from $1,950 2023-02-16
Fortiweb HIGH 8.8
CVE-2023-23781

A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below SAML server con…

Fix: 6.3.20 / 7.0.2+
Fix from $1,950 2023-02-16
Fortiweb HIGH 7.8
CVE-2023-23782

A heap-based buffer overflow in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb version 6.3.0 through 6.3.19, FortiWeb 6.4 all versions, Fort…

Fix: 6.3.20 / 7.0.2+
Fix from $1,950 2023-02-16
Fortiweb HIGH 7.8
CVE-2023-23783

A use of externally-controlled format string in Fortinet FortiWeb version 7.0.0 through 7.0.1, FortiWeb 6.4 all versions allows attacker to execute u…

Fix: 6.4.2 / 7.0.2+
Fix from $1,950 2023-02-16
Fortiweb HIGH 7.8
CVE-2023-25602

A stack-based buffer overflow in Fortinet FortiWeb 6.4 all versions, FortiWeb versions 6.3.17 and earlier, FortiWeb versions 6.2.6 and earlier, Forti…

Fix: 5.9.2 / 6.0.8+
Fix from $1,950 2023-02-16
Fortiweb MEDIUM 6.5
CVE-2023-23778

A relative path traversal vulnerability [CWE-23] in FortiWeb version 7.0.1 and below, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow …

Fix: after 6.3.21
Fix from $1,600 2023-02-16
Fortiweb MEDIUM 6.5
CVE-2023-23784

A relative path traversal in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows a…

Fix: 6.3.21 / 7.0.3+
Fix from $1,600 2023-02-16
Fortinac CRITICAL 9.8
CVE-2022-39952EPSS 100%

A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 th…

Fix: 9.1.8 / 9.2.6+
Fix from $2,300 2023-02-16
Fortinac CRITICAL 9.1
CVE-2022-39954

An improper restriction of xml external entity reference in Fortinet FortiNAC version 9.4.0 through 9.4.1, FortiNAC version 9.2.0 through 9.2.7, Fort…

Fix: 7.2.0 / 9.4.2+
Fix from $2,300 2023-02-16
Fortinac HIGH 8.8
CVE-2022-40677

A improper neutralization of argument delimiters in a command ('argument injection') in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 …

Fix: after 9.2.5
Fix from $1,950 2023-02-16
Fortiswitchmanager HIGH 8.1
CVE-2022-41335

A relative path traversal vulnerability [CWE-23] in Fortinet FortiOS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.8 and before 6.4.10, FortiProxy v…

Fix: after 7.0.8
Fix from $1,950 2023-02-16
Fortinac HIGH 7.8
CVE-2022-40678

An insufficiently protected credentials in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 th…

Fix: after 9.2.5
Fix from $1,950 2023-02-16
Fortiweb HIGH 7.8
CVE-2022-40683

A double free in Fortinet FortiWeb version 7.0.0 through 7.0.3 may allows attacker to execute unauthorized code or commands via specially crafted com…

Fix: after 7.0.3
Fix from $1,950 2023-02-16
Fortinac HIGH 7.4
CVE-2022-40675

Some cryptographic issues in Fortinet FortiNAC versions 9.4.0 through 9.4.1, 9.2.0 through 9.2.7, 9.1.0 through 9.1.8, 8.8.0 through 8.8.11, 8.7.0 th…

Fix: 7.2.0 / 9.4.2+
Fix from $1,950 2023-02-16
Fortiportal MEDIUM 6.5
CVE-2022-43954

An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a r…

Patch available
Fix from $1,600 2023-02-16
Fortios MEDIUM 6.1
CVE-2022-41334

An improper neutralization of input during web page generation [CWE-79] vulnerability in FortiOS versions 7.0.0 to 7.0.7 and 7.2.0 to 7.2.3 may allow…

Fix: after 7.2.3
Fix from $1,600 2023-02-16
Fortiproxy MEDIUM 5.4
CVE-2022-42472

A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS versions 7.2.0 through 7.2.2, 7.0.0 throu…

Fix: after 7.0.8
Fix from $1,600 2023-02-16
Fortinac MEDIUM 5.4
CVE-2023-22638

Several improper neutralization of inputs during web page generation vulnerability [CWE-79] in FortiNAC 9.4.1 and below, 9.2.6 and below, 9.1.8 and …

Fix: after 9.2.7
Fix from $1,600 2023-02-16
Fortinac CRITICAL 9.8
CVE-2022-38375

An improper authorization vulnerability [CWE-285]  in Fortinet FortiNAC version 9.4.0 through 9.4.1 and before 9.2.6 allows an unauthenticated user t…

Fix: 7.2.0 / 9.2.7+
Fix from $2,300 2023-02-16
Fortiweb HIGH 8.8
CVE-2022-30303

An improper neutralization of special elements used in an os command ('OS Command Injection') [CWE-78] in FortiWeb 7.0.0 through 7.0.1, 6.3.0 through…

Fix: 6.3.20+
Fix from $1,950 2023-02-16
Fortiweb HIGH 8.8
CVE-2022-30306

A stack-based buffer overflow vulnerability [CWE-121] in the CA sign functionality of FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3…

Fix: 6.3.20+
Fix from $1,950 2023-02-16
Fortiwan HIGH 8.8
CVE-2022-33869

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 through 4.5…

Fix: 4.5.10+
Fix from $1,950 2023-02-16
Fortiadc HIGH 7.8
CVE-2022-27482

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.1, 6.2.0 …

Fix: 6.2.4+
Fix from $1,950 2023-02-16
Fortisandbox HIGH 7.5
CVE-2022-26115

A use of password hash with insufficient computational effort vulnerability [CWE-916] in FortiSandbox before 4.2.0 may allow an attacker with access …

Mitigation only
Fix from $1,950 2023-02-16
Fortiproxy HIGH 7.4
CVE-2022-39948

An improper certificate validation vulnerability [CWE-295] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.7, 6.4 all versions, 6.2 all versions, 6…

Fix: 7.0.7 / 7.0.8+
Fix from $1,950 2023-02-16
Fortiextender Firmware HIGH 7.2
CVE-2022-27489

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.0.0 through 7.0.3, 5.3.2, 4.…

Fix: 3.2.4 / 3.3.3+
Fix from $1,950 2023-02-16