Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Antivirus Engine HIGH 8.6
CVE-2022-26122

An insufficient verification of data authenticity vulnerability [CWE-345] in FortiClient, FortiMail and FortiOS AV engines version 6.2.168 and below …

Fix: after 7.0.6
Fix from $1,950 2022-11-02
Fortios HIGH 8.1
CVE-2022-30307

A key management error vulnerability [CWE-320] affecting the RSA SSH host key in FortiOS 7.2.0 and below, 7.0.6 and below, 6.4.9 and below may allow …

Fix: 6.4.10 / 7.0.8+
Fix from $1,950 2022-11-02
Fortisiem HIGH 7.8
CVE-2022-26119

A improper authentication vulnerability in Fortinet FortiSIEM before 6.5.0 allows a local attacker with CLI access to perform operations on the Glass…

Fix: after 6.3.3
Fix from $1,950 2022-11-02
Fortitester CRITICAL 9.8
CVE-2022-33872

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Telnet login components of …

Fix: 3.9.2 / 4.2.1+
Fix from $2,300 2022-10-18
Fortitester CRITICAL 9.8
CVE-2022-33873

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in Console login components of…

Fix: 3.9.2 / 4.2.1+
Fix from $2,300 2022-10-18
Fortitester CRITICAL 9.8
CVE-2022-33874

An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in SSH login components of For…

Fix: 3.9.2 / 4.2.1+
Fix from $2,300 2022-10-18
Fortiproxy HIGH 7.5
CVE-2022-29055

A access of uninitialized pointer in Fortinet FortiOS version 7.2.0, 7.0.0 through 7.0.5, 6.4.0 through 6.4.8, 6.2.0 through 6.2.10, 6.0.x, FortiProx…

Fix: 1.2.13 / 2.0.10+
Fix from $1,950 2022-10-18
Fortitester CRITICAL 9.8
CVE-2022-35846

An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiTester Telnet port 2.3.0 through 3.9.1, 4.0.0 through 4.…

Fix: 3.9.2 / 4.2.1+
Fix from $2,300 2022-10-18
Fortiproxy CRITICAL 9.8
CVE-2022-40684 KEVEPSS 100%

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiP…

Fix: 7.0.7 / 7.2.2+
Fix from $2,300 2022-10-18
Fortitester HIGH 7.2
CVE-2022-35844

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiTester 2.3.0 through …

Fix: 3.9.2 / 4.2.1+
Fix from $1,950 2022-10-18
Fortios HIGH 8.0
CVE-2021-44171

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiOS version 6.0.0 through 6.0.14, FortiO…

Fix: after 7.0.3
Fix from $1,950 2022-10-10
Fortimanager MEDIUM 5.3
CVE-2022-26121

An exposure of resource to wrong sphere vulnerability [CWE-668] in FortiAnalyzer and FortiManager GUI 7.0.0 through 7.0.3, 6.4.0 through 6.4.8, 6.2.0…

Fix: after 7.0.3
Fix from $1,600 2022-10-10
Fortisoar HIGH 7.2
CVE-2022-29061

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2…

Fix: 7.0.3+
Fix from $1,950 2022-09-09
Fortisoar HIGH 8.8
CVE-2022-35847

An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 thro…

Fix: after 7.0.3
Fix from $1,950 2022-09-06
Fortisoar HIGH 7.8
CVE-2022-30298

An improper privilege management vulnerability [CWE-269] in Fortinet FortiSOAR before 7.2.1 allows a GUI user who has already found a way to modify s…

Fix: 7.0.3+
Fix from $1,950 2022-09-06
Fortiap HIGH 7.8
CVE-2022-29058

An improper neutralization of special elements [CWE-89] used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiAP 6.0.0…

Fix: 6.2.4 / 6.4.8+
Fix from $1,950 2022-09-06
Fortisoar MEDIUM 6.5
CVE-2022-29062

Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to write to the underly…

Fix: 7.0.3+
Fix from $1,600 2022-09-06
Fortios HIGH 7.5
CVE-2022-27491

A improper verification of source of a communication channel in Fortinet FortiOS with IPS engine version 7.201 through 7.214, 7.001 through 7.113, 6.…

Fix: 6.2.11 / 6.4.9+
Fix from $1,950 2022-09-06
Fortiadc MEDIUM 6.5
CVE-2021-43076

An improper privilege management vulnerability [CWE-269] in FortiADC versions 6.2.1 and below, 6.1.5 and below, 6.0.4 and below, 5.4.5 and below and …

Fix: after 6.1.5
Fix from $1,600 2022-09-06
Fortimail MEDIUM 6.1
CVE-2022-26114

An improper neutralization of input during web page generation vulnerability [CWE-79] in the Webmail of FortiMail before 7.2.0 may allow an unauthent…

Fix: 7.2.0+
Fix from $1,600 2022-09-06
Fortios MEDIUM 5.4
CVE-2021-43080

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.2.0, version 6.4.0 through 6.4.9, version …

Fix: 6.4.10 / 7.0.6+
Fix from $1,600 2022-09-06
Fortiadc HIGH 7.8
CVE-2022-22299

A format string vulnerability [CWE-134] in the command line interpreter of FortiADC version 6.0.0 through 6.0.4, FortiADC version 6.1.0 through 6.1.5…

Fix: 6.4.8 / 7.0.2+
Fix from $1,950 2022-08-05
Fortiddos HIGH 8.1
CVE-2022-29060

A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiDDoS API 5.5.0 through 5.5.1, 5.4.0 through 5.4.2, 5.3.0 through 5.3.1, 5.2.0, …

Patch available
Fix from $1,950 2022-07-19
Fortideceptor HIGH 8.1
CVE-2022-30302

Multiple relative path traversal vulnerabilities [CWE-23] in FortiDeceptor management interface 1.0.0 through 3.2.x, 3.3.0 through 3.3.2, 4.0.0 throu…

Fix: after 3.3.2
Fix from $1,950 2022-07-19
Fortianalyzer HIGH 7.2
CVE-2022-27483

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager version 7.0.0 through 7.0.3, 6.…

Fix: after 7.0.3
Fix from $1,950 2022-07-19
Forticlient HIGH 7.1
CVE-2022-26113

An execution with unnecessary privileges vulnerability [CWE-250] in FortiClientWindows 7.0.0 through 7.0.3, 6.4.0 through 6.4.7, 6.2.0 through 6.2.9,…

Fix: after 7.0.3
Fix from $1,950 2022-07-19
Fortiap U MEDIUM 6.7
CVE-2022-30301

A path traversal vulnerability [CWE-22] in FortiAP-U CLI 6.2.0 through 6.2.3, 6.0.0 through 6.0.4, 5.4.0 through 5.4.6 may allow an admin user to del…

Fix: after 6.2.3
Fix from $1,600 2022-07-19
Fortiedr MEDIUM 5.4
CVE-2022-29057

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiEDR version 5.1.0, 5.0.0 through 5.0.3 Patch …

Fix: 5.0.3+
Fix from $1,600 2022-07-19
Fortinac HIGH 8.8
CVE-2022-26117

An empty password in configuration file vulnerability [CWE-258] in FortiNAC version 8.3.7 and below, 8.5.2 and below, 8.5.4, 8.6.0, 8.6.5 and below, …

Fix: 9.1.6 / 9.2.4+
Fix from $1,950 2022-07-18
Fortiadc HIGH 8.8
CVE-2022-26120

Multiple improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerabilities [CWE-89] in FortiADC management interfa…

Fix: 6.2.3+
Fix from $1,950 2022-07-18