Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortianalyzer MEDIUM 6.7
CVE-2022-26118

A privilege chaining vulnerability [CWE-268] in FortiManager and FortiAnalyzer 6.0.x, 6.2.x, 6.4.0 through 6.4.7, 7.0.0 through 7.0.3 may allow a loc…

Fix: 6.4.8 / 7.0.4+
Fix from $1,600 2022-07-18
Forticlient HIGH 7.8
CVE-2021-41031

A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior and 6.2.9 and below may allow a…

Fix: after 7.0.2
Fix from $1,950 2022-07-18
Fortios MEDIUM 6.1
CVE-2022-23438

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in FortiOS version 7.0.5 and prior and…

Fix: after 7.0.5
Fix from $1,600 2022-07-18
Fortitoken Mobile MEDIUM 5.4
CVE-2021-22131

A improper validation of certificate with host mismatch in Fortinet FortiTokenAndroid version 5.0.3 and below, Fortinet FortiTokeniOS version 5.2.0 a…

Patch available
Fix from $1,600 2022-07-18
Fortiproxy MEDIUM 6.7
CVE-2021-44170

A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8 may allow a…

Fix: 2.0.8 / 6.2.11+
Fix from $1,600 2022-07-18
Fortiauthenticator Agent For Microsoft Outlook Web Access MEDIUM 6.1
CVE-2022-22304

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAuthenticator OWA Agent for Microsoft version 2.2 and 2…

Mitigation only
Fix from $1,600 2022-07-18
Fortios MEDIUM 5.3
CVE-2022-22306

An improper certificate validation vulnerability [CWE-295] in FortiOS 6.0.0 through 6.0.14, 6.2.0 through 6.2.10, 6.4.0 through 6.4.8, 7.0.0 may allo…

Fix: 6.4.9+
Fix from $1,600 2022-05-24
Forticlient HIGH 7.8
CVE-2021-43066

A external control of file name or path in Fortinet FortiClientWindows version 7.0.2 and below, version 6.4.6 and below, version 6.2.9 and below, ver…

Fix: 6.4.7 / 7.0.3+
Fix from $1,950 2022-05-11
Forticlient HIGH 7.5
CVE-2021-44167

An incorrect permission assignment for critical resource vulnerability [CWE-732] in FortiClient for Linux version 6.0.8 and below, 6.2.9 and below, 6…

Fix: after 7.0.2
Fix from $1,950 2022-05-11
Fortiproxy MEDIUM 6.1
CVE-2021-43081

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS version 7.0.3 and below, 6.4.8 and below, 6.2.10 and…

Fix: 2.0.8 / 6.4.9+
Fix from $1,600 2022-05-11
Fortinac HIGH 8.8
CVE-2022-26116

Multiple improper neutralization of special elements used in SQL commands ('SQL Injection') vulnerability [CWE-89] in FortiNAC version 8.3.7 and belo…

Fix: after 9.2.2
Fix from $1,950 2022-05-11
Fortiisolator HIGH 8.8
CVE-2021-41020

An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privileged attacker to r…

Fix: 2.3.3+
Fix from $1,950 2022-05-04
Fortisoar HIGH 7.5
CVE-2022-23443

An improper access control in Fortinet FortiSOAR before 7.2.0 allows unauthenticated attackers to access gateway API data via crafted HTTP GET reques…

Fix: after 7.0.2
Fix from $1,950 2022-05-04
Fortios MEDIUM 5.4
CVE-2021-41032

An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a…

Fix: 6.4.9 / 7.0.4+
Fix from $1,600 2022-05-04
Fortiweb MEDIUM 6.5
CVE-2021-41026

A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files…

Fix: 6.3.16 / 6.4.2+
Fix from $1,600 2022-04-06
Fortiwan MEDIUM 6.1
CVE-2021-32585

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWAN before 4.5.9 may allow an attacker to perform a sto…

Fix: 4.5.9+
Fix from $1,600 2022-04-06
Fortiauthenticator HIGH 8.8
CVE-2021-26116

An improper neutralization of special elements used in an OS command vulnerability in the command line interpreter of FortiAuthenticator before 6.3.1…

Fix: 6.3.1+
Fix from $1,950 2022-04-06
Forticlient HIGH 8.0
CVE-2021-22127

An improper input validation vulnerability in FortiClient for Linux 6.4.x before 6.4.3, FortiClient for Linux 6.2.x before 6.2.9 may allow an unauthe…

Fix: 6.2.9 / 6.4.3+
Fix from $1,950 2022-04-06
Fortianalyzer HIGH 7.8
CVE-2021-26104

Multiple OS command injection (CWE-78) vulnerabilities in the command line interface of FortiManager 6.2.7 and below, 6.4.5 and below and all version…

Fix: 5.2.6 / 5.3.6+
Fix from $1,950 2022-04-06
Fortiwan HIGH 7.5
CVE-2021-26113

A use of a one-way hash with a predictable salt vulnerability [CWE-760] in FortiWAN before 4.5.9 may allow an attacker who has previously come in pos…

Fix: 4.5.9+
Fix from $1,950 2022-04-06
Forticlient HIGH 8.8
CVE-2021-44169

A improper initialization in Fortinet FortiClient (Windows) version 6.0.10 and below, version 6.2.9 and below, version 6.4.7 and below, version 7.0.3…

Fix: after 7.0.2
Fix from $1,950 2022-04-06
Fortiedr HIGH 7.8
CVE-2022-23440

A use of hard-coded cryptographic key vulnerability [CWE-321] in the registration mechanism of FortiEDR collectors versions 5.0.2, 5.0.1, 5.0.0, 4.0.…

Patch available
Fix from $1,950 2022-04-06
Forticlient MEDIUM 5.3
CVE-2021-43205

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Linux version 7.0.2 and below, 6.4.7 and bel…

Fix: after 7.0.2
Fix from $1,600 2022-04-06
Fortiwan CRITICAL 9.8
CVE-2021-26112

Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpreter of FortiWAN before 4.5.9 m…

Fix: after 4.5.8
Fix from $2,300 2022-04-06
Fortiwan CRITICAL 9.8
CVE-2021-26114

Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may allow an unauthenticated att…

Fix: after 4.5.8
Fix from $2,300 2022-04-06
Fortiwan HIGH 8.8
CVE-2021-24009

Multiple improper neutralization of special elements used in an OS command vulnerabilities (CWE-78) in the Web GUI of FortiWAN before 4.5.9 may allow…

Fix: after 4.5.8
Fix from $1,950 2022-04-06
Fortiwan MEDIUM 6.5
CVE-2021-32593

A use of a broken or risky cryptographic algorithm vulnerability [CWE-327] in the Dynamic Tunnel Protocol of FortiWAN before 4.5.9 may allow an unaut…

Fix: after 4.5.8
Fix from $1,600 2022-04-06
Fortiedr CRITICAL 9.1
CVE-2022-23441

A use of hard-coded cryptographic key vulnerability [CWE-321] in FortiEDR versions 5.0.2, 5.0.1, 5.0.0, 4.0.0 may allow an unauthenticated attacker o…

Patch available
Fix from $2,300 2022-04-06
Fortisandbox MEDIUM 5.4
CVE-2020-29013

An improper input validation vulnerability in the sniffer interface of FortiSandbox before 3.2.2 may allow an authenticated attacker to silently halt…

Fix: after 3.1.4
Fix from $1,600 2022-04-06
Fortiwlm MEDIUM 6.5
CVE-2021-43070

Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 a…

Fix: after 8.6.2
Fix from $1,600 2022-03-02