Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortimanager MEDIUM 5.5
CVE-2022-22303

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 …

Fix: after 7.0.2
Fix from $1,600 2022-03-02
Fortiap C HIGH 7.8
CVE-2022-22301

An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] in FortiAP-C console 5.4.0 through 5.4.3, 5.2.0 through 5…

Patch available
Fix from $1,950 2022-03-02
Fortimail CRITICAL 9.8
CVE-2021-32586

An improper input validation vulnerability in the web server CGI facilities of FortiMail before 7.0.1 may allow an unauthenticated attacker to alter …

Fix: 6.0.12 / 6.2.8+
Fix from $2,300 2022-03-01
Fortiwlm HIGH 8.8
CVE-2021-43075

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.…

Fix: 8.6.3+
Fix from $1,950 2022-03-01
Fortiwlm HIGH 8.8
CVE-2021-43077

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 an…

Fix: 8.6.3+
Fix from $1,950 2022-03-01
Fortianalyzer HIGH 8.8
CVE-2022-22300

A improper handling of insufficient permissions or privileges in Fortinet FortiAnalyzer version 5.6.0 through 5.6.11, FortiAnalyzer version 6.0.0 thr…

Fix: 7.0.3+
Fix from $1,950 2022-03-01
Fortimail CRITICAL 9.8
CVE-2021-36166

An improper authentication vulnerability in FortiMail before 7.0.1 may allow a remote attacker to efficiently guess one administrative account's auth…

Fix: 6.0.12 / 6.2.8+
Fix from $2,300 2022-03-01
Fortiportal HIGH 8.1
CVE-2021-36171

The use of a cryptographically weak pseudo-random number generator in the password reset feature of FortiPortal before 6.0.6 may allow a remote unaut…

Fix: 5.2.7 / 5.3.7+
Fix from $1,950 2022-03-01
Fortiproxy MEDIUM 6.1
CVE-2021-26092

Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 through 5.6.14, 6.0.0 through 6.0.1…

Fix: after 6.4.4
Fix from $1,600 2022-02-24
Fortiweb HIGH 8.8
CVE-2021-41018

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and…

Fix: 6.2.7 / 6.3.16+
Fix from $1,950 2022-02-02
Fortiweb HIGH 7.2
CVE-2021-36193

Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may allow an authenticated attacker to achieve arbitra…

Fix: 6.2.6 / 6.3.16+
Fix from $1,950 2022-02-02
Fortiextender Firmware HIGH 8.8
CVE-2021-41016

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and be…

Fix: 4.1.8 / 4.2.4+
Fix from $1,950 2022-02-02
Fortiweb HIGH 8.8
CVE-2021-43073

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.…

Fix: 6.2.7 / 6.3.17+
Fix from $1,950 2022-02-02
Fortiweb HIGH 8.1
CVE-2021-42753

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb management interface 6.4.1 and b…

Fix: 6.3.16 / 6.4.2+
Fix from $1,950 2022-02-02
Fortimail MEDIUM 6.1
CVE-2021-43062EPSS 13%

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiMail version 7.0.1 and 7.0.0, version 6.4.5 a…

Fix: 6.2.8 / 6.4.6+
Fix from $1,600 2022-02-02
Fortimail MEDIUM 5.3
CVE-2020-15933

A exposure of sensitive information to an unauthorized actor in Fortinet FortiMail versions 6.0.9 and below, FortiMail versions 6.2.4 and below Forti…

Fix: after 6.0.9
Fix from $1,600 2022-01-05
Fortios HIGH 7.8
CVE-2021-44168 KEV

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authentic…

Fix: 6.0.14 / 6.2.10+
Fix from $1,950 2022-01-04
Forticlient HIGH 7.5
CVE-2021-41028

A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper cer…

Fix: after 6.4.6
Fix from $1,950 2021-12-16
Fortios MEDIUM 6.0
CVE-2021-36169

A Hidden Functionality in Fortinet FortiOS 7.x before 7.0.1, FortiOS 6.4.x before 6.4.7 allows attacker to Execute unauthorized code or commands via …

Fix: 6.2.10 / 6.4.7+
Fix from $1,600 2021-12-13
Fortiweb HIGH 8.8
CVE-2021-43071

A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execu…

Fix: after 6.3.16
Fix from $1,950 2021-12-09
Fortiauthenticator HIGH 8.1
CVE-2021-43068

A improper authentication in Fortinet FortiAuthenticator version 6.4.0 allows user to bypass the second factor of authentication via a RADIUS login p…

Patch available
Fix from $1,950 2021-12-09
Fortinac HIGH 7.8
CVE-2021-43065

A incorrect permission assignment for critical resource in Fortinet FortiNAC version 9.2.0, version 9.1.3 and below, version 8.8.9 and below allows a…

Fix: 8.8.10 / 9.1.4+
Fix from $1,950 2021-12-09
Meru Firmware MEDIUM 6.7
CVE-2021-42759

A violation of secure design principles in Fortinet Meru AP version 8.6.1 and below, version 8.5.5 and below allows attacker to execute unauthorized …

Fix: 8.6.2+
Fix from $1,600 2021-12-09
Forticlient MEDIUM 5.3
CVE-2021-36167

An improper authorization vulnerabiltiy [CWE-285] in FortiClient Windows versions 7.0.0 and 6.4.6 and below and 6.2.8 and below may allow an unauthen…

Fix: after 6.4.6
Fix from $1,600 2021-12-09
Fortiweb HIGH 8.8
CVE-2021-36194

Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker t…

Fix: after 6.3.15
Fix from $1,950 2021-12-09
Fortiweb CRITICAL 9.8
CVE-2021-41025

Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0…

Fix: after 6.3.15
Fix from $2,300 2021-12-08
Fortios HIGH 8.8
CVE-2021-36173

A heap-based buffer overflow in the firmware signature verification function of FortiOS versions 7.0.1, 7.0.0, 6.4.0 through 6.4.6, 6.2.0 through 6.2…

Fix: after 6.4.6
Fix from $1,950 2021-12-08
Fortiweb HIGH 8.8
CVE-2021-36195

Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2…

Fix: after 6.3.15
Fix from $1,950 2021-12-08
Fortiweb HIGH 8.8
CVE-2021-41017

Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow a remote…

Fix: after 6.3.15
Fix from $1,950 2021-12-08
Forticlient Enterprise Management Server CRITICAL 9.1
CVE-2021-41030

An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unaut…

Fix: after 6.4.4
Fix from $2,300 2021-12-08