Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortinac MEDIUM 6.7
CVE-2021-41021

A privilege escalation vulnerability in FortiNAC versions 8.8.8 and below and 9.1.2 and below may allow an admin user to escalate the privileges to r…

Patch available
Fix from $1,600 2021-12-08
Fortiweb MEDIUM 6.1
CVE-2021-36188

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below…

Fix: 6.3.16 / 6.4.2+
Fix from $1,600 2021-12-08
Fortiweb MEDIUM 5.3
CVE-2021-41013

An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Re…

Fix: after 6.3.15
Fix from $1,600 2021-12-08
Fortiweb MEDIUM 6.3
CVE-2021-36190

A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attac…

Fix: after 6.3.15
Fix from $1,600 2021-12-08
Fortiweb MEDIUM 6.1
CVE-2021-43063

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 a…

Fix: after 6.3.15
Fix from $1,600 2021-12-08
Fortiweb HIGH 7.8
CVE-2021-41027

A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute unauthorized code or commands…

Patch available
Fix from $1,950 2021-12-08
Fortiweb MEDIUM 6.1
CVE-2021-43064

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below…

Fix: after 6.3.15
Fix from $1,600 2021-12-08
Fortios CRITICAL 9.8
CVE-2021-26109

An integer overflow or wraparound vulnerability in the memory allocator of SSLVPN in FortiOS before 7.0.1 may allow an unauthenticated attacker to co…

Fix: after 6.4.5
Fix from $2,300 2021-12-08
Fortios HIGH 7.5
CVE-2021-26108

A use of hard-coded cryptographic key vulnerability in the SSLVPN of FortiOS before 7.0.1 may allow an attacker to retrieve the key by reverse engine…

Fix: after 6.4.5
Fix from $1,950 2021-12-08
Fortiweb HIGH 7.5
CVE-2021-41014

A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the htt…

Fix: after 6.3.15
Fix from $1,950 2021-12-08
Fortiproxy HIGH 7.5
CVE-2021-41024

A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unaut…

Patch available
Fix from $1,950 2021-12-08
Fortiweb MEDIUM 6.1
CVE-2021-41015

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below…

Patch available
Fix from $1,600 2021-12-08
Fortiweb MEDIUM 5.4
CVE-2021-36191

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the devic…

Fix: after 6.3.15
Fix from $1,600 2021-12-08
Fortiproxy HIGH 8.8
CVE-2021-26103

An insufficient verification of data authenticity vulnerability (CWE-345) in the user interface of FortiProxy verison 2.0.3 and below, 1.2.11 and bel…

Fix: after 6.4.6
Fix from $1,950 2021-12-08
Fortiwlm HIGH 8.8
CVE-2021-42760

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker t…

Fix: after 8.6.1
Fix from $1,950 2021-12-08
Fortiauthenticator MEDIUM 6.5
CVE-2021-43067

A exposure of sensitive information to an unauthorized actor in Fortinet FortiAuthenticator version 6.4.0, version 6.3.2 and below, version 6.2.1 and…

Fix: after 6.0.7
Fix from $1,600 2021-12-08
Fortiwlm MEDIUM 5.4
CVE-2021-41029

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker t…

Fix: after 8.6.1
Fix from $1,600 2021-12-08
Fortiwlm MEDIUM 5.4
CVE-2021-42752

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker t…

Fix: after 8.6.1
Fix from $1,600 2021-12-08
Fortiadc MEDIUM 5.3
CVE-2021-32591

A missing cryptographic steps vulnerability in the function that encrypts users' LDAP and RADIUS credentials in FortiSandbox before 4.0.1, FortiWeb b…

Fix: after 6.4.5
Fix from $1,600 2021-12-08
Fortiweb HIGH 8.8
CVE-2021-36180

Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management interface 6.4.1 and below, 6.3…

Fix: after 6.3.15
Fix from $1,950 2021-12-08
Fortiwlc HIGH 8.8
CVE-2021-42758

An improper access control vulnerability [CWE-284] in FortiWLC 8.6.1 and below may allow an authenticated and remote attacker with low privileges to …

Fix: after 8.5.5
Fix from $1,950 2021-12-08
Fortiproxy HIGH 7.8
CVE-2021-26110

An improper access control vulnerability [CWE-284] in FortiOS autod daemon 7.0.0, 6.4.6 and below, 6.2.9 and below, 6.0.12 and below and FortiProxy 2…

Fix: after 6.4.6
Fix from $1,950 2021-12-08
Fortiadc MEDIUM 6.7
CVE-2021-42757

A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local atta…

Fix: after 7.0.2
Fix from $1,600 2021-12-08
Forticlient HIGH 7.8
CVE-2021-32592

An unsafe search path vulnerability in FortiClientWindows 7.0.0, 6.4.6 and below, 6.2.x, 6.0.x and FortiClientEMS 7.0.0, 6.4.6 and below, 6.2.x, 6.0.…

Fix: 6.4.7+
Fix from $1,950 2021-12-01
Fortisiem HIGH 7.8
CVE-2021-41022

A improper privilege management in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows attacker to execute privileged code or commands vi…

Fix: after 4.1.4
Fix from $1,950 2021-11-02
Fortiweb HIGH 7.5
CVE-2021-36187

A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to cause a denial o…

Fix: after 6.3.15
Fix from $1,950 2021-11-02
Fortisiem MEDIUM 5.5
CVE-2021-41023

A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent pas…

Fix: after 4.1.4
Fix from $1,600 2021-11-02
Forticlient MEDIUM 5.0
CVE-2021-42754

An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authen…

Fix: after 6.4.5
Fix from $1,600 2021-11-02
Fortiweb CRITICAL 9.8
CVE-2021-36186

A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to execute unauthorized c…

Fix: after 6.3.15
Fix from $2,300 2021-11-02
Fortiwlm HIGH 8.8
CVE-2021-36185

A improper neutralization of special elements used in an OS command ('OS Command Injection') in Fortinet FortiWLM version 8.6.1 and below allows atta…

Fix: after 8.6.1
Fix from $1,950 2021-11-02