Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Forticlient HIGH 7.8
CVE-2021-36183

An improper authorization vulnerability [CWE-285] in FortiClient for Windows versions 7.0.1 and below and 6.4.2 and below may allow a local unprivile…

Fix: after 7.0.1
Fix from $1,950 2021-11-02
Fortiportal HIGH 7.5
CVE-2021-36174

A memory allocation with excessive size value vulnerability in the license verification function of FortiPortal before 6.0.6 may allow an attacker to…

Fix: 6.0.6+
Fix from $1,950 2021-11-02
Fortiwlm MEDIUM 6.5
CVE-2021-36184

A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker t…

Fix: after 8.6.1
Fix from $1,600 2021-11-02
Fortiportal MEDIUM 6.1
CVE-2021-36176

Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a single low-privileged user to…

Fix: 6.0.6+
Fix from $1,600 2021-11-02
Fortiportal HIGH 8.1
CVE-2021-36172

An improper restriction of XML external entity reference vulnerability in the parser of XML responses of FortiPortal before 6.0.6 may allow an attack…

Fix: 5.3.7 / 6.0.6+
Fix from $1,950 2021-11-02
Fortiportal MEDIUM 6.5
CVE-2021-32595

Multiple uncontrolled resource consumption vulnerabilities in the web interface of FortiPortal before 6.0.6 may allow a single low-privileged user to…

Fix: 5.3.7 / 6.0.6+
Fix from $1,600 2021-11-02
Fortios MEDIUM 6.5
CVE-2021-41019

An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a ma…

Fix: after 6.4.6
Fix from $1,600 2021-11-02
Fortianalyzer MEDIUM 5.4
CVE-2020-12814

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiAnalyzer version 6.0.6 and below, version 6.4…

Fix: after 6.0.6
Fix from $1,600 2021-11-02
Forticlient Enterprise Management Server MEDIUM 5.4
CVE-2020-15940

An improper neutralization of input vulnerability [CWE-79] in FortiClientEMS versions 6.4.1 and below and 6.2.9 and below may allow a remote authenti…

Fix: after 6.4.1
Fix from $1,600 2021-11-02
Forticlient Endpoint Management Server CRITICAL 9.8
CVE-2021-24019

An insufficient session expiration vulnerability [CWE- 613] in FortiClientEMS versions 6.4.2 and below, 6.2.8 and below may allow an attacker to reus…

Fix: 6.2.9 / 6.4.2+
Fix from $2,300 2021-10-06
Fortisdnconnector MEDIUM 6.5
CVE-2021-36178

A insufficiently protected credentials in Fortinet FortiSDNConnector version 1.1.7 and below allows attacker to disclose third-party devices credenti…

Fix: 1.1.8+
Fix from $1,600 2021-10-06
Forticlient Endpoint Management Server MEDIUM 5.4
CVE-2020-15941

A path traversal vulnerability [CWE-22] in FortiClientEMS versions 6.4.1 and below; 6.2.8 and below may allow an authenticated attacker to inject dir…

Fix: 6.2.9 / 6.4.2+
Fix from $1,600 2021-10-06
Fortianalyzer MEDIUM 5.4
CVE-2021-24021

An improper neutralization of input vulnerability [CWE-79] in FortiAnalyzer versions 6.4.3 and below, 6.2.7 and below and 6.0.10 and below may allow …

Fix: 6.2.8 / 6.4.4+
Fix from $1,600 2021-10-06
Fortiweb MEDIUM 5.4
CVE-2021-36175

An improper neutralization of input vulnerability [CWE-79] in FortiWebManager versions 6.2.3 and below, 6.0.2 and below may allow a remote authentica…

Fix: 6.2.4+
Fix from $1,600 2021-10-06
Fortimanager MEDIUM 6.3
CVE-2021-24016

An improper neutralization of formula elements in a csv file in Fortinet FortiManager version 6.4.3 and below, 6.2.7 and below allows attacker to exe…

Fix: 6.2.8 / 6.4.4+
Fix from $1,600 2021-09-30
Fortiweb HIGH 8.8
CVE-2021-36179

A stack-based buffer overflow in Fortinet FortiWeb version 6.3.14 and below, 6.2.4 and below allows attacker to execute unauthorized code or commands…

Fix: after 6.3.14
Fix from $1,950 2021-09-08
Fortiweb HIGH 8.8
CVE-2021-36182

A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker t…

Fix: 6.3.14+
Fix from $1,950 2021-09-08
Fortisandbox MEDIUM 5.3
CVE-2020-29012

An insufficient session expiration vulnerability in FortiSandbox versions 3.2.1 and below may allow an attacker to reuse the unexpired admin user ses…

Fix: 3.2.2+
Fix from $1,600 2021-09-08
Fortimanager HIGH 8.8
CVE-2021-24006

An improper access control vulnerability in FortiManager versions 6.4.0 to 6.4.3 may allow an authenticated attacker with a restricted user profile t…

Fix: 6.4.4+
Fix from $1,950 2021-09-06
Fortiportal MEDIUM 6.1
CVE-2021-32602

An improper neutralization of input during web page generation vulnerability (CWE-79) in FortiPortal GUI 6.0.4 and below, 5.3.6 and below, 5.2.6 and …

Fix: after 6.0.4
Fix from $1,600 2021-08-19
Fortiportal CRITICAL 9.8
CVE-2021-32588

A use of hard-coded credentials (CWE-798) vulnerability in FortiPortal versions 5.2.5 and below, 5.3.5 and below, 6.0.4 and below, versions 5.1.x and…

Fix: after 6.0.4
Fix from $2,300 2021-08-18
Fortianalyzer MEDIUM 5.4
CVE-2021-32597

Multiple improper neutralization of input during web page generation (CWE-79) in FortiManager and FortiAnalyzer versions 7.0.0, 6.4.5 and below, 6.2.…

Fix: 6.2.8 / 6.4.6+
Fix from $1,600 2021-08-06
Fortianalyzer MEDIUM 6.5
CVE-2021-32603

A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 an…

Fix: 6.2.8 / 6.4.6+
Fix from $1,600 2021-08-05
Fortiauthenticator HIGH 7.5
CVE-2021-22124

An uncontrolled resource consumption (denial of service) vulnerability in the login modules of FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4,…

Fix: 3.0.7 / 3.1.5+
Fix from $1,950 2021-08-04
Fortisandbox MEDIUM 6.1
CVE-2021-24014

Multiple instances of improper neutralization of input during web page generation vulnerabilities in FortiSandbox before 4.0.0 may allow an unauthent…

Fix: 3.2.3+
Fix from $1,600 2021-08-04
Fortisandbox HIGH 8.8
CVE-2021-26096

Multiple instances of heap-based buffer overflow in the command shell of FortiSandbox before 4.0.0 may allow an authenticated attacker to manipulate …

Fix: 3.2.3+
Fix from $1,950 2021-08-04
Fortisandbox HIGH 8.8
CVE-2020-29011

Instances of SQL Injection vulnerabilities in the checksum search and MTA-quarantine modules of FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3…

Fix: 3.1.5 / 3.2.2+
Fix from $1,950 2021-08-04
Fortisandbox HIGH 8.8
CVE-2021-26097

An improper neutralization of special elements used in an OS Command vulnerability in FortiSandbox 3.2.0 through 3.2.2, 3.1.0 through 3.1.4, and 3.0.…

Fix: 3.0.7 / 3.1.5+
Fix from $1,950 2021-08-04
Fortiportal HIGH 7.5
CVE-2021-32596

A use of one-way hash with a predictable salt vulnerability in the password storing mechanism of FortiPortal 6.0.0 through 6.04 may allow an attacker…

Fix: after 6.0.4
Fix from $1,950 2021-08-04
Fortiportal MEDIUM 6.5
CVE-2021-36168

A Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Fortinet FortiPortal 6.x before 6.0.5, FortiPortal 5.3.x before 5…

Fix: 5.2.6 / 5.3.6+
Fix from $1,600 2021-08-04