Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortios HIGH 8.8
CVE-2021-24018

A buffer underwrite vulnerability in the firmware verification routine of FortiOS before 7.0.1 may allow an attacker located in the adjacent network …

Fix: 6.2.10 / 6.4.7+
Fix from $1,950 2021-08-04
Fortisandbox MEDIUM 6.5
CVE-2021-24010

Improper limitation of a pathname to a restricted directory vulnerabilities in FortiSandbox 3.2.0 through 3.2.2, and 3.1.0 through 3.1.4 may allow an…

Fix: 3.1.5 / 3.2.3+
Fix from $1,600 2021-08-04
Fortiportal HIGH 8.8
CVE-2021-32590

Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, …

Fix: 5.2.6 / 5.3.6+
Fix from $1,950 2021-08-04
Fortiportal HIGH 8.1
CVE-2021-32594

An unrestricted file upload vulnerability in the web interface of FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.…

Fix: 5.2.6 / 5.3.6+
Fix from $1,950 2021-08-04
Fortisandbox HIGH 7.5
CVE-2021-26098

An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information piec…

Fix: 3.2.3+
Fix from $1,950 2021-08-04
Fortimail HIGH 8.8
CVE-2021-26095

The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the enc…

Fix: 6.4.5+
Fix from $1,950 2021-07-20
Fortisandbox HIGH 7.2
CVE-2021-22125

An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrato…

Fix: 3.2.2+
Fix from $1,950 2021-07-20
Fortinet Single Sign On CRITICAL 9.6
CVE-2021-26088

An improper authentication vulnerability in FSSO Collector version 5.0.295 and below may allow an unauthenticated user to bypass a FSSO firewall poli…

Fix: 6.4.6 / 7.0.1+
Fix from $2,300 2021-07-12
Fortimail HIGH 8.8
CVE-2021-24015

An improper neutralization of special elements used in an OS Command vulnerability in the administrative interface of FortiMail before 6.4.4 may allo…

Fix: 6.0.11 / 6.2.7+
Fix from $1,950 2021-07-12
Fortimail MEDIUM 6.5
CVE-2021-24013

Multiple Path traversal vulnerabilities in the Webmail of FortiMail before 6.4.4 may allow a regular user to obtain unauthorized access to files and …

Fix: 6.0.11 / 6.2.7+
Fix from $1,600 2021-07-12
Forticlient HIGH 7.8
CVE-2021-26089

An improper symlink following in FortiClient for Mac 6.4.3 and below may allow an non-privileged user to execute arbitrary privileged shell commands …

Fix: after 6.4.3
Fix from $1,950 2021-07-12
Fortimail HIGH 7.5
CVE-2021-26090

A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 may al…

Fix: 6.4.5+
Fix from $1,950 2021-07-12
Fortimail CRITICAL 9.8
CVE-2021-24007

Multiple improper neutralization of special elements of SQL commands vulnerabilities in FortiMail before 6.4.4 may allow a non-authenticated attacker…

Fix: 6.0.11 / 6.2.7+
Fix from $2,300 2021-07-09
Fortimail CRITICAL 9.8
CVE-2021-24020

A missing cryptographic step in the implementation of the hash digest algorithm in FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow a…

Fix: 6.4.5+
Fix from $2,300 2021-07-09
Fortimail HIGH 8.8
CVE-2021-22129

Multiple instances of incorrect calculation of buffer size in the Webmail and Administrative interface of FortiMail before 6.4.5 may allow an authent…

Fix: 6.0.11 / 6.2.7+
Fix from $1,950 2021-07-09
Fortiap HIGH 7.8
CVE-2021-26106

An improper neutralization of special elements used in an OS Command vulnerability in FortiAP's console 6.4.1 through 6.4.5 and 6.2.4 through 6.2.5 m…

Fix: 6.2.6 / 6.4.6+
Fix from $1,950 2021-07-09
Fortimail HIGH 7.5
CVE-2021-26100

A missing cryptographic step in the Identity-Based Encryption service of FortiMail before 7.0.0 may allow an unauthenticated attacker who intercepts …

Fix: 7.0.0+
Fix from $1,950 2021-07-09
Fortisandbox MEDIUM 5.3
CVE-2020-29014

A concurrent execution using shared resource with improper synchronization ('race condition') in the command shell of FortiSandbox before 3.2.2 may a…

Fix: 3.2.2+
Fix from $1,600 2021-07-09
Fortiauthenticator HIGH 7.5
CVE-2021-24005

Usage of hard-coded cryptographic keys to encrypt configuration files and debug logs in FortiAuthenticator versions before 6.3.0 may allow an attacke…

Fix: 6.3.0+
Fix from $1,950 2021-07-06
Fortiai Firmware HIGH 8.8
CVE-2021-24023

An improper input validation in FortiAI v1.4.0 and earlier may allow an authenticated user to gain system shell access via a malicious payload in the…

Fix: after 1.4.0
Fix from $1,950 2021-06-03
Fortios HIGH 7.3
CVE-2021-24012

An improper following of a certificate's chain of trust vulnerability in FortiGate versions 6.4.0 to 6.4.4 may allow an LDAP user to connect to SSLVP…

Fix: 6.4.5+
Fix from $1,950 2021-06-02
Fortiweb HIGH 8.8
CVE-2021-22123EPSS 77%

An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote aut…

Fix: 6.2.4 / 6.3.8+
Fix from $1,950 2021-06-01
Fortiswitch MEDIUM 6.5
CVE-2021-26111

A missing release of memory after effective lifetime vulnerability in FortiSwitch 6.4.0 to 6.4.6, 6.2.0 to 6.2.6, 6.0.0 to 6.0.6, 3.6.11 and below ma…

Fix: after 6.4.6
Fix from $1,600 2021-06-01
Fortinac HIGH 7.2
CVE-2021-24011

A privilege escalation vulnerability in FortiNAC version below 8.8.2 may allow an admin user to escalate the privileges to root by abusing the sudo p…

Fix: 8.8.2+
Fix from $1,950 2021-05-10
Fortiweb MEDIUM 6.5
CVE-2020-15942

An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.…

Fix: after 6.3.4
Fix from $1,600 2021-04-12
Fortiadc MEDIUM 6.5
CVE-2021-24024

A clear text storage of sensitive information into log file vulnerability in FortiADCManager 5.3.0 and below, 5.2.1 and below and FortiADC 5.3.7 and …

Fix: after 5.3.7
Fix from $1,600 2021-04-12
Fortiproxy MEDIUM 6.5
CVE-2019-17656

A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 and below and FortiProxy 1.0.x, 1.1.x, 1.2.9 and b…

Fix: 1.2.10 / 2.0.2+
Fix from $1,600 2021-04-12
Fortios HIGH 7.5
CVE-2020-15938

When traffic other than HTTP/S (eg: SSH traffic, etc...) traverses the FortiGate in version below 6.2.5 and below 6.4.2 on port 80/443, it is not red…

Fix: after 6.4.2
Fix from $1,950 2021-03-04
Fortios MEDIUM 6.1
CVE-2020-15937

An improper neutralization of input vulnerability in FortiGate version 6.2.x below 6.2.5 and 6.4.x below 6.4.1 may allow a remote attacker to perform…

Fix: 6.2.5 / 6.4.1+
Fix from $1,600 2021-03-03
Fortiweb MEDIUM 6.1
CVE-2021-22122EPSS 11%

An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an un…

Fix: after 6.3.7
Fix from $1,600 2021-02-08