Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortiisolator CRITICAL 9.8
CVE-2020-6649

An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired adm…

Fix: after 2.0.1
Fix from $2,300 2021-02-08
Fortiweb CRITICAL 9.8
CVE-2020-29016

A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauthenticated, remote attacker to…

Fix: 6.2.4+
Fix from $2,300 2021-01-14
Fortideceptor HIGH 8.8
CVE-2020-29017

An OS command injection vulnerability in FortiDeceptor 3.1.0, 3.0.1, 3.0.0 may allow a remote authenticated attacker to execute arbitrary commands on…

Mitigation only
Fix from $1,950 2021-01-14
Fortiweb HIGH 8.8
CVE-2020-29018

A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the content of memory and retrieve …

Fix: after 6.3.5
Fix from $1,950 2021-01-14
Fortiweb MEDIUM 5.3
CVE-2020-29019

A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow a remote, unauthenticated attacker to …

Fix: 6.2.4+
Fix from $1,600 2021-01-14
Fortiweb CRITICAL 9.8
CVE-2020-29015

A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to…

Fix: 6.2.4+
Fix from $2,300 2021-01-14
Fortiproxy MEDIUM 6.5
CVE-2020-6648

A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and earlier and FortiProxy 2.0.0, 1.2.…

Fix: 1.2.10 / 6.0.12+
Fix from $1,600 2020-10-21
Fortianalyzer MEDIUM 6.1
CVE-2020-12811

An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3and FortiAnalyzer 6.2.0, 6.2.1, 6.…

Fix: after 6.2.6
Fix from $1,600 2020-09-24
Fortianalyzer MEDIUM 5.4
CVE-2020-12815

An improper neutralization of input vulnerability in FortiTester before 3.9.0 may allow a remote authenticated attacker to inject script related HTML…

Fix: after 6.4.1
Fix from $1,600 2020-09-24
Fortianalyzer HIGH 8.8
CVE-2020-12817

An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script …

Fix: after 3.7.0
Fix from $1,950 2020-09-24
Fortinac MEDIUM 6.1
CVE-2020-12816

An improper neutralization of input vulnerability in FortiNAC before 8.7.2 may allow a remote authenticated attacker to perform a stored cross site s…

Fix: 8.7.3+
Fix from $1,600 2020-09-24
Fortios MEDIUM 5.3
CVE-2020-12818

An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker to Fortinet owned IP addresses…

Fix: 6.4.1+
Fix from $1,600 2020-09-24
Fortios MEDIUM 6.5
CVE-2019-5591 KEVEPSS 18%

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by imper…

Fix: after 6.2.0
Fix from $1,600 2020-08-14
Fortios CRITICAL 9.8
CVE-2020-12812 KEVEPSS 49%

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in succe…

Fix: 6.0.10 / 6.2.4+
Fix from $2,300 2020-07-24
Fortideceptor HIGH 8.1
CVE-2020-6644

An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpired admin user session IDs to…

Fix: after 3.0.0
Fix from $1,950 2020-06-22
Fortiwlc MEDIUM 5.4
CVE-2020-9288

An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a stored cross site scripting a…

Fix: after 8.5.1
Fix from $1,600 2020-06-22
Fortianalyzer HIGH 7.5
CVE-2020-9289

Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below ma…

Fix: after 6.2.3
Fix from $1,950 2020-06-16
Fortios HIGH 7.5
CVE-2019-17655

A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.…

Fix: 6.2.3+
Fix from $1,950 2020-06-16
Fortisiem Windows Agent CRITICAL 9.8
CVE-2020-9292

An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt ex…

Fix: after 3.1.2
Fix from $2,300 2020-06-04
Fortianalyzer MEDIUM 5.4
CVE-2020-6640

An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker to perform a stored…

Fix: 6.2.4+
Fix from $1,600 2020-06-04
Forticlient MEDIUM 5.5
CVE-2019-16150

Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0…

Fix: 6.4.0+
Fix from $1,600 2020-06-04
Forticlient HIGH 7.8
CVE-2020-9291

An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain elevated privileges via exhausting…

Fix: after 6.2.1
Fix from $1,950 2020-06-01
Fortiap S MEDIUM 6.5
CVE-2019-15709

An improper input validation in FortiAP-S/W2 6.2.0 to 6.2.2, 6.0.5 and below, FortiAP-U 6.0.1 and below CLI admin console may allow unauthorized admi…

Fix: after 6.2.2
Fix from $1,600 2020-06-01
Fortimail CRITICAL 9.8
CVE-2020-9294EPSS 78%

An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote un…

Fix: after 6.2.2
Fix from $2,300 2020-04-27
Fortiadc Firmware MEDIUM 6.5
CVE-2020-9286

An improper authorization vulnerability in FortiADC may allow a remote authenticated user with low privileges to perform certain actions such as rebo…

Fix: after 5.3.4
Fix from $1,600 2020-04-07
Fortiadc Firmware MEDIUM 5.4
CVE-2020-6647

An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform a cross site scripting …

Fix: after 5.3.4
Fix from $1,600 2020-04-07
Fortianalyzer HIGH 7.5
CVE-2019-17657

An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager bel…

Fix: 3.6.11 / 6.0.6+
Fix from $1,950 2020-04-07
Fortios HIGH 8.8
CVE-2018-13371

An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via conn…

Fix: after 6.0.2
Fix from $1,950 2020-04-02
Fortibalancer 400 Firmware HIGH 8.8
CVE-2014-2721

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain p…

Mitigation only
Fix from $1,950 2020-03-19
Fortibalancer 400 Firmware HIGH 8.8
CVE-2014-2722

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain p…

No fix yet
Fix from $1,950 2020-03-19