Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortibalancer 400 Firmware HIGH 8.8
CVE-2014-2723

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain p…

Mitigation only
Fix from $1,950 2020-03-19
Fortiweb MEDIUM 5.4
CVE-2020-6646

An improper neutralization of input vulnerability in FortiWeb allows a remote authenticated attacker to perform a stored cross site scripting attack …

Fix: after 6.2.2
Fix from $1,600 2020-03-17
Fortimanager HIGH 8.8
CVE-2019-17654

An Insufficient Verification of Data Authenticity vulnerability in FortiManager 6.2.1, 6.2.0, 6.0.6 and below may allow an unauthenticated attacker t…

Fix: after 6.0.6
Fix from $1,950 2020-03-15
Fortiap MEDIUM 6.7
CVE-2019-15708

A system command injection vulnerability in the FortiAP-S/W2 6.2.1, 6.2.0, 6.0.5 and below, FortiAP 6.0.5 and below and FortiAP-U below 6.0.0 under C…

Fix: after 6.0.5
Fix from $1,600 2020-03-15
Fortios MEDIUM 6.1
CVE-2019-6696

An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an…

Fix: after 6.0.8
Fix from $1,600 2020-03-15
Forticlient Emergency Management Server HIGH 7.8
CVE-2020-9287

An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in…

Fix: after 6.2.1
Fix from $1,950 2020-03-15
Forticlient HIGH 7.8
CVE-2020-9290

An Unsafe Search Path vulnerability in FortiClient for Windows online installer 6.2.3 and below may allow a local attacker with control over the dire…

Fix: after 6.2.3
Fix from $1,950 2020-03-15
Fortiadc MEDIUM 5.4
CVE-2019-6699

An improper neutralization of input vulnerability in Fortinet FortiADC 5.3.3 and earlier may allow an attacker to execute a stored Cross Site Scripti…

Fix: after 5.3.3
Fix from $1,600 2020-03-13
Fortiweb MEDIUM 6.5
CVE-2019-16157

An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and earlier may allow an authenticated user to view sensitive information being …

Fix: after 6.2.0
Fix from $1,600 2020-03-13
Fortisiem HIGH 8.8
CVE-2019-17653

A Cross-Site Request Forgery (CSRF) vulnerability in the user interface of Fortinet FortiSIEM 5.2.5 could allow a remote, unauthenticated attacker to…

Mitigation only
Fix from $1,950 2020-03-12
Fortiisolator MEDIUM 5.4
CVE-2020-6643

An improper neutralization of input vulnerability in the URL Description in Fortinet FortiIsolator version 1.2.2 allows a remote authenticated attack…

Fix: after 1.2.2
Fix from $1,600 2020-03-12
Forticlient CRITICAL 9.8
CVE-2019-17658

An unquoted service path vulnerability in the FortiClient FortiTray component of FortiClientWindows v6.2.2 and prior allow an attacker to gain elevat…

Fix: after 6.2.2
Fix from $2,300 2020-03-12
Fortiweb MEDIUM 6.1
CVE-2019-16156

An Improper Neutralization of Input vulnerability in the Anomaly Detection Parameter Name in Fortinet FortiWeb 6.0.5, 6.2.0, and 6.1.1 may allow a re…

Fix: after 6.1.1
Fix from $1,600 2020-03-12
Forticlient HIGH 7.1
CVE-2019-16155

A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to overwrite system files as root w…

Fix: after 6.2.1
Fix from $1,950 2020-02-07
Forticlient HIGH 7.8
CVE-2019-15711

A privilege escalation vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to run system commands under root …

Fix: after 6.2.1
Fix from $1,950 2020-02-06
Forticlient MEDIUM 6.5
CVE-2019-16152

A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to cause FortiClient processes …

Fix: after 6.2.1
Fix from $1,600 2020-02-06
Forticlient MEDIUM 6.5
CVE-2019-17652

A stack buffer overflow vulnerability in FortiClient for Linux 6.2.1 and below may allow a user with low privilege to cause FortiClient processes run…

Fix: after 6.2.1
Fix from $1,600 2020-02-06
Fortimanager CRITICAL 9.8
CVE-2015-3613

A vulnerability exists in in FortiManager 5.2.1 and earlier and 5.0.10 and earlier in the WebUI FTP backup page

Fix: after 5.2.1
Fix from $2,300 2020-02-04
Fortimanager HIGH 8.8
CVE-2015-3611EPSS 6%

A Command Injection vulnerability exists in FortiManager 5.2.1 and earlier and FortiManager 5.0.10 and earlier via unspecified vectors, which could l…

Fix: after 5.2.1
Fix from $1,950 2020-02-04
Fortimanager MEDIUM 5.4
CVE-2015-3612

A Cross-site Scripting (XSS) vulnerability exists in FortiManager 5.2.1 and earlier and 5.0.10 and earlier via an unspecified parameter in the FortiW…

Fix: after 5.2.1
Fix from $1,600 2020-02-04
Fortisiem MEDIUM 5.4
CVE-2019-17651

An Improper Neutralization of Input vulnerability in the description and title parameters of a Device Maintenance Schedule in FortiSIEM version 5.2.5…

Fix: after 5.2.5
Fix from $1,600 2020-01-28
Fortimail HIGH 7.2
CVE-2019-15712

An improper access control vulnerability in FortiMail admin webUI 6.2.0, 6.0.0 to 6.0.6, 5.4.10 and below may allow administrators to access web cons…

Fix: after 6.0.6
Fix from $1,950 2020-01-23
Fortios MEDIUM 5.5
CVE-2019-5593

Improper permission or value checking in the CLI console may allow a non-privileged user to obtain Fortinet FortiOS plaint text private keys of syste…

Fix: after 6.0.6
Fix from $1,600 2020-01-23
Fortisiem CRITICAL 9.8
CVE-2019-16153

A hard-coded password vulnerability in the Fortinet FortiSIEM database component version 5.2.5 and below may allow attackers to access the device dat…

Fix: after 5.2.5
Fix from $2,300 2020-01-23
Fortisiem MEDIUM 6.5
CVE-2019-6700

An information exposure vulnerability in the external authentication profile form of FortiSIEM 5.2.2 and earlier may allow an authenticated attacker …

Fix: 5.2.5+
Fix from $1,600 2020-01-07
Fortiauthenticator MEDIUM 6.1
CVE-2019-16154

An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cros…

Mitigation only
Fix from $1,600 2020-01-07
Fortios HIGH 7.5
CVE-2019-15705

An Improper Input Validation vulnerability in the SSL VPN portal of FortiOS versions 6.2.1 and below, and 6.0.6 and below may allow an unauthenticate…

Fix: after 6.2.1
Fix from $1,950 2019-11-27
Fortios MEDIUM 6.5
CVE-2019-6693 KEVEPSS 6%

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup f…

Fix: after 6.0.6
Fix from $1,600 2019-11-21
Forticlient HIGH 7.8
CVE-2019-17650

An Improper Neutralization of Special Elements used in a Command vulnerability in one of FortiClient for Mac OS root processes, may allow a local use…

Fix: after 6.2.1
Fix from $1,950 2019-11-21
Forticlient MEDIUM 5.5
CVE-2019-15704

A clear text storage of sensitive information vulnerability in FortiClient for Mac may allow a local attacker to read sensitive information logged in…

Fix: after 6.0.7
Fix from $1,600 2019-11-21