Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortiweb MEDIUM 5.3
CVE-2025-48840

An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions,…

Fix: 7.4.9 / 7.6.4+
Fix from $1,600 2026-03-10
Fortimanager HIGH 7.2
CVE-2025-48418

A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.…

Fix: 7.0.15 / 7.2.11+
Fix from $1,950 2026-03-10
Fortios HIGH 8.1
CVE-2026-22153

An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticat…

Fix: 7.6.5+
Fix from $1,950 2026-02-10
Fortiauthenticator HIGH 7.2
CVE-2026-21743

A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4…

Fix: 6.6.7+
Fix from $1,950 2026-02-10
Fortios HIGH 7.2
CVE-2025-64157

A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 throug…

Fix: 7.4.10 / 7.6.5+
Fix from $1,950 2026-02-10
Forticlient HIGH 7.1
CVE-2025-62676

An Improper Link Resolution Before File Access ('Link Following') vulnerability [CWE-59] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7…

Fix: 7.2.13 / 7.4.5+
Fix from $1,950 2026-02-10
Fortios MEDIUM 5.9
CVE-2025-68686 KEV

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS …

Fix: 7.4.7 / 7.6.2+
Fix from $1,600 2026-02-10
Fortisandbox CRITICAL 9.6
CVE-2025-52436EPSS 6%

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox…

Fix: 4.4.8 / 5.0.2+
Fix from $2,300 2026-02-10
Fortios MEDIUM 5.8
CVE-2025-55018

An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, Fort…

Fix: 7.4.10+
Fix from $1,600 2026-02-10
Forticlientems CRITICAL 9.8
CVE-2026-21643 KEVEPSS 94%

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an u…

Mitigation only
Fix from $2,300 2026-02-06
Fortianalyzer CRITICAL 9.8
CVE-2026-24858 KEVEPSS 86%

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, Fort…

Fix: 7.4.10 / 7.4.11+
Fix from $2,300 2026-01-27
Fortisiem CRITICAL 9.8
CVE-2025-64155EPSS 43%

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.…

Fix: 7.1.9 / 7.2.7+
Fix from $2,300 2026-01-13
Forticlientems HIGH 7.2
CVE-2025-59922EPSS 7%

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientE…

Fix: 7.2.12 / 7.4.5+
Fix from $1,950 2026-01-13
Fortivoice MEDIUM 6.5
CVE-2025-58693

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoic…

Fix: 7.0.8 / 7.2.3+
Fix from $1,600 2026-01-13
Fortios CRITICAL 9.8
CVE-2025-25249

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiO…

Fix: 6.4.17 / 7.0.6+
Fix from $2,300 2026-01-13
Fortiweb HIGH 8.1
CVE-2025-64447EPSS 8%

A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5,…

Fix: after 8.0.1
Fix from $1,950 2025-12-09
Fortiweb HIGH 7.5
CVE-2025-64471

A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWe…

Fix: after 8.0.1
Fix from $1,950 2025-12-09
Fortivoice HIGH 7.2
CVE-2025-64156

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, For…

Fix: after 7.2.1
Fix from $1,950 2025-12-09
Fortiextender Firmware HIGH 7.2
CVE-2025-64153

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExte…

Fix: after 7.6.3
Fix from $1,950 2025-12-09
Fortios MEDIUM 5.6
CVE-2025-62631

An insufficient session expiration vulnerability [CWE-613] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2 all versions, FortiOS 7.0 all version…

Fix: 7.4.1+
Fix from $1,600 2025-12-09
Fortiweb CRITICAL 9.8
CVE-2025-59719EPSS 25%

An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.…

Fix: after 7.6.4
Fix from $2,300 2025-12-09
Fortivoice HIGH 8.8
CVE-2025-60024

Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoic…

Fix: 7.0.8 / 7.2.3+
Fix from $1,950 2025-12-09
Fortisoar MEDIUM 6.8
CVE-2025-59808

An unverified password change vulnerability [CWE-620] vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.…

Fix: 7.5.2+
Fix from $1,600 2025-12-09
Fortisoar MEDIUM 6.5
CVE-2025-59810

An improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.1, FortiSOAR PaaS 7.4 all v…

Fix: 7.5.2 / 7.6.3+
Fix from $1,600 2025-12-09
Fortiproxy CRITICAL 9.8
CVE-2025-59718 KEVEPSS 63%

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 …

Fix: 7.0.6 / 7.0.18+
Fix from $2,300 2025-12-09
Fortiportal MEDIUM 6.5
CVE-2025-54838

An Incorrect Authorization vulnerability [CWE-863] in FortiPortal 7.4.0 through 7.4.5 may allow an authenticated attacker to reboot a shared FortiGat…

Fix: after 7.4.5
Fix from $1,600 2025-12-09
Fortisandbox HIGH 8.8
CVE-2025-53949EPSS 17%

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiS…

Fix: after 5.0.2
Fix from $1,950 2025-12-09
Fortisandbox HIGH 7.2
CVE-2025-53679EPSS 12%

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiS…

Fix: 4.4.8 / 5.0.3+
Fix from $1,950 2025-12-09
Fortisandbox MEDIUM 6.1
CVE-2025-54353EPSS 6%

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox…

Fix: after 5.0.2
Fix from $1,600 2025-12-09
Fortiproxy MEDIUM 6.6
CVE-2024-47570

An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; Fo…

Fix: 7.2.8 / 7.2.12+
Fix from $1,600 2025-12-09