Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortios MEDIUM 5.4
CVE-2017-14186

A Cross-site Scripting (XSS) vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.7, 5.4 and below versions under SSL VPN web portal allows…

Fix: after 5.6.2
Fix from $1,600 2017-11-29
Fortiweb MEDIUM 5.4
CVE-2017-7736

A stored Cross-site Scripting (XSS) vulnerability in Fortinet FortiWeb webUI Certificate View page in 5.8.0, 5.7.1 and earlier, allows attackers to i…

Fix: after 5.7.1
Fix from $1,600 2017-11-22
Fortios MEDIUM 6.1
CVE-2017-7739

A reflected Cross-site Scripting (XSS) vulnerability in web proxy disclaimer response web pages in Fortinet FortiOS 5.6.0, 5.4.0 to 5.4.5, 5.2.0 to 5…

Mitigation only
Fix from $1,600 2017-11-13
Fortios MEDIUM 6.5
CVE-2017-14182

A Denial of Service (DoS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 allows an authenticated user to cause the web GUI to be temporarily unresp…

Mitigation only
Fix from $1,600 2017-10-27
Fortios MEDIUM 6.1
CVE-2017-7733

A Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiOS 5.4.0 to 5.4.5 and 5.6.0 allows a remote unauthenticated attacker to execute arbitrary…

Mitigation only
Fix from $1,600 2017-10-27
Fortiwlc HIGH 7.2
CVE-2017-7341

An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file m…

Fix: after 8.3.2
Fix from $1,950 2017-10-26
Fortimail MEDIUM 6.1
CVE-2017-7732

A reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiMail 5.1 and earlier, 5.2.0 through 5.2.9, and 5.3.0 through 5.3.9 customized p…

Mitigation only
Fix from $1,600 2017-10-26
Fortiwlc MEDIUM 5.4
CVE-2017-7335

A Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWLC 6.1-x (6.1-2, 6.1-4 and 6.1-5); 7.0-x (7.0-7, 7.0-8, 7.0-9, 7.0-10); and 8.x (8.0, 8.…

Mitigation only
Fix from $1,600 2017-10-26
Fortios MEDIUM 6.1
CVE-2017-3132EPSS 8%

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to Execute unauthorized code or commands via the…

Fix: after 5.6.0
Fix from $1,600 2017-09-12
Fortios MEDIUM 6.1
CVE-2017-3133EPSS 11%

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.6.0 and earlier allows attackers to execute unauthorized code or commands via the…

Fix: after 5.6.0
Fix from $1,600 2017-09-12
Fortios MEDIUM 5.4
CVE-2017-3131EPSS 8%

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 and 5.6.0 allows attackers to execute unauthorized code or comm…

No fix yet
Fix from $1,600 2017-09-12
Fortios MEDIUM 5.4
CVE-2017-7734

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.4.0 through 5.4.4 allows attackers to execute unauthorized code or commands via '…

Mitigation only
Fix from $1,600 2017-09-12
Fortios MEDIUM 5.4
CVE-2017-7735

A Cross-Site Scripting vulnerability in Fortinet FortiOS versions 5.2.0 through 5.2.11 and 5.4.0 through 5.4.4 allows attackers to execute unauthoriz…

Mitigation only
Fix from $1,600 2017-09-12
Fortimanager Firmware HIGH 7.8
CVE-2015-3617

Fortinet FortiManager 5.0 before 5.0.11 and 5.2 before 5.2.2 allow local users to gain privileges via crafted CLI commands.

Mitigation only
Fix from $1,950 2017-08-22
Fortimanager Firmware CRITICAL 9.8
CVE-2015-3616

SQL injection vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to execute arbitrary commands vi…

Mitigation only
Fix from $2,300 2017-08-11
Fortimanager Firmware HIGH 7.5
CVE-2015-3614

Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to obtain arbitrary files via vectors involving another unspeci…

Mitigation only
Fix from $1,950 2017-08-11
Fortimanager Firmware MEDIUM 5.4
CVE-2015-3615

Cross-site scripting (XSS) vulnerability in Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote authenticated users to inject…

Mitigation only
Fix from $1,600 2017-08-11
Fortios HIGH 7.5
CVE-2017-3130

An information disclosure vulnerability in Fortinet FortiOS 5.6.0, 5.4.4 and below versions allows attacker to get FortiOS version info by inspecting…

Mitigation only
Fix from $1,950 2017-08-10
Fortiwlm CRITICAL 9.8
CVE-2017-7336

A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgr…

Fix: after 8.3.0
Fix from $2,300 2017-07-22
Forticlient HIGH 8.8
CVE-2016-8493

In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability.

Mitigation only
Fix from $1,950 2017-06-26
Fortios MEDIUM 6.1
CVE-2017-3127

A Cross-Site Scripting vulnerability in Fortinet FortiGate 5.2.0 through 5.2.10 allows attacker to execute unauthorized code or commands via the srci…

Mitigation only
Fix from $1,600 2017-06-01
Fortiportal CRITICAL 9.1
CVE-2017-7337

An improper Access Control vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to interact with unauthorized VDOMs or e…

Fix: after 4.0.0
Fix from $2,300 2017-05-27
Fortiportal HIGH 7.5
CVE-2017-7338

A password management vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to carry out information disclosure via the F…

Fix: after 4.0.0
Fix from $1,950 2017-05-27
Fortiportal HIGH 7.5
CVE-2017-7731

A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows attacker to carry out information disclosure via the F…

Fix: after 4.0.0
Fix from $1,950 2017-05-27
Fortiwlc Sd HIGH 7.2
CVE-2017-3134

An escalation of privilege vulnerability in Fortinet FortiWLC-SD versions 8.2.4 and below allows attacker to gain root access via the CLI command 'co…

Fix: after 8.2.4
Fix from $1,950 2017-05-27
Fortiweb MEDIUM 6.1
CVE-2017-3129

A Cross-Site Scripting vulnerability in Fortinet FortiWeb versions 5.7.1 and below allows attacker to execute unauthorized code or commands via an im…

Fix: after 5.7.1
Fix from $1,600 2017-05-27
Fortiportal MEDIUM 6.1
CVE-2017-7339

A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via…

Fix: after 4.0.0
Fix from $1,600 2017-05-27
Fortiportal MEDIUM 6.1
CVE-2017-7343

An open redirect vulnerability in Fortinet FortiPortal 4.0.0 and below allows attacker to execute unauthorized code or commands via the url parameter.

Fix: after 4.0.0
Fix from $1,600 2017-05-27
Fortianalyzer Firmware MEDIUM 6.1
CVE-2017-3126

An Open Redirect vulnerability in Fortinet FortiAnalyzer 5.4.0 through 5.4.2 and FortiManager 5.4.0 through 5.4.2 allows attacker to execute unauthor…

Mitigation only
Fix from $1,600 2017-05-27
Fortimail MEDIUM 6.1
CVE-2017-3125

An unauthenticated XSS vulnerability with FortiMail 5.0.0 - 5.2.9 and 5.3.0 - 5.3.8 could allow an attacker to execute arbitrary scripts in the secur…

Mitigation only
Fix from $1,600 2017-04-12