Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortiadc MEDIUM 6.1
CVE-2025-58412

A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiADC 8.0.0, FortiADC 7.6.0 through 7.6.…

Fix: 7.6.4+
Fix from $1,600 2025-11-19
Fortiweb MEDIUM 5.5
CVE-2025-59669

A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all vers…

Fix: 7.6.1+
Fix from $1,600 2025-11-18
Fortivoice HIGH 8.8
CVE-2025-58692

An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerability in Fortinet FortiVoice 7…

Fix: 7.0.8 / 7.2.3+
Fix from $1,950 2025-11-18
Fortios HIGH 7.5
CVE-2025-58413

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7…

Fix: 7.4.9 / 7.6.4+
Fix from $1,950 2025-11-18
Fortiweb HIGH 7.2
CVE-2025-58034 KEVEPSS 56%

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiW…

Fix: 7.0.12 / 7.2.12+
Fix from $1,950 2025-11-18
Fortios HIGH 7.5
CVE-2025-53843

A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7…

Fix: 7.4.9 / 7.6.4+
Fix from $1,950 2025-11-18
Fortiadc MEDIUM 6.5
CVE-2025-54971

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all versions, FortiADC 7.1 all v…

Fix: 7.4.3+
Fix from $1,600 2025-11-18
Fortiproxy MEDIUM 6.0
CVE-2025-54821

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS…

Fix: 1.6.1 / 7.6.4+
Fix from $1,600 2025-11-18
Forticlient MEDIUM 5.5
CVE-2025-54660

An active debug code vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.10, FortiClientWindows 7.…

Fix: 7.2.11 / 7.4.4+
Fix from $1,600 2025-11-18
Fortiextender Firmware HIGH 7.8
CVE-2025-46776

A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7…

Fix: 7.4.8 / 7.6.3+
Fix from $1,950 2025-11-18
Forticlient HIGH 7.8
CVE-2025-47761

An Exposed IOCTL with Insufficient Access Control vulnerability [CWE-782] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClie…

Fix: 7.2.10 / 7.4.4+
Fix from $1,950 2025-11-18
Fortiadc MEDIUM 6.6
CVE-2025-48839

An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 a…

Fix: 7.4.8 / 7.6.3+
Fix from $1,600 2025-11-18
Forticlient HIGH 7.8
CVE-2025-46373

A Heap-based Buffer Overflow vulnerability [CWE-122] vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 throu…

Fix: 7.2.9 / 7.4.4+
Fix from $1,950 2025-11-18
Fortiextender Firmware MEDIUM 5.5
CVE-2025-46775

A debug messages revealing unnecessary information vulnerability in Fortinet FortiExtender 7.6.0 through 7.6.1, FortiExtender 7.4.0 through 7.4.6, Fo…

Fix: 7.4.8 / 7.6.3+
Fix from $1,600 2025-11-18
Fortisandbox MEDIUM 5.3
CVE-2025-46215

An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7,…

Fix: 4.4.8 / 5.0.2+
Fix from $1,600 2025-11-18
Fortiweb CRITICAL 9.8
CVE-2025-64446 KEVEPSS 92%

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWe…

Fix: 7.0.12 / 7.2.12+
Fix from $2,300 2025-11-14
Fortidlp Agent HIGH 7.8
CVE-2025-53951

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's Outlookproxy pl…

Fix: after 11.5.1
Fix from $1,950 2025-10-16
Fortidlp Agent HIGH 7.8
CVE-2025-54658

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiDLP Agent's Outlookproxy pl…

Fix: after 11.5.1
Fix from $1,950 2025-10-16
Fortidlp Agent MEDIUM 6.0
CVE-2025-53950

An Exposure of Private Personal Information ('Privacy Violation') vulnerability [CWE-359] in Fortinet FortiDLP Agent's Outlookproxy plugin for MacOS …

Fix: after 11.5.1
Fix from $1,600 2025-10-16
Fortiadc MEDIUM 6.5
CVE-2025-59921

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, ve…

Fix: 7.1.5 / 7.2.4+
Fix from $1,600 2025-10-14
Fortiproxy HIGH 8.8
CVE-2025-57740

An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all …

Fix: 1.4.3 / 7.2.11+
Fix from $1,950 2025-10-14
Forticlient HIGH 7.8
CVE-2025-57741

An Incorrect Permission Assignment for Critical Resource vulnerability [CWE-732] in FortiClientMac 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all…

Fix: 7.2.12 / 7.4.4+
Fix from $1,950 2025-10-14
Forticlient HIGH 7.3
CVE-2025-57716

An Uncontrolled Search Path Element vulnerability [CWE-427] in FortiClient Windows 7.4.0 through 7.4.3, 7.2.0 through 7.2.11, 7.0 all versions may al…

Fix: 7.2.12 / 7.4.4+
Fix from $1,950 2025-10-14
Fortios MEDIUM 6.7
CVE-2025-58325

An Incorrect Provision of Specified Functionality vulnerability [CWE-684] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2.5 through 7.2.10, 7.0.0 through …

Fix: 7.0.16 / 7.2.11+
Fix from $1,600 2025-10-14
Fortianalyzer MEDIUM 6.5
CVE-2025-53845

An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated a…

Fix: 7.4.7 / 7.6.4+
Fix from $1,600 2025-10-14
Fortianalyzer MEDIUM 5.3
CVE-2025-54973

A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer versi…

Fix: 7.0.14 / 7.2.11+
Fix from $1,600 2025-10-14
Fortipam CRITICAL 9.8
CVE-2025-49201

A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, F…

Fix: 1.4.3 / 7.2.5+
Fix from $2,300 2025-10-14
Forticlient HIGH 7.8
CVE-2025-46774

An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiClient MacOS installer version 7.4.2 and below, version 7.2.9 and…

Fix: 7.2.10 / 7.4.4+
Fix from $1,950 2025-10-14
Fortios MEDIUM 6.1
CVE-2025-47890

An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, Fo…

Fix: 7.4.9 / 7.6.4+
Fix from $1,600 2025-10-14
Forticlient HIGH 7.1
CVE-2025-31365

An Improper Control of Generation of Code ('Code Injection') vulnerability [CWE-94] in FortiClientMac 7.4.0 through 7.4.3, 7.2.1 through 7.2.8 may al…

Fix: 7.2.9 / 7.4.4+
Fix from $1,950 2025-10-14