Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortisase MEDIUM 6.5
CVE-2025-24471

An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remo…

Fix: 7.4.8 / 7.6.2+
Fix from $1,600 2025-06-10
Fortipam HIGH 8.8
CVE-2025-22256

A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 thro…

Fix: 1.0.4 / 1.1.3+
Fix from $1,950 2025-06-10
Fortios HIGH 7.2
CVE-2025-22254

An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS 7.4.0 through 7.4.6, FortiOS …

Fix: 6.4.16 / 7.0.17+
Fix from $1,950 2025-06-10
Fortios MEDIUM 5.3
CVE-2025-22251

An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all version…

Fix: 7.4.6+
Fix from $1,600 2025-06-10
Forticlient MEDIUM 6.5
CVE-2024-54019

A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versi…

Fix: 7.2.7+
Fix from $1,600 2025-06-10
Fortiproxy MEDIUM 5.9
CVE-2024-50568

A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 &…

Fix: 7.0.17 / 7.2.9+
Fix from $1,600 2025-06-10
Fortios MEDIUM 5.3
CVE-2025-47294

A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated a…

Fix: 7.0.15 / 7.2.8+
Fix from $1,600 2025-05-28
Forticlient HIGH 7.8
CVE-2025-25251

An Incorrect Authorization vulnerability [CWE-863] in FortiClient Mac 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 may allow a loca…

Fix: 7.2.9 / 7.4.3+
Fix from $1,950 2025-05-28
Fortiproxy HIGH 7.2
CVE-2025-22252

A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwitchManager version 7.2.5, and FortiOS ver…

Fix: 7.4.7+
Fix from $1,950 2025-05-28
Fortimail CRITICAL 9.8
CVE-2025-32756 KEVEPSS 30%

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiC…

Fix: 6.4.6 / 6.4.11+
Fix from $2,300 2025-05-13
Forticlientems MEDIUM 5.3
CVE-2025-22859

A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remot…

Fix: 7.4.3+
Fix from $1,600 2025-05-13
Forticlient HIGH 7.8
CVE-2024-35281

An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all ver…

Fix: 7.2.9 / 7.4.3+
Fix from $1,950 2025-05-13
Fortiswitch CRITICAL 9.8
CVE-2024-48887EPSS 15%

A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a s…

Fix: 6.4.15 / 7.0.11+
Fix from $2,300 2025-04-08
Fortiisolator HIGH 7.2
CVE-2024-54024

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator before…

Fix: 2.4.7+
Fix from $1,950 2025-04-08
Fortiweb HIGH 7.2
CVE-2025-25254

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version…

Fix: 7.4.7 / 7.6.3+
Fix from $1,950 2025-04-08
Fortiisolator MEDIUM 6.7
CVE-2024-54025

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator CLI be…

Fix: 2.4.7+
Fix from $1,600 2025-04-08
Fortimanager MEDIUM 5.3
CVE-2024-52962

An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 a…

Fix: 7.0.14 / 7.2.9+
Fix from $1,600 2025-04-08
Fortiweb HIGH 7.5
CVE-2024-50565

A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 …

Fix: 6.2.14 / 6.4.9+
Fix from $1,950 2025-04-08
Fortiweb HIGH 7.2
CVE-2024-46671

An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version …

Fix: 7.2.11 / 7.4.7+
Fix from $1,950 2025-04-08
Fortios HIGH 8.8
CVE-2023-37930

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet …

Fix: 6.4.15 / 7.0.13+
Fix from $1,950 2025-04-08
Fortianalyzer HIGH 7.5
CVE-2024-26013

A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 …

Fix: 6.2.14 / 6.4.9+
Fix from $1,950 2025-04-08
Fortisiem HIGH 8.8
CVE-2023-40714

A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate pr…

Fix: after 6.7.3
Fix from $1,950 2025-04-02
Fortimail HIGH 8.8
CVE-2023-33302

A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface version 6.4.0 th…

Fix: 6.0.11 / 6.2.7+
Fix from $1,950 2025-03-31
Fortimail MEDIUM 5.3
CVE-2021-24008

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiDDoS version 5.4.0, version 5.3.2 and b…

Fix: 5.4.3 / 6.0.4+
Fix from $1,600 2025-03-28
Forticlientems MEDIUM 6.1
CVE-2019-16149

An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized co…

Fix: 6.2.1+
Fix from $1,600 2025-03-28
Fortiweb CRITICAL 9.8
CVE-2023-25610EPSS 18%

A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0…

Fix: 6.0.12 / 6.1.4+
Fix from $2,300 2025-03-24
Fortisandbox HIGH 8.8
CVE-2021-26105

A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allo…

Fix: 3.2.3+
Fix from $1,950 2025-03-24
Fortimail HIGH 7.5
CVE-2021-26091

A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of Forti…

Fix: 6.4.5+
Fix from $1,950 2025-03-24
Fortios MEDIUM 6.1
CVE-2019-16151

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote …

Fix: 6.2.10 / 6.4.2+
Fix from $1,600 2025-03-21
Fortisoar HIGH 8.4
CVE-2024-21760

An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versio…

Fix: after 7.4.5
Fix from $1,950 2025-03-18