Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortimail CRITICAL 9.8
CVE-2023-47539

An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a rem…

Mitigation only
Fix from $2,300 2025-03-18
Fortiwlc MEDIUM 6.7
CVE-2021-22126

A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2…

Fix: 8.5.3+
Fix from $1,600 2025-03-17
Fortiwlc MEDIUM 6.1
CVE-2021-26087

An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8…

Fix: 8.5.4+
Fix from $1,600 2025-03-17
Fortiwlc MEDIUM 5.3
CVE-2021-32584

An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and bel…

Fix: 8.5.4+
Fix from $1,600 2025-03-17
Fortisiem HIGH 8.1
CVE-2019-17659

A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to th…

Fix: 5.2.7+
Fix from $1,950 2025-03-17
Antivirus Engine HIGH 7.5
CVE-2020-9295

FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engin…

Fix: 6.00145+
Fix from $1,950 2025-03-17
Fortios MEDIUM 6.1
CVE-2019-6697

An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a…

Fix: 6.0.7 / 6.2.2+
Fix from $1,600 2025-03-17
Fortios MEDIUM 5.0
CVE-2020-29010

An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow rem…

Fix: 6.0.11 / 6.2.5+
Fix from $1,600 2025-03-17
Fortiproxy MEDIUM 5.4
CVE-2019-15706

An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS…

Fix: 5.6.13 / 6.0.9+
Fix from $1,600 2025-03-17
Fortiweb CRITICAL 9.8
CVE-2024-55594

An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0…

Fix: 7.4.7+
Fix from $2,300 2025-03-14
Fortimanager MEDIUM 6.5
CVE-2024-40585

An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 a…

Fix: 6.2.12 / 6.4.13+
Fix from $1,600 2025-03-14
Forticlient HIGH 7.8
CVE-2023-45588

An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may al…

Fix: 7.0.11 / 7.2.4+
Fix from $1,950 2025-03-14
Fortiweb HIGH 7.2
CVE-2022-29059

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6…

Fix: 7.0.2+
Fix from $1,950 2025-03-14
Fortinac MEDIUM 5.3
CVE-2023-33300EPSS 13%

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allow…

Fix: 7.2.2 / 9.4.4+
Fix from $1,600 2025-03-14
Fortimanager HIGH 8.8
CVE-2024-46662

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiMan…

Fix: 7.4.4+
Fix from $1,950 2025-03-14
Fortindr MEDIUM 6.5
CVE-2024-47573

An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2.1 and below, version 7.1.1 a…

Fix: 7.2.2 / 7.4.3+
Fix from $1,600 2025-03-14
Fortios MEDIUM 6.1
CVE-2024-26006

An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, ve…

Fix: 7.0.14 / 7.0.17+
Fix from $1,600 2025-03-14
Fortiweb HIGH 7.2
CVE-2024-55597

A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 through 7.6.0 allows attacker to…

Fix: 7.4.6+
Fix from $1,950 2025-03-11
Fortisandbox HIGH 8.8
CVE-2024-54026

An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.…

Fix: 4.4.7+
Fix from $1,950 2025-03-11
Fortiisolator HIGH 8.8
CVE-2024-55590

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolato…

Fix: 2.4.6+
Fix from $1,950 2025-03-11
Fortisandbox HIGH 7.2
CVE-2024-54018EPSS 10%

Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged …

Fix: 4.4.6+
Fix from $1,950 2025-03-11
Fortisandbox HIGH 8.8
CVE-2024-52960

A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.…

Fix: 4.2.8 / 4.4.7+
Fix from $1,950 2025-03-11
Fortisandbox HIGH 8.8
CVE-2024-52961

An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbo…

Fix: 4.0.6 / 4.2.8+
Fix from $1,950 2025-03-11
Fortimail MEDIUM 6.7
CVE-2024-46663

A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker t…

Fix: 7.2.7 / 7.4.4+
Fix from $1,600 2025-03-11
Fortisandbox HIGH 7.8
CVE-2024-45328

An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute elevated …

Fix: 4.4.7+
Fix from $1,950 2025-03-11
Fortios HIGH 7.2
CVE-2024-45324

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0…

Fix: 1.4.3 / 6.2.17+
Fix from $1,950 2025-03-11
Fortianalyzer MEDIUM 6.7
CVE-2024-32123

Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions …

Fix: 7.2.6 / 7.2.8+
Fix from $1,600 2025-03-11
Fortianalyzer MEDIUM 6.7
CVE-2024-33501

Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4…

Fix: 7.2.6 / 7.2.8+
Fix from $1,600 2025-03-11
Fortiweb CRITICAL 9.8
CVE-2023-42784

An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 …

Fix: 7.4.7+
Fix from $2,300 2025-03-11
Fortindr HIGH 8.8
CVE-2023-48790

A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5…

Fix: 7.0.6 / 7.1.2+
Fix from $1,950 2025-03-11