Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fortimanager CRITICAL 9.8
CVE-2024-47571

An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to Fo…

Fix: 7.0.9+
Fix from $2,300 2025-01-14
Fortimanager CRITICAL 9.1
CVE-2024-48884EPSS 15%

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiManager 7.6.0 through 7.6.1, FortiMan…

Fix: 6.4.16 / 7.0.5+
Fix from $2,300 2025-01-14
Fortisoar HIGH 8.0
CVE-2024-47572

An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code o…

Fix: 7.3.3 / 7.4.2+
Fix from $1,950 2025-01-14
Fortios HIGH 7.5
CVE-2024-46670

An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant…

Fix: 7.2.10 / 7.4.5+
Fix from $1,950 2025-01-14
Fortios MEDIUM 6.5
CVE-2024-46669

An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSASE version 23.4.b FortiOS tena…

Fix: 7.4.5+
Fix from $1,600 2025-01-14
Fortirecorder MEDIUM 6.0
CVE-2024-47566

A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.2.1 and b…

Fix: 7.0.5 / 7.2.2+
Fix from $1,600 2025-01-14
Fortisiem HIGH 7.5
CVE-2024-46667

A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, …

Fix: 7.1.6+
Fix from $1,950 2025-01-14
Fortios HIGH 7.5
CVE-2024-46668

An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8…

Fix: 6.4.16 / 7.0.16+
Fix from $1,950 2025-01-14
Fortivoice MEDIUM 6.7
CVE-2024-40587

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7…

Fix: 6.4.10 / 7.0.5+
Fix from $1,600 2025-01-14
Fortios MEDIUM 5.3
CVE-2024-46666

An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2 all vers…

Fix: 7.2.9 / 7.4.5+
Fix from $1,600 2025-01-14
Fortimanager HIGH 7.5
CVE-2024-35277

A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 …

Fix: 6.4.15 / 7.0.13+
Fix from $1,950 2025-01-14
Fortianalyzer HIGH 7.2
CVE-2024-36512

An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2…

Fix: 7.0.13 / 7.2.6+
Fix from $1,950 2025-01-14
Fortios MEDIUM 6.5
CVE-2024-36504

An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all veriso…

Fix: 7.2.9 / 7.4.5+
Fix from $1,600 2025-01-14
Forticlientems MEDIUM 5.3
CVE-2024-36506

An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions,…

Fix: 7.2.5+
Fix from $1,600 2025-01-14
Forticlientems MEDIUM 5.3
CVE-2024-36510

An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0…

Fix: 7.2.5 / 7.3.3+
Fix from $1,600 2025-01-14
Fortianalyzer CRITICAL 9.8
CVE-2024-35276

A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0.0 thr…

Fix: 6.4.15 / 7.0.12+
Fix from $2,300 2025-01-14
Fortisandbox HIGH 8.8
CVE-2024-27778

An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.…

Fix: 4.0.5 / 4.2.7+
Fix from $1,950 2025-01-14
Fortianalyzer HIGH 8.8
CVE-2024-35273

A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation o…

Fix: 7.4.3 / 7.4.4+
Fix from $1,950 2025-01-14
Fortianalyzer HIGH 8.8
CVE-2024-35275

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiMa…

Fix: 7.4.3 / 7.4.4+
Fix from $1,950 2025-01-14
Fortianalyzer HIGH 7.8
CVE-2024-33503

A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManage…

Fix: 7.2.6 / 7.2.7+
Fix from $1,950 2025-01-14
Fortianalyzer HIGH 7.2
CVE-2024-33502

An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.…

Fix: 7.2.6 / 7.4.3+
Fix from $1,950 2025-01-14
Fortimanager MEDIUM 5.5
CVE-2024-32115

A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker …

Fix: 7.2.6 / 7.4.3+
Fix from $1,600 2025-01-14
Forticlientems CRITICAL 9.8
CVE-2024-23106

An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unau…

Fix: 7.0.11 / 7.2.5+
Fix from $2,300 2025-01-14
Fortiap HIGH 7.8
CVE-2024-26012

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4.0 throug…

Fix: 6.4.10 / 7.2.4+
Fix from $1,950 2025-01-14
Fortiweb MEDIUM 6.7
CVE-2024-21758

A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a privileged user to execute arbit…

Fix: 7.2.8 / 7.4.2+
Fix from $1,600 2025-01-14
Fortios MEDIUM 6.5
CVE-2023-42785

A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.…

Fix: 7.2.6 / 7.4.2+
Fix from $1,600 2025-01-14
Fortios MEDIUM 6.5
CVE-2023-42786

A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.…

Fix: 7.2.6 / 7.4.2+
Fix from $1,600 2025-01-14
Fortiswitch CRITICAL 9.8
CVE-2023-37936

A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 …

Fix: 6.2.8 / 6.4.14+
Fix from $2,300 2025-01-14
Fortivoice HIGH 8.8
CVE-2023-37931

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0…

Fix: 6.4.9 / 7.0.2+
Fix from $1,950 2025-01-14
Fortiswitch HIGH 7.8
CVE-2023-37937

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through…

Fix: 6.2.8 / 6.4.14+
Fix from $1,950 2025-01-14