Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2023-29179 A null pointer dereference in Fortinet FortiOS version 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.12, Fortiproxy version 7.2.0 thro… Fortios 6.4.13 / 7.0.11+ Fix from $1,6002024-02-22 HIGH 8.8 CVE-2023-42791 A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12 and 6.2.0 t… Fortimanager 6.2.12 / 6.4.13+ Fix from $1,9502024-02-20 CRITICAL 9.8 CVE-2024-23113 KEVEPSS 62% A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy … Fortiproxy after 7.4.2 Fix from $2,3002024-02-15 HIGH 7.2 CVE-2023-45581 An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site admi… Forticlient Enterprise Management Server 7.0.10+ Fix from $1,9502024-02-15 MEDIUM 6.1 CVE-2023-26206 An improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiNAC 9.4.0 - 9.4.2, 9.2.0 - 9.2.8, 9.1.0 - 9.… Fortinac after 9.4.2 Fix from $1,6002024-02-15 MEDIUM 5.0 CVE-2023-44253 An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before… Fortianalyzer after 7.2.3 Fix from $1,6002024-02-15 CRITICAL 9.8 CVE-2024-21762 KEVEPSS 84% A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 throug… Fortiproxy 2.0.14 / 6.0.18+ Fix from $2,3002024-02-09 CRITICAL 9.8 CVE-2024-23109 An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute u… Fortisiem after 7.0.2 Fix from $2,3002024-02-05 CRITICAL 9.8 CVE-2024-23108EPSS 78% An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute u… Fortisiem after 7.0.2 Fix from $2,3002024-02-05 HIGH 8.8 CVE-2023-44250 An improper privilege management vulnerability [CWE-269] in a Fortinet FortiOS HA cluster version 7.4.0 through 7.4.1 and 7.2.5 and in a FortiProxy H… Fortiproxy Mitigation only Fix from $1,9502024-01-10 HIGH 8.8 CVE-2023-46712 A improper access control in Fortinet FortiPortal version 7.0.0 through 7.0.6, Fortinet FortiPortal version 7.2.0 through 7.2.1 allows attacker to es… Fortiportal after 7.2.1 Fix from $1,9502024-01-10 MEDIUM 5.4 CVE-2023-48783EPSS 22% An Authorization Bypass Through User-Controlled Key vulnerability [CWE-639] affecting PortiPortal version 7.2.1 and below, version 7.0.6 and below, v… Fortiportal 7.0.7 / 7.2.2+ Fix from $1,6002024-01-10 MEDIUM 6.5 CVE-2023-37932 An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and be… Fortivoice 6.4.8+ Fix from $1,6002024-01-10 MEDIUM 6.5 CVE-2023-37934 An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiPAM 1.0 all versions allows an authenticated attacker to perf… Fortipam 1.1.0+ Fix from $1,6002024-01-10 HIGH 8.8 CVE-2023-44251 ** UNSUPPORTED WHEN ASSIGNED **A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in Fortinet Fo… Fortiwan Mitigation only Fix from $1,9502023-12-13 HIGH 8.8 CVE-2023-44252 ** UNSUPPORTED WHEN ASSIGNED **An improper authentication vulnerability [CWE-287] in Fortinet FortiWAN version 5.2.0 through 5.2.1 and version 5.1.1 … Fortiwan Mitigation only Fix from $1,9502023-12-13 MEDIUM 5.3 CVE-2023-47536 An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy versio… Fortiproxy after 7.2.3 Fix from $1,6002023-12-13 HIGH 8.8 CVE-2023-48791 An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in FortiPortal version 7.2.0, version 7… Fortiportal after 7.0.6 Fix from $1,9502023-12-13 HIGH 8.8 CVE-2023-48782 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows … Fortiwlm after 8.6.5 Fix from $1,9502023-12-13 MEDIUM 5.3 CVE-2023-46713 An improper output neutralization for logs in Fortinet FortiWeb 6.2.0 - 6.2.8, 6.3.0 - 6.3.23, 7.0.0 - 7.0.9, 7.2.0 - 7.2.5 and 7.4.0 may allow an at… Fortiweb after 7.2.5 Fix from $1,6002023-12-13 MEDIUM 5.4 CVE-2023-45587 An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, F… Fortisandbox after 4.2.5 Fix from $1,6002023-12-13 MEDIUM 5.4 CVE-2023-41844 A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.2, Fo… Fortisandbox after 4.2.5 Fix from $1,6002023-12-13 HIGH 8.8 CVE-2023-41678 A double free in Fortinet FortiOS versions 7.0.0 through 7.0.5, FortiPAM version 1.0.0 through 1.0.3, 1.1.0 through 1.1.1 allows attacker to execute … Fortios Mitigation only Fix from $1,9502023-12-13 MEDIUM 5.4 CVE-2023-41673 An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low privileged user to read or back… Fortiadc after 7.0.5 Fix from $1,6002023-12-13 HIGH 7.8 CVE-2023-40716 An improper neutralization of special elements used in an OS command vulnerability [CWE-78]  in the command line interpreter of FortiTester 2.3.0 thr… Fortitester Mitigation only Fix from $1,9502023-12-13 HIGH 8.8 CVE-2023-36639 A use of externally-controlled format string in Fortinet FortiProxy versions 7.2.0 through 7.2.4, 7.0.0 through 7.0.10, FortiOS versions 7.4.0, 7.2.0… Fortiproxy after 7.2.4 Fix from $1,9502023-12-13 HIGH 8.8 CVE-2022-27488 A cross-site request forgery (CSRF) in Fortinet FortiVoiceEnterprise version 6.4.x, 6.0.x, FortiSwitch version 7.0.0 through 7.0.4, 6.4.0 through 6.4… Fortiai after 7.0.4 Fix from $1,9502023-12-13 MEDIUM 5.5 CVE-2023-40719 A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an attacker to… Fortianalyzer after 7.2.3 Fix from $1,6002023-11-14 MEDIUM 6.7 CVE-2023-29177 Multiple buffer copy without checking size of input ('classic buffer overflow') vulnerabilities [CWE-120] in FortiADC version 7.2.0 and before 7.1.2 … Fortiadc after 7.1.2 Fix from $1,6002023-11-14 CRITICAL 9.1 CVE-2023-25603 A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1… Fortiadc after 6.3.4 Fix from $2,3002023-11-14