Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2022-40681 A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to caus… Forticlient after 7.0.7 Fix from $1,9502023-11-14 HIGH 7.3 CVE-2023-45582 An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through … Fortimail after 7.2.4 Fix from $1,9502023-11-14 MEDIUM 5.5 CVE-2023-44248 An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow … Fortiedr after 5.2.0.4549 Fix from $1,6002023-11-14 HIGH 7.8 CVE-2023-41840 A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL … Forticlient Mitigation only Fix from $1,9502023-11-14 HIGH 7.5 CVE-2023-42783 A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.2 through 8.4.0 and 8.3.2 through 8.3.0 an… Fortiwlm after 8.6.6 Fix from $1,9502023-11-14 MEDIUM 6.5 CVE-2023-41676 An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with acces… Fortisiem after 6.7.5 Fix from $1,6002023-11-14 MEDIUM 6.5 CVE-2023-36641 A numeric truncation error in Fortinet FortiProxy version 7.2.0 through 7.2.4, FortiProxy version 7.0.0 through 7.0.10, FortiProxy 2.0 all versions, … Fortiproxy after 7.2.5 Fix from $1,6002023-11-14 MEDIUM 5.4 CVE-2023-36633 An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker … Fortimail 7.0.6 / 7.2.3+ Fix from $1,6002023-11-14 CRITICAL 9.8 CVE-2023-36553 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.… Fortisiem after 5.1.3 Fix from $2,3002023-11-14 CRITICAL 9.8 CVE-2023-34991EPSS 29% A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 thr… Fortiwlm after 8.6.5 Fix from $2,3002023-11-14 MEDIUM 5.5 CVE-2023-33304 A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system pro… Forticlient after 7.0.9 Fix from $1,6002023-11-14 MEDIUM 6.7 CVE-2023-28002 An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 a… Fortiproxy after 7.2.7 Fix from $1,6002023-11-14 HIGH 8.8 CVE-2023-26205 An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all ve… Fortiadc after 7.0.5 Fix from $1,9502023-11-14 MEDIUM 6.5 CVE-2023-44256 A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and Forti… Fortianalyzer after 7.2.3 Fix from $1,6002023-10-20 HIGH 7.5 CVE-2023-41682 A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox 4.2.1 thr… Fortisandbox after 4.2.5 Fix from $1,9502023-10-13 MEDIUM 6.1 CVE-2023-41680 A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, Fo… Fortisandbox after 4.4.1 Fix from $1,6002023-10-13 MEDIUM 6.1 CVE-2023-41681 A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, Fo… Fortisandbox after 4.4.1 Fix from $1,6002023-10-13 MEDIUM 6.1 CVE-2023-41836 An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0, FortiSandbox 4.… Fortisandbox after 4.2.4 Fix from $1,6002023-10-13 MEDIUM 5.4 CVE-2023-41843 A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.1, Fo… Fortisandbox after 4.4.1 Fix from $1,6002023-10-13 HIGH 8.1 CVE-2023-33303 A insufficient session expiration in Fortinet FortiEDR version 5.0.0 through 5.0.1 allows attacker to execute unauthorized code or commands via api r… Fortiedr after 5.0.1 Fix from $1,9502023-10-13 MEDIUM 6.5 CVE-2023-44249 An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer… Fortianalyzer 7.2.4+ Fix from $1,6002023-10-10 CRITICAL 9.8 CVE-2023-36550 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5… Fortiwlm after 8.6.5 Fix from $2,3002023-10-10 CRITICAL 9.6 CVE-2023-41679 An improper access control vulnerability [CWE-284] in FortiManager management interface 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.1… Fortimanager after 7.0.7 Fix from $2,3002023-10-10 HIGH 8.8 CVE-2023-36556 An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allo… Fortimail after 7.0.5 Fix from $1,9502023-10-10 HIGH 8.8 CVE-2023-41841 An improper authorization vulnerability in Fortinet FortiOS 7.0.0 - 7.0.11 and 7.2.0 - 7.2.4 allows an attacker belonging to the prof-admin profile t… Fortios after 7.2.4 Fix from $1,9502023-10-10 HIGH 7.5 CVE-2023-37935 A use of GET request method with sensitive query strings vulnerability in Fortinet FortiOS 7.0.0 - 7.0.12, 7.2.0 - 7.2.5 and 7.4.0 allows an attacker… Fortios after 7.2.5 Fix from $1,9502023-10-10 HIGH 7.5 CVE-2023-40718 A interpretation conflict in Fortinet IPS Engine versions 7.321, 7.166 and 6.158 allows attacker to evade IPS features via crafted TCP packets. Fortios Ips Engine after 7.312 Fix from $1,9502023-10-10 HIGH 7.1 CVE-2023-41838 An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow… Fortianalyzer after 7.2.3 Fix from $1,9502023-10-10 MEDIUM 6.7 CVE-2023-42788 An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer … Fortianalyzer after 7.2.3 Fix from $1,6002023-10-10 MEDIUM 6.5 CVE-2023-42787 A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer v… Fortianalyzer after 7.2.3 Fix from $1,6002023-10-10