Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2022-33871 A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and earlier, 6.4 all versions, version 6.3.19 and earlier may allow a… Fortiweb 6.3.20+ Fix from $1,9502023-02-16 MEDIUM 6.5 CVE-2022-30300 A relative path traversal vulnerability [CWE-23] in FortiWeb 7.0.0 through 7.0.1, 6.3.6 through 6.3.18, 6.4 all versions may allow an authenticated a… Fortiweb 6.3.19+ Fix from $1,6002023-02-16 MEDIUM 6.1 CVE-2022-30304 An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions prior to 7.2.1, 7.0.4 and 6.4.8 may a… Fortianalyzer 6.4.9 / 7.0.5+ Fix from $1,6002023-02-16 MEDIUM 6.1 CVE-2022-38376 Multiple improper neutralization of input during web page generation ('Cross-site Scripting') vulnerabilities [CWE-79] in Fortinet FortiNAC portal UI… Fortinac 9.4.2+ Fix from $1,6002023-02-16 MEDIUM 6.0 CVE-2022-38378 An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.… Fortiproxy 7.0.8 / 7.2.1+ Fix from $1,6002023-02-16 CRITICAL 9.8 CVE-2021-42756EPSS 35% Multiple stack-based buffer overflow vulnerabilities [CWE-121] in the proxy daemon of FortiWeb 5.x all versions, 6.0.7 and below, 6.1.2 and below, 6.… Fortiweb 6.0.8 / 6.1.3+ Fix from $2,3002023-02-16 CRITICAL 9.8 CVE-2021-42761 A condition for session fixation vulnerability [CWE-384] in the session management of FortiWeb versions 6.4 all versions, 6.3.0 through 6.3.16, 6.2.0… Fortiweb 5.9.2 / 6.0.8+ Fix from $2,3002023-02-16 HIGH 7.5 CVE-2022-45857 An incorrect user management vulnerability [CWE-286] in the FortiManager version 6.4.6 and below VDOM creation component may allow an attacker to acc… Fortimanager 6.2.9 / 6.4.8+ Fix from $1,9502023-01-05 HIGH 8.8 CVE-2022-35845 Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiTester 7.1.0, 7.… Fortitester after 3.9.1 Fix from $1,9502023-01-03 HIGH 8.8 CVE-2022-39947 A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiADC version 7.0.0 through 7.0.2, FortiA… Fortiadc after 6.2.3 Fix from $1,9502023-01-03 MEDIUM 5.4 CVE-2022-42471 An improper neutralization of CRLF sequences in HTTP headers ('HTTP Response Splitting') vulnerability [CWE-113] In FortiWeb version 7.0.0 through 7.… Fortiweb after 6.3.21 Fix from $1,6002023-01-03 CRITICAL 9.8 CVE-2022-42475 KEVEPSS 99% A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through… Fortios 2.0.12 / 6.0.15+ Fix from $2,3002023-01-02 CRITICAL 9.8 CVE-2022-35843 An authentication bypass by assumed-immutable data vulnerability [CWE-302] in the FortiOS SSH login component 7.2.0, 7.0.0 through 7.0.7, 6.4.0 thr… Fortiproxy after 7.0.7 Fix from $2,3002022-12-06 HIGH 8.8 CVE-2022-33875 An improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability in Fortinet FortiADC version 7.1.0, version 7.0… Fortiadc after 6.2.4 Fix from $1,9502022-12-06 HIGH 7.5 CVE-2022-30305 An insufficient logging [CWE-778] vulnerability in FortiSandbox versions 4.0.0 to 4.0.2, 3.2.0 to 3.2.3 and 3.1.0 to 3.1.5 and FortiDeceptor versions… Fortideceptor after 4.0.2 Fix from $1,9502022-12-06 MEDIUM 6.5 CVE-2022-33876 Multiple instances of improper input validation vulnerability in Fortinet FortiADC version 7.1.0, version 7.0.0 through 7.0.2 and version 6.2.4 and b… Fortiadc after 6.2.4 Fix from $1,6002022-12-06 MEDIUM 5.4 CVE-2022-38379 Improper neutralization of input during web page generation [CWE-79] in FortiSOAR 7.0.0 through 7.0.3 and 7.2.0 may allow an authenticated attacker t… Fortisoar after 7.0.3 Fix from $1,6002022-12-06 MEDIUM 5.4 CVE-2022-40680 A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiOS 6.0.7 - 6.0.15, 6.2.2 - 6.2.12, 6.4.0 - 6.… Fortios after 7.0.3 Fix from $1,6002022-12-06 MEDIUM 5.5 CVE-2022-39949 An improper control of a resource through its lifetime vulnerability [CWE-664] in FortiEDR CollectorWindows 4.0.0 through 4.1, 5.0.0 through 5.0.3.75… Fortiedr after 5.2.0.2288 Fix from $1,6002022-11-02 MEDIUM 5.5 CVE-2022-42473 A missing authentication for a critical function vulnerability in Fortinet FortiSOAR 6.4.0 - 6.4.4 and 7.0.0 - 7.0.3 and 7.2.0 allows an attacker to … Fortisoar after 7.0.3 Fix from $1,6002022-11-02 MEDIUM 5.4 CVE-2022-39950 An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.… Fortianalyzer after 7.0.4 Fix from $1,6002022-11-02 CRITICAL 9.8 CVE-2022-38381 An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 5.0 all versions, 6.0.0 all versions, 6.1.0 all versions, 6.2.0 … Fortiadc after 7.0.2 Fix from $2,3002022-11-02 MEDIUM 6.5 CVE-2022-39945 An improper access control vulnerability [CWE-284] in FortiMail 7.2.0, 7.0.0 through 7.0.3, 6.4 all versions, 6.2 all versions, 6.0 all versions may … Fortimail after 7.0.3 Fix from $1,6002022-11-02 MEDIUM 6.1 CVE-2022-38374 A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiADC 7.0.0 - 7.0.2 and 6.2.0 - 6.2.4 allows an… Fortiadc 6.2.4 / 7.0.3+ Fix from $1,6002022-11-02 MEDIUM 5.4 CVE-2022-38373 An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiDeceptor management interface 4.2.0, 4.1.0 through 4.1.… Fortideceptor Mitigation only Fix from $1,6002022-11-02 HIGH 7.8 CVE-2022-33870 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the command line interpreter of FortiTester 3.0.0 thro… Fortitester Patch available Fix from $1,9502022-11-02 HIGH 7.5 CVE-2022-35842 An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiOS SSL-VPN versions 7.2.0, versions 7.0.0 through 7.0.6… Fortios after 7.0.6 Fix from $1,9502022-11-02 MEDIUM 6.7 CVE-2022-38372 A hidden functionality vulnerability [CWE-1242] in FortiTester CLI 2.3.0 through 3.9.1, 4.0.0 through 4.2.0, 7.0.0 through 7.1.0 may allow a local, p… Fortitester after 4.2.0 Fix from $1,6002022-11-02 MEDIUM 5.5 CVE-2022-33878 An exposure of sensitive information to an unauthorized actor vulnerabiltiy [CWE-200] in FortiClient for Mac versions 7.0.0 through 7.0.5 may allow a… Forticlient after 7.0.5 Fix from $1,6002022-11-02 MEDIUM 5.4 CVE-2022-35851 An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiADC management interface 7.1.0 may allow a remote and a… Fortiadc Mitigation only Fix from $1,6002022-11-02