Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.8
CVE-2020-6649
An insufficient session expiration vulnerability in FortiNet's FortiIsolator version 2.0.1 and below may allow an attacker to reuse the unexpired adm…
Fortiisolator
after 2.0.1
CRITICAL 9.8
CVE-2020-29016
A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauthenticated, remote attacker to…
Fortiweb
6.2.4+
HIGH 8.8
CVE-2020-29017
An OS command injection vulnerability in FortiDeceptor 3.1.0, 3.0.1, 3.0.0 may allow a remote authenticated attacker to execute arbitrary commands on…
Fortideceptor
Mitigation only
HIGH 8.8
CVE-2020-29018
A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the content of memory and retrieve …
Fortiweb
after 6.3.5
MEDIUM 5.3
CVE-2020-29019
A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow a remote, unauthenticated attacker to …
Fortiweb
6.2.4+
CRITICAL 9.8
CVE-2020-29015
A blind SQL injection in the user interface of FortiWeb 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthenticated, remote attacker to…
Fortiweb
6.2.4+
MEDIUM 6.5
CVE-2020-6648
A cleartext storage of sensitive information vulnerability in FortiOS command line interface in versions 6.2.4 and earlier and FortiProxy 2.0.0, 1.2.…
Fortiproxy
1.2.10 / 6.0.12+
MEDIUM 6.1
CVE-2020-12811
An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3and FortiAnalyzer 6.2.0, 6.2.1, 6.…
Fortianalyzer
after 6.2.6
MEDIUM 5.4
CVE-2020-12815
An improper neutralization of input vulnerability in FortiTester before 3.9.0 may allow a remote authenticated attacker to inject script related HTML…
Fortianalyzer
after 6.4.1
HIGH 8.8
CVE-2020-12817
An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script …
Fortianalyzer
after 3.7.0
MEDIUM 6.1
CVE-2020-12816
An improper neutralization of input vulnerability in FortiNAC before 8.7.2 may allow a remote authenticated attacker to perform a stored cross site s…
Fortinac
8.7.3+
MEDIUM 5.3
CVE-2020-12818
An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker to Fortinet owned IP addresses…
Fortios
6.4.1+
MEDIUM 6.5
CVE-2019-5591 KEVEPSS 18%
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by imper…
Fortios
after 6.2.0
CRITICAL 9.8
CVE-2020-12812 KEVEPSS 49%
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in succe…
Fortios
6.0.10 / 6.2.4+
HIGH 8.1
CVE-2020-6644
An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpired admin user session IDs to…
Fortideceptor
after 3.0.0
MEDIUM 5.4
CVE-2020-9288
An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a stored cross site scripting a…
Fortiwlc
after 8.5.1
HIGH 7.5
CVE-2020-9289
Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below ma…
Fortianalyzer
after 6.2.3
HIGH 7.5
CVE-2019-17655
A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.…
Fortios
6.2.3+
CRITICAL 9.8
CVE-2020-9292
An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt ex…
Fortisiem Windows Agent
after 3.1.2
MEDIUM 5.4
CVE-2020-6640
An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker to perform a stored…
Fortianalyzer
6.2.4+
MEDIUM 5.5
CVE-2019-16150
Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0…
Forticlient
6.4.0+
HIGH 7.8
CVE-2020-9291
An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain elevated privileges via exhausting…
Forticlient
after 6.2.1
MEDIUM 6.5
CVE-2019-15709
An improper input validation in FortiAP-S/W2 6.2.0 to 6.2.2, 6.0.5 and below, FortiAP-U 6.0.1 and below CLI admin console may allow unauthorized admi…
Fortiap S
after 6.2.2
CRITICAL 9.8
CVE-2020-9294EPSS 78%
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote un…
Fortimail
after 6.2.2
MEDIUM 6.5
CVE-2020-9286
An improper authorization vulnerability in FortiADC may allow a remote authenticated user with low privileges to perform certain actions such as rebo…
Fortiadc Firmware
after 5.3.4
MEDIUM 5.4
CVE-2020-6647
An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform a cross site scripting …
Fortiadc Firmware
after 5.3.4
HIGH 7.5
CVE-2019-17657
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager bel…
Fortianalyzer
3.6.11 / 6.0.6+
HIGH 8.8
CVE-2018-13371
An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via conn…
Fortios
after 6.0.2
HIGH 8.8
CVE-2014-2721
In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain p…
Fortibalancer 400 Firmware
Mitigation only
HIGH 8.8
CVE-2014-2722
In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain p…
Fortibalancer 400 Firmware
No fix yet