Vulnerability index

Browse CVEs

958 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.2 CVE-2018-13378 An information disclosure vulnerability in Fortinet FortiSIEM 5.2.0 and below versions exposes the LDAP server plaintext password via the HTML source… Fortisiem after 5.2.0 Fix from $1,9502019-04-17 MEDIUM 6.1 CVE-2018-1356 A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or comman… Fortisandbox 3.0.0+ Fix from $1,6002019-04-09 MEDIUM 5.3 CVE-2018-13366 An information disclosure vulnerability in Fortinet FortiOS 6.0.1, 5.6.7 and below allows attacker to reveals serial number of FortiGate via hostname… Fortios after 5.6.7 Fix from $1,6002019-04-09 HIGH 7.2 CVE-2017-17544 A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin users to elevate their profile t… Fortios after 6.0.6 Fix from $1,9502019-04-09 CRITICAL 9.8 CVE-2017-7342 A weak password recovery process vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or co… Fortiportal after 4.0.0 Fix from $2,3002019-03-25 MEDIUM 6.1 CVE-2017-7340 A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via… Fortiportal after 4.0.0 Fix from $1,6002019-03-25 MEDIUM 5.5 CVE-2018-9190 A null pointer dereference vulnerability in Fortinet FortiClientWindows 6.0.2 and earlier allows attacker to cause a denial of service via the NDIS m… Forticlient after 6.0.2 Fix from $1,6002019-02-08 CRITICAL 9.8 CVE-2018-1352 A format string vulnerability in Fortinet FortiOS 5.6.0 allows attacker to execute unauthorized code or commands via the SSH username variable. Fortios Mitigation only Fix from $2,3002019-02-08 HIGH 7.5 CVE-2018-13376 An uninitialized memory buffer leak exists in Fortinet FortiOS 5.6.1 to 5.6.3, 5.4.6 to 5.4.7, 5.2 all versions under web proxy's disclaimer response… Fortios after 5.6.3 Fix from $1,9502018-11-27 MEDIUM 5.9 CVE-2018-9192 A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of t… Fortios after 5.4.9 Fix from $1,6002018-09-05 MEDIUM 5.9 CVE-2018-9194 A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of t… Fortios after 5.4.9 Fix from $1,6002018-09-05 MEDIUM 6.1 CVE-2017-17541 A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions al… Fortianalyzer Firmware after 5.6.4 Fix from $1,6002018-07-16 HIGH 8.1 CVE-2018-9185 An information disclosure vulnerability in Fortinet FortiOS 6.0.0 and below versions reveals user's web portal login credentials in a Javascript file… Fortios after 6.0.0 Fix from $1,9502018-07-05 MEDIUM 6.1 CVE-2018-1355 An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacke… Fortianalyzer after 5.6.5 Fix from $1,6002018-06-27 MEDIUM 6.5 CVE-2018-1354 An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allo… Fortianalyzer after 6.0.0 Fix from $1,6002018-06-27 MEDIUM 6.1 CVE-2018-9186 A cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator in versions 4.0.0 to before 5.3.0 "CSRF validation failure" page allows att… Fortiauthenticator 5.3.0+ Fix from $1,6002018-05-31 MEDIUM 5.3 CVE-2017-14185 An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to ac… Fortios after 5.6.2 Fix from $1,6002018-05-25 MEDIUM 6.2 CVE-2017-14187 A local privilege escalation and local code execution vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8, and 5.2 and below versions al… Fortios after 5.6.2 Fix from $1,6002018-05-24 CRITICAL 9.8 CVE-2017-17539 The presence of a hardcoded account in Fortinet FortiWLC 7.0.11 and earlier allows attackers to gain unauthorized read/write access via a remote shel… Fortiwlc after 8.3.3 Fix from $2,3002018-05-08 CRITICAL 9.8 CVE-2017-17540 The presence of a hardcoded account in Fortinet FortiWLC 8.3.3 allows attackers to gain unauthorized read/write access via a remote shell. Fortiwlc after 8.3.3 Fix from $2,3002018-05-08 HIGH 7.5 CVE-2017-17543 Users' VPN authentication credentials are unsafely encrypted in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.… Forticlient after 5.6.0 Fix from $1,9502018-04-26 MEDIUM 5.9 CVE-2017-14191 An Improper Access Control vulnerability in Fortinet FortiWeb 5.6.0 up to but not including 6.1.0 under "Signed Security Mode", allows attacker to by… Fortiweb 6.1.0+ Fix from $1,6002018-03-20 MEDIUM 6.1 CVE-2012-6346 Multiple cross-site scripting (XSS) vulnerabilities in FortiWeb before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1… Fortiweb 4.4.4+ Fix from $1,6002018-02-09 MEDIUM 6.1 CVE-2012-6347 Multiple cross-site scripting (XSS) vulnerabilities in Java number format exception handling in FortiGate FortiDB before 4.4.2 allow remote attackers… Fortidb after 4.4.1 Fix from $1,6002018-02-09 MEDIUM 6.1 CVE-2012-0941 Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers t… Fortios 4.3.6+ Fix from $1,6002018-02-08 MEDIUM 6.1 CVE-2017-14190 A Cross-site Scripting vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.7, 5.2 and earlier, allows attacker to inject arbitrary web scr… Fortios after 5.6.2 Fix from $1,6002018-01-29 HIGH 8.8 CVE-2017-14184 An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below version… Forticlient 4.4.2334 / 5.6.0+ Fix from $1,9502017-12-15 HIGH 8.1 CVE-2017-7344 A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows attacker to gain privilege via exploiting the Window… Forticlient after 5.4.3 Fix from $1,9502017-12-14 HIGH 7.2 CVE-2017-7738 An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and below versions allow an admin user with super_adm… Fortios after 5.6.2 Fix from $1,9502017-12-13 CRITICAL 9.8 CVE-2017-14189 An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regar… Fortiweb Manager Mitigation only Fix from $2,3002017-11-29