Vulnerability index

Browse CVEs

28 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Fortisandbox CRITICAL 9.8
CVE-2026-25089 KEVEPSS 74%

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0…

Fix: 4.4.9 / 5.0.6+
Fix from $2,300 2026-06-09
Fortisandbox CRITICAL 9.8
CVE-2026-39808 KEVEPSS 91%

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4…

Fix: after 4.4.9
Fix from $2,300 2026-04-14
Forticlientems CRITICAL 9.8
CVE-2026-35616 KEVEPSS 91%

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized …

Patch available
Fix from $2,300 2026-04-04
Fortios MEDIUM 5.9
CVE-2025-68686 KEV

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.1, FortiOS …

Fix: 7.4.7 / 7.6.2+
Fix from $1,600 2026-02-10
Forticlientems CRITICAL 9.8
CVE-2026-21643 KEVEPSS 94%

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an u…

Mitigation only
Fix from $2,300 2026-02-06
Fortianalyzer CRITICAL 9.8
CVE-2026-24858 KEVEPSS 86%

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, Fort…

Fix: 7.4.10 / 7.4.11+
Fix from $2,300 2026-01-27
Fortiproxy CRITICAL 9.8
CVE-2025-59718 KEVEPSS 63%

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 …

Fix: 7.0.6 / 7.0.18+
Fix from $2,300 2025-12-09
Fortiweb HIGH 7.2
CVE-2025-58034 KEVEPSS 56%

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiW…

Fix: 7.0.12 / 7.2.12+
Fix from $1,950 2025-11-18
Fortiweb CRITICAL 9.8
CVE-2025-64446 KEVEPSS 92%

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWe…

Fix: 7.0.12 / 7.2.12+
Fix from $2,300 2025-11-14
Fortiweb CRITICAL 9.8
CVE-2025-25257 KEVEPSS 100%

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6…

Fix: 7.0.11 / 7.2.11+
Fix from $2,300 2025-07-17
Fortimail CRITICAL 9.8
CVE-2025-32756 KEVEPSS 30%

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiC…

Fix: 6.4.6 / 6.4.11+
Fix from $2,300 2025-05-13
Fortiproxy HIGH 8.1
CVE-2025-24472 KEV

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 throu…

Fix: 7.0.17 / 7.0.20+
Fix from $1,950 2025-02-11
Fortiproxy CRITICAL 9.8
CVE-2024-55591 KEVEPSS 98%

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy ver…

Fix: 7.0.17 / 7.0.20+
Fix from $2,300 2025-01-14
Fortimanager CRITICAL 9.8
CVE-2024-47575 KEVEPSS 95%

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManage…

Fix: 6.2.13 / 6.4.15+
Fix from $2,300 2024-10-23
Forticlient Enterprise Management Server CRITICAL 9.8
CVE-2023-48788 KEVEPSS 98%

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiC…

Fix: 7.0.11 / 7.2.3+
Fix from $2,300 2024-03-12
Fortiproxy CRITICAL 9.8
CVE-2024-23113 KEVEPSS 62%

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy …

Fix: after 7.4.2
Fix from $2,300 2024-02-15
Fortiproxy CRITICAL 9.8
CVE-2024-21762 KEVEPSS 84%

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 throug…

Fix: 2.0.14 / 6.0.18+
Fix from $2,300 2024-02-09
Fortiproxy CRITICAL 9.8
CVE-2023-27997 KEVEPSS 86%

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version …

Fix: after 7.2.4
Fix from $2,300 2023-06-13
Fortios HIGH 7.1
CVE-2022-41328 KEVEPSS 12%

A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2…

Fix: 6.2.14 / 6.4.12+
Fix from $1,950 2023-03-07
Fortios CRITICAL 9.8
CVE-2022-42475 KEVEPSS 99%

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through…

Fix: 2.0.12 / 6.0.15+
Fix from $2,300 2023-01-02
Fortiproxy CRITICAL 9.8
CVE-2022-40684 KEVEPSS 100%

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiP…

Fix: 7.0.7 / 7.2.2+
Fix from $2,300 2022-10-18
Fortios HIGH 7.8
CVE-2021-44168 KEV

A download of code without integrity check vulnerability in the "execute restore src-vis" command of FortiOS before 7.0.3 may allow a local authentic…

Fix: 6.0.14 / 6.2.10+
Fix from $1,950 2022-01-04
Fortios MEDIUM 6.5
CVE-2019-5591 KEVEPSS 18%

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by imper…

Fix: after 6.2.0
Fix from $1,600 2020-08-14
Fortios CRITICAL 9.8
CVE-2020-12812 KEVEPSS 49%

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in succe…

Fix: 6.0.10 / 6.2.4+
Fix from $2,300 2020-07-24
Fortios MEDIUM 6.5
CVE-2019-6693 KEVEPSS 6%

Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file may allow an attacker with access to the backup f…

Fix: after 6.0.6
Fix from $1,600 2019-11-21
Fortiproxy CRITICAL 9.8
CVE-2018-13379 KEVEPSS 100%

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4…

Fix: 1.2.9 / 5.4.13+
Fix from $2,300 2019-06-04
Fortiproxy HIGH 7.5
CVE-2018-13382 KEVEPSS 82%

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, …

Fix: 1.2.9 / 5.4.11+
Fix from $1,950 2019-06-04
Fortiproxy MEDIUM 6.5
CVE-2018-13383 KEVEPSS 34%

A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, …

Fix: 1.2.9 / 5.2.15+
Fix from $1,600 2019-05-29