Skip to main content

Vendor/product archive

fortinet / fortios CVEs

Beta · best-effort

278 CVEs tagged to fortinet / fortios22 Critical, 64 High, 164 Medium, 28 Low, 0 Unrated.

CVE-2025-22251

Published Jun 10, 2025

An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all v…

CVSS 3.1 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-50568

Published Jun 10, 2025

A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 thro…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50562

Published Jun 10, 2025

An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29184

Published Jun 10, 2025

An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker t…

CVSS 3.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-47295

Published May 28, 2025

A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-47294

Published May 28, 2025

A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the csfd daem…

CVSS 5.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-32122

Published Apr 8, 2025

A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker t…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37930

Published Apr 8, 2025

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt m…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16151

Published Mar 21, 2025

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker to ei…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-29010

Published Mar 17, 2025

An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to re…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-6697

Published Mar 17, 2025

An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP monito…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-15706

Published Mar 17, 2025

An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, vers…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-26006

Published Mar 14, 2025

An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and For…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-24472

Published Feb 11, 2025

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.1…

CVSS 8.1 · High
evidence mentions
11
Buzz score
67.8
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2024-40591

Published Feb 11, 2025

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated adm…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-35279

Published Feb 11, 2025

A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to e…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-23439

Published Jan 22, 2025

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` heade…

CVSS 4.7 · Medium

CVE-2024-55591

Published Jan 14, 2025

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and…

CVSS 9.8 · Critical
evidence mentions
26
Buzz score
75.0
KEV listed
Vendor/product tagsBeta · best-effort
Showing 51-75 of 278 CVEsPage 3 of 12