Skip to main content

Vendor/product archive

fortinet / fortiwlm CVEs

Beta · best-effort

23 CVEs tagged to fortinet / fortiwlm7 Critical, 13 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2023-34990

Published Dec 18, 2024

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attacker to execute unauthorized code or commands via specially crafted w…

CVSS 9.8 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2023-48782

Published Dec 13, 2023

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 allows attacker to execute unauthoriz…

CVSS 8.8 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2023-42783

Published Nov 14, 2023

A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.2 through 8.4.0 and 8.3.2 through 8.3.0 and 8.2.2 allows attacker to rea…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-34991

Published Nov 14, 2023

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-36550

Published Oct 10, 2023

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attack…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-36549

Published Oct 10, 2023

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attack…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-36548

Published Oct 10, 2023

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attack…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-36547

Published Oct 10, 2023

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attack…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-34993

Published Oct 10, 2023

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attack…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-34989

Published Oct 10, 2023

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attack…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34988

Published Oct 10, 2023

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attack…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34987

Published Oct 10, 2023

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attack…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34986

Published Oct 10, 2023

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attack…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-34985

Published Oct 10, 2023

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 allows attack…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43070

Published Mar 2, 2022

Multiple relative path traversal vulnerabilities [CWE-23] in FortiWLM management interface 8.6.2 and below, 8.5.2 and below, 8.4.2 and below, 8.3.3 and below, 8.2.2 may allow an a…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-43077

Published Mar 1, 2022

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and bel…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-43075

Published Mar 1, 2022

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 a…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42760

Published Dec 8, 2021

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclose sensitive informati…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-42752

Published Dec 8, 2021

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute malicious javascript…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-41029

Published Dec 8, 2021

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to store malicious javascript c…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36185

Published Nov 2, 2021

A improper neutralization of special elements used in an OS command ('OS Command Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to execute unauthorized c…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36184

Published Nov 2, 2021

A improper neutralization of Special Elements used in an SQL Command ('SQL Injection') in Fortinet FortiWLM version 8.6.1 and below allows attacker to disclosure device, users and…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2017-7336

Published Jul 22, 2017

A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-23 of 23 CVEsPage 1 of 1