Skip to main content

Vendor archive

fortinet CVEs

Beta · best-effort

1,135 CVEs tagged to vendor fortinet92 Critical, 364 High, 603 Medium, 76 Low, 0 Unrated.

CVE-2024-52960

Published Mar 11, 2025

A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated atta…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-46663

Published Mar 11, 2025

A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or co…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45328

Published Mar 11, 2025

An incorrect authorization vulnerability [CWE-863] in FortiSandbox 4.4.0 through 4.4.6 may allow a low priviledged administrator to execute elevated CLI commands via the GUI conso…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-48790

Published Mar 11, 2025

A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5 may allow a remote unauthenti…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-42784

Published Mar 11, 2025

An improper handling of syntactically invalid structure in Fortinet FortiWeb at least verions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker…

CVSS 5.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-40723

Published Mar 11, 2025

An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1 and 6.4.0 through 6…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2023-37933

Published Mar 11, 2025

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC GUI version 7.4.0, 7.2.0 through 7.2.1 and before 7.1.3…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-24472

Published Feb 11, 2025

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.1…

CVSS 8.1 · High
evidence mentions
13
Buzz score
71.4
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-24470

Published Feb 11, 2025

An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated…

CVSS 8.6 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-52968

Published Feb 11, 2025

An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password.

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52966

Published Feb 11, 2025

An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information disclosure via filter manipulation.

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-50569

Published Feb 11, 2025

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 through 7.6.0 allows attacker to execute unauthorized code…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50567

Published Feb 11, 2025

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0 through 7.6.0 allows attacker to execute unauthorized code…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2024-40591

Published Feb 11, 2025

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated adm…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-40586

Published Feb 11, 2025

An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his p…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-35279

Published Feb 11, 2025

A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to e…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-27781

Published Feb 11, 2025

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2024-27780

Published Feb 11, 2025

Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all ve…

CVSS 2.2 · Low
Vendor/product tagsBeta · best-effort
Showing 251-275 of 1,135 CVEsPage 11 of 46