Skip to main content

Vendor archive

fortinet CVEs

Beta · best-effort

1,135 CVEs tagged to vendor fortinet92 Critical, 364 High, 603 Medium, 76 Low, 0 Unrated.

CVE-2025-25257

Published Jul 17, 2025

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4…

CVSS 9.8 · Critical
evidence mentions
9
Buzz score
61.0
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2025-24477

Published Jul 15, 2025

A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.4 through 7.2.12 allows an attacker to escalate its pr…

CVSS 4.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52965

Published Jul 8, 2025

A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.10, and before 7.0.16 & F…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-31104

Published Jun 10, 2025

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiADC 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2.0 th…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-25250

Published Jun 10, 2025

An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2 all version…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-24471

Published Jun 10, 2025

An Improper Certificate Validation vulnerability [CWE-295] in FortiOS version 7.6.1 and below, version 7.4.7 and below may allow an EAP verified remote user to connect from FortiC…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-22256

Published Jun 10, 2025

A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiSRA 1.4.0 thro…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-22251

Published Jun 10, 2025

An improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in FortiOS 7.6.0, 7.4.0 through 7.4.5, 7.2 all versions, 7.0 all versions, 6.4 all v…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-54019

Published Jun 10, 2025

A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized atta…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50568

Published Jun 10, 2025

A channel accessible by non-endpoint vulnerability [CWE-300] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.2.7 and before 7.0.14 & FortiProxy version 7.4.0 thro…

CVSS 5.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-50562

Published Jun 10, 2025

An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all versions, 6.4 all versions…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45329

Published Jun 10, 2025

A authorization bypass through user-controlled key in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.8 may allow an authenticate…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32119

Published Jun 10, 2025

An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48786

Published Jun 10, 2025

A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform intern…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29184

Published Jun 10, 2025

An incomplete cleanup vulnerability [CWE-459] in FortiOS 7.2 all versions and before & FortiProxy version 7.2.0 through 7.2.2 and before 7.0.8 allows a VDOM privileged attacker t…

CVSS 3.2 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-47295

Published May 28, 2025

A buffer over-read in Fortinet FortiOS versions 7.4.0 through 7.4.3, versions 7.2.0 through 7.2.7, and versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-47294

Published May 28, 2025

A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the csfd daem…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-46777

Published May 28, 2025

A insertion of sensitive information into log file in Fortinet FortiPortal versions 7.4.0, versions 7.2.0 through 7.2.5, and versions 7.0.0 through 7.0.9 may allow an authenticate…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-25251

Published May 28, 2025

An Incorrect Authorization vulnerability [CWE-863] in FortiClient Mac 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 may allow a local attacker to escalate privile…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-24473

Published May 28, 2025

A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort
Showing 176-200 of 1,135 CVEsPage 8 of 46