Skip to main content

Vendor archive

fortinet CVEs

Beta · best-effort

1,135 CVEs tagged to vendor fortinet92 Critical, 364 High, 603 Medium, 76 Low, 0 Unrated.

CVE-2024-54020

Published May 28, 2025

A missing authorization in Fortinet FortiManager versions 7.2.0 through 7.2.1, and versions 7.0.0 through 7.0.7 may allow an authenticated attacker to overwrite global threat feed…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-48887

Published Apr 8, 2025

A unverified password change vulnerability in Fortinet FortiSwitch GUI may allow a remote unauthenticated attacker to change admin passwords via a specially crafted request

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort

CVE-2025-25254

Published Apr 8, 2025

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, 7.2 all vers…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-22855

Published Apr 8, 2025

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator…

CVSS 2.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-54025

Published Apr 8, 2025

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator CLI before version 2.4.6 allows a pr…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-54024

Published Apr 8, 2025

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiIsolator before version 2.4.6 allows a privil…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-46671

Published Apr 8, 2025

An Incorrect User Management vulnerability [CWE-286] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, version 7.2.10 and below, version 7.0.11 and below widgets dashb…

CVSS 6.2 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-32122

Published Apr 8, 2025

A storing passwords in a recoverable format in Fortinet FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions allows attacker t…

CVSS 2.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-37930

Published Apr 8, 2025

Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vulnerabilities vulnerability in Fortinet allows a VPN user to corrupt m…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40714

Published Apr 2, 2025

A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege via uploading certain…

CVSS 9.9 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-33302

Published Mar 31, 2025

A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface version 6.4.0 through 6.4.4 and before 6.2.6 a…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-16149

Published Mar 28, 2025

An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized code by injecting malicious payl…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26105

Published Mar 24, 2025

A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26091

Published Mar 24, 2025

A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2019-16151

Published Mar 21, 2025

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker to ei…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-21760

Published Mar 18, 2025

An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-47539

Published Mar 18, 2025

An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker t…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 201-225 of 1,135 CVEsPage 9 of 46