imPC@ndo IT

Fortinet vulnerabilities

1134 CVE

CVE-2024-36512
High 7.2

An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 through 7.0.12 and 6.2.10 through 6.2.13 allows attacker to execute unauthorized cod…

fortinet fortianalyzer · fortinet fortimanager
0.01EPSS
CVE-2021-36194
High 8.8

Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to achieve arbitrary code execution via specially crafted requests.

fortinet fortiweb
0.01EPSS
CVE-2021-43073
High 8.8

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unauthorized code or commands via crafted HT…

fortinet fortiweb
0.01EPSS
CVE-2019-16152
Medium 6.5

A Denial of service (DoS) vulnerability in FortiClient for Linux 6.2.1 and below may allow an user with low privilege to cause FortiClient processes running under root privilege crashes via sending specially crafted IPC client requests to the fctsched process …

fortinet forticlient
0.01EPSS
CVE-2021-36187
Medium 5.3

A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to cause a denial of service for webserver daemon via crafted HTTP requests

fortinet fortiweb
0.01EPSS
CVE-2012-0941
Medium 6.1

Multiple cross-site scripting (XSS) vulnerabilities in Fortinet FortiGate UTM WAF appliances with FortiOS 4.3.x before 4.3.6 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Endpoint Monitor, (2) Dialup List, or (3) L…

fortinet fortios
0.01EPSS
CVE-2023-42787
Medium 6.5

A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low privileges to access a privileged web consol…

fortinet fortianalyzer · fortinet fortimanager
0.01EPSS
CVE-2014-1955
Medium 4.3

Cross-site scripting (XSS) vulnerability in FortiGuard FortiWeb before 5.0.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

fortinet fortiweb
0.01EPSS
CVE-2025-64157
Medium 6.7

A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions allows an authenticated admin to execute unauthorized code or commands via s…

fortinet fortios
0.01EPSS
CVE-2014-8619
Medium 4.3

Cross-site scripting (XSS) vulnerability in the autolearn configuration page in Fortinet FortiWeb 5.1.2 through 5.3.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

fortinet fortiweb
0.01EPSS
CVE-2014-8618
Medium 4.3

Cross-site scripting (XSS) vulnerability in the theme login page in Fortinet FortiADC D models before 4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

fortinet fortiadc-1500d · fortinet fortiadc-2000d · fortinet fortiadc-200d · fortinet fortiadc-4000d · and 2 more
0.01EPSS
CVE-2025-47856
High 7.2

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 and before 6.4.10 allows a privileged attacker to execute arbitrary code or comman…

fortinet fortivoice
0.01EPSS
CVE-2018-13384
Medium 6.1

A Host Header Redirection vulnerability in Fortinet FortiOS all versions below 6.0.5 under SSL VPN web portal allows a remote attacker to potentially poison HTTP cache and subsequently redirect SSL VPN web portal users to arbitrary web domains.

fortinet fortios
0.01EPSS
CVE-2017-14185
Medium 5.3

An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.8 and 5.2 all versions allows SSL VPN web portal users to access internal FortiOS configuration information (eg:addresses) via specifically crafted URLs inside the SSL-VPN…

fortinet fortios
0.01EPSS
CVE-2023-42788
High 7.8

An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8, version 6.4.0 through 6.4.12 and versi…

fortinet fortianalyzer · fortinet fortimanager
0.01EPSS
CVE-2014-8582
Medium 6.4

FortiNet FortiADC-E with firmware 3.1.1 before 4.0.5 and Coyote Point Equalizer with firmware 10.2.0a allows remote attackers to obtain access to arbitrary subnets via unspecified vectors.

fortinet coyote_point_equalizer · fortinet coyote_point_equalizer_firmware · fortinet fortiadc-1000e · fortinet fortiadc-300e · and 3 more
0.01EPSS
CVE-2021-26090
Medium 5.3

A missing release of memory after its effective lifetime vulnerability in the Webmail of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6 may allow an unauthenticated remote attacker to exhaust available memory via specifically crafted login requests.

fortinet fortimail
0.01EPSS
CVE-2019-15709
Medium 6.5

An improper input validation in FortiAP-S/W2 6.2.0 to 6.2.2, 6.0.5 and below, FortiAP-U 6.0.1 and below CLI admin console may allow unauthorized administrators to overwrite system files via specially crafted tcpdump commands in the CLI.

fortinet fortiap-s · fortinet fortiap-u · fortinet fortiap-w2
0.01EPSS
CVE-2023-23779
Medium 6.8

Multiple improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerabilities [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below may allow an authenticated attacker to execute unauthor…

fortinet fortiweb
0.01EPSS
CVE-2023-23777
High 7.2

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.18 and below may allow a privileged attacker to execute arbitrary bash comma…

fortinet fortiweb
0.01EPSS
CVE-2018-13371
High 8.8

An external control of system vulnerability in FortiOS may allow an authenticated, regular user to change the routing settings of the device via connecting to the ZebOS component.

fortinet fortios
0.01EPSS
CVE-2024-33502
Medium 6.5

An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 …

fortinet fortianalyzer · fortinet fortimanager
0.01EPSS
CVE-2024-33508
High 7.3

An improper neutralization of special elements used in a command ('Command Injection') vulnerability [CWE-77] in Fortinet FortiClientEMS 7.2.0 through 7.2.4, 7.0.0 through 7.0.12 may allow an unauthenticated attacker to execute limited and temporary operations…

fortinet forticlient_enterprise_management_server
0.01EPSS
CVE-2022-33869
High 8.8

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiWAN 4.0.0 through 4.5.9 may allow an authenticated attacker to execute unauthorized commands via specifically crafted arguments to e…

fortinet fortiwan
0.01EPSS
CVE-2025-24470
High 8.6

An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests.

fortinet fortiportal
0.01EPSS