imPC@ndo IT

Fortinet vulnerabilities

1134 CVE

CVE-2024-45324
High 7.2

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and b…

fortinet fortios · fortinet fortipam · fortinet fortiproxy · fortinet fortisra · and 1 more
0.01EPSS
CVE-2022-43946
High 7.5

Multiple vulnerabilities including an incorrect permission assignment for critical resource [CWE-732] vulnerability and a time-of-check time-of-use (TOCTOU) race condition [CWE-367] vulnerability in Fortinet FortiClientWindows before 7.0.7 allows attackers on …

fortinet forticlient
0.01EPSS
CVE-2023-23781
Medium 6.4

A stack-based buffer overflow vulnerability [CWE-121] in FortiWeb version 7.0.1 and below, 6.4 all versions, version 6.3.19 and below SAML server configuration may allow an authenticated attacker to achieve arbitrary code execution via specifically crafted XML…

fortinet fortiweb
0.01EPSS
CVE-2021-32585
High 7.2

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiWAN before 4.5.9 may allow an attacker to perform a stored cross-site scripting attack via specifically crafted HTTP requests.

fortinet fortiwan
0.01EPSS
CVE-2026-22153
High 8.1

An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is confi…

fortinet fortios
0.01EPSS
CVE-2019-6696
Medium 6.1

An improper input validation vulnerability in FortiOS 6.2.1, 6.2.0, 6.0.8 and below until 5.4.0 under admin webUI may allow an attacker to perform an URL redirect attack via a specifically crafted request to the admin initial password change webpage.

fortinet fortios
0.01EPSS
CVE-2019-16154
Medium 6.1

An improper neutralization of input during web page generation in FortiAuthenticator WEB UI 6.0.0 may allow an unauthenticated user to perform a cross-site scripting attack (XSS) via a parameter of the logon page.

fortinet fortiauthenticator
0.01EPSS
CVE-2018-1353
Medium 4.3

An information disclosure vulnerability in Fortinet FortiManager 6.0.1 and below versions allows a standard user with adom assignment read the interface settings of vdoms unrelated to the assigned adom.

fortinet fortimanager
0.01EPSS
CVE-2015-7363
Medium 5.4

Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware models with a hard disk, and FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.3 allows remote administrato…

fortinet fortianalyzer_firmware · fortinet fortimanager_firmware
0.01EPSS
CVE-2024-23662
Medium 5.3

An exposure of sensitive information to an unauthorized actor in Fortinet FortiOS at least version at least 7.4.0 through 7.4.1 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.15 and 6.4.0 through 6.4.15 allows attacker to information disclosure via HTTP request…

fortinet fortios
0.01EPSS
CVE-2025-47294
Medium 5.3

A integer overflow or wraparound in Fortinet FortiOS versions 7.2.0 through 7.2.7, versions 7.0.0 through 7.0.14 may allow a remote unauthenticated attacker to crash the csfd daemon via a specially crafted request.

fortinet fortios
0.01EPSS
CVE-2025-25254
High 7.2

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiWeb version 7.6.2 and below, version 7.4.6 and below, 7.2 all versions, 7.0 all versions endpoint may allow an authenticated admin to access and mo…

fortinet fortiweb
0.01EPSS
CVE-2024-46666
Medium 5.3

An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow a remote unauthenticated attacker to prevent access to the G…

fortinet fortios
0.01EPSS
CVE-2021-26095
High 7.5

The combination of various cryptographic issues in the session management of FortiMail 6.4.0 through 6.4.4 and 6.2.0 through 6.2.6, including the encryption construction of the session cookie, may allow a remote attacker already in possession of a cookie to po…

fortinet fortimail
0.01EPSS
CVE-2024-26012
Medium 6.7

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4.0 through 6.4.9, FortiAP-W2 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.3, and 7.4.0 through 7.4.2, FortiAP 6…

fortinet fortiap · fortinet fortiap-s · fortinet fortiap-w2
0.01EPSS
CVE-2022-43954
Medium 4.3

An insertion of sensitive information into log file vulnerability [CWE-532] in the FortiPortal management interface 7.0.0 through 7.0.2 may allow a remote authenticated attacker to read other devices' passwords in the audit log page.

fortinet fortiportal
0.01EPSS
CVE-2022-39950
High 8.0

An improper neutralization of input during web page generation vulnerability [CWE-79] exists in FortiManager and FortiAnalyzer 6.0.0 all versions, 6.2.0 all versions, 6.4.0 through 6.4.8, and 7.0.0 through 7.0.4. Report templates may allow a low privilege leve…

fortinet fortianalyzer · fortinet fortimanager
0.01EPSS
CVE-2023-44253
Medium 5.0

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and FortiAnalyzer-BigData before 7.2.5 allow…

fortinet fortianalyzer · fortinet fortimanager
0.01EPSS
CVE-2022-38381
Medium 5.3

An improper handling of malformed request vulnerability [CWE-228] exists in FortiADC 5.0 all versions, 6.0.0 all versions, 6.1.0 all versions, 6.2.0 through 6.2.3, and 7.0.0 through 7.0.2. This may allow a remote attacker without privileges to bypass some Web …

fortinet fortiadc
0.01EPSS
CVE-2017-7340
Medium 6.1

A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the applicationSearch parameter in the FortiView functionality.

fortinet fortiportal
0.01EPSS
CVE-2022-30304
Medium 4.3

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiAnalyzer versions prior to 7.2.1, 7.0.4 and 6.4.8 may allow a remote unauthenticated attacker to perform a stored cross site scripting (XSS) attack via the URL parame…

fortinet fortianalyzer
0.01EPSS
CVE-2021-32603
High 8.8

A server-side request forgery (SSRF) (CWE-918) vulnerability in FortiManager and FortiAnalyser GUI 7.0.0, 6.4.5 and below, 6.2.7 and below, 6.0.11 and below, 5.6.11 and below may allow a remote and authenticated attacker to access unauthorized files and servic…

fortinet fortianalyzer · fortinet fortimanager
0.01EPSS
CVE-2017-7343
Medium 6.1

An open redirect vulnerability in Fortinet FortiPortal 4.0.0 and below allows attacker to execute unauthorized code or commands via the url parameter.

fortinet fortiportal
0.01EPSS
CVE-2017-7339
Medium 6.1

A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attacker to execute unauthorized code or commands via the 'Name' and 'Description' inputs in the 'Add Revision Backup' functionality.

fortinet fortiportal
0.01EPSS
CVE-2024-35273
High 7.2

A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.

fortinet fortianalyzer · fortinet fortianalyzer_cloud · fortinet fortimanager · fortinet fortimanager_cloud
0.01EPSS