imPC@ndo IT

Fortinet vulnerabilities

1134 CVE

CVE-2022-38374
High 8.8

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiADC 7.0.0 - 7.0.2 and 6.2.0 - 6.2.4 allows an attacker to execute unauthorized code or commands via the URL and User fields observed in the traffic and even…

fortinet fortiadc
0.02EPSS
CVE-2017-17544
High 7.2

A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin users to elevate their profile to super_admin via restoring modified configurations.

fortinet fortios
0.02EPSS
CVE-2022-39951
High 7.2

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.2, FortiWeb version 6.3.6 through 6.3.20, FortiWeb 6.4 all versions allows attacker to execute unauthorized code or comm…

fortinet fortiweb
0.02EPSS
CVE-2014-2723
High 8.8

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is no…

fortinet fortibalancer_1000_firmware · fortinet fortibalancer_2000_firmware · fortinet fortibalancer_3000_firmware · fortinet fortibalancer_400_firmware
0.02EPSS
CVE-2014-2722
High 8.8

In FortiBalancer 400, 1000, 2000 and 3000, a platform-specific remote access vulnerability has been discovered that may allow a remote user to gain privileged access to affected systems using SSH. The vulnerability is caused by a configuration error, and is no…

fortinet fortibalancer_1000_firmware · fortinet fortibalancer_2000_firmware · fortinet fortibalancer_3000_firmware · fortinet fortibalancer_400_firmware
0.02EPSS
CVE-2024-48889
High 7.2

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, version 7.4.4 and below, version 7.2.7 and below, version 7.0.12 and below, version 6.4.14 and below and FortiMa…

fortinet fortimanager · fortinet fortimanager_cloud
0.02EPSS
CVE-2018-1354
Medium 6.5

An improper access control vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows a regular user edit the avatar picture of other users with arbitrary content.

fortinet fortianalyzer · fortinet fortimanager
0.02EPSS
CVE-2021-26112
High 8.1

Multiple stack-based buffer overflow vulnerabilities [CWE-121] both in network daemons and in the command line interpreter of FortiWAN before 4.5.9 may allow an unauthenticated attacker to potentially corrupt control data in memory and execute arbitrary code v…

fortinet fortiwan
0.02EPSS
CVE-2025-66178
High 7.2

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 thro…

fortinet fortiweb
0.02EPSS
CVE-2021-32590
Critical 9.9

Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiPortal 6.0.0 through 6.0.4, 5.3.0 through 5.3.5, 5.2.0 through 5.2.5, and 4.2.2 and earlier may allow an attacker with regular user's privileges to execute arbi…

fortinet fortiportal
0.02EPSS
CVE-2016-5092
Medium 4.9

Directory traversal vulnerability in Fortinet FortiWeb before 5.5.3 allows remote authenticated administrators with read and write privileges to read arbitrary files by leveraging the autolearn feature.

fortinet fortiweb
0.02EPSS
CVE-2021-36179
High 8.0

A stack-based buffer overflow in Fortinet FortiWeb version 6.3.14 and below, 6.2.4 and below allows attacker to execute unauthorized code or commands via crafted parameters in CLI command execution

fortinet fortiweb
0.02EPSS
CVE-2019-13400
Critical 9.8

Dynacolor FCM-MB40 v1.2.0.0 use /etc/appWeb/appweb.pass to store administrative web-interface credentials in cleartext. These credentials can be retrieved via cgi-bin/getuserinfo.cgi?mode=info.

fortinet fcm-mb40_firmware
0.02EPSS
CVE-2021-43075
High 8.8

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWLM version 8.6.2 and below, version 8.5.2 and below, version 8.4.2 and below, version 8.3.2 and below allows attacker to execute unauthorized code or…

fortinet fortiwlm
0.02EPSS
CVE-2018-1355
Medium 6.1

An open redirect vulnerability in Fortinet FortiManager 6.0.0, 5.6.5 and below versions, FortiAnalyzer 6.0.0, 5.6.5 and below versions allows attacker to inject script code during converting a HTML table to a PDF document under the FortiView feature. An attac…

fortinet fortianalyzer · fortinet fortimanager
0.02EPSS
CVE-2006-1966
Medium 5.0

An unspecified Fortinet product, possibly Fortinet28, allows remote attackers to cause a denial of service via a "small synflood" to the SMTP port (TCP port 25), as demonstrated by a 10-microsecond wait between sending packets. NOTE: this issue has been dispu…

fortinet fortinet28
0.02EPSS
CVE-2019-17656
Medium 5.4

A Stack-based Buffer Overflow vulnerability in the HTTPD daemon of FortiOS 6.0.10 and below, 6.2.2 and below and FortiProxy 1.0.x, 1.1.x, 1.2.9 and below, 2.0.0 and below may allow an authenticated remote attacker to crash the service by sending a malformed PU…

fortinet fortios · fortinet fortiproxy
0.02EPSS
CVE-2021-36186
High 8.8

A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests

fortinet fortiweb
0.02EPSS
CVE-2021-41024
High 7.5

A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of the server v…

fortinet fortios · fortinet fortiproxy
0.02EPSS
CVE-2020-9292
Critical 9.8

An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path.

fortinet fortisiem_windows_agent
0.02EPSS
CVE-2016-7542
Medium 4.9

A read-only administrator on Fortinet devices with FortiOS 5.2.x before 5.2.10 GA and 5.4.x before 5.4.2 GA may have access to read-write administrators password hashes (not including super-admins) stored on the appliance via the webui REST API, and may theref…

fortinet fortios
0.02EPSS
CVE-2022-29061
High 7.2

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSOAR before 7.2.1 allows an authenticated attacker to execute unauthorized code or commands via crafted HTTP GET requests.

fortinet fortisoar
0.02EPSS
CVE-2015-7360
Medium 6.1

Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface (WebUI) in Fortinet FortiSandbox before 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) serial parameter to alerts/summary/profile/; the (2) urlForCreat…

fortinet fortisandbox_firmware
0.02EPSS
CVE-2021-26114
Critical 9.8

Multiple improper neutralization of special elements used in an SQL command vulnerabilities in FortiWAN before 4.5.9 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

fortinet fortiwan
0.02EPSS
CVE-2023-45590
Critical 9.6

An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute unauthorized code or commands via tricking a FortiClientLinux user into visiting a …

fortinet forticlient
0.02EPSS