imPC@ndo EN

Vulnerabilità Fortinet

1134 CVE

CVE-2018-13379
Ransomware Critica 9.1

An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an una…

fortinet fortios · fortinet fortiproxy
1.00EPSS
CVE-2022-40684
Ransomware Critica 9.8

An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.6, FortiProxy version 7.2.0 and version 7.0.0 through 7.0.6 and FortiSwitchManager version 7.2.0 and 7.0.0 allows an una…

fortinet fortios · fortinet fortiproxy · fortinet fortiswitchmanager
1.00EPSS
CVE-2022-42475
Ransomware Critica 9.8

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.0 through 6.2.11, 6.0.15 and earlier and FortiProxy SSL-VPN 7.2.0 through 7.2.1, 7.0.7 and earlier may allow a remote u…

fortinet fortios · fortinet fortiproxy
0.99EPSS
CVE-2024-55591
Ransomware Critica 9.8

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via …

fortinet fortios · fortinet fortiproxy
0.98EPSS
CVE-2023-48788
Ransomware Critica 9.8

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted pa…

fortinet forticlient_enterprise_management_server
0.98EPSS
CVE-2025-25257
Sfruttata Critica 9.8

An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.7, FortiWeb 7.2.0 through 7.2.10, FortiWeb 7.0.0 through 7.0.10 al…

fortinet fortiweb
0.97EPSS
CVE-2024-47575
Sfruttata Critica 9.8

A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortinet FortiMan…

fortinet fortimanager · fortinet fortimanager_cloud
0.95EPSS
CVE-2026-21643
Sfruttata Critica 9.8

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests.

fortinet forticlientems
0.94EPSS
CVE-2025-64446
Sfruttata Critica 9.8

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative commands …

fortinet fortiweb
0.92EPSS
CVE-2026-39808
Sfruttata Critica 9.8

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

fortinet fortisandbox
0.91EPSS
CVE-2026-35616
Sfruttata Critica 9.8

A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unauthorized code or commands via crafted requests.

fortinet forticlientems
0.89EPSS
CVE-2026-24858
Sfruttata Critica 9.8

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiMan…

fortinet fortianalyzer · fortinet fortimanager · fortinet fortinac-f · fortinet fortios · e altri 3
0.86EPSS
CVE-2023-27997
Ransomware Critica 9.8

A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below, version 6.0.16 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below, ver…

fortinet fortios · fortinet fortiproxy
0.86EPSS
CVE-2024-21762
Ransomware Critica 9.8

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0…

fortinet fortios · fortinet fortiproxy
0.84EPSS
CVE-2018-13382
Ransomware Critica 9.1

An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the passwo…

fortinet fortios · fortinet fortiproxy
0.82EPSS
CVE-2026-25089
Sfruttata Critica 9.8

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4 through 5.0.5, Fo…

fortinet fortisandbox · fortinet fortisandbox_cloud · fortinet fortisandbox_paas
0.74EPSS
CVE-2025-59718
Sfruttata Critica 9.8

A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, …

fortinet fortios · fortinet fortiproxy · fortinet fortiswitchmanager · siemens ruggedcom_ape1808_firmware
0.63EPSS
CVE-2024-23113
Sfruttata Critica 9.8

A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, FortiPAM versions 1.2.0, 1.1.0 through…

fortinet fortios · fortinet fortipam · fortinet fortiproxy · fortinet fortiswitchmanager
0.62EPSS
CVE-2025-58034
Sfruttata Alta 7.2

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2…

fortinet fortiweb
0.56EPSS
CVE-2020-12812
Ransomware Critica 9.8

An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of…

fortinet fortios
0.49EPSS
CVE-2018-13374
Ransomware Media 4.3

A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a …

fortinet fortiadc · fortinet fortios
0.38EPSS
CVE-2018-13383
Ransomware Media 4.3

A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxy 2.0.0, 1.2.8 and earlier in the SSL VPN web portal may cause the SSL VPN web service termination for logged in users d…

fortinet fortios · fortinet fortiproxy
0.34EPSS
CVE-2025-32756
Sfruttata Critica 9.8

A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versions, FortiCamera 1.1 all versions, FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7…

fortinet forticamera_firmware · fortinet fortimail · fortinet fortindr · fortinet fortirecorder · e altri 1
0.33EPSS
CVE-2019-5591
Sfruttata Media 6.5

A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.

fortinet fortios
0.18EPSS
CVE-2022-41328
Sfruttata Media 6.7

A improper limitation of a pathname to a restricted directory vulnerability ('path traversal') [CWE-22] in Fortinet FortiOS version 7.2.0 through 7.2.3, 7.0.0 through 7.0.9 and before 6.4.11 allows a privileged attacker to read and write files on the underlyin…

fortinet fortios
0.12EPSS