fortinet

1,122 tracked vulnerabilities.

CVE-2024-40586 MEDIUM
FortiClient <7.4.0 - Privilege Escalation
Feb 11, 2025
CVSS 6.7
EPSS 0.00
CVE-2024-40584 HIGH
Fortinet FortiAnalyzer <7.4.3 - OS Command Injection
Feb 11, 2025
CVSS 7.2
EPSS 0.00
CVE-2024-36508 MEDIUM
Fortinet FortiManager <7.4.2, FortiAnalyzer <7.2.5 - Path Traversal
Feb 11, 2025
CVSS 6.0
EPSS 0.00
CVE-2024-35279 HIGH
FortiOS 7.2.4-7.2.8 and 7.4.0-7.4.4 - Unauthenticated Remote Code Execution via CAPWAP UDP Packet
Feb 11, 2025
CVSS 8.1
EPSS 0.02
CVE-2024-33504 MEDIUM
FortiManager <7.6.1 - Memory Corruption
Feb 11, 2025
CVSS 4.1
EPSS 0.00
CVE-2024-27781 HIGH
Fortinet FortiSandbox 3.0.0-4.0.4, 4.2.1-4.2.6, 4.4.0-4.4.4 - Cross-Site Scripting
Feb 11, 2025
CVSS 7.1
EPSS 0.08
CVE-2024-27780 LOW
FortiSIEM 6.7.0-6.7.8, 7.0, 7.1 - Authenticated Cross-Site Scripting via Crafted HTTP Requests
Feb 11, 2025
CVSS 2.2
EPSS 0.00
CVE-2024-50563 HIGH
Fortinet FortiManager/FortiAnalyzer <7.6.1/7.4.3 - RCE
Jan 16, 2025
CVSS 7.3
EPSS 0.00
CVE-2024-48885 MEDIUM
Fortinet FortiRecorder 7.0.0-7.0.4, 7.2.0-7.2.1; FortiVoice 6.0-6.4.9, 7.0.0-7.0.4; FortiWeb 6.4-7.6.0 - Path Traversal
Jan 16, 2025
CVSS 5.3
EPSS 0.00
CVE-2024-45331 HIGH
Fortinet FortiAnalyzer <7.4.3 - Privilege Escalation
Jan 16, 2025
CVSS 7.3
EPSS 0.00
CVE-2024-35280 MEDIUM
Fortinet FortiDeceptor 3.0-5.3.0 - Reflected Cross-Site Scripting in Recovery Endpoints
Jan 15, 2025
CVSS 5.4
EPSS 0.01
CVE-2024-56497 MEDIUM
Fortinet FortiMail <7.2.4 - Command Injection
Jan 14, 2025
CVSS 6.7
EPSS 0.00
CVE-2024-55593 LOW
FortiWeb 6.3.17-7.6.1 - SQL Injection
Jan 14, 2025
CVSS 2.7
EPSS 0.00
CVE-2024-55591 CRITICAL KEVNUCLEI
FortiProxy 7.0.0-7.0.19 and 7.2.0-7.2.12 - Authentication Bypass via Node.js Websocket Module
Jan 14, 2025
CVSS 9.8
EPSS 0.94
CVE-2024-54021 MEDIUM
FortiOS 7.2.0-7.6.0 and FortiProxy 7.2.0-7.4.5 - Unauthenticated HTTP Response Splitting via Crafted Headers
Jan 14, 2025
CVSS 6.5
EPSS 0.00
CVE-2024-52969 MEDIUM
FortiSIEM < 7.1.7 - Authenticated SQL Injection via Update/Create Case Feature
Jan 14, 2025
CVSS 4.1
EPSS 0.00
CVE-2024-52967 LOW
FortiPortal 6.0.0-6.0.14 - Cross-Site Scripting via HTML Injection
Jan 14, 2025
CVSS 3.5
EPSS 0.00
CVE-2024-52963 LOW
Fortinet FortiOS 6.4.0-6.4.15, 7.0.0-7.0.16, 7.2.0-7.2.10, 7.4.0-7.4.6, 7.6.0 - Out-of-bounds Write via Crafted Packets
Jan 14, 2025
CVSS 3.7
EPSS 0.00
CVE-2024-50566 HIGH
FortiManager 7.2.1-7.2.8 and FortiManager Cloud 7.2.2-7.2.7 - Authenticated OS Command Injection via FGFM Request
Jan 14, 2025
CVSS 7.2
EPSS 0.00
CVE-2024-50564 LOW
Fortinet FortiClientWindows <7.4.0 - Info Disclosure
Jan 14, 2025
CVSS 3.3
EPSS 0.00
CVE-2024-48893 MEDIUM
FortiSOAR 7.2.1-7.2.2, 7.3.0-7.3.3 - Authenticated Stored Cross-Site Scripting via Malicious Playbook
Jan 14, 2025
CVSS 6.8
EPSS 0.00
CVE-2024-48890 MEDIUM
FortiSOAR IMAP Connector < 3.5.8 - Authenticated OS Command Injection via Crafted Playbook
Jan 14, 2025
CVSS 6.6
EPSS 0.00
CVE-2024-48886 CRITICAL
Fortinet FortiOS/FortiProxy/FortiManager/FortiAnalyzer Cloud Weak Authentication Brute-Force
Jan 14, 2025
CVSS 9.0
EPSS 0.00
CVE-2024-48884 HIGH
Fortinet FortiManager 7.4.1-7.4.3, FortiOS 6.4.0-6.4.15 - Path Traversal & Arbitrary File Write
Jan 14, 2025
CVSS 7.5
EPSS 0.50
CVE-2024-47572 CRITICAL
Fortinet FortiSOAR <7.4.1 - Code Injection
Jan 14, 2025
CVSS 9.0
EPSS 0.01