fortinet

1,122 tracked vulnerabilities.

CVE-2023-29177 MEDIUM
FortiADC < 7.1.2 and FortiDDoS-F < 6.4.1 - Authenticated Remote Code Execution via CLI Requests
Nov 14, 2023
CVSS 6.7
EPSS 0.00
CVE-2023-25603 MEDIUM
FortiADC 7.1.0-7.1.1 and FortiDDoS-F 6.3.0-6.3.4, 6.4.0-6.4.1 - Permissive Cross-domain Policy with Untrusted Domains
Nov 14, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-45585 LOW
FortiSIEM <=7.0.0 - Authenticated Sensitive Information Disclosure in Debug Log Files
Nov 14, 2023
CVSS 2.3
EPSS 0.00
CVE-2023-45582 MEDIUM
FortiMail 6.2.0-6.2.8, 7.0.0-7.0.6, 7.2.0-7.2.4 - Unauthenticated Brute Force Attack via Repeated Login Attempts
Nov 14, 2023
CVSS 5.6
EPSS 0.00
CVE-2023-44248 MEDIUM
FortiEDRCollectorWindows <= 5.2.0.4549, <= 5.0.3.1007, 4.0 - Local Denial of Service via Registry Key Tampering
Nov 14, 2023
CVSS 4.4
EPSS 0.00
CVE-2023-42783 HIGH
Fortinet FortiWLM 8.2.2-8.6.5 - Relative Path Traversal via Crafted HTTP Requests
Nov 14, 2023
CVSS 7.5
EPSS 0.01
CVE-2023-41840 HIGH
FortiClientWindows 7.0.9 - DLL Hijack via OpenSSL Engine Library Search Path
Nov 14, 2023
CVSS 7.8
EPSS 0.00
CVE-2023-41676 MEDIUM
FortiSIEM < 6.7.5 and 7.0.0 - Unauthenticated Sensitive Information Exposure via Windows Agent Logs
Nov 14, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-36641 MEDIUM
FortiProxy & FortiOS DoS via Crafted HTTP Requests
Nov 14, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-36633 MEDIUM
FortiMail <7.2.2, >7.0.4 - Auth Bypass
Nov 14, 2023
CVSS 5.4
EPSS 0.00
CVE-2023-36553 CRITICAL
Fortinet FortiSIEM <5.4.0-5.0.1 - Command Injection
Nov 14, 2023
CVSS 9.8
EPSS 0.03
CVE-2023-34991 CRITICAL
FortiWLM 8.2.2-8.6.5 - SQL Injection via Crafted HTTP Request
Nov 14, 2023
CVSS 9.8
EPSS 0.10
CVE-2023-33304 MEDIUM
Fortinet FortiClient <7.0.10, >7.2.1 - Info Disclosure
Nov 14, 2023
CVSS 4.4
EPSS 0.00
CVE-2023-28002 MEDIUM
FortiOS <7.2.3, <7.0.12, all 6.x - Code Injection
Nov 14, 2023
CVSS 6.4
EPSS 0.00
CVE-2023-26205 HIGH
FortiADC <7.1.2 - Privilege Escalation
Nov 14, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-44256 MEDIUM
FortiAnalyzer/FortiManager SSRF via Crafted HTTP Request
Oct 20, 2023
CVSS 6.5
EPSS 0.01
CVE-2023-41843 HIGH
FortiSandbox 2.4.1-4.4.1 - Cross-Site Scripting via Crafted HTTP Requests
Oct 13, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-41836 LOW
FortiSandbox 3.0.4-3.0.7, 3.1, 3.2, 4.0, 4.2.1-4.2.4, 4.4.0 - Cross-Site Scripting via Crafted HTTP Requests
Oct 13, 2023
CVSS 3.5
EPSS 0.00
CVE-2023-41682 HIGH
FortiSandbox 2.4-4.4.0 - Path Traversal and Denial of Service via Crafted HTTP Requests
Oct 13, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-41681 HIGH
FortiSandbox 2.4.1-4.4.1 - Cross-Site Scripting via Crafted HTTP Requests
Oct 13, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-41680 HIGH
FortiSandbox 2.4.1-4.4.1 - Cross-Site Scripting via Crafted HTTP Requests
Oct 13, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-33303 HIGH
Fortinet FortiEDR 5.0.0-5.0.1 - Insufficient Session Expiration via API Request
Oct 13, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-44249 MEDIUM
FortiAnalyzer and FortiManager < 7.2.3 - Authorization Bypass via Crafted HTTP Requests
Oct 10, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-42788 HIGH
FortiAnalyzer/FortiManager OS Command Injection via CLI Arguments
Oct 10, 2023
CVSS 7.8
EPSS 0.00
CVE-2023-42787 MEDIUM
Fortinet FortiManager <7.2.3, FortiAnalyzer <7.2.3 - RCE
Oct 10, 2023
CVSS 6.5
EPSS 0.01