fortinet

1,122 tracked vulnerabilities.

CVE-2023-42782 MEDIUM
FortiAnalyzer <= 7.4.0 and < 7.2.3 - Unauthenticated Syslog Message Spoofing via Device Serial Number
Oct 10, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-41841 HIGH
FortiOS 7.0.0-7.0.11 and 7.2.0-7.2.4 - Authenticated Improper Authorization
Oct 10, 2023
CVSS 8.1
EPSS 0.00
CVE-2023-41838 HIGH
Fortinet Fortianalyzer < 6.2.11 - OS Command Injection
Oct 10, 2023
CVSS 7.1
EPSS 0.00
CVE-2023-41679 HIGH
FortiManager <7.2.2-6.4.11 - Privilege Escalation
Oct 10, 2023
CVSS 8.5
EPSS 0.00
CVE-2023-41675 MEDIUM
FortiOS <7.2.4, FortiProxy <7.2.2 - Use After Free
Oct 10, 2023
CVSS 5.3
EPSS 0.00
CVE-2023-40718 HIGH
Fortinet IPS Engine <7.321-6.158 - Evade IPS
Oct 10, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-37939 LOW
FortiClient 6.2.0-6.2.8, 6.4, 7.0, 7.2.0-7.2.1 - Sensitive Information Exposure via Malware Scan Exclusion List
Oct 10, 2023
CVSS 3.3
EPSS 0.00
CVE-2023-37935 MEDIUM
Fortinet FortiOS <7.0.12-7.2.5-7.4.0 - Info Disclosure
Oct 10, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-36637 LOW
FortiMail 7.2.0-7.2.2 and < 7.0.5 - Authenticated Cross-Site Scripting in Calendar Input Fields
Oct 10, 2023
CVSS 3.5
EPSS 0.00
CVE-2023-36556 HIGH
FortiMail 6.0.0-6.0.11, 7.0.0-7.0.5, 7.2.0-7.2.2 - Authenticated Incorrect Authorization via Crafted HTTP Requests
Oct 10, 2023
CVSS 8.8
EPSS 0.00
CVE-2023-36555 LOW
FortiOS 7.2.0-7.2.4 - Cross-Site Scripting via SAML and Security Fabric Components
Oct 10, 2023
CVSS 3.9
EPSS 0.00
CVE-2023-36550 CRITICAL
Fortinet FortiWLM <8.6.5, <8.5.4 - Command Injection
Oct 10, 2023
CVSS 9.8
EPSS 0.01
CVE-2023-36549 HIGH
Fortinet FortiWLM <8.6.5, <8.5.4 - Command Injection
Oct 10, 2023
CVSS 8.8
EPSS 0.03
CVE-2023-36548 CRITICAL
Fortinet FortiWLM <8.6.5, <8.5.4 - Code Injection
Oct 10, 2023
CVSS 9.8
EPSS 0.01
CVE-2023-36547 CRITICAL
Fortinet FortiWLM <8.6.5, <8.5.4 - Command Injection
Oct 10, 2023
CVSS 9.8
EPSS 0.01
CVE-2023-34993 CRITICAL NUCLEI
FortiWLM 8.5.0-8.5.4 and 8.6.0-8.6.5 - OS Command Injection via HTTP GET Request Parameters
Oct 10, 2023
CVSS 9.8
EPSS 0.87
CVE-2023-34992 CRITICAL
FortiSIEM 6.6.0-6.6.2 - OS Command Injection via Crafted API Requests
Oct 10, 2023
CVSS 10.0
EPSS 0.76
CVE-2023-34989 HIGH
FortiWLM 8.5.0-8.5.4 and 8.6.0-8.6.5 - OS Command Injection via HTTP GET Request Parameters
Oct 10, 2023
CVSS 8.8
EPSS 0.01
CVE-2023-34988 HIGH
Fortinet FortiWLM 8.5.0-8.5.4 and 8.6.0-8.6.5 - OS Command Injection via HTTP GET Request Parameters
Oct 10, 2023
CVSS 8.8
EPSS 0.01
CVE-2023-34987 HIGH
Fortinet FortiWLM 8.5.0-8.5.4 and 8.6.0-8.6.5 - OS Command Injection via HTTP GET Request Parameters
Oct 10, 2023
CVSS 8.8
EPSS 0.01
CVE-2023-34986 HIGH
FortiWLM 8.5.0-8.5.4 and 8.6.0-8.6.5 - OS Command Injection via HTTP GET Request Parameters
Oct 10, 2023
CVSS 8.8
EPSS 0.01
CVE-2023-34985 HIGH
FortiWLM 8.5.0-8.5.4 and 8.6.0-8.6.5 - OS Command Injection via HTTP GET Request Parameters
Oct 10, 2023
CVSS 8.8
EPSS 0.01
CVE-2023-33301 MEDIUM
Fortinet FortiOS <7.2.5-7.4.0 - Info Disclosure
Oct 10, 2023
CVSS 6.5
EPSS 0.00
CVE-2023-25607 HIGH
FortiManager 6.0-7.2.2, FortiAnalyzer 6.0-7.2.2, FortiADC 6.0-7.1.0 - OS Command Injection
Oct 10, 2023
CVSS 7.8
EPSS 0.00
CVE-2023-25604 MEDIUM
Fortinet FortiGuest 1.0.0 - Sensitive Information Exposure in RADIUS Logs
Oct 10, 2023
CVSS 5.5
EPSS 0.00