fortinet

1,122 tracked vulnerabilities.

CVE-2023-26207 LOW
Fortinet FortiOS <7.2.5 - Info Disclosure
Jun 13, 2023
CVSS 3.3
EPSS 0.00
CVE-2023-26204 LOW
FortiSIEM 5.3.0-6.7 - Plaintext Password Storage
Jun 13, 2023
CVSS 3.7
EPSS 0.00
CVE-2023-25609 MEDIUM
FortiManager and FortiAnalyzer 6.4.8-6.4.11, 7.0.0-7.0.6, 7.2.0-7.2.1 - Authenticated Server-Side Request Forgery
Jun 13, 2023
CVSS 4.3
EPSS 0.00
CVE-2023-22639 MEDIUM
FortiProxy < 1.0.7 and 2.0 - Out-of-bounds Write via Crafted Commands
Jun 13, 2023
CVSS 6.7
EPSS 0.00
CVE-2023-22633 HIGH
FortiNAC <=9.4.1, <=9.2.6, <=9.1.8, 8.8.0, 8.7.0 - Unauthenticated DoS via Client-Secure Renegotiation
Jun 13, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-27999 HIGH
FortiADC 7.1.0-7.1.1, 7.2.0 - Authenticated OS Command Injection via Crafted Arguments
May 03, 2023
CVSS 7.8
EPSS 0.00
CVE-2023-27993 MEDIUM
FortiADC 7.2.0 and before 7.1.1 - Authenticated Path Traversal via CLI Commands
May 03, 2023
CVSS 6.0
EPSS 0.00
CVE-2023-26203 MEDIUM
FortiNAC-F <7.2.0, FortiNAC <9.4.2, 9.1-9.2, 8.7-8.8 - Info Disclosure
May 03, 2023
CVSS 6.7
EPSS 0.00
CVE-2023-22640 HIGH
FortiProxy 7.2.0-7.2.1, 7.0.0-7.0.7, 2.0, 1.2, 1.1, 1.0 - Authenticated Out-of-bounds Write
May 03, 2023
CVSS 7.5
EPSS 0.01
CVE-2023-22637 MEDIUM
FortiNAC and FortiNAC-F - Authenticated Remote Code Execution via License Management
May 03, 2023
CVSS 6.5
EPSS 0.01
CVE-2023-27995 HIGH
Fortinet FortiSOAR 7.3.0-7.3.1 - Authenticated Remote Code Execution via Template Injection
Apr 11, 2023
CVSS 7.2
EPSS 0.01
CVE-2023-22642 HIGH
FortiAnalyzer & FortiManager 6.4.8-6.4.10, 7.0.0-7.0.5, 7.2.0-7.2.1 - MITM via Improper Cert Validation
Apr 11, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-22641 MEDIUM
FortiProxy 1.0.0-1.2.x and 2.0.0-2.0.11 - Authenticated Open Redirect
Apr 11, 2023
CVSS 4.1
EPSS 0.00
CVE-2023-22635 HIGH
FortiClient 4.0.0-5.6.6 - Privilege Escalation via Installer Modification
Apr 11, 2023
CVSS 7.3
EPSS 0.00
CVE-2023-26209 LOW
Fortinet FortiDeceptor <3.1.x - DoS
Mar 09, 2023
CVSS 3.7
EPSS 0.20
CVE-2023-26208 LOW
Fortinet FortiAuthenticator <6.4 - DoS
Mar 09, 2023
CVSS 3.7
EPSS 0.20
CVE-2023-25611 MEDIUM
Fortinet FortiAnalyzer <7.2.1 - Code Injection
Mar 07, 2023
CVSS 4.0
EPSS 0.00
CVE-2023-25605 HIGH
Fortinet FortiSOAR 7.3.0-7.3.1 - Authenticated Improper Access Control via Crafted HTTP Requests
Mar 07, 2023
CVSS 7.5
EPSS 0.00
CVE-2023-23776 MEDIUM
FortiAnalyzer 6.4.0-6.4.10, 7.0.0-7.0.4, 7.2.0-7.2.1 - Sensitive Info Exposure via Heartbeat
Mar 07, 2023
CVSS 4.6
EPSS 0.00
CVE-2023-22636 HIGH
FortiWeb 6.3.6-6.3.21, 6.4.0-6.4.2, 7.0.0-7.0.4 - Unauthenticated Configuration File Download via HTTP Request
Feb 27, 2023
CVSS 7.0
EPSS 0.00
CVE-2023-25602 HIGH
FortiWeb 5.6.0-6.4.0 Stack-based Buffer Overflow via Command Arguments
Feb 16, 2023
CVSS 7.8
EPSS 0.00
CVE-2023-23784 MEDIUM
FortiWeb 6.3.6-6.3.20 and 7.0.0-7.0.2 - Path Traversal via Crafted Web Requests
Feb 16, 2023
CVSS 5.7
EPSS 0.00
CVE-2023-23783 MEDIUM
FortiWeb 6.4.0-6.4.1 and 7.0.0-7.0.1 - Remote Code Execution via Format String Injection
Feb 16, 2023
CVSS 6.7
EPSS 0.00
CVE-2023-23782 HIGH
FortiWeb 6.2-6.2.6, 6.3.0-6.3.19, 6.4, 7.0.0-7.0.1 - Heap-based Buffer Overflow via Crafted Command Arguments
Feb 16, 2023
CVSS 7.8
EPSS 0.00
CVE-2023-23781 MEDIUM
FortiWeb 6.3.0-6.3.19, 6.4, <=7.0.1 - Authenticated Stack-based Buffer Overflow via SAML XML Configuration
Feb 16, 2023
CVSS 6.4
EPSS 0.01