fortinet

1,122 tracked vulnerabilities.

CVE-2025-61886 MEDIUM
FortiSandbox 5.0.0-5.0.4 and FortiSandbox PaaS 5.0.0-5.0.4 - Cross-Site Scripting via Crafted HTTP Requests
Apr 14, 2026
CVSS 5.4
EPSS 0.00
CVE-2025-61848 HIGH
FortiManager and FortiAnalyzer - Authenticated SQL Injection via JSON RPC API
Apr 14, 2026
CVSS 7.2
EPSS 0.00
CVE-2025-61624 MEDIUM
Fortinet FortiOS/FortiProxy/FortiSwitchManager/FortiPAM - Authenticated Path Traversal & Arbitrary File Write via CLI
Apr 14, 2026
CVSS 6.0
EPSS 0.00
CVE-2025-59809 MEDIUM
FortiSOAR 7.3.0-7.6.4 - Authenticated Server-Side Request Forgery
Apr 14, 2026
CVSS 4.3
EPSS 0.00
CVE-2025-53847 MEDIUM
Fortinet FortiOS <7.6.3 - Auth Bypass
Apr 14, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-68648 HIGH
Fortinet FortiAnalyzer/FortiManager - Memory Corruption
Mar 10, 2026
CVSS 7.2
EPSS 0.00
CVE-2025-68482 MEDIUM
Fortinet FortiAnalyzer/FortiManager - Info Disclosure
Mar 10, 2026
CVSS 6.9
EPSS 0.00
CVE-2025-66178 HIGH
Fortinet FortiWeb - Command Injection
Mar 10, 2026
CVSS 7.2
EPSS 0.00
CVE-2025-55717 MEDIUM
Fortinet FortiMail/FortiRecorder/FortiVoice - Info Disclosure
Mar 10, 2026
CVSS 4.0
EPSS 0.00
CVE-2025-54820 HIGH
Fortinet FortiManager - Buffer Overflow
Mar 10, 2026
CVSS 8.1
EPSS 0.00
CVE-2025-54659 MEDIUM
FortiSOAR Agent Communication Bridge 1.1.0/1.0 - Path Traversal
Mar 10, 2026
CVSS 5.8
EPSS 0.00
CVE-2025-53608 MEDIUM
FortiSandbox 4.0.0-4.4.7, 5.0.0-5.0.2 - Authenticated Cross-Site Scripting
Mar 10, 2026
CVSS 4.8
EPSS 0.00
CVE-2025-49784 MEDIUM
Fortinet FortiAnalyzer - SQL Injection
Mar 10, 2026
CVSS 6.0
EPSS 0.00
CVE-2025-48840 MEDIUM
Fortinet FortiWeb 7.0-7.6.3 - Auth Bypass
Mar 10, 2026
CVSS 5.3
EPSS 0.00
CVE-2025-48418 MEDIUM
Fortinet FortiAnalyzer/FortiManager - Auth Bypass
Mar 10, 2026
CVSS 6.7
EPSS 0.00
CVE-2025-68686 MEDIUM
Fortinet FortiOS <7.6.1 - Info Disclosure
Feb 10, 2026
CVSS 5.9
EPSS 0.00
CVE-2025-64157 MEDIUM
FortiOS 7.0-7.6.4 - Authenticated Use of Externally-Controlled Format String via Configuration
Feb 10, 2026
CVSS 6.7
EPSS 0.00
CVE-2025-62676 HIGH
FortiClientWindows 7.0-7.4.4 - Arbitrary File Write via Crafted Named Pipe Messages
Feb 10, 2026
CVSS 7.1
EPSS 0.00
CVE-2025-62439 MEDIUM
Fortinet FortiOS <7.6.4 - Info Disclosure
Feb 10, 2026
CVSS 4.2
EPSS 0.00
CVE-2025-55018 MEDIUM
Fortinet FortiOS 7.6.0, 7.4.0-7.4.9, 7.2.0-7.2.12, 7.0.0-7.0.18, 6.4.3-6.4.15 - HTTP Request Smuggling
Feb 10, 2026
CVSS 5.8
EPSS 0.00
CVE-2025-52436 HIGH
FortiSandbox 4.0.0-4.4.7, 5.0.0-5.0.1 - Unauthenticated Cross-Site Scripting
Feb 10, 2026
CVSS 8.8
EPSS 0.00
CVE-2025-67685 LOW
FortiSandbox 4.0.0-4.4.0, 5.0.0-5.0.4 - Authenticated Server-Side Request Forgery via Crafted HTTP Requests
Jan 13, 2026
CVSS 3.8
EPSS 0.00
CVE-2025-64155 CRITICAL
FortiSIEM 6.7.0-6.7.10, 7.0.0-7.0.4, 7.1.0-7.1.8, 7.3.0-7.3.4, 7.4.0 - OS Command Injection via TCP Requests
Jan 13, 2026
CVSS 9.8
EPSS 0.00
CVE-2025-59922 HIGH
Fortinet FortiClientEMS 7.0.0-7.2.10, 7.4.0-7.4.4 - Authenticated SQL Injection via HTTP Requests
Jan 13, 2026
CVSS 7.2
EPSS 0.00
CVE-2025-58693 MEDIUM
Fortinet FortiVoice <7.2.2 - Path Traversal
Jan 13, 2026
CVSS 6.5
EPSS 0.00