fortinet

1,122 tracked vulnerabilities.

CVE-2019-13399 MEDIUM
Fortinet FCM-MB40 v1.2.0.0 - Use of Hard-coded SSL/TLS Key
Jul 08, 2019
CVSS 5.9
EPSS 0.00
CVE-2019-13398 HIGH
Fortinet FCM-MB40 1.2.0.0 - OS Command Injection via CGI Script Parameters
Jul 08, 2019
CVSS 7.2
EPSS 0.03
CVE-2019-5588 MEDIUM
FortiOS 6.0.0-6.0.4 - Reflected Cross-Site Scripting via SSL VPN Error Parameter
Jun 04, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-5587 MEDIUM
Fortinet FortiOS < 6.0.5 - Unauthenticated Malicious Image Implantation via Root File System Integrity Bypass
Jun 04, 2019
CVSS 6.5
EPSS 0.00
CVE-2019-5586 MEDIUM
FortiOS 5.2.0-5.6.10, 6.0.0-6.0.4 - Reflected Cross-Site Scripting via SSL VPN Error Process Param Parameter
Jun 04, 2019
CVSS 6.1
EPSS 0.00
CVE-2019-5589 HIGH
FortiClient < 6.0.6 - Unauthenticated Remote Code Execution via DLL Hijacking
May 28, 2019
CVSS 7.8
EPSS 0.01
CVE-2018-13371 HIGH
FortiOS < 5.4.10 - Authenticated Routing Settings Manipulation via ZebOS Component
Apr 02, 2020
CVSS 8.8
EPSS 0.01
CVE-2018-9195 MEDIUM
FortiClient < 6.0.6 and < 6.2.1 - Use of Hard-coded Cryptographic Key in FortiGuard Services Communication
Nov 21, 2019
CVSS 5.9
EPSS 0.00
CVE-2018-13367 MEDIUM
FortiOS < 6.2.0 - Unauthenticated Sensitive Information Exposure via Admin WebUI JavaScript File
Aug 23, 2019
CVSS 5.3
EPSS 0.00
CVE-2018-13384 MEDIUM
FortiOS < 6.0.5 - Host Header Redirection via SSL VPN Web Portal
Jun 04, 2019
CVSS 6.1
EPSS 0.00
CVE-2018-13382 CRITICAL KEV
FortiProxy < 1.2.9 and FortiOS 5.4.1-5.4.10 - Unauthenticated Password Modification via SSL VPN Web Portal
Jun 04, 2019
CVSS 9.1
EPSS 0.87
CVE-2018-13381 MEDIUM
FortiProxy <= 1.2.8 and FortiOS < 5.2.14 - Unauthenticated Denial of Service via SSL VPN Web Portal
Jun 04, 2019
CVSS 5.3
EPSS 0.01
CVE-2018-13380 MEDIUM NUCLEI
FortiOS < 6.0.5, 5.6.8, 5.4.13 & FortiProxy < 2.0.1, 1.2.9 XSS via SSL VPN Error Handling
Jun 04, 2019
CVSS 4.7
EPSS 0.23
CVE-2018-13379 CRITICAL KEVNUCLEI
FortiProxy < 1.2.9 and FortiOS 5.4.6-5.4.12 - Unauthenticated Path Traversal via SSL VPN Web Portal
Jun 04, 2019
CVSS 9.1
EPSS 0.94
CVE-2018-9193 HIGH
FortiClient for Windows <6.0.5 - Privilege Escalation
May 30, 2019
CVSS 7.8
EPSS 0.00
CVE-2018-9191 HIGH
FortiClient < 6.0.4 - Local Privilege Escalation via Update Named Pipe
May 30, 2019
CVSS 7.8
EPSS 0.00
CVE-2018-13368 HIGH
Fortinet FortiClient < 6.0.4 - Local Privilege Escalation via Command Injection
May 30, 2019
CVSS 7.8
EPSS 0.00
CVE-2018-13365 MEDIUM
Fortinet FortiOS < 5.6.5 - Information Exposure via Application Control Block Page
May 29, 2019
CVSS 5.3
EPSS 0.00
CVE-2018-13383 MEDIUM KEV
FortiProxy < 1.2.9 and FortiOS 5.2.0-5.2.14 - Heap Buffer Overflow in SSL VPN Web Portal
May 29, 2019
CVSS 4.3
EPSS 0.02
CVE-2018-13375 MEDIUM
Fortinet FortiAnalyzer and FortiManager < 5.6.0 - Stored Cross-Site Scripting via DHCP HOSTNAME Parameter
May 28, 2019
CVSS 6.1
EPSS 0.00
CVE-2018-1360 HIGH
Fortinet FortiManager 5.2.0-5.2.7, 5.4.0-5.4.1 - Cleartext Transmission of Sensitive Information via REST API
Apr 25, 2019
CVSS 8.1
EPSS 0.00
CVE-2018-13378 HIGH
Fortinet FortiSIEM < 5.2.0 - Unauthenticated LDAP Password Exposure via HTML Source Code
Apr 17, 2019
CVSS 7.2
EPSS 0.00
CVE-2018-1356 MEDIUM
Fortinet FortiSandbox < 3.0.0 - Reflected Cross-Site Scripting via back_url Parameter
Apr 09, 2019
CVSS 6.1
EPSS 0.00
CVE-2018-13366 MEDIUM
Fortinet FortiOS <= 5.6.7 - Information Disclosure via PPTP Hostname Field
Apr 09, 2019
CVSS 5.3
EPSS 0.00
CVE-2018-9190 MEDIUM
FortiClientWindows < 6.0.2 - Denial of Service via NDIS Miniport Driver
Feb 08, 2019
CVSS 5.5
EPSS 0.00