CVEs (92)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Fortinet 3Fortianalyzer Fortianalyzer Big DataFortimanagerJun 17, 2026 Nov 12, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData 7.4.0 and...Show more |
1Fortinet 3Fortianalyzer Fortianalyzer Big DataFortimanagerJun 17, 2026 Nov 12, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 t...Show more |
1Fortinet 3Fortianalyzer Fortianalyzer Big DataFortimanagerJun 17, 2026 Nov 12, 2024 N/A· v4 4.1 MEDIUM· v3 N/A· v2 An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with admini...Show more |
1Fortinet 2Fortianalyzer Fortianalyzer CloudJun 17, 2026 Oct 8, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 A use of externally-controlled format string in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.2 through 7.2.5 allows attacker to escalate its privileges via specially crafted requests. |
1Fortinet 3Fortianalyzer Fortianalyzer Big DataFortimanagerJun 17, 2026 Sep 10, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker with low privileges...Show more |
A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versio...Show more |
1Fortinet 4Fortianalyzer Fortianalyzer Big DataFortimanager+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments. |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Feb 15, 2024 N/A· v4 5.0 MEDIUM· v3 N/A· v2 An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiManager version 7.4.0 through 7.4.1 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.1 and before 7.2.5 and...Show more |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Nov 14, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 A use of hard-coded credentials vulnerability in Fortinet FortiAnalyzer and FortiManager 7.0.0 - 7.0.8, 7.2.0 - 7.2.3 and 7.4.0 allows an attacker to access Fortinet private testing data via the use of static credentials...Show more |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Oct 20, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A server-side request forgery vulnerability [CWE-918] in Fortinet FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 and FortiManager version 7.4.0, version 7.2.0 through 7.2.3 and before 7.0.8 all...Show more |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Oct 10, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An authorization bypass through user-controlled key [CWE-639] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 allows a remote attacker with low privi...Show more |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Oct 10, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 An improper neutralization of special elements used in an os command ('OS Command Injection') vulnerability [CWE-78] in FortiManager & FortiAnalyzer version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.8...Show more |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Oct 10, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager version 7.4.0 and before 7.2.3 and FortiAnalyzer version 7.4.0 and before 7.2.3 may allow a remote attacker with low priv...Show more |
A insufficient verification of data authenticity vulnerability [CWE-345] in FortiAnalyzer version 7.4.0 and below 7.2.3 allows a remote unauthenticated attacker to send messages to the syslog server of FortiAnalyzer via...Show more |
An improper neutralization of special elements used in an os command ('os command injection') in FortiManager 7.4.0 and 7.2.0 through 7.2.3 may allow attacker to execute unauthorized code or commands via FortiManager cli...Show more |
1Fortinet 3Fortiadc FortianalyzerFortimanagerJun 17, 2026 Oct 10, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An improper neutralization of special elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78 ] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0...Show more |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Sep 13, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 An improper privilege management vulnerability [CWE-269] in FortiManager 7.2.0 through 7.2.2, 7.0.0 through 7.0.7, 6.4.0 through 6.4.11, 6.2 all versions, 6.0 all versions and FortiAnalyzer 7.2.0 through 7.2.2, 7.0.0 thr...Show more |
1Fortinet 4Fortianalyzer FortimanagerFortios+1 moreJun 17, 2026 Sep 1, 2023 N/A· v4 4.2 MEDIUM· v3 N/A· v2 An improper certificate validation vulnerability [CWE-295] in FortiManager 7.0.1 and below, 6.4.6 and below; FortiAnalyzer 7.0.2 and below, 6.4.7 and below; FortiOS 6.2.x and 6.0.x; FortiSandbox 4.0.x, 3.2.x and 3.1.x ma...Show more |
1Fortinet 4Fortianalyzer FortimanagerFortios+1 moreJun 17, 2026 Jul 18, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6.11 and b...Show more |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Jul 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-23] in FortiAnalyzer and FortiManager management interface 7.2.0 through 7.2.1, 7.0.0 through 7.0.5, 6.4 all versions...Show more |