CVEs (112)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via crafted HTTP or HTTP...Show more |
1Fortinet 3Fortianalyzer FortimanagerFortiportalJun 17, 2026 Dec 19, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.2.10 and be...Show more |
1Fortinet 2Fortimanager Fortimanager CloudJun 17, 2026 Dec 18, 2024 N/A· v4 7.2 HIGH· v3 N/A· v2 An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiManager version 7.6.0, version 7.4.4 and below, version 7.2.7 and below, version 7.0.12 and bel...Show more |
1Fortinet 3Fortianalyzer Fortianalyzer Big DataFortimanagerJun 17, 2026 Nov 12, 2024 N/A· v4 2.3 LOW· v3 N/A· v2 An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiAnalyzer versions below 7.4.2, Fortinet FortiManager versions below 7.4.2 and Fortinet FortiAnalyz...Show more |
1Fortinet 3Fortianalyzer FortimanagerFortimanager CloudJun 17, 2026 Nov 12, 2024 N/A· v4 7.3 HIGH· v3 N/A· v2 A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 th...Show more |
1Fortinet 3Fortianalyzer Fortianalyzer Big DataFortimanagerJun 17, 2026 Nov 12, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer v...Show more |
1Fortinet 3Fortianalyzer Fortianalyzer Big DataFortimanagerJun 17, 2026 Nov 12, 2024 N/A· v4 4.9 MEDIUM· v3 N/A· v2 An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and...Show more |
1Fortinet 3Fortianalyzer Fortianalyzer Big DataFortimanagerJun 17, 2026 Nov 12, 2024 N/A· v4 6.0 MEDIUM· v3 N/A· v2 Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData versio...Show more |
1Fortinet 3Fortianalyzer Fortianalyzer Big DataFortimanagerJun 17, 2026 Nov 12, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData 7.4.0 and...Show more |
1Fortinet 6Fortimanager FortiosFortipam+3 moreJun 17, 2026 Nov 12, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 thr...Show more |
1Fortinet 3Fortianalyzer Fortianalyzer Big DataFortimanagerJun 17, 2026 Nov 12, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 t...Show more |
1Fortinet 3Fortianalyzer Fortianalyzer Big DataFortimanagerJun 17, 2026 Nov 12, 2024 N/A· v4 4.1 MEDIUM· v3 N/A· v2 An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with admini...Show more |
1Fortinet 2Fortimanager Fortimanager CloudJun 17, 2026 Oct 23, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager...Show more |
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiManager 7.4.2 and below, 7.2.5 and below, 7.0.12 and below allows a remote authenticated attacker assigned to an Administrativ...Show more |
1Fortinet 3Fortianalyzer Fortianalyzer Big DataFortimanagerJun 17, 2026 Sep 10, 2024 N/A· v4 6.5 MEDIUM· v3 N/A· v2 An authorization bypass through user-controlled key [CWE-639] vulnerability in FortiAnalyzer version 7.4.1 and before 7.2.5 and FortiManager version 7.4.1 and before 7.2.5 may allow a remote attacker with low privileges...Show more |
A unverified password change in Fortinet FortiManager versions 7.0.0 through 7.0.10, versions 7.2.0 through 7.2.4, and versions 7.4.0 through 7.4.1, as well as Fortinet FortiAnalyzer versions 7.0.0 through 7.0.10, versio...Show more |
A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below, and 7.0.10 and below allows attacker to execute unauthorized code or...Show more |
1Fortinet 4Fortianalyzer Fortianalyzer Big DataFortimanager+1 moreJun 17, 2026 Mar 12, 2024 N/A· v4 6.7 MEDIUM· v3 N/A· v2 A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute unauthorized code or commands via specially crafted command arguments. |
A improper access control in Fortinet FortiManager version 7.4.0, version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.10, version 6.4.0 through 6.4.13, 6.2 all versions allows attacker to execute unauthorized code or...Show more |
A relative path traversal in Fortinet FortiManager version 7.4.0 and 7.2.0 through 7.2.3 and 7.0.0 through 7.0.8 and 6.4.0 through 6.4.12 and 6.2.0 through 6.2.11 allows attacker to execute unauthorized code or commands...Show more |