← Back

Fortinet

fortinet

1,134 CVEs • 247 products

Products (247)

Click to collapse
Toggle
Fortios
fortios
Fortiproxy
fortiproxy
Fortiweb
fortiweb
Fortimanager
fortimanager
Fortianalyzer
fortianalyzer
Forticlient
forticlient
Fortisandbox
fortisandbox
Fortimail
fortimail
Fortiportal
fortiportal
Fortiadc
fortiadc
Fortisiem
fortisiem
Fortisoar
fortisoar
Fortinac
fortinac
Fortipam
fortipam
Fortivoice
fortivoice
Fortiwlm
fortiwlm
Fortiwan
fortiwan
Fortitester
fortitester
Fortiswitch
fortiswitch
Fortiwlc
fortiwlc
Fortinac F
fortinac-f
Fortirecorder
fortirecorder
Fortideceptor
fortideceptor
Fortindr
fortindr
Fortiisolator
fortiisolator
Fortisase
fortisase
Fortiap W2
fortiap-w2
Fortiap
fortiap
Fortiap U
fortiap-u
Fortiedr
fortiedr
Fortiddos F
fortiddos-f
Fortiap S
fortiap-s
Fortiddos
fortiddos
Fortiaiops
fortiaiops
Fortisra
fortisra
Fortigate
fortigate
Fortigate 20c
fortigate-20c
Fortigate 40c
fortigate-40c
Fortigate 50b
fortigate-50b
Fortigate 60c
fortigate-60c
Fortigate 80c
fortigate-80c
Fortiadc 200d
fortiadc-200d
Fortiadc 300e
fortiadc-300e
Fortiadc 400e
fortiadc-400e
Fortiadc 600e
fortiadc-600e
Fortipresence
fortipresence

CVEs (1,134)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fortinet
1Fortisandbox
Jun 17, 2026
Mar 24, 2025
N/A· v4
8.8 HIGH· v3
N/A· v2
A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or...Show more
A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via specifically crafted HTTP requests.Show less
1Fortinet
1Fortimail
Jun 17, 2026
Mar 24, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthen...Show more
A use of a cryptographically weak pseudo-random number generator vulnerability in the authenticator of the Identity Based Encryption service of FortiMail 6.4.0 through 6.4.4, and 6.2.0 through 6.2.7 may allow an unauthenticated attacker to infer parts of users authentication tokens and reset their credentials.Show less
1Fortinet
1Fortios
Jun 17, 2026
Mar 21, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker to either redirect users to malicious websites...Show more
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiOS 6.4.1 and below, 6.2.9 and below may allow a remote unauthenticated attacker to either redirect users to malicious websites via a crafted "Host" header or to execute JavaScript code in the victim's browser context. This happens when the FortiGate has web filtering and category override enabled/configured.Show less
1Fortinet
1Fortisoar
Jun 17, 2026
Mar 18, 2025
N/A· v4
8.4 HIGH· v3
N/A· v2
An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an a...Show more
An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated attacker to execute arbitrary code on the host via a playbook code snippet.Show less
1Fortinet
1Fortimail
Jun 17, 2026
Mar 18, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP r...Show more
An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request.Show less
1Fortinet
1Fortisandbox
Jun 17, 2026
Mar 17, 2025
N/A· v4
4.4 MEDIUM· v3
N/A· v2
A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and below, version 3.1.5 and below, version 3.0.7 to...Show more
A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and below, version 3.1.5 and below, version 3.0.7 to 3.0.5 may allow a privileged attacker with super-admin profile and CLI access to read sensitive data via CLI.Show less
1Fortinet
1Fortiwlc
Jun 17, 2026
Mar 17, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to 8.2.4, version 8.1.3 may allow an unauthenticated...Show more
An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to 8.2.4, version 8.1.3 may allow an unauthenticated and remote attacker to access certain areas of the web management CGI functionality by just specifying the correct URL. The vulnerability applies only to limited CGI resources and might allow the unauthorized party to access configuration details.Show less
1Fortinet
1Fortiwlc
Jun 17, 2026
Mar 17, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web interface may allow both authenticated remote attackers and no...Show more
An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web interface may allow both authenticated remote attackers and non-authenticated attackers in the same network as the appliance to perform a stored cross site scripting attack (XSS) via injecting malicious payloads in different locations.Show less
1Fortinet
1Fortiwlc
Jun 17, 2026
Mar 17, 2025
N/A· v4
6.7 MEDIUM· v3
N/A· v2
A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may allow a local, authenticated attacker to connect to the managed...Show more
A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may allow a local, authenticated attacker to connect to the managed Access Point (Meru AP and FortiAP-U) as root using the default hard-coded username and password.Show less
1Fortinet
1Antivirus Engine
Jun 17, 2026
Mar 17, 2025
N/A· v4
7.5 HIGH· v3
N/A· v2
FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version 6.00137 and below may not immediately detect certain types of...Show more
FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and below and FortiClient 6.2 running AV engine version 6.00137 and below may not immediately detect certain types of malformed or non-standard RAR archives, potentially containing malicious files. Based on the samples provided, FortiClient will detect the malicious files upon trying extraction by real-time scanning and FortiGate will detect the malicious archive if Virus Outbreak Prevention is enabled.Show less
1Fortinet
1Fortios
Jun 17, 2026
Mar 17, 2025
N/A· v4
5.0 MEDIUM· v3
N/A· v2
An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to read the SSL VPN events log entries of user...Show more
An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to read the SSL VPN events log entries of users in other VDOMs by executing "get vpn ssl monitor" from the CLI. The sensitive data includes usernames, user groups, and IP address.Show less
1Fortinet
1Fortios
Jun 17, 2026
Mar 17, 2025
N/A· v4
6.1 MEDIUM· v3
N/A· v2
An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP monitor page may allow an unauthenticated attac...Show more
An Improper Neutralization of Input vulnerability affecting FortiGate version 6.2.0 through 6.2.1, 6.0.0 through 6.0.6 in the hostname parameter of a DHCP packet under DHCP monitor page may allow an unauthenticated attacker in the same network as the FortiGate to perform a Stored Cross Site Scripting attack (XSS) by sending a crafted DHCP packet.Show less
1Fortinet
1Fortisiem
Jun 17, 2026
Mar 17, 2025
N/A· v4
8.1 HIGH· v3
N/A· v2
A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted user "tunneluser" by leveraging knowledg...Show more
A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted user "tunneluser" by leveraging knowledge of the private key from another installation or a firmware image.Show less
1Fortinet
2Fortios
Fortiproxy
Jun 17, 2026
Mar 17, 2025
N/A· v4
5.4 MEDIUM· v3
N/A· v2
An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, version 6.0.8 and below, version 5.6.12 may a...Show more
An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, version 6.0.8 and below, version 5.6.12 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS).Show less
1Fortinet
1Fortiweb
Jun 17, 2026
Mar 14, 2025
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or command...Show more
An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests.Show less
1Fortinet
2Fortianalyzer
Fortimanager
Jun 17, 2026
Mar 14, 2025
N/A· v4
6.5 MEDIUM· v3
N/A· v2
An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and below, version 6.2.11 and below and FortiA...Show more
An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and below, version 6.2.11 and below and FortiAnalyzer version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and below, version 6.2.11 and below eventlog may allow any low privileged user with access to event log section to retrieve certificate private key and encrypted password logged as system log.Show less
1Fortinet
1Fortinac F
Jun 17, 2026
Mar 14, 2025
N/A· v4
4.8 MEDIUM· v3
N/A· v2
An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the HTTPS communication channel be...Show more
An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the HTTPS communication channel between the FortiOS device, an inventory, and FortiNAC-F.Show less
1Fortinet
1Forticlient
Jun 17, 2026
Mar 14, 2025
N/A· v4
7.8 HIGH· v3
N/A· v2
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing...Show more
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process.Show less
1Fortinet
1Fortinac
Jun 17, 2026
Mar 14, 2025
N/A· v4
5.3 MEDIUM· v3
N/A· v2
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted...Show more
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted request in inter-server communication port.Show less
1Fortinet
1Fortiweb
Jun 17, 2026
Mar 14, 2025
N/A· v4
7.2 HIGH· v3
N/A· v2
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, 6.2.7 and below may allow a privilege...Show more
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, 6.2.7 and below may allow a privileged attacker to execute SQL commands over the log database via specifically crafted strings parameters.Show less