← Back

Fortinet

fortinet

1,134 CVEs • 247 products

Products (247)

Click to collapse
Toggle
Fortios
fortios
Fortiproxy
fortiproxy
Fortiweb
fortiweb
Fortimanager
fortimanager
Fortianalyzer
fortianalyzer
Forticlient
forticlient
Fortisandbox
fortisandbox
Fortimail
fortimail
Fortiportal
fortiportal
Fortiadc
fortiadc
Fortisiem
fortisiem
Fortisoar
fortisoar
Fortinac
fortinac
Fortipam
fortipam
Fortivoice
fortivoice
Fortiwlm
fortiwlm
Fortiwan
fortiwan
Fortitester
fortitester
Fortiswitch
fortiswitch
Fortiwlc
fortiwlc
Fortinac F
fortinac-f
Fortirecorder
fortirecorder
Fortideceptor
fortideceptor
Fortindr
fortindr
Fortiisolator
fortiisolator
Fortisase
fortisase
Fortiap W2
fortiap-w2
Fortiap
fortiap
Fortiap U
fortiap-u
Fortiedr
fortiedr
Fortiddos F
fortiddos-f
Fortiap S
fortiap-s
Fortiddos
fortiddos
Fortiaiops
fortiaiops
Fortisra
fortisra
Fortigate
fortigate
Fortigate 20c
fortigate-20c
Fortigate 40c
fortigate-40c
Fortigate 50b
fortigate-50b
Fortigate 60c
fortigate-60c
Fortigate 80c
fortigate-80c
Fortiadc 200d
fortiadc-200d
Fortiadc 300e
fortiadc-300e
Fortiadc 400e
fortiadc-400e
Fortiadc 600e
fortiadc-600e
Fortipresence
fortipresence

CVEs (1,134)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fortinet
2Fortianalyzer
Fortitester
Jun 17, 2026
Sep 24, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An improper neutralization of input vulnerability in FortiTester before 3.9.0 may allow a remote authenticated attacker to inject script related HTML tags via IPv4/IPv6 address fields.
1Fortinet
2Fortianalyzer
Fortimanager
Jun 17, 2026
Sep 24, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3and FortiAnalyzer 6.2.0, 6.2.1, 6.2.2, and 6.2.3 may allow an attacker to execute a cross site scripting...Show more
An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3and FortiAnalyzer 6.2.0, 6.2.1, 6.2.2, and 6.2.3 may allow an attacker to execute a cross site scripting (XSS) via the Identify Provider name field.Show less
1Fortinet
1Fortios
Jun 17, 2026
Sep 24, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker to Fortinet owned IP addresses to go unnoticed.
1Fortinet
2Fortianalyzer
Fortitester
Jun 17, 2026
Sep 24, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Connectors.
1Fortinet
1Fortinac
Jun 17, 2026
Sep 24, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
An improper neutralization of input vulnerability in FortiNAC before 8.7.2 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the UserID of Admin Users.
1Fortinet
1Fortios
Jun 17, 2026
Aug 14, 2020
N/A· v4
6.5 MEDIUM· v3
3.3 LOW· v2
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server.
1Fortinet
1Fortios
Jun 17, 2026
Jul 24, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication...Show more
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication (FortiToken) if they changed the case of their username.Show less
1Fortinet
1Fortiwlc
Jun 17, 2026
Jun 22, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the ESS profile or the Radius Profile.
1Fortinet
1Fortideceptor
Jun 17, 2026
Jun 22, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that sess...Show more
An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that session ID via other, hypothetical attacks.Show less
1Fortinet
2Fortianalyzer
Fortimanager
Jun 17, 2026
Jun 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI bac...Show more
Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI backup file to decrypt the sensitive data, via knowledge of the hard-coded key.Show less
1Fortinet
1Fortios
Jun 17, 2026
Jun 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN use...Show more
A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN user's credentials should that attacker be able to read the session file stored on the targeted device's system.Show less
1Fortinet
1Fortisiem Windows Agent
Jun 17, 2026
Jun 4, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path.
1Fortinet
1Fortianalyzer
Jun 17, 2026
Jun 4, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Description Area.
1Fortinet
1Forticlient
Jun 17, 2026
Jun 4, 2020
N/A· v4
5.5 MEDIUM· v3
5.0 MEDIUM· v2
Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configur...Show more
Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configuration backup file to decrypt the sensitive data via knowledge of the hard-coded key.Show less
1Fortinet
1Forticlient
Jun 17, 2026
Jun 1, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain elevated privileges via exhausting the pool of temporary file names combined with a symbolic link attack.
1Fortinet
3Fortiap S
Fortiap UFortiap W2
Jun 17, 2026
Jun 1, 2020
N/A· v4
6.5 MEDIUM· v3
8.5 HIGH· v2
An improper input validation in FortiAP-S/W2 6.2.0 to 6.2.2, 6.0.5 and below, FortiAP-U 6.0.1 and below CLI admin console may allow unauthorized administrators to overwrite system files via specially crafted tcpdump comm...Show more
An improper input validation in FortiAP-S/W2 6.2.0 to 6.2.2, 6.0.5 and below, FortiAP-U 6.0.1 and below CLI admin console may allow unauthorized administrators to overwrite system files via specially crafted tcpdump commands in the CLI.Show less
1Fortinet
2Fortimail
Fortivoice
Jun 17, 2026
Apr 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by req...Show more
An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by requesting a password change via the user interface.Show less
1Fortinet
1Fortiadc Firmware
Jun 17, 2026
Apr 7, 2020
N/A· v4
6.5 MEDIUM· v3
6.8 MEDIUM· v2
An improper authorization vulnerability in FortiADC may allow a remote authenticated user with low privileges to perform certain actions such as rebooting the system.
1Fortinet
1Fortiadc Firmware
Jun 17, 2026
Apr 7, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform a cross site scripting attack (XSS) via the name parameter.
1Fortinet
5Fortianalyzer
Fortiap SFortiap W2+2 more
Jun 17, 2026
Apr 7, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause ad...Show more
An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause admin webUI denial of service (DoS) via handling special crafted HTTP requests/responses in pieces slowly, as demonstrated by Slow HTTP DoS Attacks.Show less