Fortinet
fortinet
1,134 CVEs • 247 products
Products (247)
Click to collapseToggle
Products (247)
Click to collapse
CVEs (1,134)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Fortinet 2Fortianalyzer FortitesterJun 17, 2026 Sep 24, 2020 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 An improper neutralization of input vulnerability in FortiTester before 3.9.0 may allow a remote authenticated attacker to inject script related HTML tags via IPv4/IPv6 address fields. |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Sep 24, 2020 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 An improper neutralization of script-related HTML tags in a web page in FortiManager 6.2.0, 6.2.1, 6.2.2, and 6.2.3and FortiAnalyzer 6.2.0, 6.2.1, 6.2.2, and 6.2.3 may allow an attacker to execute a cross site scripting...Show more |
An insufficient logging vulnerability in FortiGate before 6.4.1 may allow the traffic from an unauthenticated attacker to Fortinet owned IP addresses to go unnoticed. |
1Fortinet 2Fortianalyzer FortitesterJun 17, 2026 Sep 24, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 An improper neutralization of input vulnerability in FortiAnalyzer before 6.4.1 and 6.2.5 may allow a remote authenticated attacker to inject script related HTML tags via Name parameter of Storage Connectors. |
An improper neutralization of input vulnerability in FortiNAC before 8.7.2 may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the UserID of Admin Users. |
A Default Configuration vulnerability in FortiOS may allow an unauthenticated attacker on the same subnet to intercept sensitive information by impersonating the LDAP server. |
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log in successfully without being prompted for the second factor of authentication...Show more |
An improper neutralization of input vulnerability in FortiWLC 8.5.1 allows a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the ESS profile or the Radius Profile. |
An insufficient session expiration vulnerability in FortiDeceptor 3.0.0 and below allows an attacker to reuse the unexpired admin user session IDs to gain admin privileges, should the attacker be able to obtain that sess...Show more |
1Fortinet 2Fortianalyzer FortimanagerJun 17, 2026 Jun 16, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Use of a hard-coded cryptographic key to encrypt password data in CLI configuration in FortiManager 6.2.3 and below, FortiAnalyzer 6.2.3 and below may allow an attacker with access to the CLI configuration or the CLI bac...Show more |
A cleartext storage in a file or on disk (CWE-313) vulnerability in FortiOS SSL VPN 6.2.0 through 6.2.2, 6.0.9 and earlier and FortiProxy 2.0.0, 1.2.9 and earlier may allow an attacker to retrieve a logged-in SSL VPN use...Show more |
1Fortinet 1Fortisiem Windows Agent Jun 17, 2026 Jun 4, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An unquoted service path vulnerability in the FortiSIEM Windows Agent component may allow an attacker to gain elevated privileges via the AoWinAgt executable service path. |
An improper neutralization of input vulnerability in the Admin Profile of FortiAnalyzer may allow a remote authenticated attacker to perform a stored cross site scripting attack (XSS) via the Description Area. |
Use of a hard-coded cryptographic key to encrypt security sensitive data in local storage and configuration in FortiClient for Windows prior to 6.4.0 may allow an attacker with access to the local storage or the configur...Show more |
An Insecure Temporary File vulnerability in FortiClient for Windows 6.2.1 and below may allow a local user to gain elevated privileges via exhausting the pool of temporary file names combined with a symbolic link attack. |
1Fortinet 3Fortiap S Fortiap UFortiap W2Jun 17, 2026 Jun 1, 2020 N/A· v4 6.5 MEDIUM· v3 8.5 HIGH· v2 An improper input validation in FortiAP-S/W2 6.2.0 to 6.2.2, 6.0.5 and below, FortiAP-U 6.0.1 and below CLI admin console may allow unauthorized administrators to overwrite system files via specially crafted tcpdump comm...Show more |
1Fortinet 2Fortimail FortivoiceJun 17, 2026 Apr 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to access the system as a legitimate user by req...Show more |
An improper authorization vulnerability in FortiADC may allow a remote authenticated user with low privileges to perform certain actions such as rebooting the system. |
An improper neutralization of input vulnerability in the dashboard of FortiADC may allow an authenticated attacker to perform a cross site scripting attack (XSS) via the name parameter. |
1Fortinet 5Fortianalyzer Fortiap SFortiap W2+2 moreJun 17, 2026 Apr 7, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An Uncontrolled Resource Consumption vulnerability in Fortinet FortiSwitch below 3.6.11, 6.0.6 and 6.2.2, FortiAnalyzer below 6.2.3, FortiManager below 6.2.3 and FortiAP-S/W2 below 6.2.2 may allow an attacker to cause ad...Show more |