Записи Fortinet
1 142 опубликованных записей вендора fortinet.
Профиль для исследователя
- Попали в KEV
- 30 · 2,6 %
- С эксплойтом
- 33 · 2,9 %
- Pre-auth RCE
- 45
- С записью об исправлении
- 0,8 %
- Медиана: публикация → KEV
- 10 дн.
Повторяющиеся классы
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')150
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')112
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor55
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')45
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')38
- CWE-264 Permissions, Privileges, and Access Controls34
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
1 142 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2018-13379Готовый эксплойт | An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4fortinet · fortiproxy · CWE-22 | Критическая9,8 | KEV | 100,0 % | 4 июн. 2019 г. |
99Срочно | CVE-2022-40684Готовый эксплойт | An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.fortinet · fortiproxy · CWE-287 | Критическая9,8 | KEV | 100,0 % | 18 окт. 2022 г. |
99Срочно | CVE-2025-25257Готовый эксплойт | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet Forfortinet · fortiweb · CWE-89 | Критическая9,8 | KEV | 99,8 % | 17 июл. 2025 г. |
99Срочно | CVE-2022-42475Готовый эксплойт | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.fortinet · fortios · CWE-197 | Критическая9,8 | KEV | 99,5 % | 2 янв. 2023 г. |
99Срочно | CVE-2023-48788Готовый эксплойт | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.fortinet · forticlient enterprise management server · CWE-89 | Критическая9,8 | KEV | 98,4 % | 12 мар. 2024 г. |
97Срочно | CVE-2024-47575Готовый эксплойт | A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, Fofortinet · fortimanager · CWE-306 | Критическая9,8 | KEV | 94,8 % | 23 окт. 2024 г. |
97Срочно | CVE-2024-55591Готовый эксплойт | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and Fortifortinet · fortiproxy · CWE-288 | Критическая9,8 | KEV | 94,1 % | 14 янв. 2025 г. |
97Срочно | CVE-2026-21643Готовый эксплойт | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may afortinet · forticlientems · CWE-89 | Критическая9,8 | KEV | 93,7 % | 6 февр. 2026 г. |
97Срочно | CVE-2025-64446Готовый эксплойт | A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9fortinet · fortiweb · CWE-23 | Критическая9,8 | KEV | 91,8 % | 14 нояб. 2025 г. |
95Срочно | CVE-2026-24858Готовый эксплойт | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.fortinet · fortianalyzer · CWE-288 | Критическая9,8 | KEV | 85,8 % | 27 янв. 2026 г. |
95Срочно | CVE-2023-27997Готовый эксплойт | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below,fortinet · fortiproxy · CWE-122 | Критическая9,8 | KEV | 85,7 % | 13 июн. 2023 г. |
94Срочно | CVE-2024-21762Готовый эксплойт | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2fortinet · fortiproxy · CWE-787 | Критическая9,8 | KEV | 83,4 % | 9 февр. 2024 г. |
92Срочно | CVE-2026-25089Готовый эксплойт | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 thfortinet · fortisandbox · CWE-78 | Критическая9,8 | KEV | 76,1 % | 9 июн. 2026 г. |
89Срочно | CVE-2025-59718Готовый эксплойт | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, Fortifortinet · fortiproxy · CWE-347 | Критическая9,8 | KEV | 68,3 % | 9 дек. 2025 г. |
88Срочно | CVE-2024-23113Готовый эксплойт | A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, Fofortinet · fortiproxy · CWE-134 | Критическая9,8 | KEV | 61,7 % | 15 февр. 2024 г. |
85Срочно | CVE-2018-13382Готовый эксплойт | An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 tfortinet · fortiproxy · CWE-863 | Высокая7,5 | KEV | 81,7 % | 4 июн. 2019 г. |
84Срочно | CVE-2020-12812Готовый эксплойт | An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to logfortinet · fortios · CWE-178 | Критическая9,8 | KEV | 49,3 % | 24 июл. 2020 г. |
83Срочно | CVE-2026-39808Готовый эксплойт | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 thfortinet · fortisandbox · CWE-78 | Критическая9,8 | KEV | 47,4 % | 14 апр. 2026 г. |
78На этой неделе | CVE-2025-32756Готовый эксплойт | A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all versionfortinet · fortimail · CWE-121 | Критическая9,8 | KEV | 29,8 % | 13 мая 2025 г. |
75На этой неделе | CVE-2025-58034Готовый эксплойт | An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinfortinet · fortiweb · CWE-78 | Высокая7,2 | KEV | 55,6 % | 18 нояб. 2025 г. |
72На этой неделе | CVE-2026-35616Готовый эксплойт | A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unaufortinet · forticlientems · CWE-284 | Критическая9,8 | KEV | 9,1 % | 3 апр. 2026 г. |
70На этой неделе | CVE-2025-25249Готовый эксплойт | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.1fortinet · fortios · CWE-122 | Критическая9,8 | KEV | 3,9 % | 13 янв. 2026 г. |
69На этой неделе | CVE-2022-39952Готовый эксплойт | A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11,fortinet · fortinac · CWE-73 | Критическая9,8 | — | 99,8 % | 16 февр. 2023 г. |
66На этой неделе | CVE-2018-13383Готовый эксплойт | A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProxfortinet · fortiproxy · CWE-787 | Средняя6,5 | KEV | 33,6 % | 29 мая 2019 г. |
64На этой неделе | CVE-2025-24472Готовый эксплойт | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.fortinet · fortiproxy · CWE-288 | Высокая8,1 | KEV | 7,2 % | 11 февр. 2025 г. |
- CVE-2018-1337999Срочно
An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %fortinet · fortiproxy4 июн. 2019 г.
- CVE-2022-4068499Срочно
An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %fortinet · fortiproxy18 окт. 2022 г.
- CVE-2025-2525799Срочно
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet For
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %fortinet · fortiweb17 июл. 2025 г.
- CVE-2022-4247599Срочно
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS SSL-VPN 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.10, 6.2.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %fortinet · fortios2 янв. 2023 г.
- CVE-2023-4878899Срочно
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %fortinet · forticlient enterprise management server12 мар. 2024 г.
- CVE-2024-4757597Срочно
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, Fo
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %fortinet · fortimanager23 окт. 2024 г.
- CVE-2024-5559197Срочно
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and Forti
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %fortinet · fortiproxy14 янв. 2025 г.
- CVE-2026-2164397Срочно
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %fortinet · forticlientems6 февр. 2026 г.
- CVE-2025-6444697Срочно
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 92 %fortinet · fortiweb14 нояб. 2025 г.
- CVE-2026-2485895Срочно
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 86 %fortinet · fortianalyzer27 янв. 2026 г.
- CVE-2023-2799795Срочно
A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0.11 and below, version 6.4.12 and below,
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 86 %fortinet · fortiproxy13 июн. 2023 г.
- CVE-2024-2176294Срочно
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 83 %fortinet · fortiproxy9 февр. 2024 г.
- CVE-2026-2508992Срочно
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 th
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 76 %fortinet · fortisandbox9 июн. 2026 г.
- CVE-2025-5971889Срочно
A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, Forti
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 68 %fortinet · fortiproxy9 дек. 2025 г.
- CVE-2024-2311388Срочно
A use of externally-controlled format string in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, Fo
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 62 %fortinet · fortiproxy15 февр. 2024 г.
- CVE-2018-1338285Срочно
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 t
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 82 %fortinet · fortiproxy4 июн. 2019 г.
- CVE-2020-1281284Срочно
An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and below may result in a user being able to log
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 49 %fortinet · fortios24 июл. 2020 г.
- CVE-2026-3980883Срочно
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 th
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 47 %fortinet · fortisandbox14 апр. 2026 г.
- CVE-2025-3275678На этой неделе
A stack-based buffer overflow vulnerability [CWE-121] vulnerability in Fortinet FortiCamera 2.1.0 through 2.1.3, FortiCamera 2.0 all version
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 30 %fortinet · fortimail13 мая 2025 г.
- CVE-2025-5803475На этой неделе
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortin
ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 56 %fortinet · fortiweb18 нояб. 2025 г.
- CVE-2026-3561672На этой неделе
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to execute unau
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 9 %fortinet · forticlientems3 апр. 2026 г.
- CVE-2025-2524970На этой неделе
A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.1
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 4 %fortinet · fortios13 янв. 2026 г.
- CVE-2022-3995269На этой неделе
A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11,
КритическаяCVSS 9,8Готовый эксплойтEPSS 100 %fortinet · fortinac16 февр. 2023 г.
- CVE-2018-1338366На этой неделе
A heap buffer overflow in Fortinet FortiOS 6.0.0 through 6.0.4, 5.6.0 through 5.6.10, 5.4.0 through 5.4.12, 5.2.14 and earlier and FortiProx
СредняяCVSS 6,5KEVГотовый эксплойтEPSS 34 %fortinet · fortiproxy29 мая 2019 г.
- CVE-2025-2447264На этой неделе
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.
ВысокаяCVSS 8,1KEVГотовый эксплойтEPSS 7 %fortinet · fortiproxy11 февр. 2025 г.