Vulnerabilities
Vulnerabilities affecting firewalls and security appliances, with vendor fix data, CISA KEV status and EPSS.
Intelligence updated 30 Sept 2026 at 12:52 UTC
106 vulnerabilities
- CVE-2025-5374412 Aug 2025
An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.…
High7.2CVSS 3.1, High0.63% Fortinet FortiWeb SQL Injection Vulnerability
Critical9.8CVSS 3.1, Critical100%- CVE-2024-529658 Jul 2025
A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7…
High7.2CVSS 3.1, High0.28% - CVE-2025-2225410 Jun 2025
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.…
High7.2CVSS 3.1, High0.85% - CVE-2025-2225228 May 2025
A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwit…
High7.2CVSS 3.1, High0.94% Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
Critical9.8CVSS 3.1, Critical30%- CVE-2024-505658 Apr 2025
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet For…
High7.5CVSS 3.1, High0.39% - CVE-2024-260138 Apr 2025
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet For…
High7.5CVSS 3.1, High0.50% - CVE-2023-379308 Apr 2025
Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vul…
High8.8CVSS 3.1, High0.63% - CVE-2023-2561024 Mar 2025
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS ve…
Critical9.8CVSS 3.1, Critical18% - CVE-2020-929517 Mar 2025
FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and be…
High7.5CVSS 3.1, High0.32% - CVE-2024-4666214 Mar 2025
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManage…
High8.8CVSS 3.1, High2% - CVE-2024-4532411 Mar 2025
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, …
High7.2CVSS 3.1, High0.72% Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
High8.1CVSS 3.1, High7%- CVE-2024-4058411 Feb 2025
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability […
High7.2CVSS 3.1, High2% - CVE-2024-3350411 Feb 2025
A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0…
High7.7CVSS 3.1, High0.30% - CVE-2024-3527911 Feb 2025
A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and ver…
High8.1CVSS 3.1, High1% - CVE-2024-4059111 Feb 2025
An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.…
High7.2CVSS 3.1, High0.62% - CVE-2024-5056316 Jan 2025
A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 throu…
Critical9.8CVSS 3.1, Critical0.58% - CVE-2024-4533116 Jan 2025
A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7…
High7.8CVSS 3.1, High0.21% - CVE-2024-4757114 Jan 2025
An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows a…
Critical9.8CVSS 3.1, Critical0.91% - CVE-2024-3527714 Jan 2025
A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiMan…
High7.5CVSS 3.1, High0.71% - CVE-2024-3350214 Jan 2025
An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, F…
High7.2CVSS 3.1, High1% - CVE-2024-4888614 Jan 2025
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.…
Critical9.8CVSS 3.1, Critical0.48% - CVE-2024-3350314 Jan 2025
A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManage…
High7.8CVSS 3.1, High0.22% - CVE-2024-4888414 Jan 2025
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet Fo…
Critical9.1CVSS 3.1, Critical15% - CVE-2024-4666814 Jan 2025
An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 thr…
High7.5CVSS 3.1, High1.00% - CVE-2024-3527314 Jan 2025
A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 throu…
High8.8CVSS 3.1, High0.66% - CVE-2024-3527614 Jan 2025
A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.…
Critical9.8CVSS 3.1, Critical0.42% - CVE-2024-3527514 Jan 2025
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnaly…
High8.8CVSS 3.1, High0.82%