Fortinet / FortiAnalyzer
93 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-84391 | A use of uninitialized variable vulnerability in Fortinet FortiAnalyzer 7.6.3 through 7.6.6 may allow attacker to denial of service via <insert attack vector h… | MEDIUM | 6.5 | Sep 8, 2026 |
| CVE-2025-67604 | A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all v… | MEDIUM | 5.3 | May 12, 2026 |
| CVE-2025-68649 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.… | MEDIUM | 6.5 | Apr 14, 2026 |
| CVE-2025-61848 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnaly… | HIGH | 7.2 | Apr 14, 2026 |
| CVE-2026-22629 | An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4 all versions, Forti… | LOW | 3.7 | Mar 10, 2026 |
| CVE-2025-68482 | A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all version… | MEDIUM | 6.3 | Mar 10, 2026 |
| CVE-2025-48418 | A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.2.10, Fort… | HIGH | 7.2 | Mar 10, 2026 |
| CVE-2025-49784 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnaly… | HIGH | 7.2 | Mar 10, 2026 |
| CVE-2026-22572 | An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, For… | HIGH | 7.2 | Mar 10, 2026 |
| CVE-2025-68648 | A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2… | HIGH | 7.2 | Mar 10, 2026 |
| CVE-2026-24858 KEV | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer… | CRITICAL | 9.8 | Jan 27, 2026 |
| CVE-2024-40593 | A key management errors vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.2, FortiAnalyzer 7.2.0 through 7.2.5, FortiAnalyzer 7.0 all versions, FortiAn… | MEDIUM | 5.9 | Dec 11, 2025 |
| CVE-2025-53845 | An improper authentication vulnerability [CWE-287] in Fortinet FortiAnalyzer version 7.6.0 through 7.6.3 and before 7.4.6 allows an unauthenticated attacker to… | MEDIUM | 6.5 | Oct 14, 2025 |
| CVE-2025-54973 | A concurrent execution using shared resource with improper synchronization ('Race Condition') vulnerability [CWE-362] in Fortinet FortiAnalyzer version 7.6.0 t… | MEDIUM | 5.3 | Oct 14, 2025 |
| CVE-2024-50571 | A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9,… | HIGH | 7.2 | Oct 14, 2025 |
| CVE-2025-24474 | An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiManager 7.6.0 through 7.6.1, 7.4.0 throu… | LOW | 2.7 | Jul 8, 2025 |
| CVE-2024-50565 | A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.3, 7.2.0 through 7.… | HIGH | 7.5 | Apr 8, 2025 |
| CVE-2024-26013 | A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet FortiOS version 7.4.0 through 7.4.4, 7.2.0 through 7.… | HIGH | 7.5 | Apr 8, 2025 |
| CVE-2024-52962 | An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiAnalyzer version 7.6.1 and below, version 7.4.5 and below, version 7.2.8 and below,… | MEDIUM | 5.3 | Apr 8, 2025 |
| CVE-2023-25610 | A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7… | CRITICAL | 9.8 | Mar 24, 2025 |
| CVE-2024-40585 | An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 and below,… | MEDIUM | 6.5 | Mar 14, 2025 |
| CVE-2024-33501 | Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through… | MEDIUM | 6.7 | Mar 11, 2025 |
| CVE-2024-32123 | Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 thro… | MEDIUM | 6.7 | Mar 11, 2025 |
| CVE-2024-40584 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 th… | HIGH | 7.2 | Feb 11, 2025 |
| CVE-2024-36508 | An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 a… | MEDIUM | 6.0 | Feb 11, 2025 |
Showing 1 to 25 of 93 CVEs