Fortinet / FortiPAM
37 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-84392 | A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 a… | LOW | 2.7 | Sep 8, 2026 |
| CVE-2026-71407 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypas… | HIGH | 8.1 | Aug 12, 2026 |
| CVE-2026-59840 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, Fort… | MEDIUM | 4.3 | Jul 14, 2026 |
| CVE-2026-23573 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through… | MEDIUM | 6.1 | Jul 14, 2026 |
| CVE-2026-59839 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7… | MEDIUM | 5.5 | Jul 14, 2026 |
| CVE-2025-62826 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 throug… | MEDIUM | 4.3 | Jul 14, 2026 |
| CVE-2025-62675 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 throug… | MEDIUM | 4.3 | Jul 14, 2026 |
| CVE-2026-59837 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all v… | MEDIUM | 6.6 | Jul 14, 2026 |
| CVE-2025-61624 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0… | MEDIUM | 6.5 | Apr 14, 2026 |
| CVE-2024-47570 | An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; FortiProxy 7… | MEDIUM | 6.6 | Dec 9, 2025 |
| CVE-2025-54821 | An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all v… | MEDIUM | 6.0 | Nov 18, 2025 |
| CVE-2025-61713 | A Cleartext Storage of Sensitive Information in Memory vulnerability [CWE-316] in Fortinet FortiPAM 1.6.0, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions… | MEDIUM | 4.4 | Nov 18, 2025 |
| CVE-2024-26008 | An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4… | MEDIUM | 5.3 | Oct 14, 2025 |
| CVE-2024-47569 | A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all v… | MEDIUM | 4.3 | Oct 14, 2025 |
| CVE-2025-22258 | A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.… | HIGH | 7.2 | Oct 14, 2025 |
| CVE-2025-25253 | An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 and below, version 7.4.8 and below, 7.2 all versio… | HIGH | 7.5 | Oct 14, 2025 |
| CVE-2025-57740 | An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.0 all versions,… | HIGH | 8.8 | Oct 14, 2025 |
| CVE-2025-49201 | A weak authentication vulnerability in Fortinet FortiPAM 1.5.0, FortiPAM 1.4.0 through 1.4.2, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.… | CRITICAL | 9.8 | Oct 14, 2025 |
| CVE-2024-26009 | An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0 through 6.4.15, FortiOS 6.2.0 through 6.2.16, For… | HIGH | 8.1 | Aug 12, 2025 |
| CVE-2025-25248 | An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versio… | MEDIUM | 6.5 | Aug 12, 2025 |
| CVE-2023-45584 | A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, FortiOS 7.0.0 through 7.0.12, FortiOS 6.4 all versi… | HIGH | 7.2 | Aug 12, 2025 |
| CVE-2025-22256 | A improper handling of insufficient permissions or privileges in Fortinet FortiPAM 1.4.0 through 1.4.1, 1.3.0, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3,… | HIGH | 8.8 | Jun 10, 2025 |
| CVE-2024-50562 | An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL-VPN version 7.6.0, version 7.4.6 and below, version 7.2.10 and below, 7.0 all version… | MEDIUM | 4.8 | Jun 10, 2025 |
| CVE-2024-45324 | A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through… | HIGH | 7.2 | Mar 11, 2025 |
| CVE-2023-40721 | A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or comman… | MEDIUM | 6.7 | Feb 11, 2025 |
Showing 1 to 25 of 37 CVEs