FortiSIEM
Fortinet · 32 CVEs
A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIE…
Sep 8, 2026
A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIE…
Aug 12, 2026
A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4…
Jul 15, 2026
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7…
Jul 14, 2026
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet Forti…
Mar 10, 2026
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet…
Jan 13, 2026
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2,…
Oct 14, 2025
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vu…
Aug 12, 2025
A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0…
Apr 2, 2025
A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attac…
Mar 17, 2025
An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6…
Mar 11, 2025
An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6…
Mar 11, 2025
Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79]…
Feb 11, 2025
A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x al…
Jan 14, 2025
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Forti…
Jan 14, 2025
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet…
Feb 5, 2024
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet…
Feb 5, 2024
An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 a…
Nov 14, 2023
An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may…
Nov 14, 2023
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM vers…
Nov 14, 2023
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet…
Oct 10, 2023
A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows a…
Sep 13, 2023
A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all vers…
Jun 13, 2023
A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthe…
Jun 13, 2023
An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privile…
Jun 13, 2023
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-84389 | A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker… | LOW | 0.22% | Sep 8, 2026 |
| CVE-2026-70467 | A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all… | LOW | 0.26% | Aug 12, 2026 |
| CVE-2026-59838 | A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, Forti… | MEDIUM | 0.24% | Jul 15, 2026 |
| CVE-2026-59841 | A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to… | HIGH | 0.24% | Jul 14, 2026 |
| CVE-2026-25972 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.… | MEDIUM | 0.32% | Mar 10, 2026 |
| CVE-2025-64155 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 throug… | CRITICAL | 42.81% | Jan 13, 2026 |
| CVE-2025-58324 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7… | MEDIUM | 0.27% | Oct 14, 2025 |
| CVE-2025-25256 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0… | CRITICAL | 64.70% | Aug 12, 2025 |
| CVE-2023-40714 | A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege vi… | CRITICAL | 0.62% | Apr 2, 2025 |
| CVE-2019-17659 | A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervis… | HIGH | 0.65% | Mar 17, 2025 |
| CVE-2024-55592 | An incorrect authorization vulnerability [CWE-863] in FortiSIEM 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 a… | LOW | 0.26% | Mar 11, 2025 |
| CVE-2023-40723 | An exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.4 and 6.6.0 through 6.6.3 and 6.5.0 through 6.5.1… | HIGH | 0.36% | Mar 11, 2025 |
| CVE-2024-27780 | Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all v… | MEDIUM | 0.30% | Feb 11, 2025 |
| CVE-2024-46667 | A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0… | HIGH | 0.59% | Jan 14, 2025 |
| CVE-2024-52969 | An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiSIEM ersion 7.1.7 and below, version 7.1… | MEDIUM | 0.50% | Jan 14, 2025 |
| CVE-2024-23108 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized… | CRITICAL | 78.38% | Feb 5, 2024 |
| CVE-2024-23109 | An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized… | CRITICAL | 3.22% | Feb 5, 2024 |
| CVE-2023-45585 | An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 and below, version 6.6.3 and below, versi… | LOW | 0.21% | Nov 14, 2023 |
| CVE-2023-41676 | An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to window… | MEDIUM | 0.45% | Nov 14, 2023 |
| CVE-2023-36553 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.… | CRITICAL | 1.88% | Nov 14, 2023 |
| CVE-2023-34992 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized… | CRITICAL | 80.06% | Oct 10, 2023 |
| CVE-2023-36551 | A exposure of sensitive information to an unauthorized actor in Fortinet FortiSIEM version 6.7.0 through 6.7.5 allows attacker to information disclosure via a… | MEDIUM | 0.67% | Sep 13, 2023 |
| CVE-2023-26204 | A plaintext storage of a password vulnerability [CWE-256] in FortiSIEM 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions… | CRITICAL | 0.43% | Jun 13, 2023 |
| CVE-2022-43949 | A use of a broken or risky cryptographic algorithm [CWE-327] in Fortinet FortiSIEM before 6.7.1 allows a remote unauthenticated attacker to perform brute force… | HIGH | 0.36% | Jun 13, 2023 |
| CVE-2022-42478 | An Improper Restriction of Excessive Authentication Attempts [CWE-307] in FortiSIEM below 7.0.0 may allow a non-privileged user with access to several endpoint… | HIGH | 0.53% | Jun 13, 2023 |
Showing 1 to 25 of 32 CVEs