Fortinet Fortiweb
Fortinet · 30 CVEs
A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attack…
Apr 6, 2022
A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and…
Dec 9, 2021
Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may all…
Dec 9, 2021
Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 thr…
Dec 8, 2021
Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.…
Dec 8, 2021
Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 thr…
Dec 8, 2021
An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Rep…
Dec 8, 2021
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4…
Dec 8, 2021
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4…
Dec 8, 2021
A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below a…
Dec 8, 2021
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenti…
Dec 8, 2021
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below al…
Dec 8, 2021
A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute…
Dec 8, 2021
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4…
Dec 8, 2021
A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and…
Dec 8, 2021
Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management…
Dec 8, 2021
A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows atta…
Nov 2, 2021
A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allow…
Nov 2, 2021
A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.…
Sep 8, 2021
A stack-based buffer overflow in Fortinet FortiWeb version 6.3.14 and below, 6.2.4 and below allows attacker to execute…
Sep 8, 2021
An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x…
Jun 1, 2021
An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.…
Apr 12, 2021
An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and versio…
Feb 8, 2021
A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the c…
Jan 14, 2021
A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unaut…
Jan 14, 2021
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2021-41026 | A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files from the… | MEDIUM | 0.93% | Apr 6, 2022 |
| CVE-2021-43071 | A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows attacker to execute unautho… | HIGH | 1.26% | Dec 9, 2021 |
| CVE-2021-36194 | Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to achieve… | HIGH | 1.44% | Dec 9, 2021 |
| CVE-2021-41017 | Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow a remote authentic… | HIGH | 1.96% | Dec 8, 2021 |
| CVE-2021-41025 | Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6… | CRITICAL | 1.49% | Dec 8, 2021 |
| CVE-2021-36195 | Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, and 6.… | HIGH | 1.08% | Dec 8, 2021 |
| CVE-2021-41013 | An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Report Browse section of Log & Report may a… | MEDIUM | 0.97% | Dec 8, 2021 |
| CVE-2021-36188 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows at… | MEDIUM | 0.67% | Dec 8, 2021 |
| CVE-2021-43063 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below,… | MEDIUM | 0.91% | Dec 8, 2021 |
| CVE-2021-36190 | A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to acc… | MEDIUM | 0.83% | Dec 8, 2021 |
| CVE-2021-41014 | A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenticated attacker to make the httpsd daemon… | HIGH | 1.16% | Dec 8, 2021 |
| CVE-2021-36191 | A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to use the device as proxy… | MEDIUM | 0.52% | Dec 8, 2021 |
| CVE-2021-41027 | A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute unauthorized code or commands via craft… | HIGH | 0.16% | Dec 8, 2021 |
| CVE-2021-41015 | A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows at… | MEDIUM | 0.85% | Dec 8, 2021 |
| CVE-2021-43064 | A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and below allows at… | MEDIUM | 0.63% | Dec 8, 2021 |
| CVE-2021-36180 | Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management interface 6.4.1 and below, 6.3.15 and be… | HIGH | 1.15% | Dec 8, 2021 |
| CVE-2021-36186 | A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to execute unauthorized code or com… | CRITICAL | 1.61% | Nov 2, 2021 |
| CVE-2021-36187 | A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows attacker to cause a denial of service… | HIGH | 1.43% | Nov 2, 2021 |
| CVE-2021-36182 | A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows attacker to execute… | HIGH | 1.92% | Sep 8, 2021 |
| CVE-2021-36179 | A stack-based buffer overflow in Fortinet FortiWeb version 6.3.14 and below, 6.2.4 and below allows attacker to execute unauthorized code or commands via craft… | HIGH | 1.65% | Sep 8, 2021 |
| CVE-2021-22123 | An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x, 5.9.x may allow a remote authenticated… | HIGH | 77.27% | Jun 1, 2021 |
| CVE-2020-15942 | An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.2.4 and version 6.3.x below 6.3.5 may al… | MEDIUM | 0.94% | Apr 12, 2021 |
| CVE-2021-22122 | An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and version before 6.2.4 may allow an unauthentica… | MEDIUM | 10.52% | Feb 8, 2021 |
| CVE-2020-29018 | A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the content of memory and retrieve sensitive… | HIGH | 2.03% | Jan 14, 2021 |
| CVE-2020-29016 | A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unauthenticated, remote attacker to overwrite… | CRITICAL | 3.30% | Jan 14, 2021 |
Showing 1 to 25 of 30 CVEs