Fortinet Fortiweb

Fortinet · 30 CVEs

CVE-2021-41026
MEDIUM

A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attack…

Apr 6, 2022

CVE-2021-43071
HIGH

A heap-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and below, version 6.2.6 and…

Dec 9, 2021

CVE-2021-36194
HIGH

Multiple stack-based buffer overflows in the API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may all…

Dec 9, 2021

CVE-2021-41017
HIGH

Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 thr…

Dec 8, 2021

CVE-2021-41025
CRITICAL

Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.…

Dec 8, 2021

CVE-2021-36195
HIGH

Multiple command injection vulnerabilities in the command line interpreter of FortiWeb versions 6.4.1, 6.4.0, 6.3.0 thr…

Dec 8, 2021

CVE-2021-41013
MEDIUM

An improper access control vulnerability [CWE-284] in FortiWeb versions 6.4.1 and below and 6.3.15 and below in the Rep…

Dec 8, 2021

CVE-2021-36188
MEDIUM

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4…

Dec 8, 2021

CVE-2021-43063
MEDIUM

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4…

Dec 8, 2021

CVE-2021-36190
MEDIUM

A unintended proxy or intermediary ('confused deputy') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below a…

Dec 8, 2021

CVE-2021-41014
HIGH

A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows an unauthenti…

Dec 8, 2021

CVE-2021-36191
MEDIUM

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below al…

Dec 8, 2021

CVE-2021-41027
HIGH

A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute…

Dec 8, 2021

CVE-2021-41015
MEDIUM

A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4…

Dec 8, 2021

CVE-2021-43064
MEDIUM

A url redirection to untrusted site ('open redirect') in Fortinet FortiWeb version 6.4.1 and 6.4.0, version 6.3.15 and…

Dec 8, 2021

CVE-2021-36180
HIGH

Multiple improper neutralization of special elements used in a command vulnerabilities [CWE-77] in FortiWeb management…

Dec 8, 2021

CVE-2021-36186
CRITICAL

A stack-based buffer overflow in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allows atta…

Nov 2, 2021

CVE-2021-36187
HIGH

A uncontrolled resource consumption in Fortinet FortiWeb version 6.4.0, version 6.3.15 and below, 6.2.5 and below allow…

Nov 2, 2021

CVE-2021-36182
HIGH

A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.…

Sep 8, 2021

CVE-2021-36179
HIGH

A stack-based buffer overflow in Fortinet FortiWeb version 6.3.14 and below, 6.2.4 and below allows attacker to execute…

Sep 8, 2021

CVE-2021-22123
HIGH

An OS command injection vulnerability in FortiWeb's management interface 6.3.7 and below, 6.2.3 and below, 6.1.x, 6.0.x…

Jun 1, 2021

CVE-2020-15942
MEDIUM

An information disclosure vulnerability in Web Vulnerability Scan profile of Fortinet's FortiWeb version 6.2.x below 6.…

Apr 12, 2021

CVE-2021-22122
MEDIUM

An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 through 6.3.7 and versio…

Feb 8, 2021

CVE-2020-29018
HIGH

A format string vulnerability in FortiWeb 6.3.0 through 6.3.5 may allow an authenticated, remote attacker to read the c…

Jan 14, 2021

CVE-2020-29016
CRITICAL

A stack-based buffer overflow vulnerability in FortiWeb 6.3.0 through 6.3.5 and version before 6.2.4 may allow an unaut…

Jan 14, 2021

Showing 1 to 25 of 30 CVEs