Fortinet / FortiProxy
125 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-84392 | A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.9.0, FortiPAM 1.8 a… | LOW | 2.7 | Sep 8, 2026 |
| CVE-2026-84393 | A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacke… | HIGH | 8.1 | Sep 8, 2026 |
| CVE-2026-71407 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypas… | HIGH | 8.1 | Aug 12, 2026 |
| CVE-2026-59840 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, Fort… | MEDIUM | 4.3 | Jul 14, 2026 |
| CVE-2025-43892 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, Fort… | MEDIUM | 4.3 | Jul 14, 2026 |
| CVE-2026-23573 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through… | MEDIUM | 6.1 | Jul 14, 2026 |
| CVE-2026-59839 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7… | MEDIUM | 5.5 | Jul 14, 2026 |
| CVE-2025-62826 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 throug… | MEDIUM | 4.3 | Jul 14, 2026 |
| CVE-2025-62675 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] vulnerability in Fortinet FortiOS 7.6.0 throug… | MEDIUM | 4.3 | Jul 14, 2026 |
| CVE-2026-59837 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all v… | MEDIUM | 6.6 | Jul 14, 2026 |
| CVE-2025-67862 | An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 t… | MEDIUM | 6.7 | Jun 9, 2026 |
| CVE-2025-61624 | An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0… | MEDIUM | 6.5 | Apr 14, 2026 |
| CVE-2026-24858 KEV | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer… | CRITICAL | 9.8 | Jan 27, 2026 |
| CVE-2024-47570 | An insertion of sensitive information into log file vulnerability [CWE-532] in FortiOS 7.4.0 through 7.4.3, 7.2.0 through 7.2.7, 7.0 all versions; FortiProxy 7… | MEDIUM | 6.6 | Dec 9, 2025 |
| CVE-2025-59718 KEV | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.… | CRITICAL | 9.8 | Dec 9, 2025 |
| CVE-2025-54821 | An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.11, FortiOS 7.2 all v… | MEDIUM | 6.0 | Nov 18, 2025 |
| CVE-2025-31514 | A insertion of sensitive information into log file vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4 all versions, FortiOS 7.2 all versions, F… | MEDIUM | 4.3 | Oct 14, 2025 |
| CVE-2025-54822 | An improper authorization vulnerability [CWE-285] vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7.2.8, FortiOS 7.0.0 through 7.0… | MEDIUM | 4.3 | Oct 14, 2025 |
| CVE-2025-25255 | An Improperly Implemented Security Check for Standard vulnerability [CWE-358] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiProxy 7.6.0 through 7… | MEDIUM | 4.8 | Oct 14, 2025 |
| CVE-2024-26008 | An improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4… | MEDIUM | 5.3 | Oct 14, 2025 |
| CVE-2024-47569 | A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all v… | MEDIUM | 4.3 | Oct 14, 2025 |
| CVE-2023-46718 | A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.12 and 6.4.6 through 6.4.15 and 6.2… | HIGH | 7.8 | Oct 14, 2025 |
| CVE-2024-50571 | A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0 through 7.4.5, FortiAnalyzer 7.2.0 through 7.2.9,… | HIGH | 7.2 | Oct 14, 2025 |
| CVE-2025-31366 | An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 thro… | MEDIUM | 6.1 | Oct 14, 2025 |
| CVE-2025-22258 | A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1.4.2, 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.… | HIGH | 7.2 | Oct 14, 2025 |
Showing 1 to 25 of 125 CVEs