fortinet / fortios
23 known vulnerabilities in fortinet fortios.
| CVE | Priority | EPSS | CVSS | KEV | What |
|---|---|---|---|---|---|
| CVE-2022-40684 | Act now | 100.0% | 9.8 | ● | An authentication bypass using an alternate path or channel [CWE-288] in Fortine… |
| CVE-2024-55591 | Act now | 98.3% | 9.8 | ● | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2… |
| CVE-2023-27997 | Act now | 85.7% | 9.8 | ● | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 an… |
| CVE-2024-21762 | Act now | 84.3% | 9.8 | ● | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 th… |
| CVE-2020-12812 | Act now | 49.3% | 9.8 | ● | An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6… |
| CVE-2018-13374 | Act now | 37.8% | 4.3 | ● | A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC … |
| CVE-2025-68686 | Act now | 29.6% | 5.9 | ● | An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE… |
| CVE-2019-5591 | Act now | 18.4% | 6.5 | ● | A Default Configuration vulnerability in FortiOS may allow an unauthenticated at… |
| CVE-2025-24472 | Act now | 7.2% | 8.1 | ● | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-2… |
| CVE-2019-6693 | Act now | 5.8% | 6.5 | ● | Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS config… |
| CVE-2025-25249 | Act now | 2.4% | 8.1 | ● | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6… |
| CVE-2026-59837 | Low | 0.7% | 6.6 | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.… | |
| CVE-2026-71407 | Low | 0.5% | 5.6 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet … | |
| CVE-2026-71408 | Low | 0.5% | 5.3 | A allocation of resources without limits or throttling vulnerability in Fortinet… | |
| CVE-2023-50176 | Low | 0.4% | 4.2 | A session fixation vulnerability in Fortinet FortiOS 7.4.0 through 7.4.3, FortiO… | |
| CVE-2026-23573 | Low | 0.4% | 6.1 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scri… | |
| CVE-2025-43892 | Low | 0.4% | 4.3 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiO… | |
| CVE-2025-62826 | Low | 0.4% | 3.1 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Spl… | |
| CVE-2025-25252 | Low | 0.3% | 4.8 | An Insufficient Session Expiration vulnerability [CWE-613] in FortiOS SSL VPN 7.… | |
| CVE-2026-59840 | Low | 0.3% | 4.3 | A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiO… | |
| CVE-2025-62675 | Low | 0.3% | 3.4 | An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Spl… | |
| CVE-2026-59839 | Low | 0.3% | 5.5 | A improper limitation of a pathname to a restricted directory ('path traversal')… | |
| CVE-2025-67862 | Low | 0.1% | 6.7 | An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [C… |