Vulnerabilities
Vulnerabilities affecting firewalls and security appliances, with vendor fix data, CISA KEV status and EPSS.
259 vulnerabilities
- CVE-2025-5841318 Nov 2025
A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.…
High7.5CVSS 3.1, High0.32% Fortinet FortiWeb OS Command Injection Vulnerability
High7.2CVSS 3.1, High56%Fortinet FortiWeb Path Traversal Vulnerability
Critical9.8CVSS 3.1, Critical92%- CVE-2023-4671814 Oct 2025
A stack-based buffer overflow in Fortinet FortiOS version 7.4.0 through 7.4.1 and 7.2.0 through 7.2.7 and 7.0…
High7.8CVSS 3.1, High0.19% - CVE-2024-5057114 Oct 2025
A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.2, FortiAnalyzer 7.4.0…
High7.2CVSS 3.1, High0.54% - CVE-2025-2225814 Oct 2025
A heap-based buffer overflow in Fortinet FortiSRA 1.5.0, 1.4.0 through 1.4.2, FortiPAM 1.5.0, 1.4.0 through 1…
High7.2CVSS 3.1, High0.56% - CVE-2025-2525314 Oct 2025
An Improper Validation of Certificate with Host Mismatch vulnerability [CWE-297] in FortiProxy version 7.6.1 …
High7.5CVSS 3.1, High0.11% - CVE-2025-5774014 Oct 2025
An Heap-based Buffer Overflow vulnerability [CWE-122] in FortiOS version 7.6.2 and below, version 7.4.7 and b…
High8.8CVSS 3.1, High0.68% - CVE-2025-46159 Oct 2025
PAN-OS: Improper Neutralization of Input in the Management Web Interface
High7.2CVSS 3.1, High0.79% Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability
High8.6CVSS 3.1, High87%Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability
Critical9.9CVSS 3.1, Critical71%Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability
High7.7CVSS 3.1, High39%- CVE-2024-2600912 Aug 2025
An authentication bypass using an alternate path or channel [CWE-288] vulnerability in Fortinet FortiOS 6.4.0…
High8.1CVSS 3.1, High0.59% - CVE-2023-4558412 Aug 2025
A double free vulnerability [CWE-415] vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 through 7.2.5, F…
High7.2CVSS 3.1, High0.59% - CVE-2025-5374412 Aug 2025
An incorrect privilege assignment vulnerability [CWE-266] in FortiOS Security Fabric version 7.6.0 through 7.…
High7.2CVSS 3.1, High0.63% Fortinet FortiWeb SQL Injection Vulnerability
Critical9.8CVSS 3.1, Critical100%Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
Critical10CVSS 3.1, Critical68%- CVE-2024-529658 Jul 2025
A missing critical step in authentication vulnerability [CWE-304] in Fortinet FortiOS version 7.6.0 through 7…
High7.2CVSS 3.1, High0.26% Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
Critical10CVSS 3.1, Critical98%- CVE-2025-423112 Jun 2025
PAN-OS: Authenticated Admin Command Injection Vulnerability in the Management Web Interface
High7.2CVSS 3.1, High0.98% - CVE-2025-2225410 Jun 2025
An Improper Privilege Management vulnerability [CWE-269] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.…
High7.2CVSS 3.1, High0.85% - CVE-2025-2225228 May 2025
A missing authentication for critical function in Fortinet FortiProxy versions 7.6.0 through 7.6.1, FortiSwit…
High7.2CVSS 3.1, High0.94% - CVE-2025-013014 May 2025
PAN-OS: Firewall Denial-of-Service (DoS) in the Web-Proxy Feature via a Burst of Maliciously Crafted Packets
High7.5CVSS 3.1, High0.42% Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability
Critical9.8CVSS 3.1, Critical30%- CVE-2024-505658 Apr 2025
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet For…
High7.5CVSS 3.1, High0.39% - CVE-2024-260138 Apr 2025
A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in Fortinet For…
High7.5CVSS 3.1, High0.50% - CVE-2023-379308 Apr 2025
Multiple issues including the use of uninitialized ressources [CWE-908] and excessive iteration [CWE-834] vul…
High8.8CVSS 3.1, High0.63% - CVE-2023-2561024 Mar 2025
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS ve…
Critical9.8CVSS 3.1, Critical18% - CVE-2020-929517 Mar 2025
FortiOS 6.2 running AV engine version 6.00142 and below, FortiOS 6.4 running AV engine version 6.00144 and be…
High7.5CVSS 3.1, High0.32% - CVE-2024-4666214 Mar 2025
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManage…
High8.8CVSS 3.1, High2%