Vulnerabilities
Vulnerabilities affecting firewalls and security appliances, with vendor fix data, CISA KEV status and EPSS.
259 vulnerabilities
- CVE-2025-011412 Mar 2025
PAN-OS: Denial of Service (DoS) in GlobalProtect
High7.5CVSS 3.1, High0.41% - CVE-2024-4532411 Mar 2025
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, …
High7.2CVSS 3.1, High0.72% PAN-OS: Authenticated File Read Vulnerability in the Management Web Interface
Medium6.5CVSS 3.1, Medium2%PAN-OS: Authentication Bypass in the Management Web Interface
Critical9.1CVSS 3.1, Critical98%Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
High8.1CVSS 3.1, High7%- CVE-2024-4058411 Feb 2025
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability […
High7.2CVSS 3.1, High2% - CVE-2024-3350411 Feb 2025
A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0…
High7.7CVSS 3.1, High0.30% - CVE-2024-3527911 Feb 2025
A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and ver…
High8.1CVSS 3.1, High1% - CVE-2024-4059111 Feb 2025
An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.…
High7.2CVSS 3.1, High0.62% - CVE-2024-5056316 Jan 2025
A weak authentication in Fortinet FortiManager Cloud, FortiAnalyzer versions 7.6.0 through 7.6.1, 7.4.1 throu…
Critical9.8CVSS 3.1, Critical0.58% - CVE-2024-4533116 Jan 2025
A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7…
High7.8CVSS 3.1, High0.21% - CVE-2024-4757114 Jan 2025
An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows a…
Critical9.8CVSS 3.1, Critical0.91% - CVE-2024-3527714 Jan 2025
A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiMan…
High7.5CVSS 3.1, High0.71% - CVE-2024-3350214 Jan 2025
An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, F…
High7.2CVSS 3.1, High1% - CVE-2024-4888614 Jan 2025
A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.…
Critical9.8CVSS 3.1, Critical0.48% - CVE-2024-3350314 Jan 2025
A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManage…
High7.8CVSS 3.1, High0.22% - CVE-2024-4888414 Jan 2025
A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet Fo…
Critical9.1CVSS 3.1, Critical15% - CVE-2024-4666814 Jan 2025
An allocation of resources without limits or throttling vulnerability [CWE-770] in FortiOS versions 7.4.0 thr…
High7.5CVSS 3.1, High1.00% - CVE-2024-3527314 Jan 2025
A out-of-bounds write in Fortinet FortiManager version 7.4.0 through 7.4.2, FortiAnalyzer version 7.4.0 throu…
High8.8CVSS 3.1, High0.66% - CVE-2024-3527614 Jan 2025
A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnalyzer 7.2.…
Critical9.8CVSS 3.1, Critical0.42% - CVE-2024-3527514 Jan 2025
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnaly…
High8.8CVSS 3.1, High0.82% - CVE-2024-3651214 Jan 2025
An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, F…
High7.2CVSS 3.1, High1% - CVE-2024-4667014 Jan 2025
An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.…
High7.5CVSS 3.1, High0.63% - CVE-2024-5056614 Jan 2025
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in…
High8.8CVSS 3.1, High1% Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Critical9.8CVSS 3.1, Critical94%PAN-OS: Firewall Denial of Service (DoS) in DNS Security Using a Specially Crafted Packet
High7.5CVSS 3.1, High28%- CVE-2021-3258919 Dec 2024
A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.…
Critical9.8CVSS 3.1, Critical9% - CVE-2020-1282019 Dec 2024
Under non-default configuration, a stack-based buffer overflow in FortiOS version 6.0.10 and below, version 5…
High8.8CVSS 3.1, High0.89% - CVE-2020-1281919 Dec 2024
A heap-based buffer overflow vulnerability in the processing of Link Control Protocol messages in FortiGate v…
High7.5CVSS 3.1, High0.79% - CVE-2024-4888918 Dec 2024
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability […
High7.2CVSS 3.1, High2%