Skip to main content

Vendor/product archive

fortinet / fortiadc CVEs

Beta · best-effort

44 CVEs tagged to fortinet / fortiadc0 Critical, 16 High, 26 Medium, 2 Low, 0 Unrated.

CVE-2025-58412

Published Nov 19, 2025

A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiADC 8.0.0, FortiADC 7.6.0 through 7.6.3, FortiADC 7.4 all versions,…

CVSS 4.7 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-54971

Published Nov 18, 2025

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiADC 7.4.0, FortiADC 7.2 all versions, FortiADC 7.1 all versions, FortiADC 7.0 all vers…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-48839

Published Nov 18, 2025

An Out-of-bounds Write vulnerability [CWE-787] in FortiADC 8.0.0, 7.6.0 through 7.6.2, 7.4.0 through 7.4.7, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions…

CVSS 6.6 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-59921

Published Oct 14, 2025

An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiADC version 7.4.0, version 7.2.3 and below, version 7.1.4 and below, 7.0 all…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-49813

Published Aug 12, 2025

An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a r…

CVSS 7.2 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-31104

Published Jun 10, 2025

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiADC 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2.0 th…

CVSS 7.2 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2023-37933

Published Mar 11, 2025

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC GUI version 7.4.0, 7.2.0 through 7.2.1 and before 7.1.3…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-23439

Published Jan 22, 2025

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` heade…

CVSS 4.7 · Medium

CVE-2024-36511

Published Sep 10, 2024

An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF) 7.4.0 through 7.4.4, 7.2 all versions, 7.1 all versions, 7…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2023-50181

Published Jul 9, 2024

An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticated attacker to perform some wri…

CVSS 4.9 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50179

Published Jul 9, 2024

An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2 all versions, 7.1 all versions, 7.0 all versions may allow a remote and unauthenticated attacker…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-50178

Published Jul 9, 2024

An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions and 6.0 a…

CVSS 7.4 · High
Vendor/product tagsBeta · best-effort

CVE-2023-50180

Published May 14, 2024

An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, version 7.2.3 and below, version 7.1.4 a…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-41673

Published Dec 13, 2023

An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low privileged user to read or backup the full system configurati…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-29177

Published Nov 14, 2023

Multiple buffer copy without checking size of input ('classic buffer overflow') vulnerabilities [CWE-120] in FortiADC version 7.2.0 and before 7.1.2 & FortiDDoS-F version 6.5.0 an…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25603

Published Nov 14, 2023

A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacke…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-26205

Published Nov 14, 2023

An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authentica…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-35849

Published Sep 13, 2023

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in the management interface of FortiADC 7.1.0 through 7.1.1, 7.0.0 through 7.0.3, 6.2.0…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-28000

Published Jun 13, 2023

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC CLI 7.1.0, 7.0.0 through 7.0.3, 6.2.0 through 6.2.4, 6.1 all versions, 6.0…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-27999

Published May 3, 2023

An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiADC 7.2.0, 7.1.0 through 7.1.1 may allow an authenticated attacker to execute u…

CVSS 7.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-27993

Published May 3, 2023

A relative path traversal [CWE-23] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a privileged attacker to delete arbitrary directories from the underlying file system…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-43952

Published Apr 11, 2023

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC version 7.1.1 and below, version 7.0.3 and below, versio…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2022-43948

Published Apr 11, 2023

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 7.0.0 through 7.0.3, FortiADC version 7.1.0 through 7.1.1…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 44 CVEsPage 1 of 2