Skip to main content

Vendor/product archive

fortinet / fortiddos-f CVEs

Beta · best-effort

7 CVEs tagged to fortinet / fortiddos-f0 Critical, 2 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-39815

Published Apr 14, 2026

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unau…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-45325

Published Sep 9, 2025

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiDDoS-F version 7.0.0 through 7.02 and befor…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-23439

Published Jan 22, 2025

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` heade…

CVSS 4.7 · Medium

CVE-2022-27486

Published Aug 13, 2024

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiDDoS version 5.5.0 through 5.5.1, 5.4.2 through 5.4.0, 5.3.0 through…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-29177

Published Nov 14, 2023

Multiple buffer copy without checking size of input ('classic buffer overflow') vulnerabilities [CWE-120] in FortiADC version 7.2.0 and before 7.1.2 & FortiDDoS-F version 6.5.0 an…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-25603

Published Nov 14, 2023

A permissive cross-domain policy with untrusted domains vulnerability in Fortinet FortiADC 7.1.0 - 7.1.1, FortiDDoS-F 6.3.0 - 6.3.4 and 6.4.0 - 6.4.1 allow an unauthorized attacke…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1