Skip to main content

Vendor/product archive

fortinet / fortindr CVEs

Beta · best-effort

11 CVEs tagged to fortinet / fortindr1 Critical, 2 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2026-25088

Published May 12, 2026

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiNDR 7.6.0 through 7.6.2, FortiNDR 7.4.0 through 7.4.9, Forti…

CVSS 5.4 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-23104

Published Apr 14, 2026

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all v…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47569

Published Oct 14, 2025

A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManage…

CVSS 4.3 · Medium

CVE-2023-33302

Published Mar 31, 2025

A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiMail webmail and administrative interface version 6.4.0 through 6.4.4 and before 6.2.6 a…

CVSS 4.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-47573

Published Mar 14, 2025

An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2.1 and below, version 7.1.1 and below, version 7.0.6 and be…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-48790

Published Mar 11, 2025

A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5 may allow a remote unauthenti…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-23439

Published Jan 22, 2025

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` heade…

CVSS 4.7 · Medium

CVE-2021-42757

Published Dec 8, 2021

A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code…

CVSS 6.7 · Medium
Showing 1-11 of 11 CVEsPage 1 of 1