Skip to main content

Vendor/product archive

fortinet / fortivoice CVEs

Beta · best-effort

24 CVEs tagged to fortinet / fortivoice2 Critical, 9 High, 12 Medium, 1 Low, 0 Unrated.

CVE-2024-23104

Published Apr 14, 2026

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all v…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-58693

Published Jan 13, 2026

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7 allows a…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-64156

Published Dec 9, 2025

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice 7.0.0 through 7.0.7, F…

CVSS 7.2 · High
Vendor/product tagsBeta · best-effort

CVE-2025-60024

Published Dec 9, 2025

Multiple Improper Limitations of a Pathname to a Restricted Directory ('Path Traversal') vulnerabilities [CWE-22] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVo…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2025-58692

Published Nov 18, 2025

An improper neutralization of special elements used in an SQL Command ("SQL Injection") vulnerability [CWE-89] vulnerability in Fortinet FortiVoice 7.2.0 through 7.2.2, FortiVoice…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-47569

Published Oct 14, 2025

A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManage…

CVSS 4.3 · Medium

CVE-2025-47856

Published Oct 14, 2025

Two improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiVoice version 7.2.0, 7.0.0 through 7.0.6 a…

CVSS 7.2 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2022-23439

Published Jan 22, 2025

A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` heade…

CVSS 4.7 · Medium

CVE-2024-40587

Published Jan 14, 2025

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort

CVE-2023-37931

Published Jan 14, 2025

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2023-40720

Published May 14, 2024

An authorization bypass through user-controlled key vulnerability [CWE-639] in FortiVoiceEntreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenticated attacker t…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2023-37932

Published Jan 10, 2024

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability [CWE-22] in FortiVoiceEntreprise version 7.0.0 and before 6.4.7 allows an authentic…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-42757

Published Dec 8, 2021

A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code…

CVSS 6.7 · Medium

CVE-2020-9294

Published Apr 27, 2020

An improper authentication vulnerability in FortiMail 5.4.10, 6.0.7, 6.2.2 and earlier and FortiVoiceEntreprise 6.0.0 and 6.0.1 may allow a remote unauthenticated attacker to acce…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-24 of 24 CVEsPage 1 of 1