| | CVE-2023-40721 | Fortinet | medium | 6.7 | 0.0%
| | A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allo… | Feb 11, 2025 | Jan 14, 2026 |
| | CVE-2022-23439 | Fortinet | medium | 4.7 | 0.2%
| | A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows … | Jan 22, 2025 | Jan 14, 2026 |
| | CVE-2024-48885 | Fortinet | medium | 5.3 | 0.8%
| | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo… | Jan 16, 2025 | Jul 8, 2026 |
| | CVE-2024-45331 | Fortinet | high | 7.3 | 0.2%
| | A incorrect privilege assignment vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiA… | Jan 16, 2025 | Jul 8, 2026 |
| | CVE-2024-35280 | Fortinet | medium | 5.4 | 0.6%
| | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability… | Jan 15, 2025 | Feb 4, 2026 |
| | CVE-2024-55591 | Fortinet | critical | 9.8 | 98.3%
| ⚠ KEV | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiO… | Jan 14, 2025 | Aug 5, 2026 |
| | CVE-2024-50566 | Fortinet | high | 7.2 | 0.3%
| | A improper neutralization of special elements used in an os command ('os command injection') vulnera… | Jan 14, 2025 | Jan 14, 2026 |
| | CVE-2024-48884 | Fortinet | high | 7.5 | 14.9%
| | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo… | Jan 14, 2025 | Jul 8, 2026 |
| | CVE-2024-45326 | Fortinet | medium | 4.3 | 0.3%
| | An Improper Access Control vulnerability [CWE-284] vulnerability in Fortinet FortiDeceptor 6.0.0, Fo… | Jan 14, 2025 | Feb 4, 2026 |
| | CVE-2024-35276 | Fortinet | medium | 5.6 | 0.4%
| | A stack-based buffer overflow vulnerability in Fortinet FortiAnalyzer 7.4.0 through 7.4.3, FortiAnal… | Jan 14, 2025 | Jul 8, 2026 |
| | CVE-2024-33503 | Fortinet | medium | 6.7 | 0.2%
| | A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, Fo… | Jan 14, 2025 | Jul 8, 2026 |
| | CVE-2024-27778 | Fortinet | high | 8.8 | 0.5%
| | An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerab… | Jan 14, 2025 | Jan 14, 2026 |
| | CVE-2024-52963 | Fortinet | low | 3.5 | 0.8%
| | A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10,… | Jan 14, 2025 | Aug 11, 2026 |
| | CVE-2024-31490 | Fortinet | medium | 4.3 | 0.7%
| | An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiSandbox… | Sep 10, 2024 | Jan 14, 2026 |
| | CVE-2024-27785 | Fortinet | medium | 5.4 | 0.6%
| | An improper neutralization of formula elements in a CSV File [CWE-1236] vulnerability in Fortinet Fo… | Jul 9, 2024 | Jan 9, 2026 |
| | CVE-2024-27784 | Fortinet | high | 8.8 | 0.6%
| | Multiple Exposure of sensitive information to an unauthorized actor weaknesses [CWE-200] vulnerabili… | Jul 9, 2024 | Jan 9, 2026 |
| | CVE-2024-27783 | Fortinet | high | 7.6 | 1.1%
| | Multiple cross-site request forgery (CSRF) weaknesses [CWE-352] vulnerability in Fortinet FortiAIOps… | Jul 9, 2024 | Jan 9, 2026 |
| | CVE-2024-27782 | Fortinet | high | 8.1 | 0.8%
| | Multiple insufficient session expiration weaknesses [CWE-613] vulnerability in Fortinet FortiAIOps 2… | Jul 9, 2024 | Jan 9, 2026 |
| | CVE-2024-23669 | Fortinet | medium | 6.5 | 0.5%
| | An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, Fo… | Jun 5, 2024 | Jul 8, 2026 |
| | CVE-2024-23670 | Fortinet | high | 7.8 | 0.4%
| | An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, Fo… | Jun 3, 2024 | Jul 8, 2026 |
| | CVE-2024-23668 | Fortinet | high | 8.8 | 0.7%
| | An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, Fo… | Jun 3, 2024 | Jul 8, 2026 |
| | CVE-2024-23667 | Fortinet | high | 7.8 | 0.4%
| | An improper authorization in Fortinet FortiWebManager 7.2.0, FortiWebManager 7.0.0 through 7.0.4, Fo… | Jun 3, 2024 | Jul 8, 2026 |
| | CVE-2024-31491 | Fortinet | high | 8.8 | 1.1%
| | A client-side enforcement of server-side security vulnerability in Fortinet FortiSandbox 4.4.0 throu… | May 14, 2024 | Jan 14, 2026 |
| | CVE-2023-45583 | Fortinet | medium | 6.7 | 0.2%
| | A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 … | May 14, 2024 | Jun 12, 2026 |
| | CVE-2023-36640 | Fortinet | medium | 6.7 | 0.1%
| | A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.4.0, FortiOS 7.2.0 … | May 14, 2024 | Jun 12, 2026 |
| | CVE-2024-31487 | Fortinet | medium | 5.9 | 0.5%
| | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo… | Apr 9, 2024 | Jan 14, 2026 |
| | CVE-2024-23671 | Fortinet | high | 8.1 | 0.8%
| | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo… | Apr 9, 2024 | Jan 14, 2026 |
| | CVE-2024-21756 | Fortinet | high | 8.8 | 1.0%
| | A improper neutralization of special elements used in an os command ('os command injection') vulnera… | Apr 9, 2024 | Jan 14, 2026 |
| | CVE-2024-21755 | Fortinet | high | 8.8 | 1.0%
| | A improper neutralization of special elements used in an os command ('os command injection') vulnera… | Apr 9, 2024 | Jan 14, 2026 |
| | CVE-2023-47541 | Fortinet | medium | 6.7 | 0.1%
| | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F… | Apr 9, 2024 | Jan 14, 2026 |
| | CVE-2023-47540 | Fortinet | medium | 6.7 | 0.1%
| | An improper neutralization of special elements used in an os command ('os command injection') vulner… | Apr 9, 2024 | Jan 14, 2026 |
| | CVE-2023-42790 | Fortinet | high | 8.1 | 1.1%
| | A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 t… | Mar 12, 2024 | Jul 8, 2026 |
| | CVE-2023-42789 | Fortinet | critical | 9.8 | 3.3%
| | A out-of-bounds write vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2.0 through 7… | Mar 12, 2024 | Jul 8, 2026 |
| | CVE-2023-41842 | Fortinet | medium | 6.7 | 0.1%
| | A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allo… | Mar 12, 2024 | Jan 14, 2026 |
| | CVE-2024-21762 | Fortinet | critical | 9.8 | 84.3%
| ⚠ KEV | A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 t… | Feb 9, 2024 | Aug 4, 2026 |
| | CVE-2024-23109 | Fortinet | critical | 10.0 | 7.0%
| | An improper neutralization of special elements used in an os command ('os command injection') vulner… | Feb 5, 2024 | Jan 14, 2026 |
| | CVE-2024-23108 | Fortinet | critical | 10.0 | 90.4%
| | An improper neutralization of special elements used in an os command ('os command injection') vulner… | Feb 5, 2024 | Jan 14, 2026 |
| | CVE-2023-41844 | Fortinet | low | 3.5 | 0.4%
| | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability… | Dec 13, 2023 | Jan 14, 2026 |
| | CVE-2023-45587 | Fortinet | low | 3.4 | 0.4%
| | An improper neutralization of input during web page generation ('cross-site scripting') vulnerabilit… | Dec 13, 2023 | Jul 8, 2026 |
| | CVE-2023-41843 | Fortinet | high | 7.5 | 0.2%
| | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability… | Oct 13, 2023 | Jan 14, 2026 |
| | CVE-2023-41836 | Fortinet | low | 3.5 | 0.1%
| | An improper neutralization of input during web page generation ('cross-site scripting') vulnerabilit… | Oct 13, 2023 | Jan 14, 2026 |
| | CVE-2023-41682 | Fortinet | high | 8.1 | 0.4%
| | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo… | Oct 13, 2023 | Jan 14, 2026 |
| | CVE-2023-41681 | Fortinet | high | 7.5 | 0.1%
| | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability… | Oct 13, 2023 | Jan 14, 2026 |
| | CVE-2023-41680 | Fortinet | high | 7.5 | 0.1%
| | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability… | Oct 13, 2023 | Jan 14, 2026 |
| | CVE-2023-42787 | Fortinet | medium | 6.5 | 1.4%
| | A client-side enforcement of server-side security [CWE-602] vulnerability in Fortinet FortiManager v… | Oct 10, 2023 | Aug 12, 2026 |
| | CVE-2023-34992 | Fortinet | critical | 10.0 | 75.9%
| | A improper neutralization of special elements used in an os command ('os command injection') vulnera… | Oct 10, 2023 | Jan 14, 2026 |
| | CVE-2023-27997 | Fortinet | critical | 9.8 | 85.7%
| ⚠ KEV | A heap-based buffer overflow vulnerability [CWE-122] in FortiOS version 7.2.4 and below, version 7.0… | Jun 13, 2023 | Jul 31, 2026 |
| | CVE-2023-26210 | Fortinet | high | 7.8 | 0.1%
| | Multiple improper neutralization of special elements used in an os command ('OS Command Injection') … | Jun 13, 2023 | Jan 14, 2026 |
| | CVE-2022-40684 | Fortinet | critical | 9.8 | 100.0%
| ⚠ KEV | An authentication bypass using an alternate path or channel [CWE-288] in Fortinet FortiOS version 7.… | Oct 18, 2022 | Aug 6, 2026 |
| | CVE-2021-36193 | Fortinet | medium | 6.7 | 0.5%
| | Multiple stack-based buffer overflows in the command line interpreter of FortiWeb before 6.4.2 may a… | Feb 2, 2022 | Jan 13, 2026 |