| | CVE-2020-12812 | Fortinet | medium | — | 49.3%
| ⚠ KEV | An improper authentication vulnerability in SSL VPN in FortiOS 6.4.0, 6.2.0 to 6.2.3, 6.0.9 and belo… | Jul 24, 2020 | Aug 12, 2026 |
| | CVE-2019-6693 | Fortinet | medium | — | 5.7%
| ⚠ KEV | Use of a hard-coded cryptographic key to cipher sensitive data in FortiOS configuration backup file … | Nov 21, 2019 | Aug 4, 2026 |
| | CVE-2018-13374 | Fortinet | medium | 4.3 | 38.1%
| ⚠ KEV | A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.… | Jan 22, 2019 | Aug 13, 2026 |
| | CVE-2017-14184 | Fortinet | high | 8.8 | 1.6%
| | An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions… | Dec 15, 2017 | May 13, 2026 |
| | CVE-2017-7344 | Fortinet | high | 8.1 | 1.3%
| | A privilege escalation in Fortinet FortiClient Windows 5.4.3 and earlier as well as 5.6.0 allows att… | Dec 14, 2017 | May 13, 2026 |
| | CVE-2017-7738 | Fortinet | high | 7.2 | 0.3%
| | An Information Disclosure vulnerability in Fortinet FortiOS 5.6.0 to 5.6.2, 5.4.0 to 5.4.5, 5.2 and … | Dec 13, 2017 | May 13, 2026 |
| | CVE-2017-14189 | Fortinet | critical | 9.8 | 0.5%
| | An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can ac… | Nov 29, 2017 | May 13, 2026 |
| | CVE-2017-7736 | Fortinet | medium | 5.4 | 0.2%
| | A stored Cross-site Scripting (XSS) vulnerability in Fortinet FortiWeb webUI Certificate View page i… | Nov 22, 2017 | May 13, 2026 |
| | CVE-2017-7732 | Fortinet | medium | 6.1 | 0.9%
| | A reflected Cross-Site Scripting (XSS) vulnerability in Fortinet FortiMail 5.1 and earlier, 5.2.0 th… | Oct 26, 2017 | May 13, 2026 |
| | CVE-2017-7341 | Fortinet | high | 7.2 | 2.5%
| | An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10… | Oct 26, 2017 | May 13, 2026 |
| | CVE-2017-7335 | Fortinet | medium | 5.4 | 0.3%
| | A Cross-Site Scripting (XSS) vulnerability in Fortinet FortiWLC 6.1-x (6.1-2, 6.1-4 and 6.1-5); 7.0-… | Oct 26, 2017 | May 13, 2026 |
| | CVE-2017-7737 | Fortinet | medium | 4.9 | 0.4%
| | An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-… | Aug 10, 2017 | May 13, 2026 |
| | CVE-2017-7336 | Fortinet | critical | 9.8 | 0.9%
| | A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote a… | Jul 22, 2017 | May 13, 2026 |
| | CVE-2016-8493 | Fortinet | high | 8.8 | 0.6%
| | In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe… | Jun 26, 2017 | May 13, 2026 |
| | CVE-2017-7731 | Fortinet | high | 7.5 | 0.3%
| | A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows attac… | May 27, 2017 | May 13, 2026 |
| | CVE-2017-7343 | Fortinet | medium | 6.1 | 0.3%
| | An open redirect vulnerability in Fortinet FortiPortal 4.0.0 and below allows attacker to execute un… | May 27, 2017 | May 13, 2026 |
| | CVE-2017-7339 | Fortinet | medium | 6.1 | 0.3%
| | A Cross-Site Scripting vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an atta… | May 27, 2017 | May 13, 2026 |
| | CVE-2017-7338 | Fortinet | high | 7.5 | 0.3%
| | A password management vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an attac… | May 27, 2017 | May 13, 2026 |
| | CVE-2017-7337 | Fortinet | critical | 9.1 | 0.2%
| | An improper Access Control vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows an … | May 27, 2017 | May 13, 2026 |
| | CVE-2017-3129 | Fortinet | medium | 6.1 | 0.3%
| | A Cross-Site Scripting vulnerability in Fortinet FortiWeb versions 5.7.1 and below allows attacker t… | May 27, 2017 | May 13, 2026 |
| | CVE-2017-3125 | Fortinet | medium | 6.1 | 0.6%
| | An unauthenticated XSS vulnerability with FortiMail 5.0.0 - 5.2.9 and 5.3.0 - 5.3.8 could allow an a… | Apr 12, 2017 | May 13, 2026 |
| | CVE-2016-8494 | Fortinet | high | 7.2 | 1.1%
| | Insufficient verification of uploaded files allows attackers with webui administrators privileges to… | Feb 9, 2017 | May 13, 2026 |
| | CVE-2016-7561 | Fortinet | high | 7.2 | 0.3%
| | Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, and 8.2-4-0 allow admin… | Oct 5, 2016 | May 6, 2026 |
| | CVE-2016-7560 | Fortinet | critical | 9.8 | 2.6%
| | The rsyncd server in Fortinet FortiWLC 6.1-2-29 and earlier, 7.0-9-1, 7.0-10-0, 8.0-5-0, 8.1-2-0, an… | Oct 5, 2016 | May 6, 2026 |
| | CVE-2016-4969 | Fortinet | medium | 6.1 | 0.7%
| | Cross-site scripting (XSS) vulnerability in Fortinet FortiWan (formerly AscernLink) before 4.2.5 all… | Sep 21, 2016 | May 6, 2026 |
| | CVE-2016-4968 | Fortinet | medium | 6.5 | 3.5%
| | The linkreport/tmp/admin_global page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows … | Sep 21, 2016 | May 6, 2026 |
| | CVE-2016-4967 | Fortinet | medium | 6.5 | 1.9%
| | Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users to obtain sen… | Sep 21, 2016 | May 6, 2026 |
| | CVE-2016-4966 | Fortinet | medium | 6.5 | 2.3%
| | The diagnosis_control.php page in Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote… | Sep 21, 2016 | May 6, 2026 |
| | CVE-2016-4965 | Fortinet | high | 8.8 | 7.7%
| | Fortinet FortiWan (formerly AscernLink) before 4.2.5 allows remote authenticated users with access t… | Sep 21, 2016 | May 6, 2026 |
| | CVE-2016-5092 | Fortinet | medium | 4.9 | 0.3%
| | Directory traversal vulnerability in Fortinet FortiWeb before 5.5.3 allows remote authenticated admi… | Jul 13, 2016 | May 6, 2026 |
| | CVE-2016-4066 | Fortinet | high | 8.8 | 0.1%
| | Cross-site request forgery (CSRF) vulnerability in Fortinet FortiWeb before 5.5.3 allows remote atta… | Jul 13, 2016 | May 6, 2026 |
| | CVE-2015-7362 | Fortinet | high | 7.8 | 0.0%
| | Fortinet FortiClient Linux SSLVPN before build 2313, when installed on Linux in a home directory tha… | Jan 8, 2016 | May 6, 2026 |
| | CVE-2015-5737 | Fortinet | high | 7.2 | 0.1%
| | The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, (4) mdare64_52.sys, and (5) Fortishi… | Sep 3, 2015 | May 6, 2026 |
| | CVE-2015-5736 | Fortinet | high | 7.2 | 2.5%
| | The Fortishield.sys driver in Fortinet FortiClient before 5.2.4 allows local users to execute arbitr… | Sep 3, 2015 | May 6, 2026 |
| | CVE-2015-5735 | Fortinet | high | 7.2 | 0.1%
| | The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fo… | Sep 3, 2015 | May 6, 2026 |
| | CVE-2015-4077 | Fortinet | low | 2.1 | 0.2%
| | The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fo… | Sep 3, 2015 | May 6, 2026 |
| | CVE-2014-8619 | Fortinet | medium | 4.3 | 0.3%
| | Cross-site scripting (XSS) vulnerability in the autolearn configuration page in Fortinet FortiWeb 5.… | May 12, 2015 | May 6, 2026 |
| | CVE-2015-3293 | Fortinet | medium | 4.0 | 0.2%
| | FortiMail 5.0.3 through 5.2.3 allows remote administrators to obtain credentials via the "diag debug… | Apr 14, 2015 | May 6, 2026 |
| | CVE-2015-2281 | Fortinet | high | 7.5 | 31.6%
| | Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164… | Mar 19, 2015 | May 6, 2026 |
| | CVE-2014-8617 | Fortinet | medium | 4.3 | 0.3%
| | Cross-site scripting (XSS) vulnerability in the Web Action Quarantine Release feature in the WebGUI … | Mar 4, 2015 | May 6, 2026 |
| | CVE-2015-1570 | Fortinet | medium | 4.3 | 0.1%
| | The Endpoint Control protocol implementation in Fortinet FortiClient 5.2.3.091 for Android and 5.2.0… | Feb 10, 2015 | May 6, 2026 |
| | CVE-2015-1569 | Fortinet | medium | 4.3 | 0.1%
| | Fortinet FortiClient 5.2.028 for iOS does not validate certificates, which makes it easier for man-i… | Feb 10, 2015 | May 6, 2026 |
| | CVE-2015-1459 | Fortinet | medium | 4.3 | 0.4%
| | Cross-site scripting (XSS) vulnerability in Fortinet FortiAuthenticator 3.0.0 allows remote attacker… | Feb 3, 2015 | May 6, 2026 |
| | CVE-2015-1458 | Fortinet | medium | 6.9 | 0.1%
| | Fortinet FortiAuthenticator 3.0.0 allows local users to bypass intended restrictions and gain privil… | Feb 3, 2015 | May 6, 2026 |
| | CVE-2015-1457 | Fortinet | medium | 4.9 | 0.1%
| | Fortinet FortiAuthenticator 3.0.0 allows local users to read arbitrary files via the -f flag to the … | Feb 3, 2015 | May 6, 2026 |
| | CVE-2015-1456 | Fortinet | medium | 4.0 | 0.3%
| | Fortinet FortiAuthenticator 3.0.0 logs the PostgreSQL usernames and passwords in cleartext, which al… | Feb 3, 2015 | May 6, 2026 |
| | CVE-2015-1455 | Fortinet | high | 7.5 | 0.7%
| | Fortinet FortiAuthenticator 3.0.0 has a password of (1) slony for the slony PostgreSQL user and (2) … | Feb 3, 2015 | May 6, 2026 |
| | CVE-2015-1453 | Fortinet | medium | 5.0 | 0.2%
| | The qm class in Fortinet FortiClient 5.2.3.091 for Android uses a hardcoded encryption key of FoRtIn… | Feb 2, 2015 | May 6, 2026 |
| | CVE-2014-4738 | Fortinet | medium | 4.3 | 0.3%
| | Multiple cross-site scripting (XSS) vulnerabilities in FortiGuard FortiWeb 5.0.x, 5.1.x, and 5.2.x b… | Jul 11, 2014 | May 6, 2026 |
| | CVE-2014-3115 | Fortinet | medium | 6.8 | 0.2%
| | Multiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Fort… | May 8, 2014 | May 6, 2026 |