Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
fortinet fortiweb vulnerabilities and exploits
(subscribe to this query)
356
VMScore
CVE-2019-16157
An information exposure vulnerability in Fortinet FortiWeb 6.2.0 CLI and previous versions may allow an authenticated user to view sensitive information being logged via diagnose debug commands.
Fortinet Fortiweb
578
VMScore
CVE-2021-36182
A Improper neutralization of special elements used in a command ('Command Injection') in Fortinet FortiWeb version 6.3.13 and below allows malicious user to execute unauthorized code or commands via crafted HTTP requests
Fortinet Fortiweb
578
VMScore
CVE-2021-36193
Multiple stack-based buffer overflows in the command line interpreter of FortiWeb prior to 6.4.2 may allow an authenticated malicious user to achieve arbitrary code execution via specially crafted commands.
Fortinet Fortiweb
NA
CVE-2023-23783
A use of externally-controlled format string in Fortinet FortiWeb version 7.0.0 up to and including 7.0.1, FortiWeb 6.4 all versions allows malicious user to execute unauthorized code or commands via specially crafted command arguments.
Fortinet Fortiweb
NA
CVE-2023-22636
An unauthorized configuration download vulnerability in FortiWeb 6.3.6 up to and including 6.3.21, 6.4.0 up to and including 6.4.2 and 7.0.0 up to and including 7.0.4 may allow a local malicious user to access confidential configuration files via a crafted http request.
Fortinet Fortiweb
NA
CVE-2023-25602
A stack-based buffer overflow in Fortinet FortiWeb 6.4 all versions, FortiWeb versions 6.3.17 and previous versions, FortiWeb versions 6.2.6 and previous versions, FortiWeb versions 6.1.2 and previous versions, FortiWeb versions 6.0.7 and previous versions, FortiWeb versions 5.9....
Fortinet Fortiweb
NA
CVE-2022-40683
A double free in Fortinet FortiWeb version 7.0.0 up to and including 7.0.3 may allows malicious user to execute unauthorized code or commands via specially crafted commands
Fortinet Fortiweb
356
VMScore
CVE-2021-41026
A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 up to and including 6.3.15 may allow an authenticated malicious user to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.
Fortinet Fortiweb
383
VMScore
CVE-2021-22122
An improper neutralization of input during web page generation in FortiWeb GUI interface 6.3.0 up to and including 6.3.7 and version prior to 6.2.4 may allow an unauthenticated, remote malicious user to perform a reflected cross site scripting attack (XSS) by injecting malicious ...
Fortinet Fortiweb
1 Github repository
578
VMScore
CVE-2020-29018
A format string vulnerability in FortiWeb 6.3.0 up to and including 6.3.5 may allow an authenticated, remote malicious user to read the content of memory and retrieve sensitive data via the redir parameter.
Fortinet Fortiweb
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
5
6
7
8
9
NEXT »