Fortinet Fortimanager Cloud vulnerabilities
28 known vulnerabilities affecting fortinet/fortimanager_cloud.
Total CVEs
28
CISA KEV
1
actively exploited
Public exploits
1
Exploited in wild
1
Severity breakdown
CRITICAL5HIGH17MEDIUM4LOW2
Vulnerabilities
Page 2 of 2
CVE-2024-33505P3HIGHCVSS 7.3≥ 6.4.1, < 7.2.7≥ 7.4.1, < 7.4.32024-11-12
CVE-2024-33505 [HIGH] CWE-122 CVE-2024-33505: A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.
A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privilege via specially crafted http requests
nvd
CVE-2024-33503P3HIGHCVSS 7.8≥ 7.0.1, < 7.2.7≥ 7.4.1, < 7.4.4+3 more2025-01-14
CVE-2024-33503 [HIGH] CWE-266 CVE-2024-33503: A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, Fo
A improper privilege management vulnerability in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiManager Cloud 7.2.1 through 7.2.5, FortiManager Cloud 7.0 all versions, FortiManager 7.4.0 through 7.4.3, FortiManager 7.2.0 through 7.2.5, FortiManager 7.0 all versions, FortiManager 6.4 all versions allows attacker to escalation of privilege via sp
nvd
CVE-2024-52964P3MEDIUMCVSS 6.5≥ 6.4.1, ≤ 7.0.13≥ 7.2.1, < 7.2.10+1 more2025-08-12
CVE-2024-52964 [MEDIUM] CWE-22 CVE-2024-52964: An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9 and below 7.0.13 & FortiManager Cloud version 7.6.0 through 7.6.1, 7.4.0 through 7.4.5 and before 7.2.9 allows an authenticated remote attacker to overw
nvd
CVE-2025-68649P3MEDIUMCVSS 6.5≥ 7.0.0, < 7.4.8≥ 7.6.0, < 7.6.5+4 more2026-04-14
CVE-2025-68649 [MEDIUM] CWE-22 CVE-2025-68649: An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in F
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.7, FortiAnalyzer Cloud 7.2 all
nvd
CVE-2025-68482P3MEDIUMCVSS 5.9≥ 7.6.2, ≤ 7.6.3≥ 7.4.1, ≤ 7.4.7+3 more2026-03-10
CVE-2025-68482 [MEDIUM] CWE-295 CVE-2025-68482: A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, Forti
A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versi
nvd
CVE-2024-47569P4MEDIUMCVSS 4.3≥ 7.4.1, < 7.4.4≥ 7.4.1, ≤ 7.4.32025-10-14
CVE-2024-47569 [MEDIUM] CWE-201 CVE-2024-47569: A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 throug
A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager Cloud 7.4.1 through 7.4.3, FortiNDR 7.6.0 through 7.6.1, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 al
nvd
CVE-2026-22629P4LOWCVSS 3.7≥ 6.4.0, < 7.6.5≥ 7.6.2, ≤ 7.6.3+4 more2026-03-10
CVE-2026-22629 [LOW] CWE-307 CVE-2026-22629: An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer
An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4 all versions, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4 all versions, FortiAnalyzer Cloud 7.2 a
nvd
CVE-2025-24474P4LOWCVSS 2.7≥ 6.4.1, < 7.4.72025-07-08
CVE-2025-24474 [LOW] CWE-89 CVE-2025-24474: An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerabilit
An Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiManager Cloud 7.4.1 through 7.4.6, 7.2 all versions, 7.0 all versions, 6.4 all versions; FortiAnalyzer 7.6.0 through 7.6.1, 7.4
nvd
← Previous2 / 2