cbcvebase.

Fortinet Fortiproxy vulnerabilities

130 known vulnerabilities affecting fortinet/fortiproxy.

Total CVEs
130
CISA KEV
12
actively exploited
Public exploits
10
Exploited in wild
14
Severity breakdown
CRITICAL17HIGH39MEDIUM71LOW3

Vulnerabilities

Page 5 of 7
CVE-2023-33306P4MEDIUMCVSS 6.5≥ 7.0.0, < 7.0.10≥ 7.2.0, < 7.2.4+2 more2023-06-16
CVE-2023-33306 [MEDIUM] CWE-476 CVE-2023-33306: A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, Forti A null pointer dereference in Fortinet FortiOS before 7.2.5, before 7.0.11 and before 6.4.13, FortiProxy before 7.2.4 and before 7.0.10 allows attacker to denial of sslvpn service via specifically crafted request in bookmark parameter.
nvd
CVE-2025-67862P4MEDIUMCVSS 6.7≥ 7.0.0, ≤ 7.0.23≥ 7.2.0, < 7.2.15+5 more2026-06-09
CVE-2025-67862 [MEDIUM] CWE-1244 CVE-2025-67862: An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerabili An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.7, FortiOS 7.2.0 through 7.2.10, FortiOS 7.0.0 through 7.0.16, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7
nvd
CVE-2022-23439P4MEDIUMCVSS 6.1≥ 2.0.0, < 7.0.5≥ 7.2.0, < 7.4.0+5 more2025-01-22
CVE-2022-23439 [MEDIUM] CWE-610 CVE-2022-23439: A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows A externally controlled reference to a resource in another sphere vulnerability in Fortinet allows attacker to poison web caches via crafted HTTP requests, where the `Host` header points to an arbitrary webserver
nvd
CVE-2025-47890P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.6.4≥ 7.6.0, ≤ 7.6.3+3 more2025-10-14
CVE-2025-47890 [MEDIUM] CWE-601 CVE-2025-47890: An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6 An URL Redirection to Untrusted Site vulnerabilities [CWE-601] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSA
nvd
CVE-2023-47536P4MEDIUMCVSS 5.3≥ 2.0.0, ≤ 2.0.12≥ 7.0.0, ≤ 7.0.9+1 more2023-12-13
CVE-2023-47536 [MEDIUM] CWE-284 CVE-2023-47536: An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and belo An improper access control vulnerability [CWE-284] in FortiOS version 7.2.0, version 7.0.13 and below, version 6.4.14 and below and FortiProxy version 7.2.3 and below, version 7.0.9 and below, version 2.0.12 and below may allow a remote unauthenticated attacker to bypass the firewall deny geolocalisation policy via timing the bypass with a GeoIP dat
nvd
CVE-2021-44170P4MEDIUMCVSS 6.7≥ 1.0.0, ≤ 1.0.7≥ 1.1.0, ≤ 1.1.6+2 more2022-07-18
CVE-2021-44170 [MEDIUM] CWE-787 CVE-2021-44170: A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS bef A stack-based buffer overflow vulnerability [CWE-121] in the command line interpreter of FortiOS before 7.0.4 and FortiProxy before 2.0.8 may allow an authenticated attacker to execute unauthorized code or commands via specially crafted command line arguments.
nvd
CVE-2021-43072P4MEDIUMCVSS 6.7≥ 1.0.0, < 2.0.9≥ 7.0.0, < 7.0.42023-07-18
CVE-2021-43072 [MEDIUM] CWE-120 CVE-2021-43072: A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer v A buffer copy without checking size of input ('classic buffer overflow') in Fortinet FortiAnalyzer version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6.11 and below, FortiManager version 7.0.2 and below, version 6.4.7 and below, version 6.2.9 and below, version 6.0.11 and below, version 5.6
nvd
CVE-2023-28002P4MEDIUMCVSS 6.7≥ 2.0.0, ≤ 2.0.13≥ 7.0.0, ≤ 7.0.13+2 more2023-11-14
CVE-2023-28002 [MEDIUM] CWE-354 CVE-2023-28002: An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2 An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions and VMs may allow a local attacker with admin privileges to boot a malicious image on the device and bypass the filesystem integrity check in place.
nvd
CVE-2025-31366P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.6.4≥ 7.6.0, ≤ 7.6.3+3 more2025-10-14
CVE-2025-31366 [MEDIUM] CWE-79 CVE-2025-31366: An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability An Improper Neutralization of Input During Web Page Generation vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4 all versions, FortiProxy 7.2 all versions, FortiProxy 7.0
nvd
CVE-2024-52963P4MEDIUMCVSS 5.9≥ 7.4.0, ≤ 7.4.5≥ 7.2.0, ≤ 7.2.13+2 more2025-01-14
CVE-2024-52963 [MEDIUM] CWE-787 CVE-2024-52963: A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets.
nvd
CVE-2023-41675P4MEDIUMCVSS 5.3≥ 7.0.0, ≤ 7.0.8v7.2.0+3 more2023-10-10
CVE-2023-41675 [MEDIUM] CWE-416 CVE-2023-41675: A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 th A use after free vulnerability [CWE-416] in FortiOS version 7.2.0 through 7.2.4 and version 7.0.0 through 7.0.10 and FortiProxy version 7.2.0 through 7.2.2 and version 7.0.0 through 7.0.8 may allow an unauthenticated remote attacker to crash the WAD process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alo
nvd
CVE-2022-42472P4MEDIUMCVSS 5.4≥ 1.1.0, ≤ 1.1.6≥ 1.2.0, ≤ 1.2.13+5 more2023-02-16
CVE-2022-42472 [MEDIUM] CWE-113 CVE-2022-42472: A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet A improper neutralization of crlf sequences in http headers ('http response splitting') in Fortinet FortiOS versions 7.2.0 through 7.2.2, 7.0.0 through 7.0.8, 6.4.0 through 6.4.11, 6.2.0 through 6.2.12, 6.0.0 through 6.0.16, FortiProxy 7.2.0 through 7.2.1, 7.0.0 through 7.0.7, 2.0.0 through 2.0.10, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6 may allow
nvd
CVE-2026-59839P4MEDIUMCVSS 5.5≥ 7.0.0, < 7.4.14≥ 7.6.0, < 7.6.6+4 more2026-07-14
CVE-2026-59839 [MEDIUM] CWE-22 CVE-2026-59839: A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fo A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.8.0, FortiPAM 1.7.0 through 1.7.2, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM
nvd
CVE-2022-41329P4MEDIUMCVSS 5.3≥ 7.0.0, ≤ 7.0.8≥ 7.2.0, ≤ 7.2.22023-03-07
CVE-2022-41329 [MEDIUM] CWE-200 CVE-2022-41329: An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet Fo An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in Fortinet FortiProxy version 7.2.0 through 7.2.1 and 7.0.0 through 7.0.7, FortiOS version 7.2.0 through 7.2.3 and 7.0.0 through 7.0.9 allows an unauthenticated attackers to obtain sensitive logging informations on the device via crafted HTTP GET requests.
nvd
CVE-2021-42757P4MEDIUMCVSS 6.7≥ 1.0.0, ≤ 2.0.7v7.0.0+5 more2021-12-08
CVE-2021-42757 [MEDIUM] CWE-120 CVE-2021-42757: A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 thr A buffer overflow [CWE-121] in the TFTP client library of FortiOS before 6.4.7 and FortiOS 7.0.0 through 7.0.2, may allow an authenticated local attacker to achieve arbitrary code execution via specially crafted command line arguments.
nvd
CVE-2026-23573P4MEDIUMCVSS 6.1≥ 7.2.0, < 7.2.10≥ 7.4.0, < 7.4.4+3 more2026-07-14
CVE-2026-23573 [MEDIUM] CWE-79 CVE-2026-23573: An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilit An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, FortiPAM 1.8.0, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1
nvd
CVE-2023-22641P4MEDIUMCVSS 5.4≥ 1.0.0, ≤ 2.0.12≥ 7.0.0, < 7.0.9+6 more2023-04-11
CVE-2023-22641 [MEDIUM] CWE-601 CVE-2023-22641: A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2. A url redirection to untrusted site ('open redirect') in Fortinet FortiOS version 7.2.0 through 7.2.3, FortiOS version 7.0.0 through 7.0.9, FortiOS versions 6.4.0 through 6.4.12, FortiOS all versions 6.2, FortiOS all versions 6.0, FortiProxy version 7.2.0 through 7.2.2, FortiProxy version 7.0.0 through 7.0.8, FortiProxy all versions 2.0, FortiProxy
nvd
CVE-2021-26092P4MEDIUMCVSS 6.1≥ 1.2.0, ≤ 1.2.9v2.0.0+1 more2022-02-24
CVE-2021-26092 [MEDIUM] CWE-79 CVE-2021-26092: Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through Failure to sanitize input in the SSL VPN web portal of FortiOS 5.2.10 through 5.2.15, 5.4.0 through 5.4.13, 5.6.0 through 5.6.14, 6.0.0 through 6.0.12, 6.2.0 through 6.2.7, 6.4.0 through 6.4.4; and FortiProxy 1.2.0 through 1.2.9, 2.0.0 through 2.0.1 may allow a remote unauthenticated attacker to perform a reflected Cross-site Scripting (XSS) attack by
nvd
CVE-2024-26006P4MEDIUMCVSS 6.1≥ 7.0.0, < 7.0.17≥ 7.2.0, < 7.2.10+4 more2025-03-14
CVE-2024-26006 [MEDIUM] CWE-79 CVE-2024-26006: An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS ver An improper neutralization of input during web page Generation vulnerability [CWE-79] in FortiOS version 7.4.3 and below, version 7.2.7 and below, version 7.0.13 and below and FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below web SSL VPN UI may allow a remote unauthenticated attacker to perform a Cross-Site Scripti
nvd
CVE-2022-38378P4MEDIUMCVSS 6.0≥ 1.1.0, ≤ 2.0.9≥ 7.0.0, < 7.0.8+5 more2023-02-16
CVE-2022-38378 [MEDIUM] CWE-269 CVE-2022-38378: An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and befor An improper privilege management vulnerability [CWE-269] in Fortinet FortiOS version 7.2.0 and before 7.0.7 and FortiProxy version 7.2.0 through 7.2.1 and before 7.0.7 allows an attacker that has access to the admin profile section (System subsection Administrator Users) to modify their own profile and upgrade their privileges to Read Write via CLI
nvd
Fortinet Fortiproxy vulnerabilities | cvebase