Known vulnerabilities in Fortinet, Inc FortiProxy

Vendor: Fortinet, Inc
Website: https://www.fortinet.com/
Total Security Bulletins: 98

Security bulletins (98)

Secuity bulletin Severity Status Published
SB2025121064: FortiCloud SSO login authentication bypass in Fortinet products Critical
Patched Exploited
10.12.2025
SB2025120983: REST API key disclosure in Fortinet products Low
Patched
09.12.2025
SB2025111873: Improper privilege management in Fortinet products Low
Patched
18.11.2025
SB2025102464: Use of uninitialized resource in FortiOS and FortiProxy SSL-VPN Medium
Patched
24.10.2025
SB2025102162: Multiple vulnerabilities in Fortinet FortiOS, FortiProxy and FortiSASE Low
Patched
21.10.2025
SB2025101576: Stack-based buffer overflow in FortiOS and FortiProxy Low
Patched
15.10.2025
SB2025101575: Improper validation of certificate with host mismatch in FortiOS and FortiProxy Medium
Patched
15.10.2025
SB2025101507: Insertion of Sensitive Information Into Sent Data in Fortinet products Low
Patched
15.10.2025
SB2025101505: Inclusion of Sensitive Information in Log Files in FortiOS and FortiProxy Low
Patched
15.10.2025
SB2025101503: Heap-based buffer overflow in Fortinet products Low
Patched
15.10.2025
SB20251014110: Improper Authorization in FortiOS and FortiProxy Low
Patched
14.10.2025
SB20251014108: Heap-based buffer overflow in Fortinet products Medium
Patched
14.10.2025
SB20251014106: Heap-based buffer overflow in Fortinet products Low
Patched
14.10.2025
SB20251014105: Improperly implemented security check for standard in FortiOS and FortiProxy Low
Patched
14.10.2025
SB20251014102: Improper Check or Handling of Exceptional Conditions in Fortinet products Medium
Patched
14.10.2025
SB2025081299: Integer overflow in Fortinet products Low
Patched
12.08.2025
SB2025081297: Authentication bypass using an alternate path or channel in Fortinet products High
Patched
12.08.2025
SB2025081281: Double free in Fortinet products Low
Patched
12.08.2025
SB2025070844: Missing critical step in authentication in FortiOS and FortiProxy Low
Patched
08.07.2025
SB2025070843: Improperly implemented security check for standard in FortiOS and FortiProxy Medium
Patched
08.07.2025
SB2025061119: Improper privilege management in Fortinet products Low
Patched
11.06.2025
SB2025061115: Authentication bypass using an alternate path or channel in FortiOS and FortiProxy Low
Patched
11.06.2025
SB2025061110: Man-in-the-Middle (MitM) attack in FortiOS and FortiProxy Medium
Patched
11.06.2025
SB2025061107: Incomplete cleanup in FortiOS and FortiProxy Low
Patched
11.06.2025
SB2025051366: Missing authentication for critical function in Fortinet products High
Patched
13.05.2025
SB2025041046: Multiple vulnerabilities in Fortinet products High
Patched
10.04.2025
SB2025040910: MitM attack in FortiProxy High
Patched
09.04.2025
SB2025031210: Privilege escalation in FortiProxy Low
Patched
12.03.2025
SB2025021207: Privilege escalation in FortiProxy CLI Low
Patched
12.02.2025
SB2025011652: Multiple path traversal vulnerabilities in FortiProxy Medium
Patched
16.01.2025
SB2025011435: HTTP response splitting in FortiOS and FortiProxy Medium
Patched
14.01.2025
SB2025011431: Authentication bypass in FortiOS and FortiProxy Critical
Patched Exploited
14.01.2025
SB2024111836: Text injection in FortiOS and FortiProxy SSL-VPN WEB UI Low
Patched
18.11.2024
SB20241112158: Improper authentication in FortiProxy fgfmd Medium
Patched
12.11.2024
SB2024111202: MitM attack in FortiProxy RADIUS protocol Medium
Patched Public exploit
12.11.2024
SB2024081474: Insufficient session expiration in Fortinet products Low
Patched
14.08.2024
SB20240709118: Security restrictions bypass in FortiOS Low
Patched
09.07.2024
SB2024070992: XSS in SSL VPN web UI for FortiOS and FortiProxy Low
Patched
09.07.2024
SB20240611283: Weak key derivation for backup file in FortiOS and FortiProxy Low
Patched
11.06.2024


Showing elements 1 - 40 out of 98