Known vulnerabilities in FortiProxy - page 2
Vendor:
Fortinet, Inc
Software:
FortiProxy
Software CPE:
cpe:2.3:h:fortinet:fortiproxy:*:*:*:*:*:*:*:*
Website:
https://www.fortinet.com/
Total vulnerabilities:
122
Public exploits:
13
Known exploited (KEV):
12
Highest CVSSv4 Score:
9.3
Breakdown by Severity Chart
7.4.15
7.6.7
7.4.14
7.0.23
7.2.16
7.6.5
7.4.13
7.6.6
7.4.12
7.0.22
7.2.15
7.6.4
7.4.11
7.4.10
7.0.21
7.2.14
7.4.9
7.6.3
2.0.15
7.6.2
7.6.1
7.6.0
7.4.8
7.2.13
7.0.20
7.4.7
7.4.6
7.2.12
7.0.19
7.4.5
7.2.11
7.2.99
7.0.18
7.4.4
7.2.10
7.0.17
2.0.14
7.0.16
7.4.3
7.2.9
7.0.15
7.4.2
7.4.1
7.4.0
7.2.8
7.0.14
7.0.13
7.2.7
7.0.12
7.2.6
7.2.5
7.0.11
2.0.13
7.2.4
7.0.10
2.0.12
7.2.3
7.0.9
7.0.8
7.2.2
2.0.11
7.2.1
7.2.0
7.0.7
7.0.6
2.0.10
7.0.5
2.0.9
7.0.4
7.0.3
2.0.8
7.0.2
7.0.1
7.0.0
1.2.13
1.2.12
1.2.11
2.0.7
2.0.6
2.0.5
2.0.4
2.0.3
2.0.2
2.0.1
2.0.0
1.2.10
1.2.9
1.2.8
1.2.7
1.2.6
1.2.5
1.2.4
1.2.3
1.2.2
1.2.1
1.2.0
1.1.6
1.1.5
1.1.4
1.1.3
1.1.2
1.1.1
1.1.0
1.0.7
1.0.6
1.0.5
1.0.4
1.0.3
1.0.2
1.0.1
1.0.0
Vulnerabilities (122)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU117148 - Insertion of Sensitive Information Into Sent Data CVE-2024-47569 |
CWE-201 | Low | 7.2.11, 7.4.5 | 15.10.2025 |
SB2025101507 |
||
| #VU117146 - Information Exposure Through Log Files CVE-2025-31514 |
CWE-532 | Low | 7.6.4 | 15.10.2025 |
SB2025101505 |
||
| #VU117143 - Heap-based Buffer Overflow CVE-2025-22258 |
CWE-122 | Low | 7.4.8, 7.6.2 | 15.10.2025 |
SB2025101503 |
||
| #VU117139 - Improper Authorization CVE-2025-54822 |
CWE-285 | Low | 7.4.9 | 14.10.2025 |
SB20251014110 |
||
| #VU117136 - Heap-based Buffer Overflow CVE-2025-57740 |
CWE-122 | Medium | 7.4.4, 7.6.3 | 14.10.2025 |
SB20251014108 |
||
| #VU117134 - Heap-based Buffer Overflow CVE-2024-50571 |
CWE-122 | Low | 7.0.20, 7.2.13, 7.4.8, 7.6.2 | 14.10.2025 |
SB20251014106 |
||
| #VU117133 - Improperly Implemented Security Check for Standard CVE-2025-25255 |
CWE-358 | Low | 7.6.4 | 14.10.2025 |
SB20251014105 |
||
| #VU117130 - Improper Check or Handling of Exceptional Conditions CVE-2024-26008 |
CWE-703 | Medium | 7.2.10, 7.4.4 | 14.10.2025 |
SB20251014102 |
||
| #VU113960 - Integer overflow CVE-2025-25248 |
CWE-190 | Low | 7.4.4, 7.6.3 | 12.08.2025 |
SB2025081299 |
||
| #VU113958 - Authentication Bypass Using an Alternate Path or Channel CVE-2024-26009 |
CWE-288 | High | 7.0.16, 7.2.9, 7.4.3 | 12.08.2025 |
SB2025081297 |
||
| #VU113906 - Double Free CVE-2023-45584 |
CWE-415 | Low | 7.0.14, 7.2.8, 7.4.2 | 12.08.2025 |
SB2025081281 |
||
| #VU112496 - Missing Critical Step in Authentication CVE-2024-52965 |
CWE-304 | Low | 7.0.21, 7.2.14, 7.4.9, 7.6.2 | 08.07.2025 |
SB2025070844 |
||
| #VU112495 - Improperly Implemented Security Check for Standard CVE-2024-55599 |
CWE-358 | Medium | 7.4.9, 7.6.2 | 08.07.2025 |
SB2025070843 |
||
| #VU111054 - Improper Privilege Management CVE-2025-22254 |
CWE-269 | High | 7.4.8, 7.6.2 | 11.06.2025 |
SB2025061119 |
||
| #VU111050 - Authentication Bypass Using an Alternate Path or Channel CVE-2025-22862 |
CWE-288 | Low | 7.4.9, 7.6.3 | 11.06.2025 |
SB2025061115 |
||
| #VU111045 - Channel Accessible by Non-Endpoint ('Man-in-the-Middle') CVE-2024-50568 |
CWE-300 | Medium | 7.0.17, 7.2.10, 7.4.4 | 11.06.2025 |
SB2025061110 |
||
| #VU111042 - Incomplete cleanup CVE-2023-29184 |
CWE-459 | Low | 7.0.9, 7.2.3 | 11.06.2025 |
SB2025061107 |
||
| #VU109045 - Missing Authentication for Critical Function CVE-2025-22252 |
CWE-306 | High | 7.6.2 | 13.05.2025 |
SB2025051366 |
||
| #VU107372 - Weak Authentication CVE-2024-50563 |
CWE-1390 | High | 2.0.15, 7.0.18, 7.2.11, 7.4.5 | 10.04.2025 |
SB2025041046 |
||
| #VU107373 - Weak Authentication CVE-2024-48886 |
CWE-1390 | High | 2.0.15, 7.0.18, 7.2.11, 7.4.5 | 10.04.2025 |
SB2025041046 |
Showing elements 21 - 40 out of 122