CVE Feed

    Dashboard / CVE

    6.7
    Medium

    CVE-2023-29177

    Last Modified: 21 Nov 2024

    Multiple buffer copy without checking size of input ('classic buffer overflow') vulnerabilities [CWE-120] in FortiADC version 7.2.0 and before 7.1.2 & FortiDDoS-F version 6.5.0 and before 6.4.1 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI requests.

    Published: 14 Nov 2023
    5.4
    Medium

    CVE-2023-36633

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.

    Published: 14 Nov 2023
    9.8
    Critical

    CVE-2023-34991

    Last Modified: 16 Dec 2025

    A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8.4.2 and 8.3.0 through 8.3.2 and 8.2.2 allows attacker to execute unauthorized code or commands via a crafted http request.

    Published: 14 Nov 2023
    4.4
    Medium

    CVE-2023-33304

    Last Modified: 21 Nov 2024

    A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system protections via the use of static credentials.

    Published: 14 Nov 2023
    4.4
    Medium

    CVE-2023-44248

    Last Modified: 14 Jan 2026

    An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow a local attacker to prevent the collector service to start in the next system reboot by tampering with some registry keys of the service.

    Published: 14 Nov 2023
    8.1
    High

    CVE-2023-26205

    Last Modified: 16 Dec 2025

    An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script.

    Published: 14 Nov 2023
    2.3
    Low

    CVE-2023-45585

    Last Modified: 21 Nov 2024

    An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 and below, version 6.6.3 and below, version 6.5.1 and below, version 6.4.2 and below, version 6.3.3 and below, version 6.2.1 and below, version 6.1.2 and below, version 5.4.0, version 5.3.3 and below may allow an authenticated user to view an encrypted ElasticSearch password via debug log files generated when FortiSIEM is configured with ElasticSearch Event Storage.

    Published: 14 Nov 2023
    4.3
    Medium

    CVE-2023-41676

    Last Modified: 21 Nov 2024

    An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs.

    Published: 14 Nov 2023
    5.6
    Medium

    CVE-2023-45582

    Last Modified: 21 Nov 2024

    An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to  perform a brute force attack on the affected endpoints via repeated login attempts.

    Published: 14 Nov 2023
    9.8
    Critical

    CVE-2023-36553

    Last Modified: 16 Dec 2025

    A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 and 4.9.0 and 4.7.2 allows attacker to execute unauthorized code or commands via crafted API requests.

    Published: 14 Nov 2023
    6.4
    Medium

    CVE-2023-28002

    Last Modified: 11 Jun 2025

    An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions and VMs may allow a local attacker with admin privileges to boot a malicious image on the device and bypass the filesystem integrity check in place.

    Published: 14 Nov 2023
    6.5
    Medium

    CVE-2023-36641

    Last Modified: 21 Nov 2024

    A numeric truncation error in Fortinet FortiProxy version 7.2.0 through 7.2.4, FortiProxy version 7.0.0 through 7.0.10, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1, all versions, FortiProxy 1.0 all versions, FortiOS version 7.4.0, FortiOS version 7.2.0 through 7.2.5, FortiOS version 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions allows attacker to denial of service via specifically crafted HTTP requests.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-41840

    Last Modified: 16 Dec 2025

    A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path.

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-42783

    Last Modified: 21 Nov 2024

    A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.2 through 8.4.0 and 8.3.2 through 8.3.0 and 8.2.2 allows attacker to read arbitrary files via crafted http requests.

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-36018

    Last Modified: 9 Oct 2025

    Visual Studio Code Jupyter Extension Spoofing Vulnerability

    Published: 14 Nov 2023
    6.2
    Medium

    CVE-2023-36016

    Last Modified: 9 Oct 2025

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

    Published: 14 Nov 2023
    8.8
    High

    CVE-2023-36025

    Last Modified: 28 Oct 2025

    Windows SmartScreen Security Feature Bypass Vulnerability

    Published: 14 Nov 2023
    8
    High

    CVE-2023-36021

    Last Modified: 9 Oct 2025

    Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-36033

    Last Modified: 28 Oct 2025

    Windows DWM Core Library Elevation of Privilege Vulnerability

    Published: 14 Nov 2023
    7.6
    High

    CVE-2023-36031

    Last Modified: 8 Oct 2025

    Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability

    Published: 14 Nov 2023
    6.1
    Medium

    CVE-2023-36030

    Last Modified: 8 Oct 2025

    Microsoft Dynamics 365 Sales Spoofing Vulnerability

    Published: 14 Nov 2023
    9.8
    Critical

    CVE-2023-36028

    Last Modified: 9 Oct 2025

    Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability

    Published: 14 Nov 2023
    8
    High

    CVE-2023-36035

    Last Modified: 8 Oct 2025

    Microsoft Exchange Server Spoofing Vulnerability

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-36037

    Last Modified: 8 Oct 2025

    Microsoft Excel Security Feature Bypass Vulnerability

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-36045

    Last Modified: 8 Oct 2025

    Microsoft Office Graphics Remote Code Execution Vulnerability

    Published: 14 Nov 2023
    6.2
    Medium

    CVE-2023-36042

    Last Modified: 8 Oct 2025

    Visual Studio Denial of Service Vulnerability

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-36041

    Last Modified: 8 Oct 2025

    Microsoft Excel Remote Code Execution Vulnerability

    Published: 14 Nov 2023
    8
    High

    CVE-2023-36039

    Last Modified: 8 Oct 2025

    Microsoft Exchange Server Spoofing Vulnerability

    Published: 14 Nov 2023
    8
    High

    CVE-2023-36050

    Last Modified: 8 Oct 2025

    Microsoft Exchange Server Spoofing Vulnerability

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-36047

    Last Modified: 8 Oct 2025

    Windows Authentication Elevation of Privilege Vulnerability

    Published: 14 Nov 2023
    7.1
    High

    CVE-2023-36046

    Last Modified: 8 Oct 2025

    Windows Authentication Denial of Service Vulnerability

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-36392

    Last Modified: 8 Oct 2025

    DHCP Server Service Denial of Service Vulnerability

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-36393

    Last Modified: 8 Oct 2025

    Windows User Interface Application Core Remote Code Execution Vulnerability

    Published: 14 Nov 2023
    7
    High

    CVE-2023-36394

    Last Modified: 8 Oct 2025

    Windows Search Service Elevation of Privilege Vulnerability

    Published: 14 Nov 2023
    7.5
    High

    CVE-2023-36395

    Last Modified: 8 Oct 2025

    Windows Deployment Services Denial of Service Vulnerability

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-36396

    Last Modified: 8 Oct 2025

    Windows Compressed Folder Remote Code Execution Vulnerability

    Published: 14 Nov 2023
    9.8
    Critical

    CVE-2023-36397

    Last Modified: 8 Oct 2025

    Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

    Published: 14 Nov 2023
    6.5
    Medium

    CVE-2023-36398

    Last Modified: 8 Oct 2025

    Windows NTFS Information Disclosure Vulnerability

    Published: 14 Nov 2023
    7.1
    High

    CVE-2023-36399

    Last Modified: 8 Oct 2025

    Windows Storage Elevation of Privilege Vulnerability

    Published: 14 Nov 2023
    8.8
    High

    CVE-2023-36400

    Last Modified: 8 Oct 2025

    Windows HMAC Key Derivation Elevation of Privilege Vulnerability

    Published: 14 Nov 2023
    7.2
    High

    CVE-2023-36401

    Last Modified: 8 Oct 2025

    Microsoft Remote Registry Service Remote Code Execution Vulnerability

    Published: 14 Nov 2023
    8.8
    High

    CVE-2023-36402

    Last Modified: 8 Oct 2025

    Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability

    Published: 14 Nov 2023
    7
    High

    CVE-2023-36403

    Last Modified: 8 Oct 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 14 Nov 2023
    5.5
    Medium

    CVE-2023-36404

    Last Modified: 8 Oct 2025

    Windows Kernel Information Disclosure Vulnerability

    Published: 14 Nov 2023
    7
    High

    CVE-2023-36405

    Last Modified: 17 Oct 2025

    Windows Kernel Elevation of Privilege Vulnerability

    Published: 14 Nov 2023
    5.5
    Medium

    CVE-2023-36406

    Last Modified: 8 Oct 2025

    Windows Hyper-V Information Disclosure Vulnerability

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-36407

    Last Modified: 8 Oct 2025

    Windows Hyper-V Elevation of Privilege Vulnerability

    Published: 14 Nov 2023
    7.8
    High

    CVE-2023-36408

    Last Modified: 8 Oct 2025

    Windows Hyper-V Elevation of Privilege Vulnerability

    Published: 14 Nov 2023
    8
    High

    CVE-2023-36439

    Last Modified: 8 Oct 2025

    Microsoft Exchange Server Remote Code Execution Vulnerability

    Published: 14 Nov 2023
    6.1
    Medium

    CVE-2023-38177

    Last Modified: 8 Oct 2025

    Microsoft SharePoint Server Remote Code Execution Vulnerability

    Published: 14 Nov 2023