CVE-2023-29177
Last Modified: 21 Nov 2024Multiple buffer copy without checking size of input ('classic buffer overflow') vulnerabilities [CWE-120] in FortiADC version 7.2.0 and before 7.1.2 & FortiDDoS-F version 6.5.0 and before 6.4.1 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI requests.
CVE-2023-36633
Last Modified: 21 Nov 2024An improper authorization vulnerability [CWE-285] in FortiMail webmail version 7.2.0 through 7.2.2 and before 7.0.5 allows an authenticated attacker to see and modify the title of address book folders of other users via crafted HTTP or HTTPs requests.
CVE-2023-34991
Last Modified: 16 Dec 2025A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.0 through 8.4.2 and 8.3.0 through 8.3.2 and 8.2.2 allows attacker to execute unauthorized code or commands via a crafted http request.
CVE-2023-33304
Last Modified: 21 Nov 2024A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system protections via the use of static credentials.
CVE-2023-44248
Last Modified: 14 Jan 2026An improper access control vulnerability [CWE-284] in FortiEDRCollectorWindows version 5.2.0.4549 and below, 5.0.3.1007 and below, 4.0 all may allow a local attacker to prevent the collector service to start in the next system reboot by tampering with some registry keys of the service.
CVE-2023-26205
Last Modified: 16 Dec 2025An improper access control vulnerability [CWE-284] in FortiADC automation feature 7.1.0 through 7.1.2, 7.0 all versions, 6.2 all versions, 6.1 all versions may allow an authenticated low-privileged attacker to escalate their privileges to super_admin via a specific crafted configuration of fabric automation CLI script.
CVE-2023-45585
Last Modified: 21 Nov 2024An insertion of sensitive information into log file vulnerability [CWE-532] in FortiSIEM version 7.0.0, version 6.7.6 and below, version 6.6.3 and below, version 6.5.1 and below, version 6.4.2 and below, version 6.3.3 and below, version 6.2.1 and below, version 6.1.2 and below, version 5.4.0, version 5.3.3 and below may allow an authenticated user to view an encrypted ElasticSearch password via debug log files generated when FortiSIEM is configured with ElasticSearch Event Storage.
CVE-2023-41676
Last Modified: 21 Nov 2024An exposure of sensitive information to an unauthorized actor [CWE-200] in FortiSIEM version 7.0.0 and before 6.7.5 may allow an attacker with access to windows agent logs to obtain the windows agent password via searching through the logs.
CVE-2023-45582
Last Modified: 21 Nov 2024An improper restriction of excessive authentication attempts vulnerability [CWE-307] in FortiMail webmail version 7.2.0 through 7.2.4, 7.0.0 through 7.0.6 and before 6.4.8 may allow an unauthenticated attacker to perform a brute force attack on the affected endpoints via repeated login attempts.
CVE-2023-36553
Last Modified: 16 Dec 2025A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 and 4.9.0 and 4.7.2 allows attacker to execute unauthorized code or commands via crafted API requests.
CVE-2023-28002
Last Modified: 11 Jun 2025An improper validation of integrity check value vulnerability [CWE-354] in FortiOS 7.2.0 through 7.2.3, 7.0.0 through 7.0.12, 6.4 all versions, 6.2 all versions, 6.0 all versions and VMs may allow a local attacker with admin privileges to boot a malicious image on the device and bypass the filesystem integrity check in place.
CVE-2023-36641
Last Modified: 21 Nov 2024A numeric truncation error in Fortinet FortiProxy version 7.2.0 through 7.2.4, FortiProxy version 7.0.0 through 7.0.10, FortiProxy 2.0 all versions, FortiProxy 1.2 all versions, FortiProxy 1.1, all versions, FortiProxy 1.0 all versions, FortiOS version 7.4.0, FortiOS version 7.2.0 through 7.2.5, FortiOS version 7.0.0 through 7.0.12, FortiOS 6.4 all versions, FortiOS 6.2 all versions, FortiOS 6.0 all versions allows attacker to denial of service via specifically crafted HTTP requests.
CVE-2023-41840
Last Modified: 16 Dec 2025A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path.
CVE-2023-42783
Last Modified: 21 Nov 2024A relative path traversal in Fortinet FortiWLM version 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4 and 8.4.2 through 8.4.0 and 8.3.2 through 8.3.0 and 8.2.2 allows attacker to read arbitrary files via crafted http requests.
CVE-2023-36018
Last Modified: 9 Oct 2025Visual Studio Code Jupyter Extension Spoofing Vulnerability
CVE-2023-36016
Last Modified: 9 Oct 2025Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-36025
Last Modified: 28 Oct 2025Windows SmartScreen Security Feature Bypass Vulnerability
CVE-2023-36021
Last Modified: 9 Oct 2025Microsoft On-Prem Data Gateway Security Feature Bypass Vulnerability
CVE-2023-36033
Last Modified: 28 Oct 2025Windows DWM Core Library Elevation of Privilege Vulnerability
CVE-2023-36031
Last Modified: 8 Oct 2025Microsoft Dynamics 365 (on-premises) Cross-site Scripting Vulnerability
CVE-2023-36030
Last Modified: 8 Oct 2025Microsoft Dynamics 365 Sales Spoofing Vulnerability
CVE-2023-36028
Last Modified: 9 Oct 2025Microsoft Protected Extensible Authentication Protocol (PEAP) Remote Code Execution Vulnerability
CVE-2023-36035
Last Modified: 8 Oct 2025Microsoft Exchange Server Spoofing Vulnerability
CVE-2023-36037
Last Modified: 8 Oct 2025Microsoft Excel Security Feature Bypass Vulnerability
CVE-2023-36045
Last Modified: 8 Oct 2025Microsoft Office Graphics Remote Code Execution Vulnerability
CVE-2023-36042
Last Modified: 8 Oct 2025Visual Studio Denial of Service Vulnerability
CVE-2023-36041
Last Modified: 8 Oct 2025Microsoft Excel Remote Code Execution Vulnerability
CVE-2023-36039
Last Modified: 8 Oct 2025Microsoft Exchange Server Spoofing Vulnerability
CVE-2023-36050
Last Modified: 8 Oct 2025Microsoft Exchange Server Spoofing Vulnerability
CVE-2023-36047
Last Modified: 8 Oct 2025Windows Authentication Elevation of Privilege Vulnerability
CVE-2023-36046
Last Modified: 8 Oct 2025Windows Authentication Denial of Service Vulnerability
CVE-2023-36392
Last Modified: 8 Oct 2025DHCP Server Service Denial of Service Vulnerability
CVE-2023-36393
Last Modified: 8 Oct 2025Windows User Interface Application Core Remote Code Execution Vulnerability
CVE-2023-36394
Last Modified: 8 Oct 2025Windows Search Service Elevation of Privilege Vulnerability
CVE-2023-36395
Last Modified: 8 Oct 2025Windows Deployment Services Denial of Service Vulnerability
CVE-2023-36396
Last Modified: 8 Oct 2025Windows Compressed Folder Remote Code Execution Vulnerability
CVE-2023-36397
Last Modified: 8 Oct 2025Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability
CVE-2023-36398
Last Modified: 8 Oct 2025Windows NTFS Information Disclosure Vulnerability
CVE-2023-36399
Last Modified: 8 Oct 2025Windows Storage Elevation of Privilege Vulnerability
CVE-2023-36400
Last Modified: 8 Oct 2025Windows HMAC Key Derivation Elevation of Privilege Vulnerability
CVE-2023-36401
Last Modified: 8 Oct 2025Microsoft Remote Registry Service Remote Code Execution Vulnerability
CVE-2023-36402
Last Modified: 8 Oct 2025Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
CVE-2023-36403
Last Modified: 8 Oct 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-36404
Last Modified: 8 Oct 2025Windows Kernel Information Disclosure Vulnerability
CVE-2023-36405
Last Modified: 17 Oct 2025Windows Kernel Elevation of Privilege Vulnerability
CVE-2023-36406
Last Modified: 8 Oct 2025Windows Hyper-V Information Disclosure Vulnerability
CVE-2023-36407
Last Modified: 8 Oct 2025Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2023-36408
Last Modified: 8 Oct 2025Windows Hyper-V Elevation of Privilege Vulnerability
CVE-2023-36439
Last Modified: 8 Oct 2025Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2023-38177
Last Modified: 8 Oct 2025Microsoft SharePoint Server Remote Code Execution Vulnerability
