Skip to content
VulniPulse

Complete feed

Recently updated

Advisories the vendor has revised

Home overview

Android app · Google Play

Take your CVE monitoring with you.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Low3.4Fortinet

Low [CVE-2025-62675] Header injection in Web Filter warning page

CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter override token to inject arbitrary headers via tricking a user into clicking on a crafted link. Revised on 2026-07-14 00:00:00

CVE-2025-62675
FortiGateFirewallFortiOSFortiProxy
Jul 14, 2026
Low3.1Fortinet

Low [CVE-2025-62826] Header injection in captive portal authentication form

CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and modify a user's authentication request to inject arbitrary headers via crafted HTTP requests. Revised on 2026-07-14 00:00:00

CVE-2025-62826
FortiGateFirewallFortiOSFortiProxy
Jul 14, 2026
Low2.1Fortinet

Low [CVE-2026-44278] Hardcoded Encryption Key Used for VPN Saved Passwords

CVSSv3 Score: 2.1 A Missing Authorization [CWE-862] in FortiClient Windows may allow an authenticated local attacker to decrypt a currently logged in users VPN password via use of an unprotected DLL function. Revised on 2026-05-12 00:00:00

CVE-2026-44278
FortiClient
May 12, 2026
Low2.5Fortinet

Low [CVE-2026-27316] Credential disclosure in LDAP configuration web page.

CVSSv3 Score: 2.5 An Insufficiently protected credentials vulnerability [CWE-522] in FortiSanbox and FortiSanbox PaaS GUI may allow an authenticated administrator to read LDAP server credentials via client-side inspection. Revised on 2026-04-14 00:00:00

CVE-2026-27316
Unclassified
Apr 14, 2026
Low2.2Fortinet

Low [CVE-2026-21741] Open Redirection via Import CSV option

CVSSv3 Score: 2.2 An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] in FortiNAC-F may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file. Revised on 2026-04-14 00:00:00

CVE-2026-21741
FortiNAC
Apr 14, 2026
Low1.8Fortinet

Low [CVE-2025-54821] Trusted hosts bypass via SSH

CVSSv3 Score: 1.8 An Improper Privilege Management vulnerability [CWE-269] in FortiOS, FortiProxy and FortiPAM may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command. Revised on 2026-05-27 00:00:00 Affected products named by the advisory: FortiSASE.

CVE-2025-54821
FortiGateFirewallFortiOS
Nov 18, 2025
Low2.6Fortinet

Low [CVE-2025-31514] Insertion of Sensitive 2FA Information in logs and debug command

CVSSv3 Score: 2.6 An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS may allow an attacker with at least read-only privileges to retrieve sensitive 2FA-related information via observing logs or via diagnose command. Revised on 2026-06-08 00:00:00 Affected products named by the advisory: FortiProxy.

CVE-2025-31514
FortiGateFirewallFortiOSFortiProxy
Oct 14, 2025
Low3.9Fortinet

Low [CVE-2025-25250] Information Disclosure on SSLVPN endpoint

CVSSv3 Score: 3.9 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS SSL-VPN web-mode may allow an authenticated user to access full SSL-VPN settings via crafted URL. Revised on 2026-06-15 00:00:00 Affected products named by the advisory: FortiSASE.

CVE-2025-25250
FortiGateFirewallFortiOS
Jun 10, 2025