Home/Product/fortinet forticlientems
Product

fortinet forticlientems

13 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-39810
>= 7.4.0 and < 7.4.6
A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to informati
6.0MEDIUM
CVE-2026-39809
>= 7.0.0 and <= 7.0.13
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.
6.7MEDIUM
CVE-2026-35616
all versions
A improper access control vulnerability in Fortinet FortiClientEMS 7.4.5 through 7.4.6 may allow an unauthenticated attacker to ex
9.8CRITICAL
CVE-2026-21643
all versions
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7
9.8CRITICAL
CVE-2025-59922
>= 7.0.0 and < 7.2.12
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fo
7.2HIGH
CVE-2024-32119
>= 6.2.0 and <= 6.2.9
An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthentic
4.8MEDIUM
CVE-2023-48786
>= 6.4.0 and <= 6.4.9
A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may
4.3MEDIUM
CVE-2025-22859
>= 7.4.0 and < 7.4.3
A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4
5.3MEDIUM
CVE-2025-22855
>= 7.2.1 and <= 7.2.10
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiCl
2.7LOW
CVE-2019-16149
< 6.2.1
An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to exec
5.5MEDIUM
CVE-2024-36510
>= 7.0.0 and < 7.2.5
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and For
5.3MEDIUM
CVE-2024-36506
>= 6.4.0 and < 7.2.5
An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4
3.7LOW
CVE-2024-23106
>= 6.2.0 and <= 6.2.9
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.
8.1HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin