6.7

CVSS3.1

CVE-2025-64157 -

A use of externally-controlled format string vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0 all versions allows an authenticated admin to execute unauthorized code or commands via specifically crafted configuration.

πŸ“… Published: Feb. 10, 2026, 3:39 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:42 p.m.

5.2

CVSS3.1

CVE-2025-55018 -

An inconsistent interpretation of http requests ('http request smuggling') vulnerability in Fortinet FortiOS 7.6.0, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4.3 through 6.4.16 may allow an unauthenticated attacker to smuggle an unlogged http reques…

πŸ“… Published: Feb. 10, 2026, 3:39 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:42 p.m.

7.5

CVSS3.1

CVE-2026-22153 -

An Authentication Bypass by Primary Weakness vulnerability [CWE-305] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4 may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, when the remote LDAP server is configured in a specific way.

πŸ“… Published: Feb. 10, 2026, 3:39 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:42 p.m.

6.8

CVSS3.1

CVE-2026-21743 -

A missing authorization vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.6, FortiAuthenticator 6.5 all versions, FortiAuthenticator 6.4 all versions, FortiAuthenticator 6.3 all versions may allow a read-only user to make modification to local users via a file upload to an unprotected …

πŸ“… Published: Feb. 10, 2026, 3:39 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:42 p.m.

7.9

CVSS3.1

CVE-2025-52436 -

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an unauthenticated atta…

πŸ“… Published: Feb. 10, 2026, 3:39 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:42 p.m.

0.0

CVE-2026-1774 - CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.

CASL Ability, versions 2.4.0 through 6.7.4, contains a prototype pollution vulnerability.

πŸ“… Published: Feb. 10, 2026, 3:38 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:42 p.m.

4.8

CVSS4.0

CVE-2025-15572 - wasm3 NewCodePage memory leak

A vulnerability has been found in wasm3 up to 0.5.0. The affected element is the function NewCodePage. The manipulation leads to memory leak. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. Unfortunately, the project has no active maintainer at …

πŸ“… Published: Feb. 10, 2026, 3:32 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:42 p.m.

7.5

CVSS4.0

CVE-2025-11004 - Reflected XSS vulnerability in Simplicity Device Manager tool

The Simplicity Device Manager Tool has a Reflected XSS (Cross-site-scripting) vulnerability in several API endpoints. The attacker needs to be on the same network to execute this attack.Β These APIs can affect confidentiality, integrity, and availability of the system that has Simplicity Device Mana…

πŸ“… Published: Feb. 10, 2026, 3:31 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:52 p.m.

8.6

CVSS3.1

CVE-2026-1603 -

An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data.

πŸ“… Published: Feb. 10, 2026, 3:09 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:51 p.m.

6.5

CVSS3.1

CVE-2026-1602 -

SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.

πŸ“… Published: Feb. 10, 2026, 3:07 p.m. πŸ”„ Last Modified: Feb. 10, 2026, 9:51 p.m.
Total resulsts: 332195
Page 32 of 33,220
Β« previous page Β» next page
Filters