5.1

CVSS3.1

CVE-2025-27606 - Element Android PIN autologout bypass

Element Android is an Android Matrix Client provided by Element. Element Android up to version 1.6.32 can, under certain circumstances, fail to logout the user if they input the wrong PIN more than the configured amount of times. An attacker with physical access to a device can exploit this to gues…

πŸ“… Published: March 14, 2025, 4:56 p.m. πŸ”„ Last Modified: March 14, 2025, 6:11 p.m.

5.5

CVSS3.1

CVE-2024-55594 -

An improper handling of syntactically invalid structure in Fortinet FortiWeb at least vesrions 7.4.0 through 7.4.6 and 7.2.0 through 7.2.10 and 7.0.0 through 7.0.10 allows attacker to execute unauthorized code or commands via HTTP/S crafted requests.

πŸ“… Published: March 14, 2025, 4:25 p.m. πŸ”„ Last Modified: March 14, 2025, 5:15 p.m.

4.6

CVSS3.1

CVE-2025-1888 - Reflected Cross Site Scripting in Aperio Eslide Manager

The Leica Web Viewer within the Aperio Eslide Manager Application is vulnerable to reflected cross-site scripting (XSS). An authenticated user can access the slides within a project and injecting malicious JavaScript into the "memo" field. The memo field has a hover over action that will display a …

πŸ“… Published: March 14, 2025, 4:11 p.m. πŸ”„ Last Modified: March 14, 2025, 5:15 p.m.

4.4

CVSS3.1

CVE-2023-48785 -

An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the HTTPS communication channel between the FortiOS device, an inventory, and FortiNAC-F.

πŸ“… Published: March 14, 2025, 3:46 p.m. πŸ”„ Last Modified: March 14, 2025, 5:17 p.m.

4.8

CVSS3.1

CVE-2023-33300 -

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted request in inter-server communication port.

πŸ“… Published: March 14, 2025, 3:46 p.m. πŸ”„ Last Modified: March 14, 2025, 5:24 p.m.

7.8

CVSS3.1

CVE-2023-45588 -

An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process.

πŸ“… Published: March 14, 2025, 3:46 p.m. πŸ”„ Last Modified: March 14, 2025, 5:40 p.m.

5.9

CVSS3.1

CVE-2024-40585 -

An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and below, version 6.2.11 and below and FortiAnalyzer version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, versio…

πŸ“… Published: March 14, 2025, 3:45 p.m. πŸ”„ Last Modified: March 14, 2025, 5:48 p.m.

2.6

CVSS3.1

CVE-2022-29059 -

An improper neutralization of special elements used in an SQL commandΒ ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, 6.2.7 and below may allow a privileged attacker to execute SQL commands over the log database via specifically craft…

πŸ“… Published: March 14, 2025, 3:45 p.m. πŸ”„ Last Modified: March 14, 2025, 5:52 p.m.

6

CVSS3.1

CVE-2024-47573 -

An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2.1 and below, version 7.1.1 and below, version 7.0.6 and below may allow an authenticated attacker with at least Read/Write permission on system maintenance to install a corrupted…

πŸ“… Published: March 14, 2025, 3:04 p.m. πŸ”„ Last Modified: March 14, 2025, 5:53 p.m.

8.3

CVSS3.1

CVE-2024-46662 -

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted packets

πŸ“… Published: March 14, 2025, 3:03 p.m. πŸ”„ Last Modified: March 15, 2025, 3:55 a.m.
Total resulsts: 285313
Page 4 of 28,532
Β« previous page Β» next page
Filters