2.2

CVSS3.1

CVE-2024-27780 -

Multiple Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerabilities [CWE-79] in FortiSIEM 7.1 all versions, 7.0 all versions, 6.7 all versions incident page may allow an authenticated attacker to perform a cross-site scripting attack via crafted HTTP reque…

📅 Published: Feb. 11, 2025, 4:09 p.m. 🔄 Last Modified: July 16, 2025, 2:54 p.m.

6.9

CVSS3.1

CVE-2024-27781 -

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all …

📅 Published: Feb. 11, 2025, 4:09 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

6.8

CVSS3.1

CVE-2024-40584 -

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.13, 6.4.0 through 6.4.15 and 6.2.2 through 6.2.13, Fortinet FortiManager version 7.4.0 t…

📅 Published: Feb. 11, 2025, 4:09 p.m. 🔄 Last Modified: July 22, 2025, 9:37 p.m.

5.9

CVSS3.1

CVE-2024-36508 -

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allows an authenticated admin user with diagnose…

📅 Published: Feb. 11, 2025, 4:09 p.m. 🔄 Last Modified: July 24, 2025, 7:04 p.m.

6.3

CVSS3.1

CVE-2024-40586 -

An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe.

📅 Published: Feb. 11, 2025, 4:09 p.m. 🔄 Last Modified: July 16, 2025, 3:11 p.m.

6.3

CVSS3.1

CVE-2023-40721 -

A use of externally-controlled format string vulnerability [CWE-134] vulnerability in Fortinet allows a privileged attacker to execute arbitrary code or commands via specially crafted requests.

📅 Published: Feb. 11, 2025, 4:09 p.m. 🔄 Last Modified: Jan. 14, 2026, 3:15 p.m.

6.8

CVSS3.1

CVE-2024-50567 -

An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input.

📅 Published: Feb. 11, 2025, 4:09 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

3.9

CVSS3.1

CVE-2024-33504 -

A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9, 7.0 all versions, 6.4 all versions may allow an attacker with JSON API access permissions to decrypt some secrets even if the 'priva…

📅 Published: Feb. 11, 2025, 4:09 p.m. 🔄 Last Modified: July 24, 2025, 8 p.m.

7.7

CVSS3.1

CVE-2024-35279 -

A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the CAPWAP control, provided the attacker were able to…

📅 Published: Feb. 11, 2025, 4:09 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

8

CVSS3.1

CVE-2024-40591 -

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the…

📅 Published: Feb. 11, 2025, 4:09 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.
Total resulsts: 343928
Page 6266 of 34,393
« previous page » next page
Filters