4

CVSS3.1

CVE-2024-33501 -

Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 …

πŸ“… Published: March 11, 2025, 2:54 p.m. πŸ”„ Last Modified: July 24, 2025, 7:05 p.m.

4.1

CVSS3.1

CVE-2024-54026 -

An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0 all versions, FortiSandb…

πŸ“… Published: March 11, 2025, 2:54 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 3:15 p.m.

6.5

CVSS3.1

CVE-2024-32123 -

Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 through 6.2.12 and 6.0.0 through 6.0.12 and 5.6.0…

πŸ“… Published: March 11, 2025, 2:54 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

6.5

CVSS3.1

CVE-2024-54018 -

MultipleΒ improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker to execute unauthorized commands via crafted requests.

πŸ“… Published: March 11, 2025, 2:54 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

8.6

CVSS3.1

CVE-2023-37933 -

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC GUI version 7.4.0, 7.2.0 through 7.2.1 and before 7.1.3 allows an authenticated attacker to perform an XSS attack via crafted HTTP or HTTPs requests.

πŸ“… Published: March 11, 2025, 2:54 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

4.2

CVSS3.1

CVE-2024-52960 -

A client-side enforcement of server-side security vulnerability [CWE-602]Β in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via crafted requests.

πŸ“… Published: March 11, 2025, 2:54 p.m. πŸ”„ Last Modified: Jan. 14, 2026, 2:15 p.m.

8.6

CVSS3.1

CVE-2024-55590 -

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiIsolator version 2.4.0 through 2.4.5 allows an authenticated attacker with at least read-only admin permission and CLI access to execute unauthorized code vi…

πŸ“… Published: March 11, 2025, 2:54 p.m. πŸ”„ Last Modified: July 23, 2025, 3:45 p.m.

7

CVSS3.1

CVE-2024-45324 -

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 and before 7.0.19, FortiPAM version 1.4.0 th…

πŸ“… Published: March 11, 2025, 2:54 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

6.5

CVSS3.1

CVE-2024-46663 -

A stack-buffer overflow vulnerability [CWE-121] in Fortinet FortiMail CLI version 7.6.0 through 7.6.1 and before 7.4.3 allows a privileged attacker to execute arbitrary code or commands via specifically crafted CLI commands.

πŸ“… Published: March 11, 2025, 2:54 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

7.1

CVSS3.1

CVE-2023-48790 -

A cross site request forgery vulnerability [CWE-352] in Fortinet FortiNDR version 7.4.0, 7.2.0 through 7.2.1 and 7.1.0 through 7.1.1 and before 7.0.5 may allow a remote unauthenticated attacker to execute unauthorized actions via crafted HTTP GET requests.

πŸ“… Published: March 11, 2025, 2:54 p.m. πŸ”„ Last Modified: July 22, 2025, 9:22 p.m.
Total resulsts: 349182
Page 6386 of 34,919
Β« previous page Β» next page
Filters