3.9

CVSS3.1

CVE-2024-33504 -

A use of hard-coded cryptographic key to encrypt sensitive data vulnerability [CWE-321] in FortiManager 7.6.0 through 7.6.1, 7.4.0 through 7.4.5, 7.2.0 through 7.2.9, 7.0 all versions, 6.4 all versions may allow an attacker with JSON API access permissions to decrypt some secrets even if the 'priva…

πŸ“… Published: Feb. 11, 2025, 4:09 p.m. πŸ”„ Last Modified: July 24, 2025, 8 p.m.

7.7

CVSS3.1

CVE-2024-35279 -

A stack-based buffer overflow [CWE-121] vulnerability in Fortinet FortiOS version 7.2.4 through 7.2.8 and version 7.4.0 through 7.4.4 allows a remote unauthenticated attacker to execute arbitrary code or commands via crafted UDP packets through the CAPWAP control, provided the attacker were able to…

πŸ“… Published: Feb. 11, 2025, 4:09 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

8

CVSS3.1

CVE-2024-40591 -

An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the…

πŸ“… Published: Feb. 11, 2025, 4:09 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

2.2

CVSS3.1

CVE-2024-52966 -

An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information disclosure via filter manipulation.

πŸ“… Published: Feb. 11, 2025, 4:09 p.m. πŸ”„ Last Modified: July 22, 2025, 9:38 p.m.

5.8

CVSS3.1

CVE-2024-52968 -

An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password.

πŸ“… Published: Feb. 11, 2025, 4:09 p.m. πŸ”„ Last Modified: July 16, 2025, 3:15 p.m.

6.3

CVSS3.1

CVE-2024-50569 -

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input.

πŸ“… Published: Feb. 11, 2025, 4:09 p.m. πŸ”„ Last Modified: Feb. 26, 2026, 7:09 p.m.

8.1

CVSS3.1

CVE-2025-24470 -

AnΒ Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests.

πŸ“… Published: Feb. 11, 2025, 4:08 p.m. πŸ”„ Last Modified: July 22, 2025, 9:38 p.m.

6.6

CVSS4.0

CVE-2025-24976 - Distribution's token authentication allows attacker to inject an untrusted signing key in a JWT

Distribution is a toolkit to pack, ship, store, and deliver container content. Systems running registry versions 3.0.0-beta.1 through 3.0.0-rc.2 with token authentication enabled may be vulnerable to an issue in which token authentication allows an attacker to inject an untrusted signing key in a J…

πŸ“… Published: Feb. 11, 2025, 3:48 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

9.4

CVSS3.1

CVE-2025-24973 - Concorde not removing authentication tokens after logging out

Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Prior to version 12.25Q1.1, due to an improper implementation of the logout process, authentication credentials remain in cookies even after a user has explicitly logged out, which may allow an attacker to…

πŸ“… Published: Feb. 11, 2025, 3:41 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

8.6

CVSS3.1

CVE-2025-24900 - Concorde CSRF vulnerability due to insecure configuration of authentication cookie attributes

Concorde, formerly know as Nexkey, is a fork of the federated microblogging platform Misskey. Due to a lack of CSRF countermeasures and improper settings of cookies for MediaProxy authentication, there is a vulnerability that allows MediaProxy authentication to be bypassed. In versions prior to 12.…

πŸ“… Published: Feb. 11, 2025, 3:36 p.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 349182
Page 6792 of 34,919
Β« previous page Β» next page
Filters