7.5

CVSS3.1

CVE-2025-29786 - Memory Exhaustion in Expr Parser with Unrestricted Input

Expr is an expression language and expression evaluation for Go. Prior to version 1.17.0, if the Expr expression parser is given an unbounded input string, it will attempt to compile the entire string and generate an Abstract Syntax Tree (AST) node for each part of the expression. In scenarios wher…

πŸ“… Published: March 17, 2025, 1:15 p.m. πŸ”„ Last Modified: March 17, 2025, 2:15 p.m.

5.4

CVSS4.0

CVE-2025-27102 - Agate vulnerable to HTML injection in user signup - Administrator phishing risk

Agate is central authentication server software for OBiBa epidemiology applications. Prior to version 3.3.0, when registering for an Agate account, arbitrary HTML code can be injected into a user's first and last name. This HTML is then rendered in the email sent to administrative users. The Agate …

πŸ“… Published: March 17, 2025, 1:11 p.m. πŸ”„ Last Modified: March 17, 2025, 2:15 p.m.

4.9

CVSS3.1

CVE-2020-29010 -

An exposure of sensitive information to an unauthorized actor vulnerability in FortiOS version 6.2.4 and below, version 6.0.10 and belowmay allow remote authenticated actors to read the SSL VPN events log entries of users in other VDOMs by executing "get vpn ssl monitor" from the CLI. The sensitiv…

πŸ“… Published: March 17, 2025, 1:06 p.m. πŸ”„ Last Modified: March 17, 2025, 2:15 p.m.

3.6

CVSS3.1

CVE-2019-17659 -

A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted user "tunneluser" by leveraging knowledge of the private key from another installation or a firmware image.

πŸ“… Published: March 17, 2025, 1:06 p.m. πŸ”„ Last Modified: March 17, 2025, 2:15 p.m.

6.5

CVSS3.1

CVE-2021-22126 -

A use of hard-coded password vulnerability in FortiWLC version 8.5.2 and below, version 8.4.8 and below, version 8.3.3 to 8.3.2, version 8.2.7 to 8.2.6 may allow a local, authenticated attacker to connect to the managed Access Point (Meru AP and FortiAP-U) as root using the default hard-coded usern…

πŸ“… Published: March 17, 2025, 1:05 p.m. πŸ”„ Last Modified: March 17, 2025, 2:15 p.m.

4.8

CVSS3.1

CVE-2021-32584 -

An improper access control (CWE-284) vulnerability in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 and below, version 8.2.7 to 8.2.4, version 8.1.3 may allow an unauthenticated and remote attacker to access certain areas of the web management CGI functiona…

πŸ“… Published: March 17, 2025, 1:05 p.m. πŸ”„ Last Modified: March 17, 2025, 2:15 p.m.

7.8

CVSS3.1

CVE-2024-54027 -

A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, version 3.2.4 and below, version 3.1.5 and below, version 3.0.7 to 3.0.5 may allow a privileged attacker with super-admin profile and CLI access t…

πŸ“… Published: March 17, 2025, 1:05 p.m. πŸ”„ Last Modified: March 17, 2025, 2:15 p.m.

4.2

CVSS3.1

CVE-2021-26087 -

An improper neutralization of input during web page generation in FortiWLC version 8.6.0, version 8.5.3 and below, version 8.4.8 and below, version 8.3.3 web interface may allow both authenticated remote attackers and non-authenticated attackers in the same network as the appliance to perform a sto…

πŸ“… Published: March 17, 2025, 1:05 p.m. πŸ”„ Last Modified: March 17, 2025, 2:15 p.m.

4

CVSS3.1

CVE-2019-15706 -

An improper neutralization of input during web page generation in the SSL VPN portal of FortiProxy version 2.0.0, version 1.2.9 and below and FortiOS version 6.2.1 and below, version 6.0.8 and below, version 5.6.12 may allow a remote authenticated attacker to perform a stored cross site scripting a…

πŸ“… Published: March 17, 2025, 1:05 p.m. πŸ”„ Last Modified: March 17, 2025, 2:15 p.m.

6.9

CVSS4.0

CVE-2025-2378 - PHPGurukul Medical Card Generation System download-medical-cards.php sql injection

A vulnerability was found in PHPGurukul Medical Card Generation System 1.0. It has been classified as critical. This affects an unknown part of the file /download-medical-cards.php. The manipulation of the argument searchdata leads to sql injection. It is possible to initiate the attack remotely. T…

πŸ“… Published: March 17, 2025, 1 p.m. πŸ”„ Last Modified: March 17, 2025, 2:15 p.m.
Total resulsts: 285509
Page 7 of 28,551
Β« previous page Β» next page
Filters