2.2

CVSS3.1

CVE-2024-35274 -

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiAnalyzer versions below 7.4.2, Fortinet FortiManager versions below 7.4.2 and Fortinet FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a privileged attacker with read…

πŸ“… Published: Nov. 12, 2024, 6:53 p.m. πŸ”„ Last Modified: Jan. 17, 2025, 8:29 p.m.

6.3

CVSS3.1

CVE-2024-32118 -

Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer-BigData …

πŸ“… Published: Nov. 12, 2024, 6:53 p.m. πŸ”„ Last Modified: Jan. 17, 2025, 8:42 p.m.

4.8

CVSS3.1

CVE-2024-32116 -

Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allows a privileged attacker to delete files from the …

πŸ“… Published: Nov. 12, 2024, 6:53 p.m. πŸ”„ Last Modified: Jan. 21, 2025, 10:19 p.m.

3.9

CVSS3.1

CVE-2023-44255 -

An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to read event logs of another adom via crafted HTTP o…

πŸ“… Published: Nov. 12, 2024, 6:53 p.m. πŸ”„ Last Modified: Jan. 21, 2025, 10:02 p.m.

5.1

CVSS3.1

CVE-2023-47543 -

An authorization bypass through user-controlled key vulnerability [CWE-639] in Fortinet FortiPortal version 7.0.0 through 7.0.3 allows an authenticated attacker to interact with ressources of other organizations via HTTP or HTTPS requests.

πŸ“… Published: Nov. 12, 2024, 6:53 p.m. πŸ”„ Last Modified: Jan. 2, 2025, 6:29 p.m.

4.7

CVSS3.1

CVE-2024-32117 -

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-BigData version 7.4.0 and below 7.2.7 allows a pri…

πŸ“… Published: Nov. 12, 2024, 6:53 p.m. πŸ”„ Last Modified: Jan. 21, 2025, 10:19 p.m.

6.8

CVSS3.1

CVE-2024-40592 -

An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker toΒ swap the installer with a malicious package via a race condition du…

πŸ“… Published: Nov. 12, 2024, 6:53 p.m. πŸ”„ Last Modified: Nov. 14, 2024, 8:37 p.m.

6.7

CVSS3.1

CVE-2024-36507 -

A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering.

πŸ“… Published: Nov. 12, 2024, 6:53 p.m. πŸ”„ Last Modified: Nov. 14, 2024, 8:31 p.m.

3.6

CVSS3.1

CVE-2024-33510 -

AnΒ improper neutralization of special elements in output used by a downstream component ('Injection') vulnerability [CWE-74] in FortiOS version 7.4.3 and below, version 7.2.8 and below, version 7.0.16 and below; FortiProxy version 7.4.3 and below, version 7.2.9 and below, version 7.0.16 and below; …

πŸ“… Published: Nov. 12, 2024, 6:53 p.m. πŸ”„ Last Modified: Jan. 17, 2025, 8:35 p.m.

7.1

CVSS3.1

CVE-2023-50176 -

A session fixation in Fortinet FortiOS version 7.4.0 through 7.4.3 and 7.2.0 through 7.2.7 and 7.0.0 through 7.0.13 allows attacker to execute unauthorized code or commands via phishing SAML authentication link.

πŸ“… Published: Nov. 12, 2024, 6:53 p.m. πŸ”„ Last Modified: Dec. 12, 2024, 7:27 p.m.
Total resulsts: 349182
Page 7915 of 34,919
Β« previous page Β» next page
Filters