8.6

CVSS3.1

CVE-2026-34622 - Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollโ€ฆ

Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of tโ€ฆ

๐Ÿ“… Published: April 14, 2026, 4:18 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 2:14 p.m.

6.3

CVSS3.1

CVE-2026-34626 - Acrobat Reader | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollโ€ฆ

Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary file system read in the context of the current user. Exploitation ofโ€ฆ

๐Ÿ“… Published: April 14, 2026, 4:18 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 2:14 p.m.

5.4

CVSS3.1

CVE-2025-61624 - Fortinet Path Traversal Allowing Arbitrary File Write

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, Forโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:39 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

5.4

CVSS3.1

CVE-2025-68649 - Path Traversal Allows Privileged Attacker to Delete Files in FortiAnalyzer and FortiManager

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Clโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:39 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

2.2

CVSS3.1

CVE-2026-21741 - Open Redirect via Crafted CSV in Fortinet FortiNACโ€‘F

An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary wโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:39 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

9.1

CVSS3.1

CVE-2026-39813 - Privilege Escalation via Path Traversal in FortiSandbox

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here>

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

6.8

CVSS3.1

CVE-2025-61848 - SQL Injection via API in FortiAnalyzer and FortiManager Allows Code Execution

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

7.3

CVSS3.1

CVE-2026-22828 - Heap Based Buffer Overflow in Fortinet FortiAnalyzer Cloud and FortiManager Cloud Allowing Remote Cโ€ฆ

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large aโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

7.9

CVSS3.1

CVE-2026-39815 - SQL Injection in FortiDDoS-F Enabling Unauthorized Code Execution

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

6.2

CVSS3.1

CVE-2026-22573 - Path Traversal Vulnerability in FortiSOAR Allowing Remote Authenticated File Access

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-pโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.
Total resulsts: 345145
Page 81 of 34,515
ยซ previous page ยป next page
Filters