7.3

CVSS3.1

CVE-2026-22828 - Heap Based Buffer Overflow in Fortinet FortiAnalyzer Cloud and FortiManager Cloud Allowing Remote Cโ€ฆ

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large aโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

7.9

CVSS3.1

CVE-2026-39815 - SQL Injection in FortiDDoS-F Enabling Unauthorized Code Execution

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

6.2

CVSS3.1

CVE-2026-22573 - Path Traversal Vulnerability in FortiSOAR Allowing Remote Authenticated File Access

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-pโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

4.9

CVSS3.1

CVE-2025-61886 - Crossโ€‘Site Scripting via Crafted HTTP Requests in FortiSandbox 5.0.0โ€‘5.0.4

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox PaaS 5.0.0 through 5.0.4 may allow an attacker to perform an XSS attack via crafted HTTP requests.

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

5.2

CVSS3.1

CVE-2026-39810 - Hardโ€‘coded Cryptographic Key Allows Information Disclosure in FortiClientEMS

A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

4.4

CVSS3.1

CVE-2026-39811 - Integer Overflow in FortiWeb Leading to Denial of Service

A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to denial of service via <insert attack vector here>

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

5.4

CVSS3.1

CVE-2024-23104 - Sensitive Information Exposure via Crafted HTTP Requests in FortiNDR and FortiVoice

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiVoice 7.0.0 through 7.0.1 may allow a remote authenticated attacker with at leaโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

4.3

CVSS3.1

CVE-2026-39812 - Crossโ€‘Site Scripting Vulnerability in FortiSandbox and FortiSandbox PaaS

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

6.7

CVSS3.1

CVE-2026-23708 - Replay of 2FA Request Enables Authentication Bypass in FortiSOAR

A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA reโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

6.2

CVSS3.1

CVE-2026-39814 - Relative Path Traversal Vulnerability Allowing Unauthorized Commands in FortiWeb

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.0.12 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.
Total resulsts: 345148
Page 82 of 34,515
ยซ previous page ยป next page
Filters