6.2

CVSS3.1

CVE-2026-39814 - Relative Path Traversal Vulnerability Allowing Unauthorized Commands in FortiWeb

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.0.12 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

πŸ“… Published: April 14, 2026, 3:38 p.m. πŸ”„ Last Modified: April 17, 2026, 3:11 p.m.

6.2

CVSS3.1

CVE-2026-25691 - Path Traversal Enables Deletion of Arbitrary Directories in FortiSandbox

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-…

πŸ“… Published: April 14, 2026, 3:38 p.m. πŸ”„ Last Modified: April 17, 2026, 3:11 p.m.

4.1

CVSS3.1

CVE-2025-59809 - Authenticated SSRF Allows Discovery of Internal Services in FortiSOAR

A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.4, FortiSOAR on-premise 7.6…

πŸ“… Published: April 14, 2026, 3:38 p.m. πŸ”„ Last Modified: April 17, 2026, 3:11 p.m.

6.2

CVSS3.1

CVE-2026-22155 - Cleartext Transmission of Sensitive Information in FortiSOAR

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, F…

πŸ“… Published: April 14, 2026, 3:38 p.m. πŸ”„ Last Modified: April 17, 2026, 3:11 p.m.

5.4

CVSS3.1

CVE-2026-21742 - Cleartext Password Exposure in FortiSOAR Secure Message Exchange and Radius Queries

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, F…

πŸ“… Published: April 14, 2026, 3:38 p.m. πŸ”„ Last Modified: April 17, 2026, 3:11 p.m.

4.1

CVSS3.1

CVE-2026-22574 - Passwords Stored in Recoverable Format in FortiSOAR LDAP Configuration

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSO…

πŸ“… Published: April 14, 2026, 3:38 p.m. πŸ”„ Last Modified: April 17, 2026, 3:11 p.m.

4.4

CVSS3.1

CVE-2026-22154 - Stored Cross‑Site Scripting in FortiSOAR Web Interface

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, Forti…

πŸ“… Published: April 14, 2026, 3:38 p.m. πŸ”„ Last Modified: April 17, 2026, 3:11 p.m.

6.2

CVSS3.1

CVE-2025-53847 - Missing Authentication Allows Unauthenticated Code Execution in FortiOS

A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or comma…

πŸ“… Published: April 14, 2026, 3:38 p.m. πŸ”„ Last Modified: April 17, 2026, 3:11 p.m.

4.1

CVSS3.1

CVE-2026-22576 - FortiSOAR Connector Passwords Stored in Recoverable Format

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSO…

πŸ“… Published: April 14, 2026, 3:38 p.m. πŸ”„ Last Modified: April 17, 2026, 3:11 p.m.

2.5

CVSS3.1

CVE-2026-27316 - Insufficiently Protected Credentials Expose LDAP Server Secrets

A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed administrator to read LDAP server credentials via client-side inspection.

πŸ“… Published: April 14, 2026, 3:38 p.m. πŸ”„ Last Modified: April 17, 2026, 3:11 p.m.
Total resulsts: 345149
Page 83 of 34,515
Β« previous page Β» next page
Filters