5.8

CVSS3.1

CVE-2024-23664 -

A URL redirection to untrusted site ('open redirect') in Fortinet FortiAuthenticator version 6.6.0, version 6.5.3 and below, version 6.4.9 and below may allow an attacker to to redirect users to an arbitrary website via a crafted URL.

πŸ“… Published: June 3, 2024, 9:50 a.m. πŸ”„ Last Modified: Jan. 21, 2025, 9:53 p.m.

7.6

CVSS3.1

CVE-2024-23667 -

An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

πŸ“… Published: June 3, 2024, 9:48 a.m. πŸ”„ Last Modified: Dec. 17, 2024, 4:38 p.m.

8.6

CVSS3.1

CVE-2024-23668 -

An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

πŸ“… Published: June 3, 2024, 9:48 a.m. πŸ”„ Last Modified: Dec. 17, 2024, 4:38 p.m.

7.6

CVSS3.1

CVE-2024-23670 -

An improper authorization in Fortinet FortiWebManager version 7.2.0 and 7.0.0 through 7.0.4 and 6.3.0 and 6.2.3 through 6.2.4 and 6.0.2 allows attacker to execute unauthorized code or commands via HTTP requests or CLI.

πŸ“… Published: June 3, 2024, 9:48 a.m. πŸ”„ Last Modified: Dec. 17, 2024, 4:35 p.m.

9.8

CVSS3.1

CVE-2024-5404 - ifm: moneo prone to weak password recovery mechanism

An unauthenticated remote attackerΒ can change the admin password in aΒ moneo appliance due to weak password recovery mechanism.

πŸ“… Published: June 3, 2024, 9 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

4.4

CVSS3.1

CVE-2024-35637 - WordPress Church Admin plugin <= 4.3.6 - Server Side Request Forgery (SSRF) vulnerability

Server-Side Request Forgery (SSRF) vulnerability in andy_moyle Church Admin church-admin.This issue affects Church Admin: from n/a through <= 4.3.6.

πŸ“… Published: June 3, 2024, 8:59 a.m. πŸ”„ Last Modified: April 23, 2026, 3:18 p.m.

4.3

CVSS3.1

CVE-2024-35638 - WordPress ActiveDEMAND plugin <= 0.2.43 - Cross Site Request Forgery (CSRF) vulnerability

Cross-Site Request Forgery (CSRF) vulnerability in JumpDEMAND Inc. ActiveDEMAND.This issue affects ActiveDEMAND: from n/a through 0.2.43.

πŸ“… Published: June 3, 2024, 8:57 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

5.9

CVSS3.1

CVE-2024-35639 - WordPress Simple Spoiler plugin <= 1.2 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Webliberty Simple Spoiler simple-spoiler.This issue affects Simple Spoiler: from n/a through <= 1.2.

πŸ“… Published: June 3, 2024, 8:22 a.m. πŸ”„ Last Modified: April 23, 2026, 3:18 p.m.

4.1

CVSS3.1

CVE-2023-48789 -

A client-side enforcement of server-side security in Fortinet FortiPortal version 6.0.0 through 6.0.14 allows attacker to improper access control via crafted HTTP requests.

πŸ“… Published: June 3, 2024, 7:57 a.m. πŸ”„ Last Modified: Jan. 2, 2025, 6:33 p.m.

6

CVSS3.1

CVE-2024-31493 -

An improper removal of sensitive information before storage or transfer vulnerability [CWE-212] in FortiSOAR version 7.3.0, version 7.2.2 and below, version 7.0.3 and below may allow an authenticated low privileged user to read Connector passwords in plain-text via HTTP responses.

πŸ“… Published: June 3, 2024, 7:55 a.m. πŸ”„ Last Modified: Jan. 21, 2025, 9:49 p.m.
Total resulsts: 349182
Page 9607 of 34,919
Β« previous page Β» next page
Filters