2.5

CVSS3.1

CVE-2026-24641 - NULL Pointer Dereference Crash in FortiWeb HTTP Daemon

A NULL Pointer Dereference vulnerability [CWE-476] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker to crash the HTTP daemon via crafted HTTP requ…

📅 Published: March 10, 2026, 4:44 p.m. 🔄 Last Modified: April 16, 2026, 4 a.m.

5.9

CVSS3.1

CVE-2026-24640 - Stack Buffer Overflow in FortiWeb Allows Remote Code Execution via Crafted HTTP Requests

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0.2 through 7.0.12 may allow a remote authenticated attacker who can bypass stack protection a…

📅 Published: March 10, 2026, 4:44 p.m. 🔄 Last Modified: April 16, 2026, 4 a.m.

5.5

CVSS3.1

CVE-2025-54659 -

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] vulnerability in Fortinet FortiSOAR Agent Communication Bridge 1.1.0, FortiSOAR Agent Communication Bridge 1.0 all versions may allow an unauthenticated attacker to read files accessible to the …

📅 Published: March 10, 2026, 4:44 p.m. 🔄 Last Modified: April 9, 2026, 8:56 p.m.

7.3

CVSS3.1

CVE-2026-24017 - Authentication Rate‑Limit Bypass via Improper Interaction Frequency Control

An Improper Control of Interaction Frequency vulnerability [CWE-799] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to bypas…

📅 Published: March 10, 2026, 4:44 p.m. 🔄 Last Modified: April 16, 2026, 9:45 a.m.

4.1

CVSS3.1

CVE-2026-25972 - Unrestricted XSS in FortiSIEM Web UI Enables Remote Social Engineering

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4 may allow a remote unauthenticated attacker to provide arbitrary data enabling a social engineering attack via spoofed URL parameters.

📅 Published: March 10, 2026, 4:44 p.m. 🔄 Last Modified: April 17, 2026, 11:45 a.m.

3.4

CVSS3.1

CVE-2026-22629 - Fortinet FortiAnalyzer/Manager Brute‑Force Authentication Bypass via Race Condition

An improper restriction of excessive authentication attempts vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4 all versions, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAna…

📅 Published: March 10, 2026, 4:44 p.m. 🔄 Last Modified: April 16, 2026, 4 a.m.

6.3

CVSS3.1

CVE-2025-68482 -

A improper certificate validation vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, Forti…

📅 Published: March 10, 2026, 4:44 p.m. 🔄 Last Modified: March 12, 2026, 8:13 p.m.

6.4

CVSS3.1

CVE-2025-48418 -

A hidden functionality vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.0 through 7.2.10, FortiAnalyzer 7.0.0 through 7.0.14, FortiAnalyzer 6.4 all versions, FortiAnalyzer Cloud 7.6.2, FortiAnalyzer Cloud 7.4.1 through 7.4.7, FortiAna…

📅 Published: March 10, 2026, 4:44 p.m. 🔄 Last Modified: March 12, 2026, 9:21 p.m.

5.6

CVSS3.1

CVE-2025-49784 -

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer 6.4 all versions, FortiAnalyzer-BigDa…

📅 Published: March 10, 2026, 4:44 p.m. 🔄 Last Modified: March 12, 2026, 9:19 p.m.

6.8

CVSS3.1

CVE-2026-22572 - Authentication Bypass via Crafted Requests on FortiAnalyzer and FortiManager

An authentication bypass using an alternate path or channel vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.3, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2.2 through 7.2.11, FortiManager 7.6.0 through 7.6.3, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2.2 through 7.2.11 may a…

📅 Published: March 10, 2026, 4:44 p.m. 🔄 Last Modified: April 16, 2026, 4 a.m.
Total resulsts: 349182
Page 1221 of 34,919
« previous page » next page
Filters