6.5

CVSS3.1

CVE-2025-68648 -

A use of externally-controlled format string vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.7, FortiAnalyzeโ€ฆ

๐Ÿ“… Published: March 10, 2026, 4:44 p.m. ๐Ÿ”„ Last Modified: March 13, 2026, 3:31 p.m.

6

CVSS3.1

CVE-2026-25689 - Improper Neutralization of Argument Delimiters in FortiDeceptor Allows Privileged File Deletion

An improper neutralization of argument delimiters in a command ('argument injection') vulnerability in Fortinet FortiDeceptor 6.2.0, FortiDeceptor 6.0 all versions, FortiDeceptor 5.3 all versions, FortiDeceptor 5.2 all versions, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions, FortiDโ€ฆ

๐Ÿ“… Published: March 10, 2026, 4:44 p.m. ๐Ÿ”„ Last Modified: April 18, 2026, 9:45 a.m.

4.6

CVSS3.1

CVE-2025-53608 -

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.0 through 4.4.7, FortiSandbox 4.2 all versions, FortiSandbox 4.0 all versions may allow an authenticated privilโ€ฆ

๐Ÿ“… Published: March 10, 2026, 4:44 p.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:18 p.m.

7.4

CVSS3.1

CVE-2026-24018 - Unix Symlink Follow Vulnerability Allows Local Privilege Escalation

A UNIX symbolic link (Symlink) following vulnerability in Fortinet FortiClientLinux 7.4.0 through 7.4.4, FortiClientLinux 7.2.2 through 7.2.12 may allow a local and unprivileged user to escalate their privileges to root.

๐Ÿ“… Published: March 10, 2026, 4:44 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 9:45 a.m.

5

CVSS3.1

CVE-2025-48840 -

An authentication bypass by spoofing vulnerability in Fortinet FortiWeb 7.6.0 through 7.6.3, FortiWeb 7.4.0 through 7.4.8, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote unauthenticated attacker to bypass hostname restrictions via a specially crafted request.

๐Ÿ“… Published: March 10, 2026, 4:44 p.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:20 p.m.

7.7

CVSS3.1

CVE-2026-22627 - Unauthenticated Buffer Overflow via LLDP Packet in FortiSwitchAXFixed

A buffer copy without checking size of input ('classic buffer overflow') vulnerability in Fortinet FortiSwitchAXFixed 1.0.0 through 1.0.1 may allow an unauthenticated attacker within the same adjacent network to execute unauthorized code or commands on the device via sending a crafted LLDP packet.

๐Ÿ“… Published: March 10, 2026, 4:44 p.m. ๐Ÿ”„ Last Modified: April 16, 2026, 4 a.m.

7

CVSS3.1

CVE-2025-54820 -

A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiManager 7.4.0 through 7.4.2, FortiManager 7.2.0 through 7.2.10, FortiManager 6.4 all versions may allow a remote unauthenticated attacker to execute unauthorized commands via crafted requests, if the service is enaโ€ฆ

๐Ÿ“… Published: March 10, 2026, 4:44 p.m. ๐Ÿ”„ Last Modified: March 12, 2026, 9:17 p.m.

8.3

CVSS4.0

CVE-2026-30942 - Flare has a Path Traversal in /api/avatars/[filename]

Flare is a Next.js-based, self-hostable file sharing platform that integrates with screenshot tools. Prior to 1.7.3, an authenticated path traversal vulnerability in /api/avatars/[filename] allows any logged-in user to read arbitrary files from within the application container. The filename URL parโ€ฆ

๐Ÿ“… Published: March 10, 2026, 4:44 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 11:45 a.m.

3.8

CVSS3.1

CVE-2025-55717 -

A cleartext storage of sensitive information vulnerability [CWE-312] vulnerability in Fortinet FortiMail 7.6.0 through 7.6.2, FortiMail 7.4.0 through 7.4.4, FortiMail 7.2.0 through 7.2.7, FortiMail 7.0.0 through 7.0.8, FortiRecorder 7.2.0 through 7.2.3, FortiRecorder 7.0 all versions, FortiRecorderโ€ฆ

๐Ÿ“… Published: March 10, 2026, 4:44 p.m. ๐Ÿ”„ Last Modified: March 12, 2026, 8:39 p.m.

6.7

CVSS3.1

CVE-2026-25836 - OS Command Injection Vulnerability in FortiSandbox Cloud 5.0.4

An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox Cloud 5.0.4 may allow a privileged attacker with super-admin profile and CLI access to execute unauthorized code or commands via crafted HTTP requests.

๐Ÿ“… Published: March 10, 2026, 4:44 p.m. ๐Ÿ”„ Last Modified: April 15, 2026, 5 p.m.
Total resulsts: 349182
Page 1222 of 34,919
ยซ previous page ยป next page
Filters