5.4

CVSS3.1

CVE-2025-68649 - Path Traversal Allows Privileged Attacker to Delete Files in FortiAnalyzer and FortiManager

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Clโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:39 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 7:11 p.m.

2.2

CVSS3.1

CVE-2026-21741 - Open Redirect via Crafted CSV in Fortinet FortiNACโ€‘F

An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary wโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:39 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

9.1

CVSS3.1

CVE-2026-39813 - Privilege Escalation via Path Traversal in FortiSandbox

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via <insert attack vector here>

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 20, 2026, 7:11 p.m.

6.8

CVSS3.1

CVE-2025-61848 - SQL Injection via API in FortiAnalyzer and FortiManager Allows Code Execution

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

7.3

CVSS3.1

CVE-2026-22828 - Heap Based Buffer Overflow in Fortinet FortiAnalyzer Cloud and FortiManager Cloud Allowing Remote Cโ€ฆ

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large aโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: May 1, 2026, 12:38 p.m.

7.9

CVSS3.1

CVE-2026-39815 - SQL Injection in FortiDDoS-F Enabling Unauthorized Code Execution

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

6.2

CVSS3.1

CVE-2026-22573 - Path Traversal Vulnerability in FortiSOAR Allowing Remote Authenticated File Access

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-pโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: May 6, 2026, 3:57 p.m.

4.9

CVSS3.1

CVE-2025-61886 - Crossโ€‘Site Scripting via Crafted HTTP Requests in FortiSandbox 5.0.0โ€‘5.0.4

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox PaaS 5.0.0 through 5.0.4 may allow an attacker to perform an XSS attack via crafted HTTP requests.

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 7:09 p.m.

5.2

CVSS3.1

CVE-2026-39810 - Hardโ€‘coded Cryptographic Key Allows Information Disclosure in FortiClientEMS

A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 21, 2026, 5:18 p.m.

4.4

CVSS3.1

CVE-2026-39811 - Integer Overflow in FortiWeb Leading to Denial of Service

A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to denial of service via <insert attack vector here>

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 21, 2026, 5:16 p.m.
Total resulsts: 349182
Page 480 of 34,919
ยซ previous page ยป next page
Filters