5.4

CVSS3.1

CVE-2024-23104 - Sensitive Information Exposure via Crafted HTTP Requests in FortiNDR and FortiVoice

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiVoice 7.0.0 through 7.0.1 may allow a remote authenticated attacker with at leaโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 17, 2026, 3:11 p.m.

4.3

CVSS3.1

CVE-2026-39812 - Crossโ€‘Site Scripting Vulnerability in FortiSandbox and FortiSandbox PaaS

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, FortiSandโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 21, 2026, 5:12 p.m.

6.7

CVSS3.1

CVE-2026-23708 -

A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA reโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: May 6, 2026, 6 p.m.

6.2

CVSS3.1

CVE-2026-39814 - Relative Path Traversal Vulnerability Allowing Unauthorized Commands in FortiWeb

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.0.12 may allow attacker to execute unauthorized code or commands via <insert attack vector here>

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 21, 2026, 5:21 p.m.

6.2

CVSS3.1

CVE-2026-25691 - Path Traversal Enables Deletion of Arbitrary Directories in FortiSandbox

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker with super-โ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: April 22, 2026, 6:55 p.m.

4.1

CVSS3.1

CVE-2025-59809 - Authenticated SSRF Allows Discovery of Internal Services in FortiSOAR

A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.4, FortiSOAR on-premise 7.6โ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: May 6, 2026, 4:05 p.m.

6.2

CVSS3.1

CVE-2026-22155 - Cleartext Transmission of Sensitive Information in FortiSOAR

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, Fโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: May 6, 2026, 3:57 p.m.

5.4

CVSS3.1

CVE-2026-21742 - Cleartext Password Exposure in FortiSOAR Secure Message Exchange and Radius Queries

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, Fโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: May 6, 2026, 4:04 p.m.

4.1

CVSS3.1

CVE-2026-22574 -

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: May 6, 2026, 6:30 p.m.

4.4

CVSS3.1

CVE-2026-22154 - Stored Crossโ€‘Site Scripting in FortiSOAR Web Interface

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, Fortiโ€ฆ

๐Ÿ“… Published: April 14, 2026, 3:38 p.m. ๐Ÿ”„ Last Modified: May 6, 2026, 4:01 p.m.
Total resulsts: 349182
Page 481 of 34,919
ยซ previous page ยป next page
Filters