2.6

CVSS3.1

CVE-2022-29059 -

An improper neutralization of special elements used in an SQL commandย ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, 6.2.7 and below may allow a privileged attacker to execute SQL commands over the log database via specifically craftโ€ฆ

๐Ÿ“… Published: March 14, 2025, 3:45 p.m. ๐Ÿ”„ Last Modified: March 14, 2025, 5:52 p.m.

6

CVSS3.1

CVE-2024-47573 -

An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2.1 and below, version 7.1.1 and below, version 7.0.6 and below may allow an authenticated attacker with at least Read/Write permission on system maintenance to install a corruptedโ€ฆ

๐Ÿ“… Published: March 14, 2025, 3:04 p.m. ๐Ÿ”„ Last Modified: March 14, 2025, 5:53 p.m.

8.3

CVSS3.1

CVE-2024-46662 -

A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafted packets

๐Ÿ“… Published: March 14, 2025, 3:03 p.m. ๐Ÿ”„ Last Modified: March 15, 2025, 3:55 a.m.

4.4

CVSS3.1

CVE-2024-40590 -

Anย improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may allow an unauthenticated attacker in a Man-in-tโ€ฆ

๐Ÿ“… Published: March 14, 2025, 3:02 p.m. ๐Ÿ”„ Last Modified: March 14, 2025, 6:02 p.m.

4.1

CVSS3.1

CVE-2024-45638 - IBM QRadar EDR information disclosure

IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.

๐Ÿ“… Published: March 14, 2025, 2:49 p.m. ๐Ÿ”„ Last Modified: March 14, 2025, 6:50 p.m.

5.9

CVSS3.1

CVE-2024-45643 - IBM QRadar EDR information disclosure

IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information.

๐Ÿ“… Published: March 14, 2025, 2:49 p.m. ๐Ÿ”„ Last Modified: March 15, 2025, 3:55 a.m.

6.9

CVSS4.0

CVE-2025-2268 - HP LaserJet MFP M232-M237 Printer Series - Potential Denial of Service

The HP LaserJet MFP M232-M237 Printer Series may be vulnerable to a denial of service attack when a specially crafted request message is sent via Internet Printing Protocol (IPP).

๐Ÿ“… Published: March 14, 2025, 1:33 p.m. ๐Ÿ”„ Last Modified: March 14, 2025, 2:37 p.m.

8.7

CVSS4.0

CVE-2025-29776 - Azle calling `setTimer` causes infinite loop of timers

Azle is a WebAssembly runtime for TypeScript and JavaScript on ICP. Calling `setTimer` in Azle versions `0.27.0`, `0.28.0`, and `0.29.0` causes an immediate infinite loop of timers to be executed on the canister, each timer attempting to clean up the global state of the previous timer. The infiniteโ€ฆ

๐Ÿ“… Published: March 14, 2025, 1:13 p.m. ๐Ÿ”„ Last Modified: March 14, 2025, 2:46 p.m.

9.8

CVSS3.1

CVE-2025-2000 - Qiskit SDK code execution

A maliciously crafted QPY file can potential execute arbitrary-code embedded in the payload without privilege escalation when deserialising QPY formats < 13. A python process calling Qiskit 0.18.0 through 1.4.1's `qiskit.qpy.load()` function could potentially execute any arbitrary Python code embedโ€ฆ

๐Ÿ“… Published: March 14, 2025, 1:04 p.m. ๐Ÿ”„ Last Modified: March 15, 2025, 3:55 a.m.

9.8

CVSS3.1

CVE-2025-27595 - Weak hashing alghrythm

The device uses a weak hashing alghorithm to create the password hash. Hence, a matching password can be easily calculated by an attacker. This impacts the security and the integrity of the device.

๐Ÿ“… Published: March 14, 2025, 12:53 p.m. ๐Ÿ”„ Last Modified: March 14, 2025, 1:35 p.m.
Total resulsts: 285316
Page 5 of 28,532
ยซ previous page ยป next page
Filters