7.9

CVSS3.1

CVE-2024-47571 -

An operation on a resource after expiration or release in Fortinet FortiManager 6.4.12 through 7.4.0 allows an attacker to gain improper access to FortiGate via valid credentials.

πŸ“… Published: Jan. 14, 2025, 2:10 p.m. πŸ”„ Last Modified: March 19, 2025, 4:03 p.m.

8.3

CVSS3.1

CVE-2024-47572 -

An improper neutralization of formula elements in a csv file in Fortinet FortiSOAR 7.2.1 through 7.4.1 allows attacker to execute unauthorized code or commands via manipulating csv file

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: July 16, 2025, 1:03 p.m.

6.9

CVSS3.1

CVE-2024-46667 -

A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may allow an attacker to deny valid TLS traffic via consuming all allotted connections.

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: July 16, 2025, 1:16 p.m.

6.2

CVSS3.1

CVE-2024-36504 -

An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticated attacker to perform a denial of service on the SSLVPN web portal via a specially crafted URL.

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: July 22, 2025, 9:26 p.m.

6.1

CVSS3.1

CVE-2024-21758 -

A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a privileged user to execute arbitrary code via specially crafted CLI commands, provided the user is able to evade FortiWeb stack protections.

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: July 24, 2025, 7:59 p.m.

4.8

CVSS3.1

CVE-2024-46666 -

An allocation of resources without limits or throttling [CWE-770] vulnerability in FortiOS versions 7.6.0, versions 7.4.4 through 7.4.0, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow a remote unauthenticated attacker to prevent access to the GUI via specially crafted requests direc…

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: July 22, 2025, 9:26 p.m.

3.9

CVSS3.1

CVE-2024-45326 -

AnΒ Improper Access Control vulnerability [CWE-284] vulnerability in Fortinet FortiDeceptor 6.0.0, FortiDeceptor 5.3 all versions, FortiDeceptor 5.2 all versions, FortiDeceptor 5.1 all versions, FortiDeceptor 5.0 all versions may allow an authenticated attacker with none privileges to perform operat…

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Feb. 4, 2026, 2:16 p.m.

8.4

CVSS3.1

CVE-2024-35277 -

A missing authentication for critical function in Fortinet FortiPortal version 6.0.0 through 6.0.15, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to access to the configuration of the managed devices by sending specificall…

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 5:08 p.m.

6.3

CVSS3.1

CVE-2024-26012 -

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiAP-S 6.2 all verisons, and 6.4.0 through 6.4.9, FortiAP-W2 6.4 all versions, 7.0 all versions, 7.2.0 through 7.2.3, and 7.4.0 through 7.4.2, FortiAP 6.4 all versions, 7.0 all versions, 7.2.…

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 5:25 p.m.

3.5

CVSS3.1

CVE-2024-36506 -

An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, 6.4 all versions may allow a remote attacker to bypass the trusted host feature via session connection.

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 5:10 p.m.
Total resulsts: 343921
Page 6621 of 34,393
Β« previous page Β» next page
Filters