5

CVSS3.1

CVE-2024-35276 -

A stack-based buffer overflow in Fortinet FortiAnalyzer versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager versions 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager Cloud versions 7.4.1 throug…

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Jan. 31, 2025, 5:04 p.m.

6.5

CVSS3.1

CVE-2024-35275 -

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, FortiManager version 7.4.0 through 7.4.2 allows attacker to escalation of privilege via specially crafted http requests.

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Jan. 31, 2025, 4:49 p.m.

6.4

CVSS3.1

CVE-2023-42785 -

A null pointer dereference in FortiOS versions 7.4.0 through 7.4.1, 7.2.0 through 7.2.5, 7.0 all versions, 6.4 all versions , 6.2 all versions and 6.0 all versions allows attacker to trigger a denial of service via a crafted http request.

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Jan. 17, 2025, 8:42 p.m.

7

CVSS3.1

CVE-2024-36512 -

An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 through 7.0.12 and 6.2.10 through 6.2.13 allows attacker to execute unauthorized code or commands via crafted HTTP or HTTPS…

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Jan. 31, 2025, 4:32 p.m.

7.5

CVSS3.1

CVE-2024-46670 -

An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption leading to Denial of Service via crafted …

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Jan. 31, 2025, 4:12 p.m.

3.2

CVSS3.1

CVE-2024-46669 -

An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSASE version 23.4.b FortiOS tenant IPsec IKE service may allow an authenticated attacker to crash the IPsec tunnel via crafted requests, resulting in potential denial of service.

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Jan. 14, 2026, 9:15 a.m.

2.6

CVSS3.1

CVE-2024-55593 -

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Feb. 3, 2025, 10:06 p.m.

7.2

CVSS3.1

CVE-2024-50566 -

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 through 7.4.4, FortiManager Cloud 7.2.2 through 7.2.7, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.0 through…

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Jan. 15, 2026, 3:05 p.m.

9.6

CVSS3.1

CVE-2024-55591 -

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket m…

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

3.5

CVSS3.1

CVE-2024-52963 -

A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets.

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Oct. 27, 2025, 9:05 p.m.
Total resulsts: 343919
Page 6624 of 34,392
« previous page » next page
Filters