7

CVSS3.1

CVE-2024-36512 -

An improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiManager, FortiAnalyzer 7.4.0 through 7.4.3 and 7.2.0 through 7.2.5 and 7.0.2 through 7.0.12 and 6.2.10 through 6.2.13 allows attacker to execute unauthorized code or commands via crafted HTTP or HTTPS…

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Jan. 31, 2025, 4:32 p.m.

7.5

CVSS3.1

CVE-2024-46670 -

An Out-of-bounds Read vulnerability [CWE-125] in FortiOS version 7.6.0, version 7.4.4 and below, version 7.2.9 and below and FortiSASE FortiOS tenant version 24.3.b IPsec IKE service may allow an unauthenticated remote attacker to trigger memory consumption leading to Denial of Service via crafted …

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Jan. 31, 2025, 4:12 p.m.

3.2

CVSS3.1

CVE-2024-46669 -

An Integer Overflow or Wraparound vulnerability [CWE-190] in version 7.4.4 and below, version 7.2.10 and below; FortiSASE version 23.4.b FortiOS tenant IPsec IKE service may allow an authenticated attacker to crash the IPsec tunnel via crafted requests, resulting in potential denial of service.

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Jan. 14, 2026, 9:15 a.m.

2.6

CVSS3.1

CVE-2024-55593 -

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiWeb versions 6.3.17 through 7.6.1 allows attacker to gain information disclosure via crafted SQL queries

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Feb. 3, 2025, 10:06 p.m.

7.2

CVSS3.1

CVE-2024-50566 -

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiManager Cloud 7.6.0 through 7.6.1, FortiManager Cloud 7.4.0 through 7.4.4, FortiManager Cloud 7.2.2 through 7.2.7, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.0 through…

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Jan. 15, 2026, 3:05 p.m.

9.6

CVSS3.1

CVE-2024-55591 -

An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS version 7.0.0 through 7.0.16 and FortiProxy version 7.0.0 through 7.0.19 and 7.2.0 through 7.2.12 allows a remote attacker to gain super-admin privileges via crafted requests to Node.js websocket m…

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Feb. 26, 2026, 7:09 p.m.

3.5

CVSS3.1

CVE-2024-52963 -

A out-of-bounds write in Fortinet FortiOS versions 7.6.0, 7.4.0 through 7.4.6, 7.2.0 through 7.2.10, 7.0.0 through 7.0.16, 6.4.0 through 6.4.15 allows attacker to trigger a denial of service via specially crafted packets.

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Oct. 27, 2025, 9:05 p.m.

6.4

CVSS3.1

CVE-2024-48893 -

An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSOAR 7.3.0 through 7.3.3, 7.2.1 through 7.2.2 may allow an authenticated attacker to perform a stored cross site scripting (XSS) attack via the creation of malicious playbook.

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Feb. 3, 2025, 10:12 p.m.

3.5

CVSS3.1

CVE-2024-46665 -

An insertion of sensitive information into sent data vulnerability [CWE-201] in FortiOS 7.6.0, 7.4.0 through 7.4.4 may allow an attacker in a man-in-the-middle position to retrieve the RADIUS accounting server shared secret via intercepting accounting-requests.

📅 Published: Jan. 14, 2025, 2:08 p.m. 🔄 Last Modified: Jan. 31, 2025, 4:09 p.m.

8.8

CVSS3.1

CVE-2024-11497 - Phoenix Contact: CHARX-SEC3xxx Charge controllers vulnerable to privilege escalation

An authenticated attacker can use this vulnerability to perform a privilege escalation to gain root access.

📅 Published: Jan. 14, 2025, 1:55 p.m. 🔄 Last Modified: April 15, 2026, 12:35 a.m.
Total resulsts: 348147
Page 7047 of 34,815
« previous page » next page
Filters