6.4

CVSS3.1

CVE-2024-54021 -

An Improper Neutralization of CRLF Sequences in HTTP Headers ('http response splitting') vulnerability [CWE-113] in Fortinet FortiOS 7.2.0 through 7.6.0, FortiProxy 7.2.0 through 7.4.5 may allow a remote unauthenticated attacker to bypass the file filter via crafted HTTP headers.

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Aug. 8, 2025, 4:03 p.m.

4.1

CVSS3.1

CVE-2024-35278 -

A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiPortal versions 7.2.4 through 7.2.0 and 7.0.0 through 7.2.8 may allow an authenticated attacker to view the SQL query being run server-side when submitting an HTTP request, via including special …

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 5:09 p.m.

3.3

CVSS3.1

CVE-2024-52967 -

An improper neutralization of script-related html tags in a web page (basic xss) in Fortinet FortiPortal 6.0.0 through 6.0.14 allows attacker to execute unauthorized code or commands via html injection.

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Feb. 3, 2025, 9:59 p.m.

6.3

CVSS3.1

CVE-2024-40587 -

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiVoice version 7.0.0 through 7.0.4 and before 6.4.9 allows an authenticated privileged attacker to execute unauthorized code or commands via crafted CLI requests.

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 4:34 p.m.

5.2

CVSS3.1

CVE-2024-46664 -

A relative path traversal in Fortinet FortiRecorder [CWE-23] version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to read files from the underlying filesystem via crafted HTTP or HTTPs requests.

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 4:37 p.m.

4.8

CVSS3.1

CVE-2024-47566 -

A improper limitation of a pathname to a restricted directory ('path traversal') [CWE-23] in Fortinet FortiRecorder version 7.2.0 through 7.2.1 and before 7.0.4 allows a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 4:14 p.m.

8

CVSS3.1

CVE-2024-48886 -

A weak authentication in Fortinet FortiOS versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, FortiProxy versions 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.17, 2.0.0 through 2.0.14, FortiManager versions 7.6.0 through 7.6.1, 7.4.1 throug…

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Feb. 3, 2025, 10:16 p.m.

8.3

CVSS3.1

CVE-2024-27778 -

An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.4, FortiSandbox 4.2.1 through 4.2.6, FortiSandbox 4.0.0 through 4.0.4, FortiSandbox 3.2 all versions, FortiSandbox 3.1 all versions, FortiSandbox 3.0.…

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Jan. 15, 2026, 1:53 p.m.

6.7

CVSS3.1

CVE-2024-33503 -

A improper privilege management in Fortinet FortiManager version 7.4.0 through 7.4.3, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14 allows attacker to escalation of privileg…

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 5:36 p.m.

9.6

CVSS3.1

CVE-2023-37936 -

A use of hard-coded cryptographic key in Fortinet FortiSwitch version 7.4.0 and 7.2.0 through 7.2.5 and 7.0.0 through 7.0.7 and 6.4.0 through 6.4.13 and 6.2.0 through 6.2.7 and 6.0.0 through 6.0.7 allows attacker to execute unauthorized code or commands via crafted requests.

πŸ“… Published: Jan. 14, 2025, 2:09 p.m. πŸ”„ Last Modified: Jan. 31, 2025, 5:42 p.m.
Total resulsts: 348208
Page 7051 of 34,821
Β« previous page Β» next page
Filters