Show filters
1,476 Total Results
Displaying 21-30 of 1,476
Sort by:
Attacker Value
Unknown

CVE-2022-22303

Disclosure Date: March 02, 2022 (last updated February 23, 2025)
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiManager versions prior to 7.0.2, 6.4.7 and 6.2.9 may allow a low privileged authenticated user to gain access to the FortiGate users credentials via the config conflict file.
Attacker Value
Low

CVE-2020-8500

Disclosure Date: March 02, 2020 (last updated February 21, 2025)
In Artica Pandora FMS 7.42, Web Admin users can execute arbitrary code by uploading a .php file via the Updater or Extension component. NOTE: The vendor reports that this is intended functionality
Attacker Value
Moderate

CVE-2018-13382

Disclosure Date: June 04, 2019 (last updated July 25, 2024)
An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests
Attacker Value
Unknown

CVE-2025-24472

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] affecting FortiOS 7.0.0 through 7.0.16 and FortiProxy 7.2.0 through 7.2.12, 7.0.0 through 7.0.19 may allow a remote attacker to gain super-admin privileges via crafted CSF proxy requests.
0
Attacker Value
Unknown

CVE-2025-24470

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
An Improper Resolution of Path Equivalence vulnerability [CWE-41] in FortiPortal 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.11 may allow a remote unauthenticated attacker to retrieve source code via crafted HTTP requests.
0
Attacker Value
Unknown

CVE-2024-52968

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password.
0
Attacker Value
Unknown

CVE-2024-52966

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
An exposure of sensitive information to an unauthorized actor in Fortinet FortiAnalyzer 6.4.0 through 7.6.0 allows attacker to cause information disclosure via filter manipulation.
0
Attacker Value
Unknown

CVE-2024-50569

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input.
0
Attacker Value
Unknown

CVE-2024-50567

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
An improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb 7.4.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted input.
0
Attacker Value
Unknown

CVE-2024-40591

Disclosure Date: February 11, 2025 (last updated February 12, 2025)
An incorrect privilege assignment vulnerability [CWE-266] in Fortinet FortiOS version 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.9 and before 7.0.15 allows an authenticated admin whose access profile has the Security Fabric permission to escalate their privileges to super-admin by connecting the targetted FortiGate to a malicious upstream FortiGate they control.
0