Latest CVE Feed
-
8.1
HIGHCVE-2021-41034
The build of some language stacks of Eclipse Che version 6 includes pulling some binaries from an unsecured HTTP endpoint. As a consequence the builds of such stacks are vulnerable to MITM attacks that allow the replacement of the original binaries with a... Read more
Affected Products : che- Published: Sep. 29, 2021
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2021-41033
In all released versions of Eclipse Equinox, at least until version 4.21 (September 2021), installation can be vulnerable to man-in-the-middle attack if using p2 repos that are HTTP; that can then be exploited to serve incorrect p2 metadata and entirely a... Read more
Affected Products : equinox- Published: Sep. 13, 2021
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2021-41032
An improper access control vulnerability [CWE-284] in FortiOS versions 6.4.8 and prior and 7.0.3 and prior may allow an authenticated attacker with a restricted user profile to gather sensitive information and modify the SSL-VPN tunnel status of other VDO... Read more
Affected Products : fortios- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41031
A relative path traversal vulnerability [CWE-23] in FortiClient for Windows versions 7.0.2 and prior, 6.4.6 and prior and 6.2.9 and below may allow a local unprivileged attacker to escalate their privileges to SYSTEM via the named pipe responsible for For... Read more
Affected Products : forticlient- Published: Jul. 18, 2022
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2021-41030
An authentication bypass by capture-replay vulnerability [CWE-294] in FortiClient EMS versions 7.0.1 and below and 6.4.4 and below may allow an unauthenticated attacker to impersonate an existing user by intercepting and re-using valid SAML authentication... Read more
Affected Products : forticlient_enterprise_management_server- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
6.4
MEDIUMCVE-2021-41029
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWLM version 8.6.1 and below allows attacker to store malicious javascript code in the device and trigger it via crafted HTTP requests... Read more
Affected Products : fortiwlm- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2021-41028
A combination of a use of hard-coded cryptographic key vulnerability [CWE-321] in FortiClientEMS 7.0.1 and below, 6.4.6 and below and an improper certificate validation vulnerability [CWE-297] in FortiClientWindows, FortiClientLinux and FortiClientMac 7.0... Read more
- Published: Dec. 16, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41027
A stack-based buffer overflow in Fortinet FortiWeb version 6.4.1 and 6.4.0, allows an authenticated attacker to execute unauthorized code or commands via crafted certificates loaded into the device.... Read more
Affected Products : fortiweb- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41026
A relative path traversal in FortiWeb versions 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow an authenticated attacker to retrieve arbitrary files from the underlying filesystem via specially crafted web requests.... Read more
Affected Products : fortiweb- Published: Apr. 06, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2021-41025
Multiple vulnerabilities in the authentication mechanism of confd in FortiWeb versions 6.4.1, 6.4.0, 6.3.0 through 6.3.15, 6.2.0 through 6.2.6, 6.1.0 through 6.1.2, 6.0.0 thorugh 6.0.7, including an instance of concurrent execution using shared resource w... Read more
Affected Products : fortiweb- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2021-41024
A relative path traversal [CWE-23] vulnerabiltiy in FortiOS versions 7.0.0 and 7.0.1 and FortiProxy verison 7.0.0 may allow an unauthenticated, unauthorized attacker to inject path traversal character sequences to disclose sensitive information of the ser... Read more
- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2021-41023
A unprotected storage of credentials in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows an authenticated user to disclosure agent password due to plaintext credential storage in log files... Read more
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41022
A improper privilege management in Fortinet FortiSIEM Windows Agent version 4.1.4 and below allows attacker to execute privileged code or commands via powershell scripts... Read more
- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2021-41021
A privilege escalation vulnerability in FortiNAC versions 8.8.8 and below and 9.1.2 and below may allow an admin user to escalate the privileges to root via the sudo command.... Read more
Affected Products : fortinac- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41020
An improper access control vulnerability [CWE-284] in FortiIsolator versions 2.3.2 and below may allow an authenticated, non privileged attacker to regenerate the CA certificate via the regeneration URL.... Read more
Affected Products : fortiisolator- Published: May. 04, 2022
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2021-41019
An improper validation of certificate with host mismatch [CWE-297] vulnerability in FortiOS versions 6.4.6 and below may allow the connection to a malicious LDAP server via options in GUI, leading to disclosure of sensitive information, such as AD credent... Read more
Affected Products : fortios- Published: Nov. 02, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-41018
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests.... Read more
Affected Products : fortiweb- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2021-41017
Multiple heap-based buffer overflow vulnerabilities in some web API controllers of FortiWeb 6.4.1, 6.4.0, and 6.3.0 through 6.3.15 may allow a remote authenticated attacker to execute arbitrary code or commands via specifically crafted HTTP requests.... Read more
Affected Products : fortiweb- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2021-41016
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiExtender version 7.0.1 and below, 4.2.3 and below, 4.1.7 and below allows an authenticated attacker to execute privileged shell commands via CLI command... Read more
- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2021-41015
A improper neutralization of input during web page generation ('cross-site scripting') in Fortinet FortiWeb version 6.4.1 and below, 6.3.15 and below allows attacker to execute unauthorized code or commands via crafted HTTP requests to SAML login handler... Read more
Affected Products : fortiweb- Published: Dec. 08, 2021
- Modified: Nov. 21, 2024