Latest CVE Feed
-
9.8
CRITICALCVE-2023-25610
A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 throug... Read more
Affected Products : fortimanager fortios fortiswitchmanager fortiproxy fortiweb fortianalyzer fortiswitch fortios-6k7k fortianalyzer- Published: Mar. 24, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
7.8
HIGHCVE-2025-7234
IrfanView CADImage Plugin CGM File Parsing Out-of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of IrfanView CADImage Plugin. User interaction is required t... Read more
- Published: Jul. 21, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
4.3
MEDIUMCVE-2025-49550
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security ... Read more
- Published: Jun. 25, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authorization
-
2.7
LOWCVE-2025-49549
Adobe Commerce versions 2.4.8, 2.4.7-p5, 2.4.6-p10, 2.4.5-p12, 2.4.4-p13 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A high-privileged attacker could leverage this vulnerability to b... Read more
- Published: Jun. 25, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authorization
-
8.8
HIGHCVE-2021-26105
A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authenticated attacker to potentially execute unauthorized code or commands via specifically crafted ... Read more
Affected Products : fortisandbox- Published: Mar. 24, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Memory Corruption
-
8.4
HIGHCVE-2024-21760
An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated attacker to execute ar... Read more
Affected Products : fortisoar- Published: Mar. 18, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Injection
-
6.9
MEDIUMCVE-2025-7021
Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input (e.g., login credentials, email addresses) via displaying a deceptive full... Read more
Affected Products : operator- Published: Jul. 10, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Cross-Site Scripting
-
9.8
CRITICALCVE-2023-47539
An improper access control vulnerability in FortiMail version 7.4.0 configured with RADIUS authentication and remote_wildcard enabled may allow a remote unauthenticated attacker to bypass admin login via a crafted HTTP request.... Read more
Affected Products : fortimail- Published: Mar. 18, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authentication
-
7.2
HIGHCVE-2024-45324
A use of externally-controlled format string vulnerability [CWE-134] in FortiOS version 7.4.0 through 7.4.4, version 7.2.0 through 7.2.9, version 7.0.0 through 7.0.15 and before 6.4.15, FortiProxy version 7.4.0 through 7.4.6, version 7.2.0 through 7.2.12 ... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Injection
-
6.7
MEDIUMCVE-2024-33501
Two improper neutralization of special elements used in an SQL Command ('SQL Injection') vulnerability [CWE-89] in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5, FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnal... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Injection
-
6.7
MEDIUMCVE-2024-32123
Multiple improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiManager, FortiAnalyzer versions 7.4.0 through 7.4.2 7.2.0 through 7.2.5 and 7.0.0 through 7.0.12 and 6.4.0 through 6.4.14 and 6.2.0 throu... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Injection
-
6.0
MEDIUMCVE-2024-36508
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 and Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 CLI allo... Read more
- Published: Feb. 11, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Path Traversal
-
6.7
MEDIUMCVE-2023-40721
A use of externally-controlled format string vulnerability [CWE-134] in Fortinet FortiOS version 7.4.0 through 7.4.1 and before 7.2.6, FortiProxy version 7.4.0 and before 7.2.7, FortiPAM version 1.1.2 and before 1.0.3, FortiSwitchManager version 7.2.0 thr... Read more
- Published: Feb. 11, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Injection
-
5.0
MEDIUMCVE-2024-50570
A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13 and FortiClientLinux 7.4.0 through 7.4.2, 7.2.0 through 7.2.7, 7.0.0 through 7.0.13 may permit a loca... Read more
Affected Products : forticlient- Published: Dec. 18, 2024
- Modified: Jul. 24, 2025
-
6.5
MEDIUMCVE-2024-47573
An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2.1 and below, version 7.1.1 and below, version 7.0.6 and below may allow an authenticated attacker with at least Read/Write permission ... Read more
Affected Products : fortindr- Published: Mar. 14, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2024-46662
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafte... Read more
- Published: Mar. 14, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Injection
-
4.8
MEDIUMCVE-2024-40590
An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may all... Read more
Affected Products : fortiportal- Published: Mar. 14, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Misconfiguration
-
7.2
HIGHCVE-2024-55597
A improper limitation of a pathname to a restricted directory ('path traversal') in Fortinet FortiWeb versions 7.0.0 through 7.6.0 allows attacker to execute unauthorized code or commands via crafted requests.... Read more
Affected Products : fortiweb- Published: Mar. 11, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Path Traversal
-
8.8
HIGHCVE-2024-54026
An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox Cloud version 23.4, FortiSandbox at least 4.4.0 through 4.4.6 and 4.2.0 through 4.2.7 and 4.0.0 through 4.0.5 and 3.2.0 through 3.2.4 and 3.1.... Read more
- Published: Mar. 11, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Injection
-
8.8
HIGHCVE-2024-52960
A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows an authenticated attacker with at least read-only permission to execute unauthorized commands via... Read more
Affected Products : fortisandbox- Published: Mar. 11, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Authorization