Latest CVE Feed
-
5.5
MEDIUMCVE-2025-25873
Cross Site Request Forgery vulnerability in Open Panel OpenAdmin v.0.3.4 allows a remote attacker to escalate privileges via the Change Root Password function... Read more
Affected Products : openadmin- Published: Mar. 14, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Cross-Site Request Forgery
-
5.5
MEDIUMCVE-2025-25872
An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function... Read more
Affected Products : openpanel- Published: Mar. 14, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Authorization
-
8.0
HIGHCVE-2025-25871
An issue in Open Panel v.0.3.4 allows a remote attacker to escalate privileges via the Fix Permissions function... Read more
Affected Products : openpanel- Published: Mar. 14, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Authorization
-
6.5
MEDIUMCVE-2024-40585
An insertion of sensitive information into log file vulnerabilities [CWE-532] in FortiManager version 7.4.0, version 7.2.3 and below, version 7.0.8 and below, version 6.4.12 and below, version 6.2.11 and below and FortiAnalyzer version 7.4.0, version 7.2.... Read more
- Published: Mar. 14, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Information Disclosure
-
4.8
MEDIUMCVE-2023-48785
An improper certificate validation vulnerability [CWE-295] in FortiNAC-F version 7.2.4 and below may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the HTTPS communication channel between the FortiOS device, an invent... Read more
Affected Products : fortinac-f- Published: Mar. 14, 2025
- Modified: Jul. 25, 2025
- Vuln Type: Misconfiguration
-
8.2
HIGHCVE-2023-45588
An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /... Read more
Affected Products : forticlient- Published: Mar. 14, 2025
- Modified: Jul. 15, 2025
- Vuln Type: Path Traversal
-
5.3
MEDIUMCVE-2023-33300
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiNAC 7.2.1 and earlier, 9.4.3 and earlier allows attacker a limited, unauthorized file access via specifically crafted request in inter-server communica... Read more
Affected Products : fortinac- Published: Mar. 14, 2025
- Modified: Jul. 23, 2025
- Vuln Type: Injection
-
7.2
HIGHCVE-2022-29059
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] in FortiWeb version 7.0.1 and below, 6.4.2 and below, 6.3.20 and below, 6.2.7 and below may allow a privileged attacker to execute SQL commands ... Read more
Affected Products : fortiweb- Published: Mar. 14, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Injection
-
6.5
MEDIUMCVE-2024-47573
An improper validation of integrity check value vulnerability [CWE-354] in FortiNDR version 7.4.2 and below, version 7.2.1 and below, version 7.1.1 and below, version 7.0.6 and below may allow an authenticated attacker with at least Read/Write permission ... Read more
Affected Products : fortindr- Published: Mar. 14, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Misconfiguration
-
8.8
HIGHCVE-2024-46662
A improper neutralization of special elements used in a command ('command injection') in Fortinet FortiManager versions 7.4.1 through 7.4.3, FortiManager Cloud versions 7.4.1 through 7.4.3 allows attacker to escalation of privilege via specifically crafte... Read more
- Published: Mar. 14, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Injection
-
7.5
HIGHCVE-2024-45643
IBM Security QRadar 3.12 EDR uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt sensitive credential information.... Read more
- Published: Mar. 14, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Cryptography
-
4.4
MEDIUMCVE-2024-45638
IBM Security QRadar 3.12 EDR stores user credentials in plain text which can be read by a local privileged user.... Read more
- Published: Mar. 14, 2025
- Modified: Jul. 16, 2025
- Vuln Type: Information Disclosure
-
4.8
MEDIUMCVE-2024-40590
An improper certificate validation vulnerability [CWE-295] in FortiPortal version 7.4.0, version 7.2.4 and below, version 7.0.8 and below, version 6.0.15 and below when connecting to a FortiManager device, a FortiAnalyzer device, or an SMTP server may all... Read more
Affected Products : fortiportal- Published: Mar. 14, 2025
- Modified: Jul. 24, 2025
- Vuln Type: Misconfiguration
-
5.5
MEDIUMCVE-2023-52927
In the Linux kernel, the following vulnerability has been resolved: netfilter: allow exp not to be removed in nf_ct_find_expectation Currently nf_conntrack_in() calling nf_ct_find_expectation() will remove the exp from the hash table. However, in some s... Read more
Affected Products : linux_kernel- Published: Mar. 14, 2025
- Modified: Aug. 19, 2025
- Vuln Type: Misconfiguration
-
6.9
MEDIUMCVE-2025-2268
The HP LaserJet MFP M232-M237 Printer Series may be vulnerable to a denial of service attack when a specially crafted request message is sent via Internet Printing Protocol (IPP).... Read more
Affected Products :- Published: Mar. 14, 2025
- Modified: Mar. 14, 2025
- Vuln Type: Denial of Service
-
8.7
HIGHCVE-2025-29776
Azle is a WebAssembly runtime for TypeScript and JavaScript on ICP. Calling `setTimer` in Azle versions `0.27.0`, `0.28.0`, and `0.29.0` causes an immediate infinite loop of timers to be executed on the canister, each timer attempting to clean up the glob... Read more
Affected Products :- Published: Mar. 14, 2025
- Modified: Mar. 14, 2025
- Vuln Type: Denial of Service
-
5.9
MEDIUMCVE-2025-29032
Tenda AC9 v15.03.05.19(6318) was discovered to contain a buffer overflow via the formWifiWpsOOB function.... Read more
- Published: Mar. 14, 2025
- Modified: Apr. 03, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-29031
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the fromAddressNat function.... Read more
- Published: Mar. 14, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-29030
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formWifiWpsOOB function.... Read more
- Published: Mar. 14, 2025
- Modified: Mar. 19, 2025
- Vuln Type: Memory Corruption
-
9.8
CRITICALCVE-2025-29029
Tenda AC6 v15.03.05.16 was discovered to contain a buffer overflow via the formSetSpeedWan function.... Read more
- Published: Mar. 14, 2025
- Modified: Mar. 18, 2025
- Vuln Type: Memory Corruption