991
|
- |
|
-
|
-
|
A allocation of resources without limits or throttling in Fortinet FortiSIEM 5.3 all versions, 5.4 all versions, 6.x all versions, 7.0 all versions, and 7.1.0 through 7.1.5 may allow an attacker to d…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-46667
|
2025-01-15 00:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
992
|
- |
|
-
|
-
|
An out-of-bounds read vulnerability [CWE-125] in FortiOS SSLVPN web portal versions 7.4.0 through 7.4.4, versions 7.2.0 through 7.2.8, 7.0 all verisons, and 6.4 all versions may allow an authenticate…
|
CWE-125
Out-of-bounds Read
|
CVE-2024-36504
|
2025-01-15 00:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
993
|
- |
|
-
|
-
|
A relative path traversal vulnerability [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5 allows a privileged attacker to delete files from the underlying filesystem via…
|
CWE-23 CWE-22
Relative Path Traversal Path Traversal
|
CVE-2024-32115
|
2025-01-15 00:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
994
|
- |
|
-
|
-
|
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack a…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2024-23106
|
2025-01-15 00:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
995
|
- |
|
-
|
-
|
A stack-based buffer overflow in Fortinet FortiWeb versions 7.2.0 through 7.2.7, and 7.4.0 through 7.4.1 may allow a privileged user to execute arbitrary code via specially crafted CLI commands, prov…
|
CWE-121 CWE-120
Stack-based Buffer Overflow Classic Buffer Overflow
|
CVE-2024-21758
|
2025-01-15 00:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
996
|
- |
|
-
|
-
|
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability [CWE-88] in FortiVoice Entreprise version 7.0.0 through 7.0.1 and before 6.4.8 allows an authenti…
|
CWE-89
SQL Injection
|
CVE-2023-37931
|
2025-01-15 00:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
997
|
- |
|
-
|
-
|
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /common/autocomplete.php.
|
-
|
CVE-2023-42250
|
2025-01-15 00:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
998
|
- |
|
-
|
-
|
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via vam/vam_visits.php.
|
-
|
CVE-2023-42249
|
2025-01-15 00:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
999
|
- |
|
-
|
-
|
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via monitor/s_monitor_map.php.
|
-
|
CVE-2023-42247
|
2025-01-15 00:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
1000
|
- |
|
-
|
-
|
Selesta Visual Access Manager < 4.42.2 is vulnerable to Cross Site Scripting (XSS) via /vam/vam_ep.php.
|
-
|
CVE-2023-42246
|
2025-01-15 00:15 |
2025-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|