CVE-2026-30897
- EPSS 0.63%
- Veröffentlicht 10.03.2026 16:44:04
- Zuletzt bearbeitet 12.03.2026 17:10:03
A stack-based buffer overflow vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow a remote authenticated attacker who can ...
CVE-2026-24858
- EPSS 85.84%
- Veröffentlicht 27.01.2026 19:18:23
- Zuletzt bearbeitet 09.06.2026 18:30:13
An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15...
CVE-2025-59719
- EPSS 25.05%
- Veröffentlicht 09.12.2025 17:20:11
- Zuletzt bearbeitet 09.06.2026 10:16:39
An improper verification of cryptographic signature vulnerability in Fortinet FortiWeb 8.0.0, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9 may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a cra...
CVE-2025-64471
- EPSS 0.34%
- Veröffentlicht 09.12.2025 17:18:44
- Zuletzt bearbeitet 25.09.2026 23:10:00
A use of password hash instead of password for authentication vulnerability [CWE-836] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 t...
CVE-2025-64447
- EPSS 8.35%
- Veröffentlicht 09.12.2025 17:18:42
- Zuletzt bearbeitet 25.09.2026 23:10:00
A reliance on cookies without validation and integrity checking vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allo...
CVE-2025-59669
- EPSS 0.12%
- Veröffentlicht 18.11.2025 17:01:19
- Zuletzt bearbeitet 20.11.2025 14:36:53
A use of hard-coded credentials vulnerability in Fortinet FortiWeb 7.6.0, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow an authenticated attacker with shell access to the device to connect to redis service ...
CVE-2025-58034
- EPSS 55.58%
- Veröffentlicht 18.11.2025 17:01:13
- Zuletzt bearbeitet 21.11.2025 18:27:43
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4.0 through 7.4.10, FortiWeb 7.2.0 t...
CVE-2025-64446
- EPSS 91.84%
- Veröffentlicht 14.11.2025 15:50:52
- Zuletzt bearbeitet 21.11.2025 18:27:33
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.1, FortiWeb 7.6.0 through 7.6.4, FortiWeb 7.4.0 through 7.4.9, FortiWeb 7.2.0 through 7.2.11, FortiWeb 7.0.0 through 7.0.11 may allow an attacker to execute administrative...
CVE-2024-47569
- EPSS 0.43%
- Veröffentlicht 14.10.2025 15:23:03
- Zuletzt bearbeitet 14.01.2026 10:16:02
A insertion of sensitive information into sent data vulnerability in Fortinet FortiMail 7.4.0 through 7.4.2, FortiMail 7.2.0 through 7.2.6, FortiMail 7.0 all versions, FortiManager 7.6.0 through 7.6.1, FortiManager 7.4.1 through 7.4.3, FortiManager C...
CVE-2025-53609
- EPSS 8.96%
- Veröffentlicht 09.09.2025 13:50:41
- Zuletzt bearbeitet 10.09.2025 15:14:32
A Relative Path Traversal vulnerability [CWE-23] in FortiWeb 7.6.0 through 7.6.4, 7.4.0 through 7.4.8, 7.2.0 through 7.2.11, 7.0.2 through 7.0.11 may allow an authenticated attacker to perform an arbitrary file read on the underlying system via craft...