CVE-2026-21643
- EPSS 0.04%
- Veröffentlicht 06.02.2026 08:24:43
- Zuletzt bearbeitet 17.02.2026 21:34:17
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP reques...
CVE-2025-59922
- EPSS 0.07%
- Veröffentlicht 13.01.2026 16:32:28
- Zuletzt bearbeitet 14.01.2026 21:38:33
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.4, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2.0 through 7.2.10, Fort...
CVE-2023-48786
- EPSS 0.04%
- Veröffentlicht 10.06.2025 16:36:19
- Zuletzt bearbeitet 16.07.2025 15:17:53
A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests.
CVE-2024-32119
- EPSS 0.02%
- Veröffentlicht 10.06.2025 16:36:15
- Zuletzt bearbeitet 16.07.2025 15:20:12
An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or taggi...
CVE-2025-22859
- EPSS 0.32%
- Veröffentlicht 13.05.2025 14:46:42
- Zuletzt bearbeitet 16.07.2025 15:16:59
A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload request...
CVE-2025-22855
- EPSS 0.17%
- Veröffentlicht 08.04.2025 14:15:32
- Zuletzt bearbeitet 23.07.2025 16:03:19
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code.
CVE-2019-16149
- EPSS 0.1%
- Veröffentlicht 28.03.2025 09:07:30
- Zuletzt bearbeitet 15.07.2025 18:59:31
An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized code by injecting malicious payload in the user profile of a FortiClient instance being managed by the ...
CVE-2024-36506
- EPSS 0.26%
- Veröffentlicht 14.01.2025 14:15:30
- Zuletzt bearbeitet 31.01.2025 17:10:44
An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, 6.4 all versions may allow a remote attacker to bypass the trusted host feature via session connecti...
CVE-2024-36510
- EPSS 0.39%
- Veröffentlicht 14.01.2025 14:15:30
- Zuletzt bearbeitet 31.01.2025 16:30:50
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow a...
CVE-2024-23106
- EPSS 0.91%
- Veröffentlicht 14.01.2025 14:15:28
- Zuletzt bearbeitet 16.07.2025 13:33:49
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP ...