CVE-2024-35274
- EPSS 0.04%
- Published 12.11.2024 19:15:09
- Last modified 17.01.2025 20:29:43
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiAnalyzer versions below 7.4.2, Fortinet FortiManager versions below 7.4.2 and Fortinet FortiAnalyzer-BigData version 7.4.0 and b...
CVE-2024-33505
- EPSS 0.34%
- Published 12.11.2024 19:15:09
- Last modified 31.01.2025 17:41:27
A heap-based buffer overflow in Fortinet FortiAnalyzer version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6.4.14, FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.5, 7.0.0 through 7.0.12, 6.4.0 through 6....
CVE-2024-32118
- EPSS 0.3%
- Published 12.11.2024 19:15:09
- Last modified 17.01.2025 20:42:17
Multiple improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerabilities [CWE-78] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, Fortinet FortiAnalyzer version 7.4.0 through 7.4.2 and...
CVE-2024-32117
- EPSS 0.36%
- Published 12.11.2024 19:15:09
- Last modified 21.01.2025 22:19:39
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability [CWE-22] in Fortinet FortiManager version 7.4.0 through 7.4.2 and below 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and below 7.2.5 & FortiAnalyzer-B...
CVE-2024-26011
- EPSS 0.05%
- Published 12.11.2024 19:15:08
- Last modified 12.12.2024 19:33:58
A missing authentication for critical function in Fortinet FortiManager version 7.4.0 through 7.4.2, 7.2.0 through 7.2.4, 7.0.0 through 7.0.11, 6.4.0 through 6.4.14, FortiPAM version 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiProxy version...
CVE-2024-31496
- EPSS 0.04%
- Published 12.11.2024 19:15:08
- Last modified 21.01.2025 22:11:48
A stack-based buffer overflow vulnerability [CWE-121] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData 7.4.0 and before 7.2.7 allows a privileg...
- EPSS 0.12%
- Published 12.11.2024 19:15:08
- Last modified 21.01.2025 22:19:07
Multiple relative path traversal vulnerabilities [CWE-23] in Fortinet FortiManager version 7.4.0 through 7.4.2 and before 7.2.5, FortiAnalyzer version 7.4.0 through 7.4.2 and before 7.2.5 and FortiAnalyzer-BigData version 7.4.0 and before 7.2.7 allow...
CVE-2024-23666
- EPSS 8.31%
- Published 12.11.2024 19:15:07
- Last modified 21.01.2025 22:04:37
A client-side enforcement of server-side security in Fortinet FortiAnalyzer-BigData at least version 7.4.0 and 7.2.0 through 7.2.6 and 7.0.1 through 7.0.6 and 6.4.5 through 6.4.7 and 6.2.5, FortiManager version 7.4.0 through 7.4.1 and 7.2.0 through...
CVE-2023-44255
- EPSS 0.16%
- Published 12.11.2024 19:15:06
- Last modified 21.01.2025 22:02:45
An exposure of sensitive information to an unauthorized actor [CWE-200] in Fortinet FortiManager before 7.4.2, FortiAnalyzer before 7.4.2 and FortiAnalyzer-BigData before 7.2.5 may allow a privileged attacker with administrative read permissions to r...
CVE-2024-47575
- EPSS 91.38%
- Published 23.10.2024 15:15:30
- Last modified 08.11.2024 21:16:28
A missing authentication for critical function in FortiManager 7.6.0, FortiManager 7.4.0 through 7.4.4, FortiManager 7.2.0 through 7.2.7, FortiManager 7.0.0 through 7.0.12, FortiManager 6.4.0 through 6.4.14, FortiManager 6.2.0 through 6.2.12, Fortine...