CVE-2026-84389
- EPSS 0.14%
- Veröffentlicht 08.09.2026 16:41:45
- Zuletzt bearbeitet 10.09.2026 04:18:17
A url redirection to untrusted site ('open redirect') vulnerability in Fortinet FortiSIEM 7.5.0 through 7.5.1, FortiSIEM 7.4.1 through 7.4.2 may allow attacker to execute unauthorized code or commands via <insert attack vector here>
CVE-2026-70467
- EPSS 0.26%
- Veröffentlicht 12.08.2026 12:19:02
- Zuletzt bearbeitet 08.09.2026 21:00:55
A server-side request forgery (ssrf) vulnerability in Fortinet FortiSIEM 7.5.0, FortiSIEM 7.4.0 through 7.4.2, FortiSIEM 7.3.0 through 7.3.5, FortiSIEM 7.2 all versions, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM 6.7 all versio...
CVE-2026-59838
- EPSS 0.14%
- Veröffentlicht 15.07.2026 14:18:33
- Zuletzt bearbeitet 15.07.2026 18:47:38
A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through 7.2.6, FortiSIEM 7.1 all versions, FortiSIEM 7.0 all versions, FortiSIEM...
CVE-2026-59841
- EPSS 0.15%
- Veröffentlicht 14.07.2026 15:15:08
- Zuletzt bearbeitet 15.07.2026 05:17:23
A improper restriction of communication channel to intended endpoints vulnerability in Fortinet FortiSIEMWindowsAgent 7.4.0 through 7.4.1 may allow attacker to escalation of privilege via <insert attack vector here>
CVE-2026-25972
- EPSS 0.33%
- Veröffentlicht 10.03.2026 16:44:19
- Zuletzt bearbeitet 12.03.2026 16:05:03
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4 may allow a remote unauthenticated attacker to provide arbitrary data enabling a social e...
CVE-2025-64155
- EPSS 43.22%
- Veröffentlicht 13.01.2026 16:32:28
- Zuletzt bearbeitet 20.01.2026 16:16:06
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.1.0 through 7.1.8, FortiSIEM 7.0.0 through 7.0.4, FortiSIEM 6.7.0 thro...
CVE-2025-58324
- EPSS 0.25%
- Veröffentlicht 14.10.2025 15:22:35
- Zuletzt bearbeitet 14.10.2025 20:25:09
An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 ...
CVE-2025-25256
- EPSS 60.34%
- Veröffentlicht 12.08.2025 18:59:14
- Zuletzt bearbeitet 18.08.2026 21:16:32
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, FortiSIEM 7.0....
CVE-2023-40714
- EPSS 0.58%
- Veröffentlicht 02.04.2025 08:15:13
- Zuletzt bearbeitet 15.07.2025 19:41:08
A relative path traversal in Fortinet FortiSIEM versions 7.0.0, 6.7.0 through 6.7.2, 6.6.0 through 6.6.3, 6.5.1, 6.5.0 allows attacker to escalate privilege via uploading certain GUI elements
CVE-2019-17659
- EPSS 0.64%
- Veröffentlicht 17.03.2025 13:06:07
- Zuletzt bearbeitet 15.07.2025 16:48:48
A use of hard-coded cryptographic key vulnerability in FortiSIEM version 5.2.6 may allow a remote unauthenticated attacker to obtain SSH access to the supervisor as the restricted user "tunneluser" by leveraging knowledge of the private key from anot...