CVE-2025-49813
- EPSS 0.12%
- Veröffentlicht 12.08.2025 18:59:19
- Zuletzt bearbeitet 15.08.2025 12:26:02
An improper neutralization of special elements used in an OS Command ("OS Command Injection") vulnerability [CWE-78] in Fortinet FortiADC version 7.2.0 and before 7.1.1 allows a remote and authenticated attacker with low privilege to execute unauthor...
CVE-2025-31104
- EPSS 0.07%
- Veröffentlicht 10.06.2025 16:36:13
- Zuletzt bearbeitet 22.07.2025 17:06:49
An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] in FortiADC 7.6.0 through 7.6.1, 7.4.0 through 7.4.6, 7.2.0 through 7.2.7, 7.1.0 through 7.1.4, 7.0 all versions, 6.2 all versions, 6...
CVE-2023-37933
- EPSS 0.03%
- Veröffentlicht 11.03.2025 14:54:35
- Zuletzt bearbeitet 22.07.2025 21:39:07
An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiADC GUI version 7.4.0, 7.2.0 through 7.2.1 and before 7.1.3 allows an authenticated attacker to perform an XSS attack via crafted H...
CVE-2022-23439
- EPSS 0.06%
- Veröffentlicht 22.01.2025 10:15:07
- Zuletzt bearbeitet 12.02.2025 13:39:42
A externally controlled reference to a resource in another sphere in Fortinet FortiManager before version 7.4.3, FortiMail before version 7.0.3, FortiAnalyzer before version 7.4.3, FortiVoice version 7.0.0, 7.0.1 and before 6.4.8, FortiProxy before v...
CVE-2024-36511
- EPSS 0.09%
- Veröffentlicht 10.09.2024 15:15:16
- Zuletzt bearbeitet 20.09.2024 19:43:25
An improperly implemented security check for standard vulnerability [CWE-358] in FortiADC Web Application Firewall (WAF) 7.4.0 through 7.4.4, 7.2 all versions, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions, 6.0 all versions w...
CVE-2023-50181
- EPSS 0.16%
- Veröffentlicht 09.07.2024 16:15:03
- Zuletzt bearbeitet 21.11.2024 08:36:36
An improper access control vulnerability [CWE-284] in Fortinet FortiADC version 7.4.0 through 7.4.1 and before 7.2.4 allows a read only authenticated attacker to perform some write actions via crafted HTTP or HTTPS requests.
CVE-2023-50179
- EPSS 0.16%
- Veröffentlicht 09.07.2024 16:15:03
- Zuletzt bearbeitet 21.11.2024 08:36:36
An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2 all versions, 7.1 all versions, 7.0 all versions may allow a remote and unauthenticated attacker to perform a Man-in-the-Middle attack on the communication channel betw...
CVE-2023-50178
- EPSS 0.11%
- Veröffentlicht 09.07.2024 16:15:03
- Zuletzt bearbeitet 21.11.2024 08:36:36
An improper certificate validation vulnerability [CWE-295] in FortiADC 7.4.0, 7.2.0 through 7.2.3, 7.1 all versions, 7.0 all versions, 6.2 all versions, 6.1 all versions and 6.0 all versions may allow a remote and unauthenticated attacker to perform ...
CVE-2023-50180
- EPSS 0.14%
- Veröffentlicht 14.05.2024 17:15:27
- Zuletzt bearbeitet 21.11.2024 08:36:36
An exposure of sensitive system information to an unauthorized control sphere vulnerability [CWE-497] in FortiADC version 7.4.1 and below, version 7.2.3 and below, version 7.1.4 and below, version 7.0.5 and below, version 6.2.6 and below may allow a ...
CVE-2023-41673
- EPSS 0.16%
- Veröffentlicht 13.12.2023 07:15:15
- Zuletzt bearbeitet 21.11.2024 08:21:27
An improper authorization vulnerability [CWE-285] in Fortinet FortiADC version 7.4.0 and before 7.2.2 may allow a low privileged user to read or backup the full system configuration via HTTP or HTTPS requests.