Everything you care about in one place

Follow feeds: blogs, news, RSS and more. An effortless way to read and digest content of your choice.

Get Feeder

filestore.fortinet.com

FortiGuard Labs | FortiGuard Center - IR Advisories

Get the latest updates from FortiGuard Labs | FortiGuard Center - IR Advisories directly as they happen.

Follow now 89 followers

Latest posts

Last updated 28 days ago

Use of uninitialized resource in SSLVPN websocket

28 days ago

Multiple potential issues, including the use of uninitialized ressources [CWE-908] and excessive...

Log Pollution via login page

28 days ago

An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiManager and FortiAnalyzer...

OS command injection on diagnose feature (GUI)

28 days ago

An improper neutralization of special elements used in an OS command ('OS...

Directory Traversal

28 days ago

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...

LDAP Clear-text credentials retrievable with IP modification

28 days ago

An insufficiently protected credentials [CWE-522] vulnerability in FortiOS may allow a privileged...

Incorrect user management in widgets dashboard

28 days ago

An Incorrect User Management vulnerability [CWE-286] in FortiWeb widgets dashboard may allow...

No certificate name verification for fgfm connection

28 days ago

A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in...

EMS can send javascript code to client through messages

28 days ago

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79]...

OS command injection on gen-ca-cert command

28 days ago

An improper neutralization of special elements used in an OS command ('OS...

Unverified password change via set_password endpoint

28 days ago

An unverified password change vulnerability [CWE-620] in FortiSwitch GUI may allow a...

Incorrect authorization in incident page

about 2 months ago

An incorrect authorization vulnerability [CWE-863] in FortiSIEM may allow an authenticated attacker...

Os command injection on vm download feature

about 2 months ago

An improper neutralization of special elements used in an OS Command vulnerability...