Everything you care about in one place

Follow feeds: blogs, news, RSS and more. An effortless way to read and digest content of your choice.

Get Feeder

filestore.fortinet.com

FortiGuard Labs | FortiGuard Center - IR Advisories

Get the latest updates from FortiGuard Labs | FortiGuard Center - IR Advisories directly as they happen.

Follow now 426 followers

Latest posts

Last updated 3 days ago

EMS can send javascript code to client through messages

about 1 month ago

An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79]...

LDAP Clear-text credentials retrievable with IP modification

about 1 month ago

An insufficiently protected credentials [CWE-522] vulnerability in FortiOS may allow a privileged...

Use of uninitialized resource in SSLVPN websocket

about 1 month ago

Multiple potential issues, including the use of uninitialized ressources [CWE-908] and excessive...

Log Pollution via login page

about 1 month ago

An Improper Output Neutralization for Logs vulnerability [CWE-117] in FortiManager and FortiAnalyzer...

OS command injection on gen-ca-cert command

about 1 month ago

An improper neutralization of special elements used in an OS command ('OS...

No certificate name verification for fgfm connection

about 1 month ago

A improper restriction of communication channel to intended endpoints vulnerability [CWE-923] in...

OS command injection on diagnose feature (GUI)

about 1 month ago

An improper neutralization of special elements used in an OS command ('OS...

Incorrect user management in widgets dashboard

about 1 month ago

An Incorrect User Management vulnerability [CWE-286] in FortiWeb widgets dashboard may allow...

Directory Traversal

about 1 month ago

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')...

Unverified password change via set_password endpoint

about 1 month ago

An unverified password change vulnerability [CWE-620] in FortiSwitch GUI may allow a...

Multiple format string vulnerabilities

about 2 months ago

A use of externally-controlled format string vulnerability [CWE-134] in FortiOS, FortiProxy, FortiPAM...

Os command injection on vm download feature

about 2 months ago

An improper neutralization of special elements used in an OS Command vulnerability...