Everything you care about in one place

Follow feeds: blogs, news, RSS and more. An effortless way to read and digest content of your choice.

Get Feeder

filestore.fortinet.com

FortiGuard Labs | FortiGuard Center - IR Advisories

Get the latest updates from FortiGuard Labs | FortiGuard Center - IR Advisories directly as they happen.

Follow now 511 followers

Latest posts

Last updated 14 days ago

Out-Of-Bounds Write in administrative interface

14 days ago

CVSSv3 Score: 6.7 An out-of-bounds write vulnerability [CWE-787] in FortiWeb CGI daemon...

Integer Overflow Denial of Service in administrative interface

15 days ago

CVSSv3 Score: 4.4 An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiWeb...

Arbitrary directory delete on vmimages delete feature

15 days ago

CVSSv3 Score: 6.2 An Improper Limitation of a Pathname to a Restricted...

Multiple Path traversals in CLI

15 days ago

CVSSv3 Score: 6.2 Multiple Relative Path Traversal vulnerabilities [CWE-23] in FortiWeb may...

Credential disclosure in LDAP configuration web page.

15 days ago

CVSSv3 Score: 2.5 An Insufficiently protected credentials vulnerability [CWE-522] in FortiSanbox and...

Missing Authentication for critical function in CAPWAP daemon

15 days ago

CVSSv3 Score: 6.2 A missing authentication for critical function vulnerability [CWE-306] in...

Heap-based buffer overflow in oftpd daemon

15 days ago

CVSSv3 Score: 7.3 A heap-based buffer overflow vulnerability [CWE-122] in FortiAnalyzer Cloud...

Clear-text credentials retrievable with IP modification for connectors

15 days ago

CVSSv3 Score: 4.1 A Storing Passwords in a Recoverable Format vulnerability [CWE-257]...

Cleartext Credentials in response for API endpoints

15 days ago

CVSSv3 Score: 6.2 A Cleartext Transmission of Sensitive Information vulnerability [CWE-319] in...

Clear-text credentials retrievable with IP modification for LDAP

15 days ago

CVSSv3 Score: 4.1 A Storing Passwords in a Recoverable Format vulnerability [CWE-257]...

Multiple SQL Injections

15 days ago

CVSSv3 Score: 7.1 An Improper Neutralization of Special Elements used in an...

Hardcoded symmetric encryption key for Postgresql

15 days ago

CVSSv3 Score: 5.2 A use of hard-coded cryptographic key vulnerability [CWE 321]...