|
801
|
- |
|
-
|
-
|
Plaintext Storage of a Password vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud Server.
In a setup where OpenID is used as the primary method of authentication to authenticate to Sparx EA, P…
|
CWE-256
Plaintext Storage of a Password
|
CVE-2025-15624
|
2026-04-18 00:13 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
802
|
- |
|
-
|
-
|
Unauthenticated user is able to execute arbitrary SQL commands in Sparx Pro Cloud Server database in certain cases.
|
CWE-89 CWE-200
SQL Injection Information Exposure
|
CVE-2025-15625
|
2026-04-18 00:13 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
803
|
6.0 |
MEDIUM
Local
|
-
|
-
|
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all…
|
CWE-22
Path Traversal
|
CVE-2025-68649
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
804
|
5.7 |
MEDIUM
Network
|
-
|
-
|
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-21742
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
805
|
4.6 |
MEDIUM
Network
|
-
|
-
|
An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR Paa…
|
CWE-79
Cross-site Scripting
|
CVE-2026-22154
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
806
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-22155
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
807
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all…
|
CWE-22
Path Traversal
|
CVE-2026-22573
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
808
|
4.1 |
MEDIUM
Network
|
-
|
-
|
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all v…
|
CWE-257
Storing Passwords in a Recoverable Format
|
CVE-2026-22574
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
809
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all v…
|
CWE-257
Storing Passwords in a Recoverable Format
|
CVE-2026-22576
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
810
|
8.1 |
HIGH
Network
|
-
|
-
|
A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-22828
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|