|
631
|
- |
|
-
|
-
|
CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc re…
Update
|
CWE-93
CRLF Injection
|
CVE-2026-2400
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
632
|
- |
|
-
|
-
|
CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an a…
Update
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-2401
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
633
|
- |
|
-
|
-
|
CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authenticat…
Update
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-2402
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
634
|
- |
|
-
|
-
|
CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting log integrity when a Web Admin user alters the POST /logsetti…
Update
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-2403
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
635
|
- |
|
-
|
-
|
CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /j_security check request payload.
Update
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2026-2404
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
636
|
- |
|
-
|
-
|
CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of service when a Web Admin user floods the system with POST /he…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-2405
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
637
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code…
Update
|
CWE-78
OS Command
|
CVE-2026-39808
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
638
|
6.7 |
MEDIUM
Local
|
-
|
-
|
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEM…
Update
|
CWE-89
SQL Injection
|
CVE-2026-39809
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
639
|
6.0 |
MEDIUM
Local
|
-
|
-
|
A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.
Update
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-39810
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
640
|
4.9 |
MEDIUM
Network
|
-
|
-
|
A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions …
Update
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-39811
|
2026-04-18 00:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|