CVE-2025-32932 – FortiSOAR XSS

An Improper neutralization of input during web page generation (‘cross-site scripting’) vulnerability [CWE-79] in FortiSOAR version 7.6.1 and below, version 7.5.1 and below, 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions WEB UI may allow an authenticated remote attacker to perform an XSS attack via stored malicious service […]

CVE-2025-25256 – Fortinet FortiSIEM OS Command Injection

The following table lists the changes that have been made to the CVE-2025-25256 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 12, 2025 Action […]

CVE-2025-27759 – Fortinet FortiWeb OS Command Injection

The following table lists the changes that have been made to the CVE-2025-27759 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 12, 2025 Action […]

CVE-2025-25248 – FortiOS Integer Overflow in SSL-VPN Bookmarks

An Integer Overflow or Wraparound vulnerability [CWE-190] in FortiOS version 7.6.2 and below, version 7.4.7 and below, version 7.2.10 and below, 7.2 all versions, 6.4 all versions, FortiProxy version 7.6.2 and below, version 7.4.3 and below, 7.2 all versions, 7.0 all versions, 2.0 all versions and FortiPAM version 1.5.0, version 1.4.2 and below, 1.3 all versions, […]

CVE-2024-52964 – Fortinet FortiManager Path Traversal Vulnerability

The following table lists the changes that have been made to the CVE-2024-52964 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 12, 2025 Action […]

CVE-2024-48892 – FortiSOAR Relative Path Traversal Vulnerability

The following table lists the changes that have been made to the CVE-2024-48892 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 12, 2025 Action […]

CVE-2024-40588 – Fortinet FortiMail, FortiVoice, FortiRecorder, FortiCamera, FortiNDR Path Traversal Vulnerability

The following table lists the changes that have been made to the CVE-2024-40588 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 12, 2025 Action […]

CVE-2023-45584 – Fortinet FortiOS Double Free Vulnerability

The following table lists the changes that have been made to the CVE-2023-45584 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 12, 2025 Action […]

CVE-2024-26009 – Fortinet FortiOS Authentication Bypass via FGFM Requests

The following table lists the changes that have been made to the CVE-2024-26009 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Aug. 12, 2025 Action […]

Docker Hub still hosts dozens of Linux images with the XZ backdoor

Docker Hub still hosts dozens of Linux images with the XZ backdoor The XZ-Utils backdoor, first discovered in March 2024, is still present in at least 35 Linux images on Docker Hub, potentially putting users, organizations, and their data at risk. Docker Hub is the o … Read more Published Date: Aug 12, 2025 (2 hours, […]