Nyhetsnavet

Samlar nyheter från utvalda källor. Logga in för att spara urval och skapa profiler.

Uppdaterad 2026-08-02 13:16 Nästa om --:-- Försenad
111 av 111 källor 20 per källa

En blandad vy med nyheter från alla kategorier. Perfekt för en snabb daglig överblick utan att växla mellan flöden.

Toppnyheter Mix
Sverige 0 artiklar
Världen 4 artiklar
DW World ikon
DW World
Germany: As temperatures rise, so does climate skepticism

Some 98% of active climate scientists say climate change is happening, and is man-made. Nonetheless, a new study shows the number of climate-change skeptics in Germany has increased. Why is that?

DW World ikon DW World
Euronews ikon
Euronews
Five wildfires still burn in Turkey as risk extends into next week

Of 206 fires recorded since Wednesday, 202 had been brought under control by Friday, but some remained active across western and southern coasts, with high temperatures and strong winds forecast to persist across 10...

Euronews ikon Euronews
Teknik 11 artiklar
Hacker News ikon
Hacker News
Go 1.27 Interactive Tour

Article URL: https://victoriametrics.com/blog/go-1-27/index.html Comments URL: https://news.ycombinator.com/item?id=49140218 Points: 236 # Comments: 89

Hacker News ikon Hacker News
MacRumors ikon
MacRumors
6 Things We Already Know About the 2028 iPhone

Rumors about Apple's 2028 iPhone are already starting to circulate, offering an early look at how the company plans to evolve the iPhone's design, display, and cameras. The 2028 device will follow the 20th anniversary...

6 Things We Already Know About the 2028 iPhone
The Verge ikon
The Verge
Angela Nissel faces down grief with a laugh

Angela Nissel's latest book, Good Grief, Pass the Bread, Mom Is Dead, is my kind of memoir. Sure, it's a deeply emotional tale about caring for a terminally ill parent. But it's delivered with the sort of gallows...

Angela Nissel faces down grief with a laugh
MacRumors ikon
MacRumors
How Apple Changed Under Tim Cook: 15 Years in Numbers

Apple CEO Tim Cook participated in his final Apple earnings call yesterday, with incoming CEO John Ternus set to take over on September 1. With Cook's tenure coming to an end, we thought we'd take a look at how Apple...

How Apple Changed Under Tim Cook: 15 Years in Numbers
MacRumors ikon
MacRumors
Set a Custom EQ for Your AirPods in iOS 27

Sony, Bose, and Sennheiser owners have been able to adjust the audio frequency spectrum of their headphones for years, whereas AirPods owners have had to make do with Apple's default tuning. That's no longer the case...

Set a Custom EQ for Your AirPods in iOS 27
MacRumors ikon
MacRumors
MacBook Ultra's New Design Won't Stay Exclusive for Long

The touchscreen and the OLED panel have dominated discussion about Apple's next high-end laptop, but the redesign wrapped around them may prove to be an equally consequential change, largely because it is not expected...

MacBook Ultra's New Design Won't Stay Exclusive for Long
MacRumors ikon
MacRumors
Apple Reports 3Q 2026 Results: $29.8B Profit on $109.4B Revenue

Apple today announced financial results for its third fiscal quarter of 2026, which corresponds to the second calendar quarter of the year. For the quarter, Apple posted revenue of $109.4 billion and net quarterly...

Apple Reports 3Q 2026 Results: $29.8B Profit on $109.4B Revenue
Sport 0 artiklar
Hälsa & träning 8 artiklar
ScienceDaily (Health) ikon
ScienceDaily (Health)
Rice bran compound may help ease irritable bowel symptoms

A compound in rice bran may help calm an overactive gut by reducing the calcium signals that cause intestinal muscles to contract. Ferulic acid suppressed contractions triggered by several chemical messengers in...

ScienceDaily (Health) ikon ScienceDaily (Health)
WHO News ikon
WHO News
Timor-Leste certified malaria-free by WHO

The World Health Organization (WHO) has certified Timor-Leste as malaria-free, a remarkable achievement for a country that prioritized the disease and embarked on a concerted, nation-wide response shortly after...

WHO News ikon WHO News
Breaking Muscle ikon
Breaking Muscle
The Strongest Pre-Workout Powders to Fuel Your Training in 2025

Whether you’re starting your fitness journey or you’re a weightlifting junkie, there are several supplements that should be staples in your stack. As a certified personal trainer and nutrition coach, I’d put a high-...

The Strongest Pre-Workout Powders to Fuel Your Training in 2025
Säkerhet 97 artiklar
BleepingComputer ikon
BleepingComputer
Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

BleepingComputer ikon BleepingComputer
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
GitHub Security Advisories ikon
GitHub Security Advisories
CVE-2016-1000305: guard-livereload has a directory traversal vulnerability

The vulnerability allows remote attackers to read arbitrary files on the server by exploiting improper path validation in the livereload server functionality. This vulnerability is related to the handling of file...

GitHub Security Advisories ikon GitHub Security Advisories
1 fler källor
Cisco PSIRT Cisco Secure Firewall Management Center Software Static Credential Vulnerability 2026-07-31 21:49
SecurityWeek Vulnerabilities ikon
SecurityWeek Vulnerabilities
Critical Flaw Allowed to Azure Cosmos DB Pwnage

Named CosmosEscape, the vulnerability exposed the primary key for Cosmos DB accounts, granting full read and write access. The post Critical Flaw Allowed to Azure Cosmos DB Pwnage appeared first on SecurityWeek.

SecurityWeek Vulnerabilities ikon SecurityWeek Vulnerabilities
BleepingComputer ikon
BleepingComputer
VMware fixes three critical flaws allowing auth bypass, VM escapes

Broadcom has released security updates to fix five vulnerabilities in VMware vCenter, ESX, Workstation, and Fusion, including three critical flaws that allow attackers to bypass authentication, execute arbitrary code,...

BleepingComputer ikon BleepingComputer
1 fler källor
Microsoft MSRC CVE-2026-24304 Azure Cosmos DB Remote Code Execution Vulnerability 2026-07-30 16:00
CISA Alerts ikon
CISA Alerts
MikroTik RouterOS

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to extract the router's WireGuard private key in plaintext using only low‑privilege API access, enabling full VPN impersonation...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Johnson Controls OpenBlue Employee

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to upload malicious files, execute stored cross-site scripting attacks, or inject arbitrary HTML content. The following...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
NASA Core Flight System (cFS) Health & Safety (HS) Application

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to cause a denial-of-service condition. The following versions of NASA Core Flight System (cFS) Health & Safety (HS) Application...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Mitsubishi Electric CC-Link IE TSN Communication Protocol

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Schneider Electric IGSS

View CSAF Summary Schneider Electric is aware of a vulnerability in its IGSS Definition module for the IGSS (Interactive Graphical SCADA System) product. The [IGSS](https://igss.schneider-electric.com/) product is a...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Toptech Systems RCU II+ and Multiload II+

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain full system control and misuse it to access or manipulate connected networks and resources. The following versions of...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Watchfire Controller Software

View CSAF Summary Successful exploitation of this vulnerability could allow a malicious user the ability to deliver malicious firmware that can update and gain full control of the controller. The following versions of...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
MZ Automation GmbH libiec61850

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the device. The following versions of MZ Automation GmbH libiec61850 are affected:...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
o6 Automation open62541

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose sensitive information, cause a denial of service, or potentially execute arbitrary code. The following versions of...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
MZ Automation lib60870

View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed. The following versions of MZ Automation lib60870 are affected: lib60870 2.4.0 (CVE-2026-61893, CVE-2026-63033)...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20316 Cisco Secure Firewall Management Center Use of Hard-coded Password...

CISA Alerts ikon CISA Alerts
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-20316 – Cisco Secure Firewall Management Center (FMC)

Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an...

CISA KEV-katalog ikon CISA KEV-katalog
CISA Alerts ikon
CISA Alerts
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP

View CSAF Summary Multiple vulnerabilities have been identified in the additional GNU/Linux subsystem of the firmware version V3.1.6 for the SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP (incl. SIPLUS variant). Siemens is...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
Siemens Desigo CC

View CSAF Summary OpenSSL has published a stack based buffer overflow vulnerability that allows a remote attacker to cause a denial of service (DoS) or potentially allow for remote code execution. Siemens has released...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
igloohome Smart Lock Mobile Application

View CSAF Summary Successful exploitation of this vulnerability could allow an unauthorized actor to access functions or backend services. The following versions of igloohome Smart Lock Mobile Application are...

CISA Alerts ikon CISA Alerts
CISA Alerts ikon
CISA Alerts
ABB KNX Update Tool

View CSAF Summary ABB has been contacted by a researcher who identified a vulnerability in one of its products. ABB has been contacted by a researcher who identified a vulnerability in one of its products. The...

CISA Alerts ikon CISA Alerts
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-13390 — MEDIUM — CVSS 5.3

The Events Calendar WordPress plugin before 6.16.5.1 does not perform an authorization check on one of its Event Aggregator import REST API routes and skips an integrity check for a particular status value, allowing...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-10082 — MEDIUM — CVSS 6.1 2026-07-27 09:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-13332 — CRITICAL — CVSS 9.1

The Masteriyo LMS WordPress plugin before 2.3.1 does not correctly verify authorization on an unauthenticated AJAX action used to clear user sessions, allowing unauthenticated attackers to terminate the active...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-12394 — CRITICAL — CVSS 9.8 2026-07-27 09:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-12493 — HIGH — CVSS 7.5

The Clover Payment Gateway by Zaytech for WooCommerce WordPress plugin before 1.3.6 does not verify that an approved external payment record actually belongs to the WooCommerce order being completed, nor that the paid...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-12255 — HIGH — CVSS 8.1 2026-07-27 09:16
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2025-15662 — HIGH — CVSS 8.6

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-supplied URL before fetching it server-side and does not enforce a valid authorization check, allowing...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2025-68686 – Fortinet FortiOS

Fortinet FortiOS contains an exposure of sensitive information to an unauthorized actor vulnerability. This may allow a remote unauthenticated attacker to bypass the patch developed for the symbolic link persistency...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-16812 – Arista VeloCloud Orchestrator

Arista VeloCloud Orchestrator On-Prem contains an OS command injection vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may...

CISA KEV-katalog ikon CISA KEV-katalog
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-57990 — HIGH — CVSS 7.4

Files or directories accessible to external parties in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over a network.

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
1 fler källor
NVD (National Vulnerability Database) CVE-2026-57989 — HIGH — CVSS 7.4 2026-07-26 20:18
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-57978 — MEDIUM — CVSS 5.4

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
NVD (National Vulnerability Database) ikon
NVD (National Vulnerability Database)
CVE-2026-17497 — HIGH — CVSS 8.3

NoteGen before 0.32.0 grants the Tauri shell plugin shell:allow-execute capability for bash, python, and python3 with arbitrary arguments in the default desktop capabilities. JavaScript running in the application...

NVD (National Vulnerability Database) ikon NVD (National Vulnerability Database)
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-16232 – Check Point SmartConsole

Check Point SmartConsole contains an improper authentication vulnerability which could allow an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-50522 – Microsoft SharePoint

Microsoft SharePoint contains a deserialization of untrusted data vulnerability which could allow an unauthorized attacker to execute code over a network. | Åtgärd: Apply mitigations in accordance with vendor...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-63030 – WordPress Core

WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137. |...

CISA KEV-katalog ikon CISA KEV-katalog
1 fler källor
CISA KEV-katalog CVE-2026-60137 – WordPress Core 2026-07-21 02:00
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2021-27137 – DD-WRT DD-WRT

DD-WRT contains a stack-based buffer overflow vulnerability that could allow an unauthenticated attacker to overflow an internal buffer used by UPnP and trigger a code execution vulnerability. | Åtgärd: Apply...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-39808 – Fortinet FortiSandbox

Fortinet FortiSandbox contains an OS command injection vulnerability that could allow an unauthenticated attacker to execute unauthorized code or commands via crafted HTTP requests. | Åtgärd: Apply mitigations in...

CISA KEV-katalog ikon CISA KEV-katalog
Cisco PSIRT ikon
Cisco PSIRT
Cisco Identity Services Engine Path Traversal Vulnerability

A vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform path traversal attacks on the underlying operating...

Cisco PSIRT ikon Cisco PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Path traversal in CLI command allows deletion of root file system

CVSSv3 Score: 5.0 An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability [CWE-22] in FortiOS, FortiPAM, FortiProxy and FortiSwitch Manager may allow a privileged authenticated...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Buffer overread in authd and wad daemon

CVSSv3 Score: 4.1 A buffer over-read vulnerability [CWE-126] in FortiOS, FortiProxy, and FortiSASE may allow an authenticated remote attacker to return a portion of device memory in the redirect response via...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Cross-Site Scripting in Domain parameter

CVSSv3 Score: 5.3 An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability [CWE-80] in FortiSIEM may allow a privileged administrator to execute unauthorized commands via crafted...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Header injection in Web Filter warning page

CVSSv3 Score: 3.4 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy may allow an attacker in possession of a valid web filter...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Header injection in captive portal authentication form

CVSSv3 Score: 3.1 An Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability [CWE-113] in FortiOS and FortiProxy captive portal may allow an attacker able to intercept and...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Out of bounds read in GUI

CVSSv3 Score: 7.0 An out of bounds read [CWE-125] vulnerability in FortiAuthenticator may allow a remote unauthenticated attacker to retrieve sensitive information via a specially crafted request. Revised on...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
SSL-VPN Reflected XSS

CVSSv3 Score: 6.1 An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] in FortiOS, FortiProxy, FortiPAM and FortiSwitch-Manager Agentless SSL-VPN may allow an...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Stack Buffer Overflow in Log Report

CVSSv3 Score: 5.9 A Stack-based Buffer Overflow vulnerability [CWE-121] in FortiOS, FortiProxy and FortiPAM may allow a privileged authenticated attacker who can bypass stack protection and ASLR to execute arbitrary...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Supers override fails to properly override supervisor address

CVSSv3 Score: 6.9 An Improper Restriction of Communication Channel to Intended Endpoints [CWE-923] vulnerability in FortiSIEM Windows Agent may allow an unauthorized attacker on the same local network to execute...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Unauthenticated VNC access exposed on all interfaces

CVSSv3 Score: 7.7 An Exposure of Resource to Wrong Sphere vulnerability [CWE-668] in FortiSandbox may allow an unauthenticated attacker to access the VNC server of VMs performing scanning via network requests. Revised...

Fortinet PSIRT ikon Fortinet PSIRT
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-56155 – Microsoft Active Directory Federation Services

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. | Åtgärd: Apply mitigations in...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-15409 – SonicWall SMA1000 Appliances

SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location. | Åtgärd:...

CISA KEV-katalog ikon CISA KEV-katalog
CISA KEV-katalog ikon
CISA KEV-katalog
CVE-2026-56291 – Balbooa Forms

Balbooa Forms contains an unrestricted upload of file with dangerous type vulnerability that allows an unauthenticated arbitrary file upload which could allow uploading of executable files leading to full RCE. |...

CISA KEV-katalog ikon CISA KEV-katalog
Cisco PSIRT ikon
Cisco PSIRT
Cisco Catalyst Center Arbitrary File Read Vulnerability

A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to insufficient validation of user-supplied...

Cisco PSIRT ikon Cisco PSIRT
Cisco PSIRT ikon
Cisco PSIRT
ClamAV Vulnerabilities Affecting Cisco Products: July 2026

Multiple vulnerabilities in ClamAV could allow a remote attacker to cause a denial of service (DoS) condition, interrupting scanning operations. For more information about these vulnerabilities, see the Details...

Cisco PSIRT ikon Cisco PSIRT
Cisco PSIRT ikon
Cisco PSIRT
Cisco Finesse Remote File Inclusion Vulnerability

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to browser-based...

Cisco PSIRT ikon Cisco PSIRT
Cisco PSIRT ikon
Cisco PSIRT
Cisco Umbrella Virtual Appliance Privilege Escalation Vulnerability

A vulnerability in the vmadmin CLI of Cisco Umbrella Virtual Appliance could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to insufficient validation of...

Cisco PSIRT ikon Cisco PSIRT
1 fler källor
Cisco PSIRT Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability 2026-06-16 19:39
Fortinet PSIRT ikon
Fortinet PSIRT
Improper access control in API endpoints

CVSSv3 Score: 6.2 An improper access control vulnerability [CWE-284] in FortiPortal API endpoints may allow a remote privileged attacker with organization user role to obtain sensitive network configuration data via...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Restricted CLI escape using Lua

CVSSv3 Score: 6.0 An Internal Asset Exposed to Unsafe Debug Access Level or State vulnerability [CWE-1244] in FortiOS and FortiProxy may allow an authenticated admin to execute lua scripts via crafted CLI commands....

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Second-Order OS Command Injection via JSON Input on start vnc feature

CVSSv3 Score: 9.1 An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSandbox, FortiSandbox Cloud and FortiSandbox PaaS WEB UI may allow an unauthenticated attacker to...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
LDAP authentication bypass in Agentless VPN and FSSO

CVSSv3 Score: 7.5 An Authentication Bypass by Primary Weakness vulnerability [CWE-305] in FortiOS fnbamd may allow an unauthenticated attacker to bypass LDAP authentication of Agentless VPN or FSSO policy, under...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Trusted hosts bypass via SSH

CVSSv3 Score: 1.8 An Improper Privilege Management vulnerability [CWE-269] in FortiOS, FortiProxy and FortiPAM may allow an authenticated administrator to bypass the trusted host policy via crafted CLI command....

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Insertion of Sensitive 2FA Information in logs and debug command

CVSSv3 Score: 2.6 An Insertion of Sensitive Information into Log File vulnerability [CWE-532] in FortiOS may allow an attacker with at least read-only privileges to retrieve sensitive 2FA-related information via...

Fortinet PSIRT ikon Fortinet PSIRT
Fortinet PSIRT ikon
Fortinet PSIRT
Information Disclosure on SSLVPN endpoint

CVSSv3 Score: 3.9 An Exposure of Sensitive Information to an Unauthorized Actor vulnerability [CWE-200] in FortiOS SSL-VPN web-mode may allow an authenticated user to access full SSL-VPN settings via crafted URL....

Fortinet PSIRT ikon Fortinet PSIRT
Ladda fler
Visar 120 av 133 artiklar