Browsing: Alerts

CVSSv3 Score: 6.8 An improper neutralization of special elements used in an SQL command (‘SQL injection’) [CWE-89] in FortiAnalyzer, FortiAnalyzer…

HomeDescriptionlibexpat before 2.7.6 uses insufficient entropy, and thus hash flooding can occur via a crafted XML document.PUBLISHED Reserved 2026-04-16 | Published 2026-04-16 |…

Summary An Improper neutralization of input during web page generation (‘cross-site scripting’) vulnerability [CWE-79] in FortiSOAR may allow an authenticated…

CVSSv3 Score: 4.3 An Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability [CWE-79] in FortiSandbox and FortiSandbox…