Post

2025-10-17 Daily Vulns

NEW:

CVEvendor-productdescriptionmetricReferenceurltitleGithubURL 
CVE-2025-10699Lenovo - LeCloud ClientA vulnerability was reported in the Lenovo LeCloud client application that, under certain conditions, could allow information disclosure.CVSS4.0: 6 - MEDIUM CVSS3.1: 5.3 - MEDIUM0 1Exploitation: noneAutomatable: noTechnical Impact: partialundefinedgithub
CVE-2024-26008Fortinet - FortiOSFortinet - FortiSwitchManagerFortinet - FortiPAMFortinet - FortiProxyAn improper check or handling of exceptional conditions vulnerability [CWE-703] in FortiOS version 7.4.0 through 7.4.3 and before 7.2.7, FortiProxy version 7.4.0 through 7.4.3 and before 7.2.9, FortiPAM before 1.2.0 and FortiSwitchManager version 7.2.0 through 7.2.3 and version 7.0.0 through 7.0.3 fgfm daemon may allow an unauthenticated attacker to repeatedly reset the fgfm connection via crafted SSL encrypted TCP requests.CVSS3.1: 5 - MEDIUM0Exploitation: noneAutomatable: yesTechnical Impact: partialundefinedgithub
CVE-2024-56143strapi - strapiStrapi is an open-source headless content management system. In versions from 5.0.0 to before 5.5.2, the lookup operator provided by the document service does not properly sanitize query parameters for private fields. An attacker can access private fields, including admin passwords and reset tokens, by crafting queries with the lookup parameter. This vulnerability is fixed in 5.5.2.CVSS3.1: 8.2 - HIGH0 1Exploitation: pocAutomatable: yesTechnical Impact: partialStrapi Allows Unauthorized Access to Private Fields via parms.lookupgithub
CVE-2024-47569Fortinet - FortiVoiceFortinet - FortiManagerFortinet - FortiRecorderFortinet - FortiOSFortinet - FortiNDRFortinet - FortiPAMFortinet - FortiTesterFortinet - FortiMailFortinet - FortiWebFortinet - FortiProxyA insertion of sensitive information into sent data in Fortinet FortiManager Cloud 7.4.1 through 7.4.3, FortiVoice 7.0.0 through 7.0.4, 6.4.0 through 6.4.9, 6.0.7 through 6.0.12, FortiMail 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.9, FortiOS 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.8, 7.0.0 through 7.0.15, 6.4.0 through 6.4.15, 6.2.0 through 6.2.17, 6.0.0 through 6.0.18, FortiWeb 7.6.0, 7.4.0 through 7.4.4, 7.2.0 through 7.2.11, 7.0.0 through 7.0.11, 6.4.0 through 6.4.3, FortiRecorder 7.2.0 through 7.2.1, 7.0.0 through 7.0.4, FortiNDR 7.6.0 through 7.6.1, 7.4.0 through 7.4.8, 7.2.0 through 7.2.5, 7.1.0 through 7.1.1, 7.0.0 through 7.0.7, 1.5.0 through 1.5.3, FortiPAM 1.3.0 through 1.3.1, 1.2.0, 1.1.0 through 1.1.2, 1.0.0 through 1.0.3, FortiTester 7.4.0 through 7.4.2, 7.3.0 through 7.3.2, 7.2.0 through 7.2.3, 7.1.0 through 7.1.1, 7.0.0, 4.2.0 through 4.2.1, FortiProxy 7.4.0 through 7.4.4, 7.2.0 through 7.2.10, 7.0.0 through 7.0.21, 2.0.0 through 2.0.14, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7, FortiManager 7.6.0 through 7.6.1, 7.4.1 through 7.4.3 allows attacker to disclose sensitive information via specially crafted packets.CVSS3.1: 4.2 - MEDIUM0Exploitation: noneAutomatable: noTechnical Impact: partialundefinedgithub
This post is licensed under CC BY 4.0 by the author.