Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
135 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.81% | — | Fortinet Fortisandbox | 4/8/2021 | 17/6/2026 | An instance of small space of random values in the RPC API of FortiSandbox before 4.0.0 may allow an attacker in possession of a few information pieces about the state of the device to possibly predict valid session IDs. | |
| Modificada | Alta (7.2) | 1.4% | — | Fortinet Fortisandbox | 20/7/2021 | 17/6/2026 | An instance of improper neutralization of special elements in the sniffer module of FortiSandbox before 3.2.2 may allow an authenticated administrator to execute commands on the underlying system's shell via altering the content of its configuration file. | |
| Modificada | Media (5.3) | 0.50% | — | Fortinet Fortisandbox | 9/7/2021 | 17/6/2026 | A concurrent execution using shared resource with improper synchronization ('race condition') in the command shell of FortiSandbox before 3.2.2 may allow an authenticated attacker to bring the system into an unresponsive state via specifically orchestrated sequences of commands. | |
| Modificada | Media (6.1) | 0.92% | — | Fortinet Fortisandbox | 9/4/2019 | 17/6/2026 | A reflected Cross-Site-Scripting (XSS) vulnerability in Fortinet FortiSandbox before 3.0 may allow an attacker to execute unauthorized code or commands via the back_url parameter in the file scan component. | |
| Modificada | Crítica (10) | 2.4% | — | Sandboxie-plus Sandboxie | 29/10/2018 | 17/6/2026 | Sandboxie 5.26 allows a Sandbox Escape via an "import os" statement, followed by os.system("cmd") or os.system("powershell"), within a .py file. NOTE: the vendor disputes this issue because the observed behavior is consistent with the product's intended functionality | |
| Modificada | Alta (7.8) | 0.99% | — | Sandboxie Installer | 6/8/2017 | 17/6/2026 | Sandboxie installer 5071703 has a DLL Hijacking or Unsafe DLL Loading Vulnerability via a Trojan horse dwmapi.dll or profapi.dll file in an AppData\Local\Temp directory. | |
| Modificada | Media (6.1) | 1.5% | — | Fortinet Fortisandbox Firmware | 26/5/2016 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Web User Interface (WebUI) in Fortinet FortiSandbox before 2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) serial parameter to alerts/summary/profile/; the (2) urlForCreatingReport parameter to csearch/report/export/; the (3) id… | |
| Modificada | Alta (10) | 2.2% | — | Sandbox | 19/12/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in lib/jpgraph/jpgraph_errhandler.inc.php in Sandbox 1.4.1 might allow remote attackers to execute arbitrary PHP code via unspecified vectors. NOTE: the issue, if any, may be located in Aditus JpGraph rather than Sandbox. If so, then this should not be treated as an issue in… | |
| Modificada | Baja (2.1) | 0.37% | — | Norman Sandbox Analyzer | 2/3/2007 | 16/6/2026 | Norman SandBox Analyzer does not use the proper range for Interrupt Descriptor Table (IDT) entries, which allows local users to determine that the local machine is an emulator, or a similar environment not based on a physical Intel processor, which allows attackers to produce malware that is more difficult to analyze. | |
| Modificada | Baja (1.2) | 0.30% | — | Sandbox | 3/8/2005 | 16/6/2026 | Race condition in sandbox before 1.2.11 allows local users to create or overwrite arbitrary files via symlink attack on sandboxpids.tmp. |