CVE Browser

Search and filter CVEs by severity, ecosystem, EPSS score, and more.

Clear
More filters (active)

Page 1 (more results available)

CVE-2026-26084 CRITICAL

A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5,…

CVSS 9.9 EPSS 0.39% Sep 8, 2026
CVE-2026-84387 HIGH

A improper neutralization of special elements used in a command ('command injection') vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through…

CVSS 7.2 EPSS 1.40% Sep 8, 2026
CVE-2026-59835 HIGH

A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticate…

CVSS 8.6 EPSS 0.40% Jul 14, 2026
CVE-2026-25089 KEV CRITICAL

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiS…

CVSS 9.8 EPSS 76.11% Jun 9, 2026
CVE-2026-26083 CRITICAL

A missing authorization vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.2 through 5.0.5, F…

CVSS 9.8 EPSS 0.50% May 12, 2026
CVE-2026-39813 CRITICAL

A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of…

CVSS 9.8 EPSS 0.72% Apr 14, 2026
CVE-2025-61886 MEDIUM

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 thr…

CVSS 5.4 EPSS 0.27% Apr 14, 2026
CVE-2026-39812 MEDIUM

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox…

CVSS 4.8 EPSS 0.24% Apr 14, 2026
CVE-2026-25691 MEDIUM

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0…

CVSS 6.7 EPSS 0.47% Apr 14, 2026
CVE-2026-27316 LOW

A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 throu…

CVSS 2.7 EPSS 0.30% Apr 14, 2026
CVE-2026-39808 KEV CRITICAL

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may all…

CVSS 9.8 EPSS 47.36% Apr 14, 2026
CVE-2025-53608 MEDIUM

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 thr…

CVSS 4.8 EPSS 0.31% Mar 10, 2026
CVE-2025-52436 CRITICAL

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 thr…

CVSS 9.6 EPSS 6.53% Feb 10, 2026
CVE-2025-67685 LOW

A Server-Side Request Forgery (SSRF) vulnerability [CWE-918] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox 4.4 all versions, FortiSa…

CVSS 3.8 EPSS 0.42% Jan 13, 2026
CVE-2025-53679 HIGH

An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0…

CVSS 7.2 EPSS 12.30% Dec 9, 2025
CVE-2025-54353 MEDIUM

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 thr…

CVSS 6.1 EPSS 6.31% Dec 9, 2025
CVE-2025-53949 HIGH

An Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0…

CVSS 8.8 EPSS 17.19% Dec 9, 2025
CVE-2025-46215 MEDIUM

An Improper Isolation or Compartmentalization vulnerability [CWE-653] in Fortinet FortiSandbox 5.0.0 through 5.0.1, FortiSandbox 4.4.0 through 4.4.7, FortiSand…

CVSS 5.3 EPSS 0.32% Nov 18, 2025
CVE-2024-27779 MEDIUM

An insufficient session expiration vulnerability [CWE-613] in FortiSandbox FortiSandbox version 4.4.4 and below, version 4.2.6 and below, 4.0 all versions, 3.2…

CVSS 6.7 EPSS 0.47% Jul 18, 2025
CVE-2021-26105 HIGH

A stack-based buffer overflow vulnerability (CWE-121) in the profile parser of FortiSandbox version 3.2.2 and below, version 3.1.4 and below may allow an authe…

CVSS 8.8 EPSS 0.50% Mar 24, 2025
CVE-2024-54027 HIGH

A Use of Hard-coded Cryptographic Key vulnerability [CWE-321] in FortiSandbox version 4.4.6 and below, version 4.2.7 and below, version 4.0.5 and below, versio…

CVSS 7.8 EPSS 0.15% Mar 17, 2025
CVE-2024-54026 HIGH

An improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiSandbox 4.4.0 through 4.4.6, FortiSandbox 4.2 all vers…

CVSS 8.8 EPSS 0.41% Mar 11, 2025
CVE-2024-54018 HIGH

Multiple improper neutralization of special elements used in an OS Command vulnerabilities [CWE-78] in FortiSandbox before 4.4.5 allows a privileged attacker t…

CVSS 7.2 EPSS 10.04% Mar 11, 2025
CVE-2024-52960 HIGH

A client-side enforcement of server-side security vulnerability [CWE-602] in Fortinet FortiSandbox version 5.0.0, 4.4.0 through 4.4.6 and before 4.2.7 allows a…

CVSS 8.8 EPSS 0.33% Mar 11, 2025
CVE-2024-52961 HIGH

An improper neutralization of special elements used in an OS Command vulnerability [CWE-78] vulnerability in Fortinet FortiSandbox 5.0.0, FortiSandbox 4.4.0 th…

CVSS 8.8 EPSS 0.54% Mar 11, 2025

Showing 1 to 25 CVEs · page 1 (more available)