2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-0209 | MEDIUM | 6.9 | 0.4% | Apr 14, 2026 | Under certain administrative conditions, FlashArray Purity may apply snapshot retention policies earlier or later than c... |
| CVE-2026-0207 | HIGH | 8.5 | 0.4% | Apr 14, 2026 | A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions. |
| CVE-2026-34626 | MEDIUM | 6.3 | 0.3% | Apr 14, 2026 | Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Mo... |
| CVE-2026-34622 | HIGH | 8.6 | 0.4% | Apr 14, 2026 | Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Mo... |
| CVE-2026-27291 | HIGH | 7.8 | 0.1% | Apr 14, 2026 | InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could resul... |
| CVE-2026-27286 | MEDIUM | 5.5 | 0.2% | Apr 14, 2026 | InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could... |
| CVE-2026-27285 | MEDIUM | 5.5 | 0.1% | Apr 14, 2026 | InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could... |
| CVE-2026-27284 | HIGH | 7.8 | 0.2% | Apr 14, 2026 | InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a cr... |
| CVE-2026-27283 | HIGH | 7.8 | 0.2% | Apr 14, 2026 | InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Use After Free vulnerability that could result in a... |
| CVE-2026-27238 | HIGH | 7.8 | 0.2% | Apr 14, 2026 | InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could... |
| CVE-2026-22692 | MEDIUM | 6.8 | 0.4% | Apr 14, 2026 | October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4... |
| CVE-2026-5713 | MEDIUM | 5.3 | 0.1% | Apr 14, 2026 | The "profiling.sampling" module (Python 3.15+) and "asyncio introspection capabilities" (3.14+, "python -m asyncio ps" a... |
| CVE-2026-4832 | MEDIUM | 6.9 | 0.3% | Apr 14, 2026 | CWE-798 Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to sensitive device info... |
| CVE-2026-39815 | HIGH | 8.8 | 0.4% | Apr 14, 2026 | A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDD... |
| CVE-2026-39814 | MEDIUM | 6.7 | 0.1% | Apr 14, 2026 | A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb... |
| CVE-2026-39813 | CRITICAL | 9.8 | 16.7% | Apr 14, 2026 | A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.... |
| CVE-2026-39812 | MEDIUM | 4.8 | 0.2% | Apr 14, 2026 | A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSa... |
| CVE-2026-39811 | MEDIUM | 4.9 | 0.4% | Apr 14, 2026 | A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, F... |
| CVE-2026-39810 | MEDIUM | 5.5 | 0.1% | Apr 14, 2026 | A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to... |
| CVE-2026-39809 | MEDIUM | 6.7 | 0.1% | Apr 14, 2026 | A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiCl... |
| CVE-2026-39808 | CRITICAL | 9.8 | 48.7% | Apr 14, 2026 | A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet F... |
| CVE-2026-38533 | MEDIUM | 6.5 | 0.3% | Apr 14, 2026 | An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attac... |
| CVE-2026-38532 | HIGH | 8.1 | 0.4% | Apr 14, 2026 | A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2... |
| CVE-2026-38530 | HIGH | 8.1 | 0.4% | Apr 14, 2026 | A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.... |
| CVE-2026-38529 | HIGH | 8.8 | 0.6% | Apr 14, 2026 | A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allo... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now