2026 CVE Vulnerabilities
65,293 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-38528 | HIGH | 7.1 | 0.2% | Apr 14, 2026 | Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parameter at /Lead/LeadDat... |
| CVE-2026-38527 | HIGH | 8.5 | 0.2% | Apr 14, 2026 | A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attac... |
| CVE-2026-38526 | CRITICAL | 9.9 | 0.8% | Apr 14, 2026 | An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a... |
| CVE-2026-2405 | MEDIUM | 6.5 | 0.2% | Apr 14, 2026 | CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creat... |
| CVE-2026-2404 | MEDIUM | 5.3 | 0.2% | Apr 14, 2026 | CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when ... |
| CVE-2026-2403 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log tru... |
| CVE-2026-2402 | MEDIUM | 5.3 | 0.3% | Apr 14, 2026 | CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to g... |
| CVE-2026-2401 | MEDIUM | 5 | 0.1% | Apr 14, 2026 | CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information... |
| CVE-2026-2400 | MEDIUM | 4.3 | 0.2% | Apr 14, 2026 | CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application us... |
| CVE-2026-2399 | MEDIUM | 6.1 | 0.2% | Apr 14, 2026 | CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could ca... |
| CVE-2026-27316 | LOW | 2.7 | 0.3% | Apr 14, 2026 | A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all ... |
| CVE-2026-25691 | MEDIUM | 6.7 | 0.5% | Apr 14, 2026 | A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox ... |
| CVE-2026-23708 | HIGH | 8.1 | 0.3% | Apr 14, 2026 | A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5... |
| CVE-2026-22828 | HIGH | 8.1 | 0.9% | Apr 14, 2026 | A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2... |
| CVE-2026-22576 | MEDIUM | 6.5 | 0.3% | Apr 14, 2026 | A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS... |
| CVE-2026-22574 | MEDIUM | 6.5 | 0.3% | Apr 14, 2026 | A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS... |
| CVE-2026-22573 | MEDIUM | 6.5 | 0.4% | Apr 14, 2026 | An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR Pa... |
| CVE-2026-22155 | HIGH | 7.5 | 0.2% | Apr 14, 2026 | A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOA... |
| CVE-2026-22154 | MEDIUM | 5.4 | 0.2% | Apr 14, 2026 | An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS... |
| CVE-2026-21742 | MEDIUM | 6.5 | 0.1% | Apr 14, 2026 | A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOA... |
| CVE-2026-21741 | MEDIUM | 4.8 | 0.2% | Apr 14, 2026 | An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.... |
| CVE-2026-4914 | MEDIUM | 5.4 | 0.3% | Apr 14, 2026 | Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information f... |
| CVE-2026-4913 | MEDIUM | 5.7 | 0.6% | Apr 14, 2026 | Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker t... |
| CVE-2026-4369 | HIGH | 7.1 | 0.2% | Apr 14, 2026 | A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and... |
| CVE-2026-4345 | HIGH | 7.1 | 0.2% | Apr 14, 2026 | A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripti... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now