2026 CVE Vulnerabilities

65,293 CVEs published in 2026.

CVE IDSeverityCVSSDescription
CVE-2026-38528HIGH7.1Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parameter at /Lead/LeadDat...
CVE-2026-38527HIGH8.5A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attac...
CVE-2026-38526CRITICAL9.9An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x a...
CVE-2026-2405MEDIUM6.5CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creat...
CVE-2026-2404MEDIUM5.3CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when ...
CVE-2026-2403MEDIUM4.3CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log tru...
CVE-2026-2402MEDIUM5.3CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to g...
CVE-2026-2401MEDIUM5CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information...
CVE-2026-2400MEDIUM4.3CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application us...
CVE-2026-2399MEDIUM6.1CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could ca...
CVE-2026-27316LOW2.7A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all ...
CVE-2026-25691MEDIUM6.7A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox ...
CVE-2026-23708HIGH8.1A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5...
CVE-2026-22828HIGH8.1A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2...
CVE-2026-22576MEDIUM6.5A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS...
CVE-2026-22574MEDIUM6.5A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS...
CVE-2026-22573MEDIUM6.5An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR Pa...
CVE-2026-22155HIGH7.5A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOA...
CVE-2026-22154MEDIUM5.4An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiS...
CVE-2026-21742MEDIUM6.5A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOA...
CVE-2026-21741MEDIUM4.8An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6....
CVE-2026-4914MEDIUM5.4Stored XSS in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker to obtain limited information f...
CVE-2026-4913MEDIUM5.7Improper protection of an alternate path in Ivanti N-ITSM before version 2025.4 allows a remote authenticated attacker t...
CVE-2026-4369HIGH7.1A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and...
CVE-2026-4345HIGH7.1A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripti...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now