2026 CVE Vulnerabilities
52,241 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-25184 | HIGH | 7 | 0.2% | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (... |
| CVE-2026-23666 | HIGH | 7.5 | 1.3% | Apr 14, 2026 | Improper input validation in .NET Framework allows an unauthorized attacker to deny service over a network. |
| CVE-2026-23657 | HIGH | 7.8 | 0.4% | Apr 14, 2026 | Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally. |
| CVE-2026-20930 | HIGH | 7.8 | 0.2% | Apr 14, 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Servic... |
| CVE-2026-0207 | HIGH | 8.5 | 0.4% | Apr 14, 2026 | A vulnerability exists in FlashBlade whereby sensitive information may be logged under specific conditions. |
| CVE-2026-34622 | HIGH | 8.6 | 0.4% | Apr 14, 2026 | Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Mo... |
| CVE-2026-27291 | HIGH | 7.8 | 0.1% | Apr 14, 2026 | InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could resul... |
| CVE-2026-27284 | HIGH | 7.8 | 0.2% | Apr 14, 2026 | InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a cr... |
| CVE-2026-27283 | HIGH | 7.8 | 0.2% | Apr 14, 2026 | InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Use After Free vulnerability that could result in a... |
| CVE-2026-27238 | HIGH | 7.8 | 0.2% | Apr 14, 2026 | InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could... |
| CVE-2026-39815 | HIGH | 8.8 | 0.4% | Apr 14, 2026 | A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDD... |
| CVE-2026-38532 | HIGH | 8.1 | 0.4% | Apr 14, 2026 | A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2... |
| CVE-2026-38530 | HIGH | 8.1 | 0.4% | Apr 14, 2026 | A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.... |
| CVE-2026-38529 | HIGH | 8.8 | 0.6% | Apr 14, 2026 | A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allo... |
| CVE-2026-38528 | HIGH | 7.1 | 0.2% | Apr 14, 2026 | Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parameter at /Lead/LeadDat... |
| CVE-2026-38527 | HIGH | 8.5 | 0.2% | Apr 14, 2026 | A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attac... |
| CVE-2026-23708 | HIGH | 8.1 | 0.3% | Apr 14, 2026 | A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5... |
| CVE-2026-22828 | HIGH | 8.1 | 0.9% | Apr 14, 2026 | A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2... |
| CVE-2026-22155 | HIGH | 7.5 | 0.2% | Apr 14, 2026 | A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOA... |
| CVE-2026-4369 | HIGH | 7.1 | 0.2% | Apr 14, 2026 | A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and... |
| CVE-2026-4345 | HIGH | 7.1 | 0.2% | Apr 14, 2026 | A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripti... |
| CVE-2026-4344 | HIGH | 7.1 | 0.2% | Apr 14, 2026 | A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked... |
| CVE-2026-2450 | HIGH | 7.4 | 0.3% | Apr 14, 2026 | .NET misconfiguration: use of impersonation vulnerability in upKeeper Solutions upKeeper Instant Privilege Access allows... |
| CVE-2026-33892 | HIGH | 7.1 | 0.2% | Apr 14, 2026 | A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial... |
| CVE-2026-31923 | HIGH | 7.5 | 0.3% | Apr 14, 2026 | Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in o... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now