Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.9 CRITICAL
CVE-2026-38526 — Krayin CRM PHP File Upload Code Execution Vulnerability

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.

Remote | Misconfiguration
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
5.3 MEDIUM
CVE-2026-2405 — Apache Web Server Uncontrolled Resource Consumption Denial of Service

CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of service when a Web Admin user floods the system with POST /he…

Remote | Denial of Service
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
6.9 MEDIUM
CVE-2026-2404 — Apache Struts Log Injection Vulnerability

CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /j_security check request payload.

Remote | Injection
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
5.3 MEDIUM
CVE-2026-2403 — Citrix Web Admin Improper Input Validation Vulnerability

CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting log integrity when a Web Admin user alters the POST /logsetti…

Remote | Misconfiguration
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
6.9 MEDIUM
CVE-2026-2402 — Apache Brute Force Authentication Bypass

CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authenticat…

Remote | Authentication
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
2.4 LOW
CVE-2026-2401 — Apache Web Admin Sensitive Information Exposure

CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an a…

| Information Disclosure
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
5.3 MEDIUM
CVE-2026-2400 — Apache Web Server CRLF Injection

CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc re…

Remote | Injection
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
6.9 MEDIUM
CVE-2026-2399 — Apache Web Server Path Traversal Vulnerability

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data when a Web Admin user alters the …

| Path Traversal
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
2.7 LOW
CVE-2026-27316 — Fortinet FortiSandbox Credentials Disclosure

A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed adm…

fortisandbox fortisandboxpaas | Remote | Information Disclosure
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
6.7 MEDIUM
CVE-2026-25691 — Fortinet FortiSandbox Path Traversal Vulnerability

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all ver…

fortisandbox fortisandboxcloud fortisandboxpaas | Remote | Path Traversal
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
7.5 HIGH
CVE-2026-23708 — Fortinet FortiSOAR Fortified Authentication Bypass

A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 throug…

fortisoaron-premise fortisoarpaas | Remote | Authentication
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
8.1 HIGH
CVE-2026-22828 — Fortinet FortiAnalyzer Cloud/Manager Buffer Overflow

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary…

fortimanagercloud fortianalyzercloud | Remote | Memory Corruption
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
4.3 MEDIUM
CVE-2026-22576 — Fortinet FortiSOAR Password Recovery Vulnerability

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all v…

fortisoaron-premise fortisoarpaas | Remote | Cryptography
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
4.1 MEDIUM
CVE-2026-22574 — Fortinet FortiSOAR Password Storage Vulnerability

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all v…

fortisoaron-premise fortisoarpaas | Remote | Cryptography
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
6.5 MEDIUM
CVE-2026-22573 — Fortinet FortiSOAR Path Traversal Vulnerability

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all…

fortisoaron-premise fortisoarpaas | Remote | Path Traversal
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
6.5 MEDIUM
CVE-2026-22155 — Fortinet FortiSOAR Clear Text Information Disclosure

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3…

fortisoaron-premise fortisoarpaas | Remote | Cryptography
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
4.6 MEDIUM
CVE-2026-22154 — Fortinet FortiSOAR Cross-Site Scripting Vulnerability

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR Paa…

fortisoaron-premise fortisoarpaas | Remote | Cross-Site Scripting
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
5.7 MEDIUM
CVE-2026-21742 — Fortinet FortiSOAR Cleartext Password Transmission Vulnerability

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3…

fortisoaron-premise fortisoarpaas | Remote | Cryptography
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
2.4 LOW
CVE-2026-21741 — Fortinet FortiNAC Open Redirect Vulnerability

An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may a…

fortinac-f | Remote | Misconfiguration
Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
6.0 MEDIUM
CVE-2025-68649 — Fortinet FortiAnalyzer and FortiManager Path Traversal Privilege Escalation Vulnerability

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all…

Apr 14, 2026 Apr 14, 2026
Apr 14, 2026
Apr 14, 2026
Showing 20 of 6642 Results