Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.0 MEDIUM
CVE-2026-39810 — Fortinet FortiClientEMS Cryptographic Key Information Disclosure Vulnerability

A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.

forticlientems | Cryptography
Apr 14, 2026 Apr 21, 2026
Apr 14, 2026
Apr 21, 2026
6.7 MEDIUM
CVE-2026-39809 — Fortinet FortiClientEMS SQL Injection Vulnerability

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEM…

forticlientems | Injection
Apr 14, 2026 Apr 21, 2026
Apr 14, 2026
Apr 21, 2026
9.8 CRITICAL
CVE-2026-39808 — Fortinet FortiSandbox OS Command Injection

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet FortiSandbox 4.4.0 through 4.4.8 may allow attacker to execute unauthorized code…

fortisandbox fortisandboxpaas | Remote | Injection
Apr 14, 2026 Apr 22, 2026
Apr 14, 2026
Apr 22, 2026
6.5 MEDIUM
CVE-2026-38533 — Snipe-IT Improper Authorization Authentication Bypass

An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and acco…

Remote | Authorization
Apr 14, 2026 Apr 17, 2026
Apr 14, 2026
Apr 17, 2026
8.1 HIGH
CVE-2026-38532 — Webkul Krayin CRM Object-Level Authorization Bypass

A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanentl…

Remote | Authorization
Apr 14, 2026 Apr 17, 2026
Apr 14, 2026
Apr 17, 2026
8.1 HIGH
CVE-2026-38530 — Webkul Krayin CRM Broken Object-Level Authorization (BOLA)

A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently…

Remote | Authorization
Apr 14, 2026 Apr 17, 2026
Apr 14, 2026
Apr 17, 2026
8.8 HIGH
CVE-2026-38529 — Krayin CRM Broken Object-Level Authorization (BOLA)

A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a fu…

Remote | Authorization
Apr 14, 2026 Apr 17, 2026
Apr 14, 2026
Apr 17, 2026
7.1 HIGH
CVE-2026-38528 — Krayin CRM SQL Injection Vulnerability

Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parameter at /Lead/LeadDataGrid.php.

Remote | Injection
Apr 14, 2026 Apr 17, 2026
Apr 14, 2026
Apr 17, 2026
8.5 HIGH
CVE-2026-38527 — Webkul Krayin CRM SSRF

A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request.

Remote | Server-Side Request Forgery
Apr 14, 2026 Apr 17, 2026
Apr 14, 2026
Apr 17, 2026
9.9 CRITICAL
CVE-2026-38526 — Krayin CRM PHP File Upload Code Execution Vulnerability

An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.

Remote | Misconfiguration
Apr 14, 2026 Apr 17, 2026
Apr 14, 2026
Apr 17, 2026
6.5 MEDIUM
CVE-2026-2405 — Apache Web Server Uncontrolled Resource Consumption Denial of Service

CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of service when a Web Admin user floods the system with POST /he…

powerchute_serial_shutdown | Remote | Denial of Service
Apr 14, 2026 Apr 22, 2026
Apr 14, 2026
Apr 22, 2026
6.9 MEDIUM
CVE-2026-2404 — Apache Struts Log Injection Vulnerability

CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /j_security check request payload.

powerchute_serial_shutdown | Remote | Injection
Apr 14, 2026 Apr 22, 2026
Apr 14, 2026
Apr 22, 2026
5.3 MEDIUM
CVE-2026-2403 — Citrix Web Admin Improper Input Validation Vulnerability

CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting log integrity when a Web Admin user alters the POST /logsetti…

powerchute_serial_shutdown | Remote | Misconfiguration
Apr 14, 2026 Apr 22, 2026
Apr 14, 2026
Apr 22, 2026
6.9 MEDIUM
CVE-2026-2402 — Apache Brute Force Authentication Bypass

CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authenticat…

powerchute_serial_shutdown | Remote | Authentication
Apr 14, 2026 Apr 22, 2026
Apr 14, 2026
Apr 22, 2026
5.0 MEDIUM
CVE-2026-2401 — Apache Web Admin Sensitive Information Exposure

CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an a…

powerchute_serial_shutdown | Information Disclosure
Apr 14, 2026 Apr 22, 2026
Apr 14, 2026
Apr 22, 2026
5.3 MEDIUM
CVE-2026-2400 — Apache Web Server CRLF Injection

CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc re…

powerchute_serial_shutdown | Remote | Injection
Apr 14, 2026 Apr 22, 2026
Apr 14, 2026
Apr 22, 2026
6.9 MEDIUM
CVE-2026-2399 — Apache Web Server Path Traversal Vulnerability

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data when a Web Admin user alters the …

powerchute_serial_shutdown | Path Traversal
Apr 14, 2026 Apr 22, 2026
Apr 14, 2026
Apr 22, 2026
2.7 LOW
CVE-2026-27316 — Fortinet FortiSandbox Credentials Disclosure

A insufficiently protected credentials vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4 all versions, FortiSandbox PaaS 5.0.1 through 5.0.5 may allow an authenticathed adm…

fortisandbox fortisandbox_cloud fortisandboxpaas | Remote | Information Disclosure
Apr 14, 2026 Apr 22, 2026
Apr 14, 2026
Apr 22, 2026
6.7 MEDIUM
CVE-2026-25691 — Fortinet FortiSandbox Path Traversal Vulnerability

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all ver…

Apr 14, 2026 Apr 22, 2026
Apr 14, 2026
Apr 22, 2026
7.5 HIGH
CVE-2026-23708 — Fortinet FortiSOAR Fortified Authentication Bypass

A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 throug…

fortisoaron-premise fortisoarpaas | Remote | Authentication
Apr 14, 2026 Apr 17, 2026
Apr 14, 2026
Apr 17, 2026
Showing 20 of 6447 Results