Total CVEs

138,940

Critical Severity

3,615

High Severity

12,982

Last 7 Days

1,046
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,241 - 6,260 of 12,679 CVEs
CVE-2026-38530 HIGH - 8.1

A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request.

Published: Apr 14, 2026
Source: NVD
CVE-2026-38529 HIGH - 8.8

A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request.

Published: Apr 14, 2026
Source: NVD
CVE-2026-38528 HIGH - 7.1

Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parameter at /Lead/LeadDataGrid.php.

Published: Apr 14, 2026
Source: NVD
CVE-2026-38527 HIGH - 8.5

A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request.

Published: Apr 14, 2026
Source: NVD
CVE-2026-23708 HIGH - 7.5

A improper authentication vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5.0 through 7.5.2 may allow an unauthenticated attacker to bypass authentication via replaying captured 2FA req...

Vendor: Fortinet
Product: FortiSOAR PaaS, FortiSOAR on-premise
Published: Apr 14, 2026
Source: NVD
CVE-2026-22828 HIGH - 8.1

A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large am...

Vendor: Fortinet
Product: FortiAnalyzer Cloud, FortiManager Cloud
Published: Apr 14, 2026
Source: NVD
CVE-2025-61848 HIGH - 7.2

An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, F...

Vendor: Fortinet
Product: FortiManager, FortiAnalyzer, FortiManager Cloud, FortiAnalyzer Cloud
Published: Apr 14, 2026
Source: NVD
CVE-2026-4369 HIGH - 7.1

A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to r...

Published: Apr 14, 2026
Source: NVD
CVE-2026-4345 HIGH - 7.1

A maliciously crafted HTML payload, stored in a design name and exported to CSV, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of...

Published: Apr 14, 2026
Source: NVD
CVE-2026-4344 HIGH - 7.1

A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read loca...

Published: Apr 14, 2026
Source: NVD
CVE-2026-2332 HIGH - 7.4

In Eclipse Jetty, the HTTP/1.1 parser is vulnerable to request smuggling when chunk extensions are used, similar to the "funky chunks" techniques outlined here: * https://w4ke.info/2025/06/18/funky-chunks.html * https://w4ke.info/2025/10/29/funky-chunks-2.html Jetty terminates chu...

Vendor: maven
Product: org.eclipse.jetty:jetty-http
Published: Apr 14, 2026
Source: NVD
CVE-2026-33892 HIGH - 7.1

A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial Edge Management Pro V2 (All versions >= V2.0.0 < V2.1.1), Industrial Edge Management Virtual (All versions >= V2.2.0 < V2.8.0). Affected management systems do no...

Vendor: Siemens
Product: Industrial Edge Management Pro V1, Industrial Edge Management Pro V2, Industrial Edge Management Virtual
Published: Apr 14, 2026
Source: NVD
CVE-2026-31923 HIGH - 7.5

Cleartext Transmission of Sensitive Information vulnerability in Apache APISIX. This can occur due to `ssl_verify` in openid-connect plugin configuration being set to false by default. This issue affects Apache APISIX: from 0.7 through 3.15.0. Users are recommended to upgrade to version 3.16.0, wh...

Vendor: Apache Software Foundation
Product: Apache APISIX
Published: Apr 14, 2026
Source: NVD
CVE-2026-27668 HIGH - 8.8

A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowed to administer groups they belong to. This could allow an authenticated User Administrator to escalate their own privileges and grant themselves ac...

Vendor: Siemens
Product: RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P)
Published: Apr 14, 2026
Source: NVD
CVE-2026-25654 HIGH - 8.8

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing password reset requests. This could allow an authenticated remote attacker to bypass authorization checks, leading to the ability to reset the ...

Vendor: Siemens
Product: SINEC NMS
Published: Apr 14, 2026
Source: NVD
CVE-2026-24032 HIGH - 7.3

A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains an authentication weakness due to insufficient validation of user identity in the UMC component. This could allow an unauthenticated remote attacker to bypass authentication and...

Vendor: Siemens
Product: SINEC NMS
Published: Apr 14, 2026
Source: NVD
CVE-2026-3017 HIGH - 7.2

The Smart Post Show โ€“ Post Grid, Post Carousel & Slider, and List Category Posts plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 3.0.12 via deserialization of untrusted input in the import_shortcodes() function. This makes it possible for authenti...

Published: Apr 14, 2026
Source: NVD
CVE-2026-40287 HIGH - 8.4

PraisonAI is a multi-agent teams system. Versions 4.5.138 and below are vulnerable to arbitrary code execution through automatic, unsanitized import of a tools.py file from the current working directory. Components including call.py (import_tools_from_file()), tool_resolver.py (_load_local_tools()),...

Vendor: MervinPraison
Product: PraisonAI, praisonaiagents
Published: Apr 14, 2026
Source: NVD
CVE-2026-6227 HIGH - 7.2

The BackWPup plugin for WordPress is vulnerable to Local File Inclusion via the `block_name` parameter of the `/wp-json/backwpup/v1/getblock` REST endpoint in all versions up to, and including, 5.6.6 due to a non-recursive `str_replace()` sanitization of path traversal sequences. This makes it possi...

Published: Apr 14, 2026
Source: NVD
CVE-2026-4388 HIGH - 7.2

The Form Maker by 10Web plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Matrix field (Text Box input type) in form submissions in all versions up to, and including, 1.15.40. This is due to insufficient input sanitization (`sanitize_text_field` strips tags but not quotes) an...

Published: Apr 14, 2026
Source: NVD