Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,806
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 6,481 - 6,500 of 13,553 CVEs
CVE-2026-24906 MEDIUM - 5.4

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.14 and 4.1.10 contain a Stored Cross-Site Scripting (XSS) vulnerability in the Backend Editor Settings. The Markup Classes fields (used for paragraph styles, inline styles, table styles, etc.) did not sanitize input...

Vendor: octobercms
Product: october
Published: Apr 14, 2026
Source: NVD
CVE-2026-23670 MEDIUM - 5.7

Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-23653 MEDIUM - 5.7

Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-21331 MEDIUM - 6.1

Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browse...

Vendor: Adobe
Product: Adobe Connect
Published: Apr 14, 2026
Source: NVD
CVE-2026-20945 MEDIUM - 4.6

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

Published: Apr 14, 2026
Source: NVD
CVE-2026-20928 MEDIUM - 4.6

Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.

Published: Apr 14, 2026
Source: NVD
CVE-2026-20806 MEDIUM - 5.5

Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-0390 MEDIUM - 6.7

Reliance on untrusted inputs in a security decision in Windows Boot Loader allows an authorized attacker to bypass a security feature locally.

Published: Apr 14, 2026
Source: NVD
CVE-2026-34626 MEDIUM - 6.3

Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary file system read in the context of the current user. Exploi...

Vendor: Adobe
Product: Acrobat Reader
Published: Apr 14, 2026
Source: NVD
CVE-2026-27286 MEDIUM - 5.5

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in ...

Vendor: Adobe
Product: InDesign Desktop
Published: Apr 14, 2026
Source: NVD
CVE-2026-27285 MEDIUM - 5.5

InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application or disrupt its functionality. Exploitation of this issue requires user...

Vendor: Adobe
Product: InDesign Desktop
Published: Apr 14, 2026
Source: NVD
CVE-2026-22692 MEDIUM - 4.9

October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vulnerability in the optional Twig safe mode feature (CMS_SAFE_MODE). Certain methods on the collect() helper were not properly restricted, allowing authe...

Vendor: octobercms
Product: october
Published: Apr 14, 2026
Source: NVD
CVE-2026-39814 MEDIUM - 6.7

A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7.0.12 may allow attacker to execute unauthorized code or commands via <insert attack vector here&g...

Vendor: Fortinet
Product: FortiWeb
Published: Apr 14, 2026
Source: NVD
CVE-2026-39812 MEDIUM - 4.8

A improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox PaaS 5.0.0 through 5.0.5, FortiSandbox PaaS 4.4.0 through 4.4.8, ...

Vendor: Fortinet
Product: FortiSandbox, FortiSandbox PaaS
Published: Apr 14, 2026
Source: NVD
CVE-2026-39811 MEDIUM - 4.9

A integer overflow or wraparound vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.3, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attacker to denial of service via <insert attack vector here>

Vendor: Fortinet
Product: FortiWeb
Published: Apr 14, 2026
Source: NVD
CVE-2026-39810 MEDIUM - 6.0

A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.

Vendor: Fortinet
Product: FortiClientEMS
Published: Apr 14, 2026
Source: NVD
CVE-2026-39809 MEDIUM - 6.7

A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized code or commands via sending ...

Vendor: Fortinet
Product: FortiClientEMS
Published: Apr 14, 2026
Source: NVD
CVE-2026-38533 MEDIUM - 6.5

An improper authorization vulnerability in the /api/v1/users/{id} endpoint of Snipe-IT v8.4.0 allows authenticated attackers with the users.edit permission to modify sensitive authentication and account-state fields of other non-admin users via supplying a crafted PUT request.

Published: Apr 14, 2026
Source: NVD
CVE-2026-25691 MEDIUM - 6.7

A improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox 4.2 all versions, FortiSandbox Cloud 5.0.4, FortiSandbox PaaS 5.0.4 may allow a privileged attacker wi...

Vendor: Fortinet
Product: FortiSandbox PaaS, FortiSandbox Cloud, FortiSandbox
Published: Apr 14, 2026
Source: NVD
CVE-2026-22576 MEDIUM - 4.3

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOA...

Vendor: Fortinet
Product: FortiSOAR PaaS, FortiSOAR on-premise
Published: Apr 14, 2026
Source: NVD