Total CVEs

140,406

Critical Severity

3,747

High Severity

13,541

Last 7 Days

1,806
Quick preset (or use dates below)
Clear Filters
šŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years →
Showing 6,501 - 6,520 of 13,553 CVEs
CVE-2026-22574 MEDIUM - 4.1

A storing passwords in a recoverable format vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.4, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.4, FortiSOAR on-premise 7.5.0 through 7.5.2, FortiSOA...

Vendor: Fortinet
Product: FortiSOAR PaaS, FortiSOAR on-premise
Published: Apr 14, 2026
Source: NVD
CVE-2026-22573 MEDIUM - 6.5

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, Forti...

Vendor: Fortinet
Product: FortiSOAR on-premise, FortiSOAR PaaS
Published: Apr 14, 2026
Source: NVD
CVE-2026-22155 MEDIUM - 6.5

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, Fo...

Vendor: Fortinet
Product: FortiSOAR on-premise, FortiSOAR PaaS
Published: Apr 14, 2026
Source: NVD
CVE-2026-22154 MEDIUM - 4.6

An improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6...

Vendor: Fortinet
Product: FortiSOAR PaaS, FortiSOAR on-premise
Published: Apr 14, 2026
Source: NVD
CVE-2026-21742 MEDIUM - 5.7

A cleartext transmission of sensitive information vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.2, FortiSOAR on-premise 7.5.0 through 7.5.1, Fo...

Vendor: Fortinet
Product: FortiSOAR PaaS, FortiSOAR on-premise
Published: Apr 14, 2026
Source: NVD
CVE-2025-68649 MEDIUM - 6.0

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAn...

Vendor: Fortinet
Product: FortiManager Cloud, FortiManager, FortiAnalyzer, FortiAnalyzer Cloud
Published: Apr 14, 2026
Source: NVD
CVE-2025-65136 MEDIUM - 6.1

In manikandan580 School-management-system 1.0, a reflected XSS vulnerability exists in /studentms/admin/contact-us.php via the pagedes POST parameter.

Published: Apr 14, 2026
Source: NVD
CVE-2025-65132 MEDIUM - 6.1

alandsilva26 hotel-management-php 1.0 is vulnerable to Cross Site Scripting (XSS) in /public/admin/edit_room.php which allows an attacker to inject and execute arbitrary JavaScript via the room_id GET parameter.

Published: Apr 14, 2026
Source: NVD
CVE-2025-61886 MEDIUM - 5.4

An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox PaaS 5.0.0 through 5.0.4 may allow an attacker to perform an XSS attack via crafted HTTP requests.

Vendor: Fortinet
Product: FortiSandbox PaaS, FortiSandbox
Published: Apr 14, 2026
Source: NVD
CVE-2025-61624 MEDIUM - 6.0

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all vers...

Vendor: Fortinet
Product: FortiOS, FortiProxy, FortiSwitchManager, FortiPAM
Published: Apr 14, 2026
Source: NVD
CVE-2025-59809 MEDIUM - 4.3

A server-side request forgery (ssrf) vulnerability [CWE-918] vulnerability in Fortinet FortiSOAR PaaS 7.6.4, FortiSOAR PaaS 7.6.0 through 7.6.2, FortiSOAR PaaS 7.5.0 through 7.5.2, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.4, FortiSOAR on-premise 7.6....

Vendor: Fortinet
Product: FortiSOAR on-premise, FortiSOAR PaaS
Published: Apr 14, 2026
Source: NVD
CVE-2025-53847 MEDIUM - 6.5

A missing authentication for critical function vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiOS 6.2.9 through 6.2.17 allows attacker to execute unauthorized code or comman...

Vendor: Fortinet
Product: FortiOS
Published: Apr 14, 2026
Source: NVD
CVE-2024-23104 MEDIUM - 5.4

An exposure of sensitive information to an unauthorized actor vulnerability in Fortinet FortiNDR 7.6.0, FortiNDR 7.4.0 through 7.4.8, FortiNDR 7.2 all versions, FortiNDR 7.1 all versions, FortiNDR 7.0 all versions, FortiVoice 7.0.0 through 7.0.1 may allow a remote authenticated attacker with at leas...

Vendor: Fortinet
Product: FortiVoice, FortiNDR
Published: Apr 14, 2026
Source: NVD
CVE-2026-4914 MEDIUM - 5.4

Stored XSSĀ inĀ IvantiĀ N-ITSMĀ beforeĀ version 2025.4Ā allows aĀ remoteĀ authenticatedĀ attacker toĀ obtain limited information from other user sessions.Ā User interaction is required.

Published: Apr 14, 2026
Source: NVD
CVE-2026-4913 MEDIUM - 5.7

Improper protection of an alternate pathĀ inĀ IvantiĀ N-ITSMĀ beforeĀ version 2025.4Ā allows aĀ remote authenticatedĀ attacker toĀ retain access when their account has beenĀ disabled.

Published: Apr 14, 2026
Source: NVD
CVE-2026-37980 MEDIUM - 6.9

A flaw was found in Keycloak, specifically in the organization selection login page. A remote attacker with `manage-realm` or `manage-organizations` administrative privileges can exploit a Stored Cross-Site Scripting (XSS) vulnerability. This flaw occurs because the `organization.alias` is placed in...

Vendor: Red Hat
Product: Red Hat Build of Keycloak
Published: Apr 14, 2026
Source: NVD
CVE-2026-30480 MEDIUM - 6.5

A Local File Inclusion (LFI) vulnerability in the NFSen module (nfsen.inc.php) of LibreNMS 22.11.0-23-gd091788f2 allows authenticated attackers to include arbitrary PHP files from the server filesystem via path traversal sequences in the nfsen parameter.

Published: Apr 14, 2026
Source: NVD
CVE-2025-69993 MEDIUM - 6.1

Leaflet versions up to and including 1.9.4 are vulnerable to Cross-Site Scripting (XSS) via the bindPopup() method. This method renders user-supplied input as raw HTML without sanitization, allowing attackers to inject arbitrary JavaScript code through event handler attributes (e.g., <img src=x o...

Vendor: leafletjs
Product: leaflet
Published: Apr 14, 2026
Source: NVD
CVE-2025-69893 MEDIUM - 4.6

A side-channel vulnerability exists in the implementation of BIP-39 mnemonic processing, as observed in Trezor One v1.13.0 to v1.14.0, Trezor T v1.13.0 to v1.14.0, and Trezor Safe v1.13.0 to v1.14.0 hardware wallets. This originates from the BIP-39 standard guidelines, which induce non-constant time...

Published: Apr 14, 2026
Source: NVD
CVE-2026-24069 MEDIUM - 5.4

Kiuwan SAST improperly authorizes SSO logins for locally disabled mapped user accounts, allowing disabled users to continue accessing the application. Kiuwan Cloud was affected, and Kiuwan SAST on-premise (KOP) was affected before 2.8.2509.4.

Vendor: Kiuwan
Product: SAST
Published: Apr 14, 2026
Source: NVD