Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 14 April 2026

RSS

761 vulnerabilities published on 14 April 2026

Severity:
AsyncHttpClient leaks credentials on redirects to untrusted domains
GHSA-cmxv-58fp-fm3g
A security issue affects AsyncHttpClient, allowing an attacker to steal credentials when the software redirects to a different domain. This can happen when the software is configured to follow redirec...
6.8
AsyncHttpClient leaks credentials on redirects to untrusted domains
GHSA-cmxv-58fp-fm3g
A security issue in AsyncHttpClient allows attackers to capture credentials when a user is redirected to a different website. To fix this, update to version 3.0.9 or set the stripAuthorizationOnRedire...
6.8
SQL Server Allows Privilege Escalation via Malicious Input
CVE-2026-32176
An attacker can use malicious input to gain elevated privileges on a SQL Server database, potentially allowing them to access sensitive data or disrupt operations. This issue affects SQL Server instal...
6.7
SQL Server allows malicious database access by authorized users
CVE-2026-32167
SQL Server has a security weakness that could allow an authorized user to gain unauthorized access to its database. This could happen if an attacker enters specific, malicious information into a datab...
6.7
Windows Boot Loader Allows Local Privilege Escalation
CVE-2026-0390
An attacker with local access to a Windows system can exploit this issue to gain elevated privileges. This could allow them to install malicious software or access sensitive data. Users should apply t...
6.7
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through...
CVE-2026-39814
A relative path traversal vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.1 through 7.4.12, FortiWeb 7.2.7 through 7.2.12, FortiWeb 7.0.10 through 7....
6.7
Fortinet FortiClientEMS: Unauthorized Code Execution via SQL Injection
CVE-2026-39809
Certain versions of Fortinet FortiClientEMS are vulnerable to a SQL injection attack, which could allow an attacker to execute unauthorized code or commands. This could potentially lead to unauthorize...
6.7
Fortinet FortiSandbox: Malicious Files Can Be Deleted
CVE-2026-25691
A security issue in Fortinet FortiSandbox versions 5.0.0 to 5.0.5, 4.4.0 to 4.4.8, and all versions of 4.2, and FortiSandbox Cloud 5.0.4 and FortiSandbox PaaS 5.0.4 allows a skilled attacker to delete...
6.7
frp Authentication Bypass in HTTP vhost Routing with routeByHTTPUser
GHSA-pq96-pwvg-vrr9
If you're using frp with routeByHTTPUser for access control, an attacker may be able to access a protected backend without the correct password. This is because frp uses different credentials for rout...
6.5
WWBN AVideo allows unauthorized file access through URL trickery
GHSA-m63r-m9jh-3vc6
A fix to prevent directory traversal was not fully implemented, allowing attackers to access sensitive files by manipulating the URL's query string. This can lead to unauthorized access to sensitive d...
6.5
WWBN AVideo: Malicious File Access via URL Query String
GHSA-m63r-m9jh-3vc6
A fix for a previous vulnerability in WWBN AVideo was not fully effective. Attackers can still access arbitrary files on the server by using a specific type of URL query string. To protect against thi...
6.5
Jellyfin versions before 10.11.7 can be crashed by a malicious group name
CVE-2026-35034
If you're using an outdated version of Jellyfin, an attacker could potentially crash your media server by sending a very long group name. This would make it harder for others to use the service. Updat...
6.5
WWBN AVideo exposes other users' stream keys and tokens
GHSA-gpgp-w4x2-h3h7
An attacker can see the live stream keys and OAuth tokens of other users, including those from services like YouTube Live and Twitch. This can happen when an attacker knows the username of the user th...
6.5
XWiki page history compare allows malicious JavaScript execution
GHSA-w4fj-87j5-f25c CVE-2026-40105
A security flaw in XWiki's page history compare feature allows an attacker to execute malicious code in the user's browser. If the user is an administrator, this could compromise the entire XWiki inst...
6.5
Chamilo LMS: Students can read other users' private course notes
CVE-2026-34370
A security issue in older versions of Chamilo LMS allows students to access private course notes belonging to other users. This is a concern because sensitive information could be revealed. To fix thi...
6.5
Windows Shell Leaks Sensitive Information Over Network
CVE-2026-32151
An issue in Windows Shell may allow an attacker to access sensitive information that should not be shared. This could happen if an attacker is able to connect to the same network as the affected syste...
6.5
Windows Universal Plug and Play (UPnP) allows unauthorized network snooping
CVE-2026-27925
Attackers on your network might be able to see sensitive information about your devices and network setup. This is a security risk because it could let hackers learn more about your network layout and...
6.5
Windows Local Security Service Can Leak Sensitive Information
CVE-2026-26155
A weakness in the Windows Local Security Authority Subsystem Service could allow an attacker to access sensitive data. This affects Windows systems and could lead to unauthorized access to user creden...
6.5
Fortinet FortiSOAR PaaS allows attackers to access unauthorized files
CVE-2026-22573
Fortinet FortiSOAR PaaS versions 7.6.0 to 7.6.3 and all versions of 7.5, 7.4, and 7.3 may allow an attacker to access files they shouldn't be able to access. This is a concern because it could lead to...
6.5
FortiSOAR PaaS and On-Premise Leaks Sensitive Info in Transit
CVE-2026-22155
FortiSOAR software versions 7.6.0 through 7.6.3, 7.5.0 through 7.5.2, and 7.4, as well as on-premise versions 7.6.0 through 7.6.2 and 7.5.0 through 7.5.1, may allow attackers to intercept and read sen...
6.5
Fortinet FortiOS: Unauthorized Code Execution via Crafted Packets
CVE-2025-53847
Fortinet's FortiOS versions 7.0 through 7.6 and 6.2.9 through 6.4 are vulnerable to a critical issue that allows an attacker to execute unauthorized code or commands. This means an attacker could pote...
6.5
The Germanized for WooCommerce plugin allows hackers to run unauthorized code on your site
CVE-2026-2582
The Germanized for WooCommerce plugin for WordPress has a security flaw that allows hackers to run code of their choice on your website without needing a password. This is a serious issue because it a...
6.5
SAP HCM for S/4HANA Leaks Sensitive Info with Low Privileges
CVE-2026-34264
An attacker with limited access to SAP's Human Capital Management system for S/4HANA can accidentally get sensitive information by guessing specific error messages. This could lead to unauthorized acc...
6.5
SAP Business Analytics and Content Management: Unauthorized Access to Sensitive Data
CVE-2026-34261
An authenticated user can potentially access sensitive information they shouldn't have access to. This is a confidentiality risk, not a data breach or system crash. SAP is expected to release a patch ...
6.5
gdown: Malicious Archives Can Overwrite Files Outside Destination Directory
GHSA-76hw-p97h-883f
The gdown library can extract files from archives in a way that allows malicious files to be written outside the intended destination directory, potentially leading to sensitive data being overwritten...
6.5