Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 14 April 2026

RSS

744 vulnerabilities published on 14 April 2026

Severity:
Fortinet FortiSandbox: Malicious Web Requests Can Execute Code
CVE-2025-61886
An attacker can inject malicious code into FortiSandbox's web interface by sending a specially crafted HTTP request, potentially allowing them to take control of the system or steal sensitive informat...
5.4
FortiNDR and FortiVoice: Sensitive Info Leaked via Malformed HTTP Requests
CVE-2024-23104
Fortinet's FortiNDR and FortiVoice software has a security flaw that could allow an authorized but unauthorized actor to access sensitive backup information by sending specially crafted HTTP requests....
5.4
Ivanti N-ITSM Stored XSS lets attackers steal session data
CVE-2026-4914
Ivanti N-ITSM versions before 2025.4 contain a security weakness that lets an attacker who has already logged in to the system steal information from other users' sessions. This requires the attacker ...
5.4
Kiuwan SAST: Disabled users can still access the application
CVE-2026-24069
A security issue in Kiuwan SAST affects how it handles user accounts. Disabled users can still access the application through single sign-on (SSO) logins. Affected versions of Kiuwan Cloud and on-prem...
5.4
Craft CMS: Removing Users from Groups Without Proper Permission
GHSA-jq2f-59pj-p3m3
Craft CMS 5.6.0 through 5.9.14 allows users with limited permissions to remove users from groups. This means that someone with only viewing permissions could accidentally or intentionally remove other...
5.3
AVideo's LiveLinks proxy still exposes internal IP addresses
GHSA-793q-xgj6-7frp
AVideo's LiveLinks proxy in AVideo has a security issue that allows hackers to view internal IP addresses. This is a concern because it could allow unauthorized access to sensitive areas of your netwo...
5.3
AVideo LiveLinks proxy has DNS rebinding vulnerabilities
GHSA-793q-xgj6-7frp
The AVideo LiveLinks proxy in AVideo has not fully fixed a security weakness that could allow attackers to access internal systems. This affects users of AVideo who rely on the LiveLinks proxy. To sta...
5.3
AVideo CAPTCHA Easily Bypassed via Length Parameter and Missing Token Invalidation
GHSA-hg7g-56h5-5pqr
An attacker can easily bypass the CAPTCHA protection on AVideo by manipulating the CAPTCHA length parameter, allowing them to bypass CAPTCHAs in as few as 33 attempts. This vulnerability affects CAPTC...
5.3
AVideo CAPTCHA Can Be Bypassed with a Single Request
GHSA-hg7g-56h5-5pqr
AVideo's CAPTCHA can be easily bypassed by an attacker, allowing them to force the server to generate a single-character CAPTCHA word. This makes it possible for an attacker to brute-force CAPTCHA val...
5.3
SiYuan has incomplete fix for CVE-2026-33066: XSS
GHSA-8q5w-mmxf-48jg
### Summary The incomplete fix for SiYuan's bazaar README rendering enables the Lute HTML sanitizer but fails to block `<iframe>` tags, allowing stored XSS via `srcdoc` attributes containing embedded...
5.3
AVideo Exposes Developer Emails and Commit Hashes to Unauthenticated Users
GHSA-52hf-63q4-r926
An unauthenticated user can access a PHP script that reveals developer email addresses and the exact version of AVideo's code deployed, which can be used to identify potential security vulnerabilities...
5.3
AVideo Exposes Deployed Version, Developer Info, and Internal References
GHSA-52hf-63q4-r926
AVideo's git.json.php script allows anyone to access sensitive information, including deployed version, developer emails, and internal system references. This can be used to identify potential vulnera...
5.3
October CMS Platform: Malicious SVG Uploads Can Hijack User Sessions
CVE-2026-25133 GHSA-gcqv-f29m-67gr
October CMS versions 3.7.13 and earlier, and 4.1.9 and earlier, contain a security flaw that allows hackers to upload malicious SVG files through the Media Manager. If a site administrator views or em...
5.3
Nexi XPay plugin on WordPress allows unauthorized order changes
CVE-2025-15565
The Nexi XPay plugin for WordPress is not properly securing redirects, allowing unauthorized users to mark WooCommerce orders as paid or completed. This could lead to incorrect order status and potent...
5.3
October CMS: Untrusted Editor Settings Can Execute Malicious Code
CVE-2026-24906 GHSA-6qmh-j78v-ffp7
Old versions of October CMS have a security flaw that could allow an attacker to take over the system by tricking an administrator into opening a specially crafted document. To fix this, update to ver...
5.3
Excessive Zip File Creation Can Crash System
CVE-2026-2405
A user with administrative access can crash the system by flooding it with requests, causing the system to create too many zip files and run out of resources. This can happen when an administrator rep...
5.3
Web Admin Log Settings Truncation Risk in [Software Name]
CVE-2026-2403
A vulnerability in the Web Admin interface can cause log entries to be cut off prematurely, potentially hiding important information about what's happening on your system. This can make it harder to t...
5.3
Resetting credentials possible via malicious Web Admin user input
CVE-2026-2400
A vulnerability in the application's POST request handling could allow a malicious Web Admin user to reset user credentials. This could happen if a user with elevated privileges alters a specific requ...
5.3
Python 3.14+ Remote Debugging Feature Allows Malicious Access
CVE-2026-5713 PSF-2026-19
A security risk exists in Python versions 3.14 and later, specifically in the remote debugging feature. This allows a malicious process to potentially access and control a target process if it is conn...
5.3
MCPHub: Unauthenticated Users Can Act as Others
CVE-2025-13822 GHSA-9vq7-9h42-j88h
Versions of MCPHub below 0.11.0 have a security issue where anyone can access and act as other users without being authorized. This can lead to unauthorized access and actions on the system. Update to...
5.3
Apache APISIX exposes sensitive data in plaintext
CVE-2026-31924
Apache APISIX versions 2.99.0 to 3.15.0 send sensitive information over an unsecured connection. This means that anyone with access to the network could intercept and read that information. To fix thi...
5.3
MaxKB Chat Export Feature Allows Malicious Excel Files
CVE-2026-39424
The chat export feature in MaxKB versions 2.7.1 and below can create Excel files that can harm your computer if you open them with Microsoft Excel. This is a security risk, so update to version 2.8.0 ...
5.3
Chamilo LMS: Malicious Files Can Hijack User Sessions
CVE-2026-34161
A security issue in older Chamilo LMS versions allows an attacker to upload a malicious file, which can take over a user's session and perform actions on their behalf. This affects users who have not ...
5.1
October CMS: Malicious Emails Can Run Code on Your Website
CVE-2026-24907 GHSA-j4j5-9x6g-rgxc
Older versions of the October CMS platform are vulnerable to a security risk that allows malicious emails to run code on your website. This could allow hackers to steal sensitive information or take c...
5.1
MaxKB AI Assistant: Stored XSS in Versions 2.7.1 and Below
CVE-2026-39426
Older versions of MaxKB contain a security flaw that allows attackers to inject malicious code into the system, potentially allowing them to access sensitive information and take unauthorized actions....
5.1