Monitor vulnerabilities that affect your stack. Sign up free to get alerts when software you use is affected.

CVE Vulnerabilities - 14 April 2026

RSS

744 vulnerabilities published on 14 April 2026

Severity:
Patient Appointment Scheduler System SQL Injection Vulnerability
CVE-2026-37600
The Patient Appointment Scheduler System's 'view_details' page allows hackers to access sensitive data by manipulating the URL, potentially exposing patient information. This can happen if an attacker...
2.7
Patient Appointment Scheduler System v1.0 allows attackers to run malicious code
CVE-2026-37598
The Patient Appointment Scheduler System version 1.0 has a security issue that allows unauthorized access to run malicious code. This could lead to unauthorized changes to system settings or even comp...
2.7
SQL Injection vulnerability in Online Employees Work From Home Attendance System
CVE-2026-37597
A hacker can access sensitive data in the online attendance system by manipulating input fields. This could lead to the exposure of confidential information and unauthorized access to the system. To f...
2.7
SQL Injection in Online Employees Attendance System Can Let Attackers Access Data
CVE-2026-37596
The Online Employees Work From Home Attendance System, version 1.0, has a security issue that could allow hackers to access sensitive information. If left unaddressed, this vulnerability could lead to...
2.7
PHP Attendance System Allows Malicious Database Access
CVE-2026-37595
The SourceCodester Online Employees Work From Home Attendance System version 1.0 has a security weakness that allows hackers to access sensitive data in the database. This is a serious issue because i...
2.7
Online Employees Attendance System SQL Injection in admin view
CVE-2026-37594
The Online Employees Work From Home Attendance System version 1.0 contains a vulnerability that allows an attacker to manipulate database queries, potentially exposing sensitive employee data or disru...
2.7
SQL Injection in SourceCodester Online Employees Work From Home Attendance System
CVE-2026-37593
The SourceCodester Online Employees Work From Home Attendance System has a weakness in how it handles user input, which could allow an attacker to access sensitive data or take control of the system. ...
2.7
Storage Unit Rental Management System exposes sensitive data
CVE-2026-37592
The Storage Unit Rental Management System's pricing page allows an attacker to access and potentially modify sensitive data. This could lead to unauthorized access to user information or pricing chang...
2.7
SQL Injection Vulnerability in Sourcecodester Storage Unit Rental Management System
CVE-2026-37591
A hacker could inject malicious code into the Storage Unit Rental Management System's database, potentially stealing sensitive information or taking control of the system. This is a serious risk becau...
2.7
Storage Unit Rental Management System SQL Injection Vulnerability
CVE-2026-37590
The Storage Unit Rental Management System has a security weakness that allows an attacker to potentially access or manipulate sensitive data. This could happen if an attacker sends malicious input to ...
2.7
Storage Unit Rental Management System: SQL Injection Risk
CVE-2026-37589
The Storage Unit Rental Management System, version 1.0, contains a security weakness in its database handling that could allow an attacker to access or modify data. This could lead to unauthorized acc...
2.7
Adobe ColdFusion versions 2023.18 and earlier: High-privilege attacker can slow down your app
CVE-2026-27308
A malicious person with high-level access can use this flaw to exhaust your system's resources, making your ColdFusion application run slowly or even shut down. This requires no action from regular us...
2.4
ColdFusion: High-Privileged Attackers Can Slow Down Your Website
CVE-2026-27307
High-privileged attackers can exploit a weakness in older ColdFusion versions, causing your website to slow down or stop responding. This can happen even if an attacker doesn't interact with your webs...
2.4
Sensitive Data Leaked to Log Files When Malicious File Executed
CVE-2026-2401
A vulnerability in the Web Admin interface allows an attacker to trick a user into running a malicious file, which can then expose confidential information to logs. This could potentially lead to sens...
2.4
FortiNAC-F Users May Be Redirected to Untrusted Websites
CVE-2026-21741
A security issue in FortiNAC-F software could allow a malicious attacker to redirect users to a different website, potentially leading to phishing or other types of attacks. This issue affects certain...
2.4
Fat Free CRM allows any user to delete emails of others
GHSA-9pm8-vwc5-w2hm
A bug in Fat Free CRM allows any authenticated user to delete emails that belong to other users when the Email Dropbox feature is in use. This means someone could delete important emails from another ...
2.1
Kimai Leaks API Token Hash in Invoice Templates
GHSA-rh42-6rj2-xwmc
Sensitive API token hashes may be exposed in invoice templates created by admins on OnPremise installations with template upload enabled. This allows an attacker to obtain hashed API passwords of user...
2.0
Kimai Leaks API Token Hash in Invoice Templates
GHSA-rh42-6rj2-xwmc
Kimai's invoice templates can reveal sensitive API token hashes of users who generate invoices with a vulnerable template. This issue affects on-premise installations that allow template uploads. To f...
2.0
SAP Landscape Transformation allows attackers to inject malicious code
CVE-2026-27675
A high-privileged attacker can inject code that could alter certain data in SAP Landscape Transformation, but the impact is limited. This issue affects SAP Landscape Transformation and requires attent...
2.0
Craft CMS Commerce discloses order data to unauthorized users
CVE-2026-32270 GHSA-3vxg-x5f8-f5qf
Craft CMS Commerce versions 4.0.0 to 4.10.2 and 5.0.0 to 5.5.4 disclose sensitive order information to anyone who knows an order number, potentially exposing customer details. This is a concern for bu...
1.7
Justhtml Sanitization Flaw Affects Programmatic DOM Input
GHSA-4p64-v8f5-r2gx
The justhtml library versions 1.15.0 and earlier contain multiple security flaws that can allow malicious code to bypass sanitization. These flaws can occur when using custom policies or programmatic ...
1.3
NuGet Client update adds package validation to prevent tampering
GHSA-g4vj-cjjj-v7hg
The NuGet Client has been updated to validate package IDs and versions during download to prevent malicious packages from being installed. This update affects NuGet.exe, NuGet.CommandLine, and .NET SD...
NuGet Client Package Download Validation Updated
GHSA-g4vj-cjjj-v7hg
The NuGet client now checks package ID and version during download to prevent tampering. This update affects various NuGet and .NET SDK versions, including .NET 8 and .NET 9. To stay secure, update to...
DotNetNuke May Expose Sensitive Data to Attack
GHSA-fcpv-w245-r2q7
The DotNetNuke Core code may contain areas that could allow attackers to access sensitive data. This is because of some outdated security settings, such as disabling XML document security checks and u...
Novu's Webhook Bypass Allows Unvalidated URL Calls
GHSA-4x48-cgf9-q33f
A Novu webhook can be tricked into calling unvalidated URLs, allowing potential attacks. This is a security risk because an attacker could use this to access internal systems or data. To protect again...