Newest CVEs

IDDescriptionSeverityUpdated
CVE-2026-40245free5gc UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body without authentication
high
CVE-2026-34625Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage.
medium
2026-04-14
CVE-2026-34624Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage.
medium
2026-04-14
CVE-2026-34623Adobe Experience Manager versions 6.5.24, FP11.7 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a specially crafted web page.
medium
2026-04-14
CVE-2026-5756Unauthenticated Configuration File Modification Vulnerability in DRC Central Office Services (COS) allows an attacker to modify the server's configuration file, potentially leading to mass data exfiltration, malicious traffic interception, or disruption of testing services.
high
2026-04-14
CVE-2026-5754Reflected Cross-Site Scripting (XSS) Vulnerability in Radware Alteon 34.5.4.0 vADC load-balancer allows an attacker to inject malicious scripts into the website, potentially leading to unauthorized actions, data theft, or other malicious activities.
medium
2026-04-14
CVE-2026-5752Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal.
critical
2026-04-14
CVE-2026-34629InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
high
2026-04-14
CVE-2026-34628InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
high
2026-04-14
CVE-2026-34627InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
high
2026-04-14
CVE-2026-34617Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.
high
2026-04-14
CVE-2026-34615Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
critical
2026-04-14
CVE-2026-34614Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
medium
2026-04-14
CVE-2026-33829Exposure of sensitive information to an unauthorized actor in Windows Snipping Tool allows an unauthorized attacker to perform spoofing over a network.
medium
2026-04-14
CVE-2026-33827Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
high
2026-04-14
CVE-2026-33826Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.
high
2026-04-14
CVE-2026-33825Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
high
2026-04-14
CVE-2026-33824Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
critical
2026-04-14
CVE-2026-33822Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
medium
2026-04-14
CVE-2026-33120Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
high
2026-04-14
CVE-2026-33116Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
high
2026-04-14
CVE-2026-33115Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high
2026-04-14
CVE-2026-33114Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high
2026-04-14
CVE-2026-33104Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
high
2026-04-14
CVE-2026-33103Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.
medium
2026-04-14
CVE-2026-33101Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
high
2026-04-14
CVE-2026-33100Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
high
2026-04-14
CVE-2026-33099Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
high
2026-04-14
CVE-2026-33098Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally.
high
2026-04-14
CVE-2026-33096Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
high
2026-04-14
CVE-2026-33095Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
high
2026-04-14
CVE-2026-32226Concurrent execution using shared resource with improper synchronization ('race condition') in .NET Framework allows an unauthorized attacker to deny service over a network.
medium
2026-04-14
CVE-2026-32225Protection mechanism failure in Windows Shell allows an unauthorized attacker to bypass a security feature over a network.
high
2026-04-14
CVE-2026-32224Use after free in Windows Server Update Service allows an authorized attacker to elevate privileges locally.
high
2026-04-14
CVE-2026-32223Heap-based buffer overflow in Windows USB Print Driver allows an unauthorized attacker to elevate privileges with a physical attack.
medium
2026-04-14
CVE-2026-32222Untrusted pointer dereference in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
high
2026-04-14
CVE-2026-32221Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.
high
2026-04-14
CVE-2026-32220Improper access control in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
medium
2026-04-14
CVE-2026-32219Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
high
2026-04-14
CVE-2026-32218Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
medium
2026-04-14
CVE-2026-32217Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
medium
2026-04-14
CVE-2026-32216Null pointer dereference in Windows Redirected Drive Buffering allows an authorized attacker to deny service locally.
medium
2026-04-14
CVE-2026-32215Insertion of sensitive information into log file in Windows Kernel allows an authorized attacker to disclose information locally.
medium
2026-04-14
CVE-2026-32214Improper access control in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
medium
2026-04-14
CVE-2026-32212Improper link resolution before file access ('link following') in Universal Plug and Play (upnp.dll) allows an authorized attacker to disclose information locally.
medium
2026-04-14
CVE-2026-32203Stack-based buffer overflow in .NET and Visual Studio allows an unauthorized attacker to deny service over a network.
high
2026-04-14
CVE-2026-32202Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
medium
2026-04-14
CVE-2026-32201Improper input validation in Microsoft Office SharePoint allows an unauthorized attacker to perform spoofing over a network.
medium
2026-04-14
CVE-2026-32200Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally.
high
2026-04-14
CVE-2026-32199Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
high
2026-04-14