CVE Feed

    Dashboard / CVE

    7
    High

    CVE-2026-27926

    Last Modified: 24 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Cloud Files Mini Filter Driver allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-27924

    Last Modified: 24 Apr 2026

    Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-27921

    Last Modified: 24 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-27919

    Last Modified: 24 Apr 2026

    Untrusted pointer dereference in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-27918

    Last Modified: 24 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Shell allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-27917

    Last Modified: 24 Apr 2026

    Use after free in Windows WFP NDIS Lightweight Filter Driver (wfplwfs.sys) allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-27915

    Last Modified: 24 Apr 2026

    Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-27908

    Last Modified: 24 Apr 2026

    Use after free in Windows TDI Translation Driver (tdx.sys) allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-27907

    Last Modified: 24 Apr 2026

    Integer underflow (wrap or wraparound) in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    4.4
    Medium

    CVE-2026-27906

    Last Modified: 24 Apr 2026

    Improper input validation in Windows Hello allows an authorized attacker to bypass a security feature locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26183

    Last Modified: 24 Apr 2026

    Improper access control in Windows RPC API allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26181

    Last Modified: 24 Apr 2026

    Use after free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26180

    Last Modified: 24 Apr 2026

    Heap-based buffer overflow in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26179

    Last Modified: 24 Apr 2026

    Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    4.6
    Medium

    CVE-2026-26175

    Last Modified: 24 Apr 2026

    Use of uninitialized resource in Windows Boot Manager allows an unauthorized attacker to bypass a security feature with a physical attack.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-26174

    Last Modified: 24 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Server Update Service allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    8.8
    High

    CVE-2026-26167

    Last Modified: 24 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-26166

    Last Modified: 24 Apr 2026

    Double free in Windows Shell allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-26165

    Last Modified: 24 Apr 2026

    Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26162

    Last Modified: 24 Apr 2026

    Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26161

    Last Modified: 24 Apr 2026

    Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-26160

    Last Modified: 24 Apr 2026

    Missing authentication for critical function in Windows Remote Desktop Licensing Service allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    6.5
    Medium

    CVE-2026-26155

    Last Modified: 24 Apr 2026

    Microsoft Local Security Authority Subsystem Service Information Disclosure Vulnerability

    Published: 14 Apr 2026
    7.5
    High

    CVE-2026-26154

    Last Modified: 24 Apr 2026

    Improper input validation in Windows Server Update Service allows an unauthorized attacker to perform tampering over a network.

    Published: 14 Apr 2026
    7.1
    High

    CVE-2026-26151

    Last Modified: 26 May 2026

    Insufficient ui warning of dangerous operations in Windows Remote Desktop allows an unauthorized attacker to perform spoofing over a network.

    Published: 14 Apr 2026
    9
    Critical

    CVE-2026-26149

    Last Modified: 7 May 2026

    Improper neutralization of escape, meta, or control sequences in Microsoft Power Apps allows an authorized attacker to perform spoofing over a network.

    Published: 14 Apr 2026
    5.7
    Medium

    CVE-2026-23670

    Last Modified: 24 Apr 2026

    Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.

    Published: 14 Apr 2026
    4.6
    Medium

    CVE-2026-20945

    Last Modified: 6 May 2026

    Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.

    Published: 14 Apr 2026
    7
    High

    CVE-2026-25184

    Last Modified: 24 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    5.7
    Medium

    CVE-2026-23653

    Last Modified: 6 May 2026

    Improper neutralization of special elements used in a command ('command injection') in GitHub Copilot and Visual Studio Code allows an authorized attacker to disclose information over a network.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-20930

    Last Modified: 24 Apr 2026

    Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.

    Published: 14 Apr 2026
    4.9
    Medium

    CVE-2026-22692

    Last Modified: 21 Apr 2026

    October is a Content Management System (CMS) and web platform. Versions prior to 3.7.13 and versions 4.0.0 through 4.1.4 contain a sandbox bypass vulnerability in the optional Twig safe mode feature (CMS_SAFE_MODE). Certain methods on the collect() helper were not properly restricted, allowing authenticated users with template editing permissions to bypass sandbox protections. Exploitation requires authenticated backend access with CMS template editing permissions and only affects installations with CMS_SAFE_MODE enabled (disabled by default). This issue has been fixed in versions 3.7.13 and 4.1.5. To workaround this issue, users can disable CMS_SAFE_MODE if untrusted template editing is not required, and restrict CMS template editing permissions to fully trusted administrators only.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-27284

    Last Modified: 16 Apr 2026

    InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to execute code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Apr 2026
    5.5
    Medium

    CVE-2026-27285

    Last Modified: 16 Apr 2026

    InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to crash the application or disrupt its functionality. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Apr 2026
    5.5
    Medium

    CVE-2026-27286

    Last Modified: 16 Apr 2026

    InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could lead to memory exposure. An attacker could leverage this vulnerability to disclose sensitive information stored in memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-27283

    Last Modified: 16 Apr 2026

    InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Apr 2026
    5.4
    Medium

    CVE-2026-27238

    Last Modified: 8 Sept 2026

    Adobe Experience Manager is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

    Published: 14 Apr 2026
    7.8
    High

    CVE-2026-27291

    Last Modified: 16 Apr 2026

    InDesign Desktop versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Apr 2026
    8.6
    High

    CVE-2026-34622

    Last Modified: 16 Apr 2026

    Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Apr 2026
    6.3
    Medium

    CVE-2026-34626

    Last Modified: 16 Apr 2026

    Acrobat Reader versions 26.001.21411, 24.001.30360, 24.001.30362 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary file system read in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 14 Apr 2026
    6
    Medium

    CVE-2025-61624

    Last Modified: 12 May 2026

    An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') [CWE-22] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.4, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, FortiOS 6.4 all versions, FortiPAM 1.7.0, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions, FortiPAM 1.4 all versions, FortiPAM 1.3 all versions, FortiPAM 1.2 all versions, FortiPAM 1.1 all versions, FortiPAM 1.0 all versions, FortiProxy 7.6.0 through 7.6.4, FortiProxy 7.4.0 through 7.4.11, FortiProxy 7.2 all versions, FortiProxy 7.0 all versions, FortiSwitchManager 7.2.0 through 7.2.7, FortiSwitchManager 7.0.0 through 7.0.6 may allow an authenticated attacker with admin profile and at least read-write permissions to write or delete arbitrary files via specific CLI commands.

    Published: 14 Apr 2026
    6
    Medium

    CVE-2025-68649

    Last Modified: 22 Apr 2026

    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.7, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.0 through 7.6.4, FortiAnalyzer Cloud 7.4.0 through 7.4.7, FortiAnalyzer Cloud 7.2 all versions, FortiAnalyzer Cloud 7.0 all versions, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.7, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.0 through 7.6.4, FortiManager Cloud 7.4.0 through 7.4.7, FortiManager Cloud 7.2 all versions, FortiManager Cloud 7.0 all versions may allow a privileged attacker to delete files from the underlying filesystem via crafted CLI requests.

    Published: 14 Apr 2026
    2.4
    Low

    CVE-2026-21741

    Last Modified: 20 Apr 2026

    An URL Redirection to Untrusted Site ('Open Redirect') vulnerability [CWE-601] vulnerability in Fortinet FortiNAC-F 7.6.0 through 7.6.5, FortiNAC-F 7.4 all versions, FortiNAC-F 7.2 all versions may allow a remote privileged attacker with system administrator role to redirect users to an arbitrary website via crafted CSV file.

    Published: 14 Apr 2026
    9.8
    Critical

    CVE-2026-39813

    Last Modified: 10 Sept 2026

    A path traversal: '../filedir' vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8 may allow attacker to escalation of privilege via specially crafted HTTP requests.

    Published: 14 Apr 2026
    7.2
    High

    CVE-2025-61848

    Last Modified: 14 Aug 2026

    An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.4, FortiAnalyzer 7.4.0 through 7.4.8, FortiAnalyzer 7.2 all versions, FortiAnalyzer 7.0 all versions, FortiAnalyzer Cloud 7.6.2 through 7.6.3, FortiAnalyzer-BigData 7.6.0 through 7.6.1, FortiAnalyzer-BigData 7.4.0 through 7.4.5, FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.8, FortiManager 7.2 all versions, FortiManager 7.0 all versions, FortiManager Cloud 7.6.2 through 7.6.4 may allow a privileged authenticated attacker to execute unauthorized code or commands via JSON RPC API

    Published: 14 Apr 2026
    8.1
    High

    CVE-2026-22828

    Last Modified: 1 May 2026

    A heap-based buffer overflow vulnerability in Fortinet FortiAnalyzer Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.6.2 through 7.6.4 may allow a remote unauthenticated attacker to execute arbitrary code or commands via specifically crafted requests. Successful exploitation would require a large amount of effort in preparation because of ASLR and network segmentation

    Published: 14 Apr 2026
    8.8
    High

    CVE-2026-39815

    Last Modified: 20 Apr 2026

    A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiDDoS-F 7.2.1 through 7.2.2 may allow attacker to execute unauthorized code or commands via sending crafted HTTP requests

    Published: 14 Apr 2026
    6.5
    Medium

    CVE-2026-22573

    Last Modified: 6 May 2026

    An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.3, FortiSOAR PaaS 7.5 all versions, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 through 7.6.3, FortiSOAR on-premise 7.5 all versions, FortiSOAR on-premise 7.4 all versions, FortiSOAR on-premise 7.3 all versions may allow an authenticated remote attacker to perform path traversal attack via File Content Extraction actions.

    Published: 14 Apr 2026
    5.4
    Medium

    CVE-2025-61886

    Last Modified: 22 Apr 2026

    An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability [CWE-79] vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.4, FortiSandbox PaaS 5.0.0 through 5.0.4 may allow an attacker to perform an XSS attack via crafted HTTP requests.

    Published: 14 Apr 2026
    6
    Medium

    CVE-2026-39810

    Last Modified: 21 Apr 2026

    A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.

    Published: 14 Apr 2026