|
981
|
7.3 |
HIGH
Local
|
-
|
-
|
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated …
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-4134
|
2026-04-18 00:09 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
982
|
6.6 |
MEDIUM
Local
|
-
|
-
|
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file w…
|
CWE-59
Link Following
|
CVE-2026-4135
|
2026-04-18 00:09 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
983
|
7.8 |
HIGH
Local
|
-
|
-
|
During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated p…
|
CWE-88
Argument Injection
|
CVE-2026-4145
|
2026-04-18 00:09 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
984
|
8.4 |
HIGH
Local
|
-
|
-
|
Command injection in the connect function in NietThijmen ShoppingCart 0.0.2 allows an attacker to execute arbitrary shell commands and achieve remote code execution via injection of malicious payload…
|
CWE-77
Command Injection
|
CVE-2024-53412
|
2026-04-18 00:09 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
985
|
7.5 |
HIGH
Network
|
-
|
-
|
CentSDR commit e40795 was discovered to contain a stack overflow in the "Thread1" function.
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-30364
|
2026-04-18 00:09 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
986
|
- |
|
-
|
-
|
HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate this potential vulnerability.
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2026-4667
|
2026-04-18 00:09 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
987
|
- |
|
-
|
-
|
Certain HP DeskJet All in One devices
may be vulnerable to remote code execution caused by a buffer overflow when
specially crafted Web Services for Devices (WSD) scan requests are improperly
validat…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-4682
|
2026-04-18 00:09 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
988
|
- |
|
-
|
-
|
In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as par…
|
CWE-200
Information Exposure
|
CVE-2025-12141
|
2026-04-18 00:09 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
989
|
7.5 |
HIGH
Network
|
-
|
-
|
Nordic Semiconductor IronSide SE for nRF54H20 before 23.0.2+17 has an Algorithmic complexity issue.
|
CWE-407
Inefficient Algorithmic Complexity
|
CVE-2025-67841
|
2026-04-18 00:09 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
990
|
6.6 |
MEDIUM
Network
|
-
|
-
|
In Splunk Enterprise versions below 10.2.2, 10.0.5, 9.4.10, and 9.3.11, and Splunk Cloud Platform versions below 10.4.2603.0, 10.3.2512.6, 10.2.2510.10, 10.1.2507.20, 10.0.2503.13, and 9.3.2411.127, …
|
CWE-176
Improper Handling of Unicode Encoding
|
CVE-2026-20202
|
2026-04-18 00:09 |
2026-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|