|
961
|
7.5 |
HIGH
Network
|
-
|
-
|
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-33096
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
962
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Container Isolation FS Filter Driver allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-33098
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
963
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-33099
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
964
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-33100
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
965
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-33101
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
966
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.
|
CWE-284
Improper Access Control
|
CVE-2026-33103
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
967
|
8.4 |
HIGH
Local
|
-
|
-
|
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-33114
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
968
|
8.4 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
|
CWE-416
Use After Free
|
CVE-2026-33115
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
969
|
7.5 |
HIGH
Network
|
-
|
-
|
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
|
CWE-20 CWE-400 CWE-835
Improper Input Validation Uncontrolled Resource Consumption Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-33116
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
970
|
8.8 |
HIGH
Network
|
-
|
-
|
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-33120
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|