|
931
|
8.4 |
HIGH
Local
|
-
|
-
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-32091
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
932
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-32152
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
933
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-32154
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
934
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-32155
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
935
|
7.4 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally.
|
CWE-416
Use After Free
|
CVE-2026-32156
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
936
|
8.8 |
HIGH
Network
|
-
|
-
|
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
|
CWE-416
Use After Free
|
CVE-2026-32157
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
937
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
|
CWE-89
SQL Injection
|
CVE-2026-32167
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
938
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
|
CWE-20
Improper Input Validation
|
CVE-2026-32168
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
939
|
8.8 |
HIGH
Network
|
-
|
-
|
Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-32171
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
940
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
|
CWE-89
SQL Injection
|
CVE-2026-32176
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|