|
391
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An issue was discovered in ToToLink A3300R firmware v17.0.0cu.557_B20221024 allowing attackers to execute arbitrary commands via the interval parameter to /cgi-bin/cstecgi.cgi.
New
|
CWE-77
Command Injection
|
CVE-2026-31173
|
2026-04-24 23:41 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
392
|
8.0 |
HIGH
Network
|
dnnsoftware
|
dotnetnuke
|
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could incl…
Update
|
CWE-87
Improper Neutralization of Alternate XSS Syntax
|
CVE-2026-40321
|
2026-04-24 23:41 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
393
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Improper access control in Microsoft Partner Center allows an authorized attacker to elevate privileges over a network.
New
|
CWE-284
Improper Access Control
|
CVE-2026-24303
|
2026-04-24 23:41 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
394
|
8.6 |
HIGH
Network
|
-
|
-
|
Server-side request forgery (ssrf) in Microsoft Purview allows an unauthorized attacker to elevate privileges over a network.
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-26150
|
2026-04-24 23:41 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
395
|
3.7 |
LOW
Network
|
-
|
-
|
A request smuggling vulnerability exists in libsoup's HTTP/1 header parsing logic. The soup_message_headers_append_common() function in libsoup/soup-message-headers.c unconditionally appends each hea…
New
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-2708
|
2026-04-24 23:41 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
396
|
8.0 |
HIGH
Network
|
-
|
-
|
Uncontrolled search path element in Microsoft Power Apps allows an unauthorized attacker to execute code over a network.
New
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-32172
|
2026-04-24 23:41 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
397
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Server-side request forgery (ssrf) in Microsoft Dynamics 365 (Online) allows an unauthorized attacker to perform spoofing over a network.
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-32210
|
2026-04-24 23:41 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
398
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
New
|
CWE-601
Open Redirect
|
CVE-2026-33102
|
2026-04-24 23:41 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
399
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Deserialization of untrusted data in Microsoft Bing allows an unauthorized attacker to execute code over a network.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-33819
|
2026-04-24 23:41 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
400
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Server-side request forgery (ssrf) in Microsoft Entra ID Entitlement Management allows an unauthorized attacker to perform spoofing over a network.
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-35431
|
2026-04-24 23:41 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|