|
601
|
9.1 |
CRITICAL
Network
|
-
|
-
|
SourceCodester Payroll Management and Information System v1.0 is vulnerable to SQL Injection in the file /payroll/view_employee.php.
Update
|
CWE-89
SQL Injection
|
CVE-2026-37347
|
2026-04-18 00:15 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
602
|
8.2 |
HIGH
Network
|
-
|
-
|
Zohocorp ManageEngine Log360 versions 13000 through 13013 are vulnerable to authentication bypass on certain actions due to improper filter configuration.
Update
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-3324
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
603
|
5.1 |
MEDIUM
Physics
|
-
|
-
|
Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leadi…
Update
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2025-36579
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
604
|
4.1 |
MEDIUM
Local
|
-
|
-
|
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper check for unusual or exceptional conditions vulnerability. A high privileged attacker with local access could potentially explo…
Update
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2025-43883
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
605
|
- |
|
-
|
-
|
Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds condition without RMP checks, resulting in…
New
|
CWE-788
Access of Memory Location After End of Buffer
|
CVE-2023-20585
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
606
|
4.4 |
MEDIUM
Local
|
-
|
-
|
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A high privileged attacker with local access could potentially exploit this vulnera…
New
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2025-43935
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
607
|
6.6 |
MEDIUM
Local
|
-
|
-
|
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit th…
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2025-43937
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
608
|
- |
|
-
|
-
|
A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privileges to alter MMIO routing on some Zen 5-based products, poten…
New
|
CWE-414
Missing Lock Check
|
CVE-2025-54510
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
609
|
- |
|
-
|
-
|
Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulti…
New
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2025-54502
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
610
|
8.4 |
HIGH
Local
|
-
|
-
|
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.1…
New
|
CWE-1391
Use of Weak Credentials
|
CVE-2026-23853
|
2026-04-18 00:13 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|