|
791
|
- |
|
-
|
-
|
Insufficient checks of the RMP on host buffer access in IOMMU may allow an attacker with privileges and a compromised hypervisor to trigger an out of bounds condition without RMP checks, resulting in…
|
CWE-788
Access of Memory Location After End of Buffer
|
CVE-2023-20585
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
792
|
4.4 |
MEDIUM
Local
|
-
|
-
|
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an improper resource shutdown or release vulnerability. A high privileged attacker with local access could potentially exploit this vulnera…
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2025-43935
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
793
|
6.6 |
MEDIUM
Local
|
-
|
-
|
Dell PowerScale OneFS, versions prior to 9.12.0.0, contains an insertion of sensitive information into log file vulnerability. A low privileged attacker with local access could potentially exploit th…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2025-43937
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
794
|
- |
|
-
|
-
|
A missing lock verification in AMD Secure Processor (ASP) firmware may permit a locally authenticated attacker with administrative privileges to alter MMIO routing on some Zen 5-based products, poten…
|
CWE-414
Missing Lock Check
|
CVE-2025-54510
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
795
|
- |
|
-
|
-
|
Incorrect use of boot service in the AMD Platform Configuration Blob (APCB) SMM driver could allow a privileged attacker with local access (Ring 0) to achieve privilege escalation potentially resulti…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2025-54502
|
2026-04-18 00:14 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
796
|
8.4 |
HIGH
Local
|
-
|
-
|
Dell PowerProtect Data Domain with Data Domain Operating System (DD OS) of Feature Release versions 7.7.1.0 through 8.5, LTS2025 release version 8.3.1.0 through 8.3.1.20, LTS2024 release versions 7.1…
|
CWE-1391
Use of Weak Credentials
|
CVE-2026-23853
|
2026-04-18 00:13 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
797
|
7.2 |
HIGH
Network
|
-
|
-
|
In JetBrains YouTrack before 2025.3.131383 high privileged user can achieve RCE via sandbox bypass
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-33392
|
2026-04-18 00:13 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
798
|
5.0 |
MEDIUM
Local
|
-
|
-
|
Red Magic 11 Pro (NX809J) contains a vulnerability that allows non-privileged applications to trigger sensitive operations. The vulnerability stems from the lack of validation for applications access…
|
CWE-269
Improper Privilege Management
|
CVE-2026-40002
|
2026-04-18 00:13 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
799
|
- |
|
-
|
-
|
Insufficiently Protected Credentials vulnerability in Sparx Systems Pty Ltd. Sparx Enterprise Architect. Client reveals plaintext OAuth2 client secretDesktop client decodes the secret and uses the pl…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2025-15622
|
2026-04-18 00:13 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
800
|
- |
|
-
|
-
|
Exposure of Private Personal Information to an Unauthorized Actor, : Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Sparx Systems Pty Ltd. Sparx Pro Cloud…
|
CWE-359 CWE-497
Exposure of Private Personal Information to an Unauthorized Actor Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2025-15623
|
2026-04-18 00:13 |
2026-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|