|
21
|
7.8 |
HIGH
Local
|
-
|
-
|
Adobe Framemaker versions 2022.8 and earlier are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structur…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-27294
|
2026-04-15 08:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
22
|
7.8 |
HIGH
Local
|
-
|
-
|
Adobe Framemaker versions 2022.8 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation …
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-27293
|
2026-04-15 08:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
23
|
7.8 |
HIGH
Local
|
-
|
-
|
Adobe Framemaker versions 2022.8 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issu…
New
|
CWE-416
Use After Free
|
CVE-2026-27292
|
2026-04-15 08:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
24
|
8.6 |
HIGH
Local
|
-
|
-
|
Adobe Framemaker versions 2022.8 and earlier are affected by an Untrusted Search Path vulnerability that might allow attackers to execute arbitrary code in the context of the current user. If the app…
New
|
CWE-426
Untrusted Search Path
|
CVE-2026-27290
|
2026-04-15 08:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
25
|
8.8 |
HIGH
Network
|
-
|
-
|
Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an insecure direct object modification vulnerability in the PUT /api/users/{id} endpoint allows any authenti…
New
|
CWE-269 CWE-863
Improper Privilege Management Incorrect Authorization
|
CVE-2026-40291
|
2026-04-15 07:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
26
|
- |
|
-
|
-
|
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose an unauthenticated WCF SOAP endpoint on TCP port 1208 that accepts unsanitized file paths in the ReadLicense action's L…
New
|
CWE-73
External Control of File Name or Path
|
CVE-2026-39907
|
2026-04-15 07:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
27
|
- |
|
-
|
-
|
Unisys WebPerfect Image Suite versions 3.0.3960.22810 and 3.0.3960.22604 expose a deprecated .NET Remoting TCP channel that allows remote unauthenticated attackers to leak NTLMv2 machine-account hash…
New
|
CWE-441
Confused Deputy
|
CVE-2026-39906
|
2026-04-15 07:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
28
|
8.8 |
HIGH
Network
|
-
|
-
|
Chamilo LMS is an open-source learning management system. In versions prior to 2.0.0-RC.3, an OS Command Injection vulnerability exists in the main/inc/ajax/gradebook.ajax.php endpoint within the exp…
New
|
CWE-78
OS Command
|
CVE-2026-35196
|
2026-04-15 07:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
29
|
7.8 |
HIGH
Local
|
-
|
-
|
InCopy versions 20.5.2, 21.2 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this is…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-34631
|
2026-04-15 07:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
30
|
7.7 |
HIGH
Network
|
-
|
-
|
ColdFusion versions 2023.18, 2025.6 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature…
New
|
CWE-22
Path Traversal
|
CVE-2026-34619
|
2026-04-15 07:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|