|
2141
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Desktop Window Manager allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-32155
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2142
|
7.4 |
HIGH
Local
|
-
|
-
|
Use after free in Windows Universal Plug and Play (UPnP) Device Host allows an unauthorized attacker to execute code locally.
|
CWE-416
Use After Free
|
CVE-2026-32156
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2143
|
8.8 |
HIGH
Network
|
-
|
-
|
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
|
CWE-416
Use After Free
|
CVE-2026-32157
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2144
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
|
CWE-89
SQL Injection
|
CVE-2026-32167
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2145
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
|
CWE-20
Improper Input Validation
|
CVE-2026-32168
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2146
|
8.8 |
HIGH
Network
|
-
|
-
|
Insufficiently protected credentials in Azure Logic Apps allows an authorized attacker to elevate privileges over a network.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-32171
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2147
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an authorized attacker to elevate privileges locally.
|
CWE-89
SQL Injection
|
CVE-2026-32176
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2148
|
7.5 |
HIGH
Network
|
-
|
-
|
Improper neutralization of special elements in .NET allows an unauthorized attacker to perform spoofing over a network.
|
CWE-138
Improper Neutralization of Special Elements
|
CVE-2026-32178
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2149
|
7.8 |
HIGH
Local
|
-
|
-
|
Deserialization of untrusted data in Microsoft High Performance Compute Pack (HPC) allows an authorized attacker to elevate privileges locally.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-32184
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2150
|
7.1 |
HIGH
Local
|
-
|
-
|
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-32188
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|