|
2241
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.
|
CWE-284
Improper Access Control
|
CVE-2026-33103
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2242
|
8.4 |
HIGH
Local
|
-
|
-
|
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-33114
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2243
|
8.4 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
|
CWE-416
Use After Free
|
CVE-2026-33115
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2244
|
7.5 |
HIGH
Network
|
-
|
-
|
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
|
CWE-20 CWE-400 CWE-835
Improper Input Validation Uncontrolled Resource Consumption Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-33116
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2245
|
8.8 |
HIGH
Network
|
-
|
-
|
Untrusted pointer dereference in SQL Server allows an authorized attacker to execute code over a network.
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-33120
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2246
|
6.1 |
MEDIUM
Local
|
-
|
-
|
Out-of-bounds read in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-33822
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2247
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Double free in Windows IKE Extension allows an unauthorized attacker to execute code over a network.
|
CWE-415
Double Free
|
CVE-2026-33824
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2248
|
8.0 |
HIGH
Adjacent
|
-
|
-
|
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.
|
CWE-20
Improper Input Validation
|
CVE-2026-33826
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2249
|
8.1 |
HIGH
Network
|
-
|
-
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
|
CWE-362
Race Condition
|
CVE-2026-33827
|
2026-04-18 00:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2250
|
2.7 |
LOW
Network
|
-
|
-
|
Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Wo…
|
CWE-862
Missing Authorization
|
CVE-2026-27769
|
2026-04-18 00:09 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|