|
1581
|
9.8 |
CRITICAL
Network
|
microsoft
|
bing_images
|
Neutralización incorrecta de elementos especiales utilizados en un comando de sistema operativo ('inyección de comandos de sistema operativo') en Microsoft Bing Images permite a un atacante no autori…
|
CWE-78
OS Command
|
CVE-2026-32191
|
2026-04-15 01:35 |
2026-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1582
|
9.8 |
CRITICAL
Network
|
microsoft
|
bing_images
|
Improper neutralization of special elements used in a command ('command injection') in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.
|
CWE-77
Command Injection
|
CVE-2026-32194
|
2026-04-15 01:35 |
2026-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1583
|
9.8 |
CRITICAL
Network
|
microsoft
|
bing_images
|
Neutralización incorrecta de elementos especiales utilizados en un comando ('inyección de comandos') en Microsoft Bing Images permite a un atacante no autorizado ejecutar código a través de una red.
|
CWE-77
Command Injection
|
CVE-2026-32194
|
2026-04-15 01:35 |
2026-03-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1584
|
5.4 |
MEDIUM
Network
|
smoothwall
|
smoothwall_express
|
Smoothwall Express versions prior to 3.1 Update 13 contain a stored cross-site scripting vulnerability in the /cgi-bin/vpnmain.cgi script due to improper sanitation of the VPN_IP parameter. Authentic…
|
CWE-79
Cross-site Scripting
|
CVE-2026-26352
|
2026-04-15 01:34 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1585
|
5.4 |
MEDIUM
Network
|
smoothwall
|
smoothwall_express
|
Smoothwall Express versiones anteriores a 3.1 Update 13 contienen una vulnerabilidad de cross-site scripting almacenado en el script /cgi-bin/vpnmain.cgi debido a una sanitización inadecuada del pará…
|
CWE-79
Cross-site Scripting
|
CVE-2026-26352
|
2026-04-15 01:34 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1586
|
4.7 |
MEDIUM
Local
|
huawei
|
harmonyos
|
UAF vulnerability in the screen management module.
Impact: Successful exploitation of this vulnerability may affect availability.
|
CWE-362
Race Condition
|
CVE-2026-34849
|
2026-04-15 01:34 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1587
|
6.1 |
MEDIUM
Network
|
smoothwall
|
smoothwall_express
|
Smoothwall Express versions prior to 3.1 Update 13 contain a reflected cross-site scripting vulnerability in the /redirect.cgi endpoint due to improper sanitation of the url parameter. Attackers can …
|
CWE-79
Cross-site Scripting
|
CVE-2026-27508
|
2026-04-15 01:32 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1588
|
6.1 |
MEDIUM
Network
|
smoothwall
|
smoothwall_express
|
Las versiones de Smoothwall Express anteriores a 3.1 Update 13 contienen una vulnerabilidad de cross-site scripting reflejado en el endpoint /redirect.cgi debido a una sanitización inadecuada del par…
|
CWE-79
Cross-site Scripting
|
CVE-2026-27508
|
2026-04-15 01:32 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1589
|
4.3 |
MEDIUM
Network
|
powerdns
|
dnsdist
|
When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information abo…
|
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-0397
|
2026-04-15 01:27 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1590
|
8.2 |
HIGH
Network
|
powerdns
|
dnsdist
|
An attacker might be able to trigger an out-of-bounds read by sending a crafted DNS response packet, when custom Lua code uses newDNSPacketOverlay to parse DNS packets. The out-of-bounds read might t…
|
CWE-126
Buffer Over-read
|
CVE-2026-24028
|
2026-04-15 01:27 |
2026-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|