|
1471
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2022_23h2 windows_server_2025
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-26172
|
2026-04-25 02:21 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1472
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locall…
|
CWE-362 CWE-416 CWE-476
Race Condition Use After Free NULL Pointer Dereference
|
CVE-2026-26173
|
2026-04-25 02:20 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1473
|
6.1 |
MEDIUM
Network
|
-
|
-
|
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Versions prior to 8.5.10 do not escape `</style>` sequences when s…
|
CWE-79
Cross-site Scripting
|
CVE-2026-41305
|
2026-04-25 02:16 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1474
|
8.0 |
HIGH
Network
|
-
|
-
|
Totara LMS v19.1.5 and before is vulnerable to HTML Injection. An attacker can inject malicious HTML code in a message and send it to all the users in the application, resulting in executing the code…
|
CWE-79
Cross-site Scripting
|
CVE-2026-31281
|
2026-04-25 02:16 |
2026-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1475
|
6.5 |
MEDIUM
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-transaction provides the transaction primitive to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryTreeProof::verify` panics on a malformed proof where `history.len() != …
|
CWE-617
Reachable Assertion
|
CVE-2026-34067
|
2026-04-25 02:12 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1476
|
5.3 |
MEDIUM
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. Prior to version 1.3.0, `HistoryStore::put_historic_txns` uses an `assert!` to enforce invariants about `HistoricTr…
|
CWE-20 CWE-617 CWE-754
Improper Input Validation Reachable Assertion Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-34066
|
2026-04-25 02:12 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1477
|
7.5 |
HIGH
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-primitives contains primitives (e.g., block, account, transaction) to be used in Nimiq's Rust implementation. Prior to version 1.3.0, an untrusted p2p peer can cause a node to panic by announci…
|
CWE-252 CWE-755
Unchecked Return Value Improper Handling of Exceptional Conditions
|
CVE-2026-34065
|
2026-04-25 02:12 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1478
|
8.2 |
HIGH
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-account contains account primitives to be used in Nimiq's Rust implementation. Prior to version 1.3.0, `VestingContract::can_change_balance` returns `AccountError::InsufficientFunds` when `new_…
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-34064
|
2026-04-25 02:12 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1479
|
7.5 |
HIGH
Network
|
nimiq
|
nimiq_proof-of-stake
|
Nimiq's network-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `network-libp2p` discovery uses a libp2p `ConnectionHandler` state machine. the handler assumes there…
|
CWE-617
Reachable Assertion
|
CVE-2026-34063
|
2026-04-25 02:12 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1480
|
5.3 |
MEDIUM
Network
|
nimiq
|
nimiq_proof-of-stake
|
nimiq-libp2p is a Nimiq network implementation based on libp2p. Prior to version 1.3.0, `MessageCodec::read_request` and `read_response` call `read_to_end()` on inbound substreams, so a remote peer c…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-34062
|
2026-04-25 02:11 |
2026-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|