|
2091
|
4.7 |
MEDIUM
Network
|
-
|
-
|
In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member in an institution f…
|
CWE-284
Improper Access Control
|
CVE-2025-59308
|
2026-04-25 02:54 |
2026-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2092
|
5.4 |
MEDIUM
Network
|
opensourcepos
|
open_source_point_of_sale
|
Open Source Point of Sale is a web based point-of-sale application written in PHP using CodeIgniter framework. Prior to 3.4.3, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Stock Lo…
|
CWE-79
Cross-site Scripting
|
CVE-2026-39380
|
2026-04-25 02:51 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2093
|
10.0 |
CRITICAL
Network
|
flatpak
|
flatpak
|
Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at …
|
CWE-61
UNIX Symbolic Link (Symlink) Following
|
CVE-2026-34078
|
2026-04-25 02:50 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2094
|
4.3 |
MEDIUM
Network
|
pretix
|
pretix
|
A new API endpoint introduced in pretix 2025 that is supposed to
return all check-in events of a specific event in fact returns all
check-in events belonging to the respective organizer. This allow…
|
CWE-653
Improper Isolation or Compartmentalization
|
CVE-2026-5600
|
2026-04-25 02:46 |
2026-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2095
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ice: fix crash in ethtool offline loopback test
Since the conversion of ice to page pool, the ethtool loopback test
crashes:
BU…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-23353
|
2026-04-25 02:45 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2096
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
ice: corrige un fallo en la prueba de bucle invertido fuera de línea de ethtool
Desde la conversión de ice a 'page pool', la pru…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-23353
|
2026-04-25 02:45 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2097
|
7.0 |
HIGH
Local
|
microsoft
|
windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2022_23h2 windows_server_2025
|
Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-26165
|
2026-04-25 02:39 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2098
|
7.0 |
HIGH
Local
|
microsoft
|
windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2022_23h2 windows_server_2025
|
Double free in Windows Shell allows an authorized attacker to elevate privileges locally.
|
CWE-415
Double Free
|
CVE-2026-26166
|
2026-04-25 02:38 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2099
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-26167
|
2026-04-25 02:37 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2100
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locall…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-26168
|
2026-04-25 02:35 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|