|
3541
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
ice: corrige un fallo en la prueba de bucle invertido fuera de línea de ethtool
Desde la conversión de ice a 'page pool', la pru…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-23353
|
2026-04-25 02:45 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3542
|
7.0 |
HIGH
Local
|
microsoft
|
windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2022_23h2 windows_server_2025
|
Use after free in Windows Shell allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-26165
|
2026-04-25 02:39 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3543
|
7.0 |
HIGH
Local
|
microsoft
|
windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2022_23h2 windows_server_2025
|
Double free in Windows Shell allows an authorized attacker to elevate privileges locally.
|
CWE-415
Double Free
|
CVE-2026-26166
|
2026-04-25 02:38 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3544
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-26167
|
2026-04-25 02:37 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3545
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locall…
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-26168
|
2026-04-25 02:35 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3546
|
- |
|
dnnsoftware
|
dotnetnuke
|
DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or c…
|
NVD-CWE-Other
|
CVE-2004-2323
|
2026-04-25 02:34 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3547
|
- |
|
dnnsoftware
|
dotnetnuke
|
SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database via the (1) table and (2) field parameters in LinkCl…
|
NVD-CWE-Other
|
CVE-2004-2324
|
2026-04-25 02:34 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3548
|
- |
|
dnnsoftware
|
dotnetnuke
|
Cross-site scripting (XSS) vulnerability in EditModule.aspx for DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to inject arbitrary web script or HTML.
|
NVD-CWE-Other
|
CVE-2004-2325
|
2026-04-25 02:34 |
2004-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3549
|
- |
|
dnnsoftware
|
dotnetnuke
|
Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or …
|
NVD-CWE-Other
|
CVE-2005-0040
|
2026-04-25 02:34 |
2005-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3550
|
- |
|
dnnsoftware
|
dotnetnuke
|
** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privileges via unspecified vectors, as used in an attack …
|
NVD-CWE-Other
|
CVE-2006-3601
|
2026-04-25 02:34 |
2006-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|