|
2221
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Authorization Bypass Through User-Controlled Key vulnerability in g5theme Essential Real Estate essential-real-estate allows Exploiting Incorrectly Configured Access Control Security Levels.This issu…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-68071
|
2026-04-25 05:16 |
2025-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2222
|
7.5 |
HIGH
Network
|
-
|
-
|
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in PenciDesign Soledad soledad allows PHP Local File Inclusion.This issue affects…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2025-68066
|
2026-04-25 05:16 |
2025-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2223
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Themefic Hydra Booking hydra-booking allows SQL Injection.This issue affects Hydra Booking: from …
|
CWE-89
SQL Injection
|
CVE-2025-68055
|
2026-04-25 05:16 |
2025-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2224
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2022_…
|
Access of resource using incompatible type ('type confusion') in Windows COM allows an authorized attacker to disclose information locally.
|
CWE-843
Type Confusion
|
CVE-2026-20806
|
2026-04-25 05:16 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2225
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in sonalsinha21 SKT Page Builder skt-builder allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SKT Page Builder: from n/a …
|
CWE-862
Missing Authorization
|
CVE-2025-54005
|
2026-04-25 05:16 |
2025-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2226
|
7.8 |
HIGH
Local
|
giskard
|
giskard
|
Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the ConformityCheck class rendered the rule parameter through Jinja2's default Template() constructor, silentl…
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-40320
|
2026-04-25 05:15 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2227
|
4.6 |
MEDIUM
Physics
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Improper removal of sensitive information before storage or transfer in Windows Recovery Environment Agent allows an unauthorized attacker to bypass a security feature with a physical attack.
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2026-20928
|
2026-04-25 05:11 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2228
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_server_2019 windows_server_2022 windows_server_2022_23h2 windows_ser…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Management Services allows an authorized attacker to elevate privileges locally.
|
CWE-362
Race Condition
|
CVE-2026-20930
|
2026-04-25 05:10 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2229
|
5.7 |
MEDIUM
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Untrusted pointer dereference in Windows Virtualization-Based Security (VBS) Enclave allows an authorized attacker to bypass a security feature locally.
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-23670
|
2026-04-25 05:09 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2230
|
7.0 |
HIGH
Local
|
microsoft
|
windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022_23h2 windows_server_2025
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Applocker Filter Driver (applockerfltr.sys) allows an authorized attacker to elevate privileges locally.
|
CWE-362
Race Condition
|
CVE-2026-25184
|
2026-04-25 05:08 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|