|
1031
|
8.2 |
HIGH
Network
|
firebirdsql
|
firebird
|
Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, when the server receives an op_crypt_key_callback packet without prior authentication, …
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-28224
|
2026-04-25 04:45 |
2026-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1032
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2022_…
|
Untrusted pointer dereference in Windows Sensor Data Service allows an authorized attacker to elevate privileges locally.
|
CWE-20 CWE-822
Improper Input Validation Untrusted Pointer Dereference
|
CVE-2026-26161
|
2026-04-25 04:32 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1033
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Access of resource using incompatible type ('type confusion') in Windows OLE allows an authorized attacker to elevate privileges locally.
|
CWE-843
Type Confusion
|
CVE-2026-26162
|
2026-04-25 04:31 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1034
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Double free in Windows Kernel allows an authorized attacker to elevate privileges locally.
|
CWE-415
Double Free
|
CVE-2026-26163
|
2026-04-25 04:30 |
2026-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1035
|
7.2 |
HIGH
Network
|
dlink
|
dir-823x_firmware
|
A command injection vulnerability in D-Link DIR-823X 240126 and 240802 allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiti…
|
CWE-77
Command Injection
|
CVE-2025-29635
|
2026-04-25 04:27 |
2025-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1036
|
7.2 |
HIGH
Network
|
dlink
|
dir-823x_firmware
|
Una vulnerabilidad de inyección de comandos en D-Link DIR-823X 240126 y 240802 permite a un atacante autorizado ejecutar comandos arbitrarios en dispositivos remotos enviando una solicitud POST a /go…
|
CWE-77
Command Injection
|
CVE-2025-29635
|
2026-04-25 04:27 |
2025-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1037
|
7.2 |
HIGH
Network
|
simple-help
|
simplehelp
|
SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to…
|
CWE-59 CWE-22
Link Following Path Traversal
|
CVE-2024-57728
|
2026-04-25 04:27 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1038
|
7.2 |
HIGH
Network
|
simple-help
|
simplehelp
|
El software de soporte remoto SimpleHelp v5.5.7 y versiones anteriores permite a los usuarios administradores cargar archivos arbitrarios en cualquier parte del sistema de archivos mediante la carga…
|
CWE-59 CWE-22
Link Following Path Traversal
|
CVE-2024-57728
|
2026-04-25 04:27 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1039
|
9.9 |
CRITICAL
Network
|
simple-help
|
simplehelp
|
SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate p…
|
NVD-CWE-noinfo CWE-862
Missing Authorization
|
CVE-2024-57726
|
2026-04-25 04:26 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1040
|
9.9 |
CRITICAL
Network
|
simple-help
|
simplehelp
|
El software de soporte remoto SimpleHelp v5.5.7 y versiones anteriores tiene una vulnerabilidad que permite a los técnicos con pocos privilegios crear claves API con permisos excesivos. Estas claves…
|
NVD-CWE-noinfo CWE-862
Missing Authorization
|
CVE-2024-57726
|
2026-04-25 04:26 |
2025-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|