Vulnerebility APRIL
H
ECV
KB
KEV
|
2026()
2025()
|
Vulnerebility Calendar
Top Vulnerebility
List of Attack
CWE
Anti-Debug
Tricks
2026 January February March April May June July August September October November December
|
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
| 30.4.26 | CVE-2026-26268 | Sandbox escape via Git hooks | VULNEREBILITY | VULNEREBILITY |
| 30.4.26 | CVE-2026-31431 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. | VULNEREBILITY | VULNEREBILITY |
| 29.4.26 | CVE-2026-32202 | Microsoft Windows Protection Mechanism Failure Vulnerability: Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. | VULNEREBILITY | VULNEREBILITY |
| 29.4.26 | CVE-2024-1708 | ConnectWise ScreenConnect Path Traversal Vulnerability: ConnectWise ScreenConnect contains a path traversal vulnerability which could allow an attacker to execute remote code or directly impact confidential data and critical systems. | VULNEREBILITY | VULNEREBILITY |
| 29.4.26 | CVE-2026-42208 | SQL injection in Proxy API key verification | VULNEREBILITY | VULNEREBILITY |
| 29.4.26 | CVE-2026-3854 | An improper neutralization of special elements... | VULNEREBILITY | VULNEREBILITY |
| 28.4.26 | CVE-2026-25874 | LeRobot Unsafe Deserialization Remote Code Execution via gRPC | VULNEREBILITY | VULNEREBILITY |
| 28.4.26 | CVE-2026-32202 | Windows Shell Spoofing Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 26.4.26 | CVE-2026-41651 | PackageKit is a a D-Bus abstraction layer that allows the user to manage packages in a secure way using a cross-distro, cross-architecture API. PackageKit between and including versions 1.0.2 and 1.3.4 is vulnerable to a time-of-check time-of-use (TOCTOU) race condition on transaction flags that allows unprivileged users to install packages as root and thus leads to a local privilege escalation. | VULNEREBILITY | VULNEREBILITY |
| 25.4.26 | CVE-2024-57726 | (CVSS score: 9.9) - A missing authorization vulnerability in SimpleHelp that could allow low-privileged technicians to create API keys with excessive permissions, which can then be used to escalate privileges to the server admin role. | VULNEREBILITY | VULNEREBILITY |
| 25.4.26 | CVE-2024-57728 | (CVSS score: 7.2) - A path traversal vulnerability in SimpleHelp that allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e., zip slip), which can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. | VULNEREBILITY | VULNEREBILITY |
| 25.4.26 | CVE-2024-7399 | (CVSS score: 8.8) - A path traversal vulnerability in Samsung MagicINFO 9 Server that could allow an attacker to write arbitrary files as system authority. | VULNEREBILITY | VULNEREBILITY |
| 25.4.26 | CVE-2025-29635 | (CVSS score: 7.5) - A command injection vulnerability in end-of-life D-Link DIR-823X series routers that allows an authorized attacker to execute arbitrary commands on remote devices by sending a POST request to /goform/set_prohibiting via the corresponding function. | VULNEREBILITY | VULNEREBILITY |
| 25.4.26 | CVE-2025-20333 | (CVSS score: 9.9) - An improper validation of user-supplied input vulnerability that could allow an authenticated, remote attacker with valid VPN user credentials to execute arbitrary code as root on an affected device by sending crafted HTTP requests. | VULNEREBILITY | VULNEREBILITY |
| 25.4.26 | CVE-2025-20362 | (CVSS score: 6.5) - An improper validation of user-supplied input vulnerability that could allow an unauthenticated, remote attacker to access restricted URL endpoints without authentication by sending crafted HTTP requests. | VULNEREBILITY | VULNEREBILITY |
| 24.4.26 | CVE-2026-33626 | Server-Side Request Forgery (SSRF) in Vision-Language Image Loading | VULNEREBILITY | VULNEREBILITY |
| 23.4.26 | CVE-2026-28950 | A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.7.8 and iPadOS 18.7.8, iOS 26.4.2 and iPadOS 26.4.2. Notifications marked for deletion could be unexpectedly retained on the device. | VULNEREBILITY | VULNEREBILITY |
| 22.4.26 | CVE-2026-40372 | ASP.NET Core Elevation of Privilege Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 22.4.26 | CVE-2026-5752 | Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal. | VULNEREBILITY | VULNEREBILITY |
| 22.4.26 | Bridge:Break | Bridge:Break: Vulnerabilities Thrive in Serial-to-Ethernet Converters | VULNEREBILITY | VULNEREBILITY |
| 18.4.26 | CVE-2026-5194 | Missing hash/digest size and OID checks allow digests smaller than allowed when verifying ECDSA certificates, or smaller than is appropriate for the relevant key type, to be accepted by signature verification functions. This could lead to reduced security of ECDSA certificate-based authentication if the public CA key used is also known. This affects ECDSA/ECC verification when EdDSA or ML-DSA is also enabled. | VULNEREBILITY | VULNEREBILITY |
| 18.4.26 | CVE-2026-39987 | marimo is a reactive Python notebook. Prior to 0.23.0, Marimo has a Pre-Auth RCE vulnerability. The terminal WebSocket endpoint /terminal/ws lacks authentication validation, allowing an unauthenticated attacker to obtain a full PTY shell and execute arbitrary system commands | VULNEREBILITY | VULNEREBILITY |
| 17.4.26 | CVE-2026-20180 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have at least Read Only Admin credentials. This vulnerability is due to insufficient validation of user-supplied input | VULNEREBILITY | VULNEREBILITY |
| 17.4.26 | CVE-2026-20186 | A vulnerability in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. | VULNEREBILITY | VULNEREBILITY |
| 17.4.26 | CVE-2026-20147 | (CVSS score: 9.9) - An insufficient validation of user-supplied input vulnerability in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that could allow an authenticated, remote attacker in possession of valid administrative credentials to achieve remote code execution by sending crafted HTTP requests | VULNEREBILITY | VULNEREBILITY |
| 17.4.26 | CVE-2026-20184 | (CVSS score: 9.8) - An improper certificate validation in the integration of single sign-on (SSO) with Control Hub in Webex Services that could allow an unauthenticated, remote attacker to impersonate any user within the service and gain unauthorized access to legitimate Cisco Webex services. | VULNEREBILITY | VULNEREBILITY |
| 17.4.26 | CVE-2026-34197 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. | VULNEREBILITY | VULNEREBILITY |
| 15.4.26 | CVE-2026-33824 | Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 15.4.26 | CVE-2026-33825 | Microsoft Defender Elevation of Privilege Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 15.4.26 | CVE-2026-32201 | Microsoft SharePoint Server Spoofing Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 15.4.26 | CVE-2026-40176 | (CVSS score: 7.8) - An improper input validation vulnerability that could allow an attacker controlling a repository configuration in a malicious composer.json declaring a Perforce VCS repository to inject arbitrary commands, resulting in command execution in the context of the user running Composer. | VULNEREBILITY | VULNEREBILITY |
| 15.4.26 | CVE-2026-40261 | (CVSS score: 8.8) - An improper input validation vulnerability stemming from inadequate escaping that could allow an attacker to inject arbitrary commands through a crafted source reference containing shell metacharacters. | VULNEREBILITY | VULNEREBILITY |
| 14.4.26 | CVE-2026-21643 | (CVSS score: 9.1) - An SQL injection vulnerability in Fortinet FortiClient EMS that could allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | VULNEREBILITY | VULNEREBILITY |
| 14.4.26 | CVE-2020-9715 | (CVSS score: 7.8) - A use-after-free vulnerability in Adobe Acrobat Reader that could result in remote code execution. | VULNEREBILITY | VULNEREBILITY |
| 14.4.26 | CVE-2023-36424 | (CVSS score: 7.8) - An out-of-bounds read vulnerability in Microsoft Windows Common Log File System Driver that could result in privilege escalation. | VULNEREBILITY | VULNEREBILITY |
| 14.4.26 | CVE-2023-21529 | (CVSS score: 8.8) - A deserialization of untrusted data in Microsoft Exchange Server that could allow an authenticated attacker to achieve remote code execution. | VULNEREBILITY | VULNEREBILITY |
| 14.4.26 | CVE-2025-60710 | (CVSS score: 7.8) - An improper link resolution before file access vulnerability in Host Process for Windows Tasks that could allow an authorized attacker to elevate privileges locally. | VULNEREBILITY | VULNEREBILITY |
| 14.4.26 | CVE-2012-1854 | (CVSS score: 7.8) - An insecure library loading vulnerability in Microsoft Visual Basic for Applications (VBA) that could result in remote code execution. | VULNEREBILITY | VULNEREBILITY |
| 14.4.26 | CVE-2025-0520 | ShowDoc unrestricted file upload vulnerability | VULNEREBILITY | VULNEREBILITY |
| 13.4.26 | CVE-2026-34621 | Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. | VULNEREBILITY | VULNEREBILITY |
| 12.4.26 | CVE-2026-1340 | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | VULNEREBILITY | VULNEREBILITY |
| 12.4.26 | CVE-2026-34197 | Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console. | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2026-1731 | BeyondTrust Remote Support (RS) and certain older versions of Privileged Remote Access (PRA) contain a critical pre-authentication remote code execution vulnerability. By sending specially crafted requests, an unauthenticated remote attacker may be able to execute operating system commands in the context of the site user. | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2026-23760 | SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2025-52691 | Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution. | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2025-10035 | SmarterTools SmarterMail versions prior to build 9511 contain an authentication bypass vulnerability in the password reset API. The force-reset-password endpoint permits anonymous requests and fails to verify the existing password or a reset token when resetting system administrator accounts | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE‑2025‑31161 | Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution. | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2024-57728 | A deserialization vulnerability in the License Servlet of Fortra's GoAnywhere MFT allows an actor with a validly forged license response signature to deserialize an arbitrary actor-controlled object, possibly leading to command injection. | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2024-57727 | CrushFTP 10 before 10.8.4 and 11 before 11.3.1 allows authentication bypass and takeover of the crushadmin account (unless a DMZ proxy instance is used), as exploited in the wild in March and April 2025, aka "Unauthenticated HTTP(S) port access." A race condition exists in the AWS4-HMAC (compatible with S3) authorization method of the HTTP component of the FTP server. | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2024-57726 | SimpleHelp remote support software v5.5.7 and before allows admin users to upload arbitrary files anywhere on the file system by uploading a crafted zip file (i.e. zip slip). This can be exploited to execute arbitrary code on the host in the context of the SimpleHelp server user. | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2024-27199 | SimpleHelp remote support software v5.5.7 and before has a vulnerability that allows low-privileges technicians to create API keys with excessive permissions. These API keys can be used to escalate privileges to the server admin role. | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2024-27198 | In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2024-1709 | In JetBrains TeamCity before 2023.11.4 authentication bypass allowing to perform admin actions was possible | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2024-1708 | ConnectWise ScreenConnect 23.9.7 and prior are affected by path-traversal vulnerability, which may allow an attacker the ability to execute remote code or directly impact confidential data or critical systems. | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2024-21887 | A command injection vulnerability in web components of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows an authenticated administrator to send specially crafted requests and execute arbitrary commands on the appliance. | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2023-46805 | An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a remote attacker to access restricted resources by bypassing control checks. | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2023-27351 | This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Build 63914). Authentication is not required to exploit this vulnerability. The specific flaw exists within the SecurityRequestFilter class. The issue results from improper implementation of the authentication algorithm. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-19226. | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2023-21529 | Microsoft Exchange Server Remote Code Execution Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2025-59528 | RCE in FlowiseAI/Flowise | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2023-50224 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. | VULNEREBILITY | VULNEREBILITY |
| 8.4.26 | CVE-2026-34040 | AuthZ plugin bypass with oversized request body | VULNEREBILITY | VULNEREBILITY |
| 5.4.26 | CVE-2025-53521 | When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | VULNEREBILITY | VULNEREBILITY |
| 5.4.26 | CVE-2026-3502 | TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. If the payload is executed or installed by the updater, this may result in arbitrary code execution in the context of the updating process or user. | VULNEREBILITY | VULNEREBILITY |
| 5.4.26 | CVE-2026-4415 | VULNEREBILITY | VULNEREBILITY | VULNEREBILITY |
| 3.4.26 | CVE-2026-21643 | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP requests. | VULNEREBILITY | VULNEREBILITY |
| 3.4.26 | CVE-2026-3098 | The Smart Slider 3 plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 3.5.1.33 via the 'actionExportAll' function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to read the contents of arbitrary files on the server, which can contain sensitive information. | VULNEREBILITY | VULNEREBILITY |
| 3.4.26 | CVE-2026-20093 | Cisco Integrated Management Controller Authentication Bypass Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 1.4.26 | CVE-2026-5281 | Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High) | VULNEREBILITY | VULNEREBILITY |
| 1.4.26 | CVE-2026-3502 | TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. | VULNEREBILITY | VULNEREBILITY |