1.3

CVSS4.0

CVE-2025-12141 - Grafana Alerting Editors can edit destination of webhooks they did not create

In Grafana's alerting system, users with edit permissions for a contact point, specifically the permissions “alert.notifications:write” or “alert.notifications.receivers:test” that are granted as part of the fixed role "Contact Point Writer", which is part of the basic role Editor - can edit contac…

📅 Published: April 15, 2026, 2:59 p.m. 🔄 Last Modified: April 17, 2026, 7 a.m.

8.7

CVSS4.0

CVE-2026-4682 - Certain HP DeskJet All In One (AIO) Devices – Potential Remote Code Execution & Potential Buffer Ov…

Certain HP DeskJet All in One devices may be vulnerable to remote code execution caused by a buffer overflow when specially crafted Web Services for Devices (WSD) scan requests are improperly validated and handled by the MFP. WSD Scan is a Microsoft Windows–based network scanning protocol that a…

📅 Published: April 15, 2026, 2:32 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

7.3

CVSS4.0

CVE-2026-4667 - HP System Optimizer - Escalation of Privilege

HP System Optimizer might potentially be vulnerable to escalation of privilege. HP is releasing an update to mitigate this potential vulnerability.

📅 Published: April 15, 2026, 2:22 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

6.5

CVSS3.1

CVE-2026-25219 - Apache Airflow: Sensitive Azure Service Bus connection string (and possibly other providers) expose…

The `access_key` and `connection_string` connection properties were not marked as sensitive names in secrets masker. This means that user with read permission could see the values in Connection UI, as well as when Connection was accidentaly logged to logs, those values could be seen in the logs. Az…

📅 Published: April 15, 2026, 12:30 p.m. 🔄 Last Modified: April 17, 2026, 6:37 p.m.

8.5

CVSS4.0

CVE-2026-4145 - Local Privilege Escalation in Lenovo Software Fix

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix that could allow a local authenticated user to perform arbitrary code execution with elevated privileges.

📅 Published: April 15, 2026, 12:28 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

5.2

CVSS4.0

CVE-2026-4135 - Local Authenticated File Write Vulnerability in Lenovo Software Fix

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to perform an arbitrary file write with elevated privileges.

📅 Published: April 15, 2026, 12:28 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

7

CVSS4.0

CVE-2026-4134 - Local Privilege Escalation During Lenovo Software Fix Installation

During an internal security assessment, a potential vulnerability was discovered in Lenovo Software Fix, that during installation could allow a local authenticated user to execute code with elevated privileges.

📅 Published: April 15, 2026, 12:28 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

5.4

CVSS4.0

CVE-2026-1636 - Potential DLL Hijacking in Lenovo Service Bridge Enables Local Privilege Escalation

A potential DLL hijacking vulnerability was reported in Lenovo Service Bridge that, under certain conditions, could allow a local authenticated user to execute code with elevated privileges.

📅 Published: April 15, 2026, 12:27 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

6.9

CVSS4.0

CVE-2026-0827 - Local Privilege Escalation via Arbitrary File Write in Lenovo Diagnostics and Vantage

During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated priv…

📅 Published: April 15, 2026, 12:27 p.m. 🔄 Last Modified: April 17, 2026, 3:09 p.m.

6.1

CVSS3.1

CVE-2026-1852 - Product Pricing Table by WooBeWoo <= 1.1.0 - Cross-Site Request Forgery to Stored XSS and Pricing T…

The Product Pricing Table by WooBeWoo plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1.0. This is due to missing or incorrect nonce validation on the updateLabel() and remove() functions. This makes it possible for unauthenticated attackers …

📅 Published: April 15, 2026, 11:30 a.m. 🔄 Last Modified: April 15, 2026, 11:30 a.m.
Total resulsts: 345161
Page 46 of 34,517
« previous page » next page
Filters