Sandbox Escape Vulnerability in Terrarium allows arbitrary code execution with root privileges on a host process via JavaScript prototype chain traversal.
CVSSv3.1 9.3 (CRITICAL)
TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-04-14
2026-04-14 18:17Z
HIGH
CVE-2026-34617 — Adobe: Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS)
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Cross-Site Scripting (XSS) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised we
CVSSv3.1 8.7 (HIGH)
CWECWE 79VNDAdobeTYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-04-14
2026-04-14 18:17Z
CRIT
CVE-2026-34615 — Adobe: Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
CVSSv3.1 9.3 (CRITICAL)
CWECWE 502VNDAdobeTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-04-14
2026-04-14 18:17Z
HIGH
CVE-2026-33827 — Concurrent: execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
CVSSv3.1 8.1 (HIGH)
CWECWE 362VNDConcurrentTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-04-14
2026-04-14 18:17Z
HIGH
CVE-2026-33826 — Windows: Improper input validation in Windows Active Directory allows an authorized attacker to execute code
Improper input validation in Windows Active Directory allows an authorized attacker to execute code over an adjacent network.
CVSSv3.1 8.0 (HIGH)
CWECWE 20TYPVulnerability
8.0
CVSS v3.1
90
Edit Score
2026-04-14
2026-04-14 18:17Z
HIGH
CVE-2026-33825 — Microsoft Defender_antimalware_platform: Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate
NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-33825in the wild
Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally.
CVSSv3.1 7.8 (HIGH) · EPSS 93th percentile
Heap-based buffer overflow in Microsoft Graphics Component allows an unauthorized attacker to execute code locally.
CVSSv3.1 8.4 (HIGH)
CWECWE 122VNDHeapTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-04-14
2026-04-14 18:17Z
MED
CVE-2026-32202 — Microsoft Windows_10_1607: Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over
NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32202in the wild
Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network.
CVSSv3.1 4.3 (MEDIUM) · EPSS 92th percentile
Acceptance of extraneous untrusted data with trusted data in Windows COM allows an unauthorized attacker to elevate privileges locally.
CVSSv3.1 8.4 (HIGH)
CWECWE 349VNDAcceptanceTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-04-14
2026-04-14 18:17Z
HIGH
CVE-2026-32157 — Use: after free in Remote Desktop Client allows an unauthorized attacker to execute code
Concurrent execution using shared resource with improper synchronization ('race condition') in Microsoft Brokering File System allows an unauthorized attacker to elevate privileges locally.
CVSSv3.1 8.4 (HIGH)
CWECWE 416CWECWE 362VNDConcurrentTYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-04-14
2026-04-14 18:17Z
HIGH
CVE-2026-27928 — Windows: Improper input validation in Windows Hello allows an unauthorized attacker to bypass a security
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.
CVSSv3.1 9.6 (CRITICAL)
CWECWE 502VNDAdobeTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-04-14
2026-04-14 18:16Z
CRIT
CVE-2026-27246 — Adobe: Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a DOM-based Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this issue by manipulating the DOM environment to execute malicious JavaScript within the context of the victim's browser. Exploitation of this issue requires user interaction in that a victim must visit a crafted webpage. Scope is changed.
CVSSv3.1 9.3 (CRITICAL)
CWECWE 79VNDAdobeTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-04-14
2026-04-14 18:16Z
CRIT
CVE-2026-27245 — Adobe: Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
CVSSv3.1 9.3 (CRITICAL)
CWECWE 79VNDAdobeTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-04-14
2026-04-14 18:16Z
CRIT
CVE-2026-27243 — Adobe: Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting
Adobe Connect versions 2025.3, 12.10 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. Scope is changed.
CVSSv3.1 9.3 (CRITICAL)
CWECWE 79VNDAdobeTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-04-14
2026-04-14 18:16Z
HIGH
CVE-2026-26178 — Microsoft Windows_10_1607: Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to
Integer size truncation in Windows Advanced Rasterization Platform (WARP) allows an unauthorized attacker to elevate privileges locally.
CVSSv3.1 8.8 (HIGH)