Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In April 2026
Improper access control in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information locally.
CVSS Score
5.5
EPSS Score
0.002
Published
2026-04-14
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to elevate privileges locally.
CVSS Score
7.0
EPSS Score
0.002
Published
2026-04-14
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVSS Score
8.4
EPSS Score
0.003
Published
2026-04-14
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVSS Score
8.4
EPSS Score
0.003
Published
2026-04-14
Loop with unreachable exit condition ('infinite loop') in .NET, .NET Framework, Visual Studio allows an unauthorized attacker to deny service over a network.
CVSS Score
7.5
EPSS Score
0.021
Published
2026-04-14
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVSS Score
7.0
EPSS Score
0.002
Published
2026-04-14
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
CVSS Score
7.0
EPSS Score
0.002
Published
2026-04-14
Use after free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.002
Published
2026-04-14
Use after free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
CVSS Score
7.8
EPSS Score
0.004
Published
2026-04-14
Out-of-bounds read in Windows HTTP.sys allows an unauthorized attacker to deny service over a network.
CVSS Score
7.5
EPSS Score
0.012
Published
2026-04-14


Contact Us

Shodan ® - All rights reserved