#1 · PT-2026-32884 · Microsoft · Defender

Diffract

+2

·

Published

2026-04-02

·

Updated

2026-04-17

·

CVE-2026-33825

7.8

High

Base

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions Microsoft Defender (affected versions not specified) Windows 10 (affected versions not specified) Windows 11 (affected versions not specified) Windows Server 2019 and later (affected versions not specified)
Description Insufficient granularity of access control in Microsoft Defender allows an authorized attacker to elevate privileges locally to SYSTEM level. One method of ex...
More

Fix

DoS

LPE

RCE

41 Posts
457Reposts
442.9 K Audience
Graph

#2 · PT-2025-48817 · Meta · React-Server-Dom-Parcel

Published

2025-12-03

·

Updated

2026-04-17

·

CVE-2025-55182

10

Critical

Base

AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions React versions 19.0.0 through 19.2.1 Next.js versions 15.x and 16.x
Description React Server Components (RSC) is affected by a critical remote code execution (RCE) vulnerability (CVE-2025-55182) with a CVSS score of 10.0. This vulnerability stems from unsafe deserialization of HTTP request payloads within Server Function endpoints. Exploitation allows unauthenticated attacke...
More

Exploit

Fix

DoS

LPE

RCE

Deserialization of Untrusted Data

2.0 K Posts
8.8 KReposts
9.9 M Audience
Graph

#3 · PT-2026-32853 · Microsoft · Sharepoint Server

Published

2026-04-14

·

Updated

2026-04-17

·

CVE-2026-32201

6.5

Medium

Base

AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Name of the Vulnerable Software and Affected Versions Microsoft SharePoint Server (affected versions not specified) Microsoft SharePoint Server Subscription Edition (affected versions not specified) Microsoft SharePoint Enterprise Server (affected versions not specified)
Description Improper input validation in Microsoft Office SharePoint allows an unauthorized and unauthenticated remote attacker to perform spoofing over a netw...
More

Fix

LPE

RCE

SSRF

65 Posts
206Reposts
157.1 K Audience
Graph

#4 · PT-2026-32887 · Microsoft · Snipping Tool

Marcos Díaz

·

Published

2026-04-14

·

Updated

2026-04-17

·

CVE-2026-33829

4.3

Medium

Base

AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Name of the Vulnerable Software and Affected Versions Windows Snipping Tool (affected versions not specified)
Description An issue in Windows Snipping Tool allows remote attackers to capture NTLM authentication responses from users. NTLM (New Technology LAN Manager) is a suite of Microsoft security protocols used to authenticate users. Exploitation occurs when a user is tricked into visiting a malicious webpage or opening a cra...
More

Information Disclosure

7 Posts
171Reposts
114.3 K Audience
Graph

#5 · PT-2025-34177 · Apple · Macos Sonoma

Published

2025-08-20

·

Updated

2026-04-17

·

CVE-2025-43300

10

Critical

Base

AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Name of the Vulnerable Software and Affected Versions: Apple iOS, iPadOS, and macOS versions 15.6.1, 15.7, 15.8.5, 16.7.12, 17.7.10, and 18.6.2 are affected.
Description: Apple has addressed a zero-day vulnerability (CVE-2025-43300) in the ImageIO framework. This is an out-of-bounds write issue that can be exploited by processing a maliciously crafted image file, potentially leading to remote code execution. The vulnerability has been...
More

Exploit

Fix

DoS

RCE

Memory Corruption

580 Posts
1.9 KReposts
502.4 M Audience
Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph
  • Graph