Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-43065 — ext4: always drain queued discard work in ext4_mb_release()

In the Linux kernel, the following vulnerability has been resolved: ext4: always drain queued discard work in ext4_mb_release() While reviewing recent ext4 patch[1], Sashiko raised the following co…

linux_kernel | Misconfiguration
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
0.0 NA
CVE-2026-43064 — dmaengine: idxd: Fix not releasing workqueue on .release()

In the Linux kernel, the following vulnerability has been resolved: dmaengine: idxd: Fix not releasing workqueue on .release() The workqueue associated with an DSA/IAA device is not released when t…

linux_kernel | Misconfiguration
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
7.8 HIGH
CVE-2026-43063 — xfs: don't irele after failing to iget in xfs_attri_recover_work

In the Linux kernel, the following vulnerability has been resolved: xfs: don't irele after failing to iget in xfs_attri_recover_work xlog_recovery_iget* never set @ip to a valid pointer if they ret…

linux_kernel | Memory Corruption
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
7.1 HIGH
CVE-2026-43062 — Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp()

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix type confusion in l2cap_ecred_reconf_rsp() l2cap_ecred_reconf_rsp() casts the incoming data to struct l2cap…

linux_kernel | Memory Corruption
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
0.0 NA
CVE-2026-43061 — serial: 8250: Fix TX deadlock when using DMA

In the Linux kernel, the following vulnerability has been resolved: serial: 8250: Fix TX deadlock when using DMA `dmaengine_terminate_async` does not guarantee that the `__dma_tx_complete` callback…

linux_kernel | Denial of Service
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
7.8 HIGH
CVE-2026-43060 — netfilter: nft_ct: drop pending enqueued packets on removal

In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: drop pending enqueued packets on removal Packets sitting in nfqueue might hold a reference to: - templates th…

linux_kernel | Memory Corruption
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
0.0 NA
CVE-2026-43059 — Bluetooth: MGMT: Fix list corruption and UAF in command complete handlers

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: MGMT: Fix list corruption and UAF in command complete handlers Commit 302a1f674c00 ("Bluetooth: MGMT: Fix possible UAF…

linux_kernel | Memory Corruption
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
5.5 MEDIUM
CVE-2026-39103 — GPAC Buffer Overflow Denial of Service

Buffer Overflow vulnerability in GPAC before commit v391dc7f4d234988ea0bc3cc294eb725eddf8f702 allows an attacker to cause a denial of service via the src/scenegraph/svg_attributes.c, svg_parse_string…

| Memory Corruption
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
6.5 MEDIUM
CVE-2026-35192 — Session fixation via public cached pages and SESSION_SAVE_EVERY_REQUEST

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. Response headers do not vary on cookies if a session is not modified, but `SESSION_SAVE_EVERY_REQUEST` is `True`. A remote attacker …

django | Remote | Information Disclosure
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
5.9 MEDIUM
CVE-2026-34956 — Openvswitch: open vswitch: denial of service via malformed ftp epasv command

A flaw was found in Open vSwitch. When Open vSwitch is configured with a conntrack flow using FTP helpers over the userspace datapath, a remote attacker can send a specially crafted FTP stream with a…

Remote | Denial of Service
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
9.1 CRITICAL
CVE-2026-34002 — Xorg: xwayland: x.org x server: information disclosure or denial of service via out-of-bo…

A flaw was found in the X.Org X server. This vulnerability, an out-of-bounds read, affects the XKB (X Keyboard Extension) modifier map handling. An attacker with access to the X11 server can exploit …

enterprise_linux x_server | Remote | Memory Corruption
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
9.1 CRITICAL
CVE-2026-34000 — Xwayland: xorg: x.org x server: information disclosure and denial of service via out-of-b…

A flaw was found in the X.Org X server. This out-of-bounds read vulnerability in the XKB geometry processing, specifically within the `CheckSetGeom()` and `XkbAddGeomKeyAlias` functions, allows an at…

enterprise_linux x_server | Remote | Information Disclosure
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
8.7 HIGH
CVE-2026-32689 — Long-poll NDJSON body splitting causes unbounded memory allocation in Phoenix

Allocation of Resources Without Limits or Throttling vulnerability in phoenixframework phoenix allows a denial of service via the long-poll transport's NDJSON body handling. In 'Elixir.Phoenix.Trans…

phoenix | Remote | Denial of Service
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
8.8 HIGH
CVE-2026-31196 — ALTICE LABS SFR France GR140DG GR140IG fibre CPE/Router/Gateway Remote Command Execution …

The traceroute diagnostic handler in /bin/httpd_clientside for ALTICE LABS / SFR France GR140DG and GR140IG fibre CPE/Router/Gateway, inserts unsanitized user input into a system() call, allowing aut…

Remote | Injection
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
8.8 HIGH
CVE-2026-31195 — ALTICE LABS SFR France GR140DG/GR140IG Fibre CPE/Router/Gateway Remote Command Execution …

The ping diagnostic handler in /bin/httpd_clientside for ALTICE LABS / SFR France GR140DG and GR140IG fibre CPE/Router/Gateway, inserts unsanitized user input into a system() call, allowing authentic…

Remote | Injection
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
7.5 HIGH
CVE-2025-66369 — Samsung Exynos 5G NR NAS Registration Denial of Service Vulnerability

An issue was discovered in MM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, W920, W930, W1000, Modem 5123, and Modem…

Remote | Denial of Service
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
6.3 MEDIUM
CVE-2025-61669 — jupyter_server next parameter open redirect can redirect users to external domains

Jupyter Server is the backend for Jupyter web applications. In jupyter_server versions through 2.17.0, the next query parameter in the login flow is insufficiently validated in `LoginFormHandler._red…

jupyter_server | Remote | Misconfiguration
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
4.7 MEDIUM
CVE-2025-52206 — ISPConfig XSS Attack

ISPConfig 3.3.0 is vulnerable to Cross Site Scripting (XSS) via the system status webpage.

Remote | Cross-Site Scripting
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
10.0 HIGH
CVE-2026-7834 — EFM ipTIME NAS1dual misc_main.cgi get_csrf_whites stack-based overflow

A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cgi. Such manipulation leads to stack-bas…

Remote | Memory Corruption
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
5.0 MEDIUM
CVE-2026-7778 — runZero Platform dashboard configuration exposure

An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved. This is an instance of CWE-269: Improper Privilege Management, an…

runzero_platform | Remote | Authorization
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
Showing 20 of 5786 Results