Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-23863 — WhatsApp for Windows Attachment Spoofing Vulnerability

An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the a…

whatsapp | Remote | Misconfiguration
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.8 HIGH
CVE-2026-22167 — GPU DDK - Cache resident PM buffers writable by other GPU requestors, leading to arbitrar…

Software installed and run as a non-privileged user may conduct improper GPU system calls to force GPU to write to arbitrary physical memory pages. Under certain circumstances this exploit could b…

ddk | Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
9.6 CRITICAL
CVE-2026-22166 — GPU DDK - Write UAF in KEGLGetPoolBuffers, WebGL reachable

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the proce…

ddk | Remote | Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
8.1 HIGH
CVE-2026-22165 — GPU DDK - UAF read of GLES3Context::psDrawParams and GLES3Context::psMode and UAF read/wr…

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger a write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the pro…

ddk | Remote | Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
4.3 MEDIUM
CVE-2026-7583 — Open5GS BSF context.c bsf_sess_find_by_ipv6prefix denial of service

A flaw has been found in Open5GS up to 2.7.7. This issue affects the function bsf_sess_find_by_ipv6prefix of the file /src/bsf/context.c of the component BSF. This manipulation of the argument ipv6Pr…

open5gs | Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-43507 — Prosody XML Parsing Resource Amplification Denial of Service

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by XML parsing resource amplification from unauthen…

prosody | Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-43506 — Prosody Denial of Service Vulnerability

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by memory leaks from unauthenticated connections.

prosody | Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
6.5 MEDIUM
CVE-2026-43505 — Prosody Mod Proxy65 Authentication Relaying Vulnerability

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in the activation scenario, relayin…

prosody | Remote | Authentication
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
6.5 MEDIUM
CVE-2026-43504 — Prosody Mod Proxy65 Authentication Bypass Vulnerability

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5, when mod_proxy65 is enabled. Because mod_proxy65 mishandles access control in a paused scenario, relaying of u…

prosody | Remote | Authentication
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-43057 — net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback

In the Linux kernel, the following vulnerability has been resolved: net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback NETIF_F_IPV6_CSUM only advertises support for checksum offload o…

linux_kernel | Remote | Misconfiguration
May 01, 2026 May 03, 2026
May 01, 2026
May 03, 2026
7.8 HIGH
CVE-2026-43056 — net: mana: fix use-after-free in add_adev() error path

In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in add_adev() error path If auxiliary_device_add() fails, add_adev() jumps to add_fail and calls au…

linux_kernel | Memory Corruption
May 01, 2026 May 03, 2026
May 01, 2026
May 03, 2026
7.5 HIGH
CVE-2026-43055 — scsi: target: file: Use kzalloc_flex for aio_cmd

In the Linux kernel, the following vulnerability has been resolved: scsi: target: file: Use kzalloc_flex for aio_cmd The target_core_file doesn't initialize the aio_cmd->iocb for the ki_write_strea…

linux_kernel | Remote | Memory Corruption
May 01, 2026 May 03, 2026
May 01, 2026
May 03, 2026
0.0 NA
CVE-2026-43054 — scsi: target: tcm_loop: Drain commands in target_reset handler

In the Linux kernel, the following vulnerability has been resolved: scsi: target: tcm_loop: Drain commands in target_reset handler tcm_loop_target_reset() violates the SCSI EH contract: it returns …

linux_kernel | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
0.0 NA
CVE-2026-43053 — xfs: close crash window in attr dabtree inactivation

In the Linux kernel, the following vulnerability has been resolved: xfs: close crash window in attr dabtree inactivation When inactivating an inode with node-format extended attributes, xfs_attr3_n…

linux_kernel | Misconfiguration
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
0.0 NA
CVE-2026-43052 — wifi: mac80211: check tdls flag in ieee80211_tdls_oper

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: check tdls flag in ieee80211_tdls_oper When NL80211_TDLS_ENABLE_LINK is called, the code only checks if the stati…

linux_kernel | Authorization
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
8.1 HIGH
CVE-2026-43051 — HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq

In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq The wacom_intuos_bt_irq() function processes Bluetooth HID reports with…

linux_kernel | Memory Corruption
May 01, 2026 May 03, 2026
May 01, 2026
May 03, 2026
0.0 NA
CVE-2026-43050 — atm: lec: fix use-after-free in sock_def_readable()

In the Linux kernel, the following vulnerability has been resolved: atm: lec: fix use-after-free in sock_def_readable() A race condition exists between lec_atm_close() setting priv->lecd to NULL an…

linux_kernel | Race Condition
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
0.0 NA
CVE-2026-43049 — HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure

In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure Presently, if the force feedback initialisat…

linux_kernel | Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
8.8 HIGH
CVE-2026-43048 — HID: core: Mitigate potential OOB by removing bogus memset()

In the Linux kernel, the following vulnerability has been resolved: HID: core: Mitigate potential OOB by removing bogus memset() The memset() in hid_report_raw_event() has the good intention of cle…

linux_kernel | Memory Corruption
May 01, 2026 May 03, 2026
May 01, 2026
May 03, 2026
7.8 HIGH
CVE-2026-43047 — HID: multitouch: Check to ensure report responses match the request

In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Check to ensure report responses match the request It is possible for a malicious (or clumsy) device to respond …

linux_kernel | Memory Corruption
May 01, 2026 May 03, 2026
May 01, 2026
May 03, 2026
Showing 20 of 5654 Results