Total CVEs

140,303

Critical Severity

3,711

High Severity

13,353

Last 7 Days

1,800
Quick preset (or use dates below)
Clear Filters
Showing 5,361 - 5,380 of 13,353 CVEs
CVE-2026-37552 HIGH - 8.4

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) receives data from a TCP socket, passes it directly to Opis\Closure\unserialize(), then executes the result via call_user_func(). No authentication or signature verification exists on...

Published: May 01, 2026
Source: NVD
CVE-2026-22167 HIGH - 7.8

Software installed and run as a non-privileged user may conduct improper GPU system calls to force GPU to write to arbitrary physical memory pages. Under certain circumstances this exploit could be used to corrupt data pages not allocated by the GPU driver but memory pages in use by the kernel an...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: May 01, 2026
Source: NVD
CVE-2026-22165 HIGH - 8.1

A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger a write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the process executing graphics workload has system privileges this could enable further exploits on the devi...

Vendor: Imagination Technologies
Product: Graphics DDK
Published: May 01, 2026
Source: NVD
CVE-2026-43507 HIGH - 7.5

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by XML parsing resource amplification from unauthenticated connections.

Vendor: prosody
Product: prosody
Published: May 01, 2026
Source: NVD
CVE-2026-43506 HIGH - 7.5

An issue was discovered in Prosody before 0.12.6 and 1.0.0 through 13.0.0 before 13.0.5. A Denial of Service can occur via memory exhaustion caused by memory leaks from unauthenticated connections.

Vendor: prosody
Product: prosody
Published: May 01, 2026
Source: NVD
CVE-2026-43057 HIGH - 7.5

In the Linux kernel, the following vulnerability has been resolved: net: correctly handle tunneled traffic on IPV6_CSUM GSO fallback NETIF_F_IPV6_CSUM only advertises support for checksum offload of packets without IPv6 extension headers. Packets with extension headers must fall back onto software...

Vendor: Linux
Product: Linux
Published: May 01, 2026
Source: NVD
CVE-2026-43056 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: net: mana: fix use-after-free in add_adev() error path If auxiliary_device_add() fails, add_adev() jumps to add_fail and calls auxiliary_device_uninit(adev). The auxiliary device has its release callback set to adev_release(), wh...

Vendor: Linux
Product: Linux
Published: May 01, 2026
Source: NVD
CVE-2026-43055 HIGH - 7.5

In the Linux kernel, the following vulnerability has been resolved: scsi: target: file: Use kzalloc_flex for aio_cmd The target_core_file doesn't initialize the aio_cmd->iocb for the ki_write_stream. When a write command fd_execute_rw_aio() is executed, we may get a bogus ki_write_stream v...

Vendor: Linux
Product: Linux
Published: May 01, 2026
Source: NVD
CVE-2026-43052 HIGH - 7.1

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: check tdls flag in ieee80211_tdls_oper When NL80211_TDLS_ENABLE_LINK is called, the code only checks if the station exists but not whether it is actually a TDLS station. This allows the operation to proceed for non...

Vendor: Linux
Product: Linux
Published: May 01, 2026
Source: NVD
CVE-2026-43051 HIGH - 8.1

In the Linux kernel, the following vulnerability has been resolved: HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq The wacom_intuos_bt_irq() function processes Bluetooth HID reports without sufficient bounds checking. A maliciously crafted short report can trigger an out-of-bounds read ...

Vendor: Linux
Product: Linux
Published: May 01, 2026
Source: NVD
CVE-2026-43050 HIGH - 7.0

In the Linux kernel, the following vulnerability has been resolved: atm: lec: fix use-after-free in sock_def_readable() A race condition exists between lec_atm_close() setting priv->lecd to NULL and concurrent access to priv->lecd in send_to_lecd(), lec_handle_bridge(), and lec_atm_send(). W...

Vendor: Linux
Product: Linux
Published: May 01, 2026
Source: NVD
CVE-2026-43049 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: HID: logitech-hidpp: Prevent use-after-free on force feedback initialisation failure Presently, if the force feedback initialisation fails when probing the Logitech G920 Driving Force Racing Wheel for Xbox One, an error number wil...

Vendor: Linux
Product: Linux
Published: May 01, 2026
Source: NVD
CVE-2026-43048 HIGH - 8.8

In the Linux kernel, the following vulnerability has been resolved: HID: core: Mitigate potential OOB by removing bogus memset() The memset() in hid_report_raw_event() has the good intention of clearing out bogus data by zeroing the area from the end of the incoming data string to the assumed end ...

Vendor: Linux
Product: Linux
Published: May 01, 2026
Source: NVD
CVE-2026-43047 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: HID: multitouch: Check to ensure report responses match the request It is possible for a malicious (or clumsy) device to respond to a specific report's feature request using a completely different report ID. This can cause c...

Vendor: Linux
Product: Linux
Published: May 01, 2026
Source: NVD
CVE-2026-43044 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: crypto: caam - fix DMA corruption on long hmac keys When a key longer than block size is supplied, it is copied and then hashed into the real key. The memory allocated for the copy needs to be rounded to DMA cache alignment, as o...

Vendor: Linux
Product: Linux
Published: May 01, 2026
Source: NVD
CVE-2026-43042 HIGH - 7.1

In the Linux kernel, the following vulnerability has been resolved: mpls: add seqcount to protect the platform_label{,s} pair The RCU-protected codepaths (mpls_forward, mpls_dump_routes) can have an inconsistent view of platform_labels vs platform_label in case of a concurrent resize (resize_platf...

Vendor: Linux
Product: Linux
Published: May 01, 2026
Source: NVD
CVE-2026-43040 HIGH - 7.1

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: ndisc: fix ndisc_ra_useropt to initialize nduseropt_padX fields to zero to prevent an info-leak When processing Router Advertisements with user options the kernel builds an RTM_NEWNDUSEROPT netlink message. The nduserop...

Vendor: Linux
Product: Linux
Published: May 01, 2026
Source: NVD
CVE-2026-43033 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: crypto: authencesn - Do not place hiseq at end of dst for out-of-place decryption When decrypting data that is not in-place (src != dst), there is no need to save the high-order sequence bits in dst as it could simply be re-copied...

Vendor: Linux
Product: Linux
Published: May 01, 2026
Source: NVD
CVE-2026-43031 HIGH - 7.5

In the Linux kernel, the following vulnerability has been resolved: net: xilinx: axienet: Fix BQL accounting for multi-BD TX packets When a TX packet spans multiple buffer descriptors (scatter-gather), axienet_free_tx_chain sums the per-BD actual length from descriptor status into a caller-provide...

Vendor: Linux
Product: Linux
Published: May 01, 2026
Source: NVD
CVE-2026-43030 HIGH - 7.8

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix regsafe() for pointers to packet In case rold->reg->range == BEYOND_PKT_END && rcur->reg->range == N regsafe() may return true which may lead to current state with valid packet range not being explored...

Vendor: Linux
Product: Linux
Published: May 01, 2026
Source: NVD