|
21
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have allowed a user to trigg…
New
|
CWE-940
Improper Verification of Source of a Communication Channel
|
CVE-2026-23866
|
2026-05-2 03:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
22
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An attachment spoofing issue in WhatsApp for Windows prior to v2.3000.1032164386.258709 could have allowed maliciously formatted documents with embedded NUL bytes in the filename to be shown in the a…
New
|
CWE-158
Improper Neutralization of Null Byte or NUL Character
|
CVE-2026-23863
|
2026-05-2 03:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
23
|
9.6 |
CRITICAL
Network
|
-
|
-
|
A web page that contains unusual WebGPU content loaded into the GPU GLES render process and can trigger write UAF crash in the GPU GLES user-space shared library. On certain platforms, when the proce…
New
|
CWE-416
Use After Free
|
CVE-2026-22166
|
2026-05-2 03:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
24
|
3.3 |
LOW
Local
|
-
|
-
|
An unprivileged attacker can reliably trigger a crash of the dtrace process with a malicious ELF binary due to an integer Divide-by-Zero in Pbuild_file_symtab()
New
|
-
|
CVE-2026-21996
|
2026-05-2 03:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
25
|
- |
|
-
|
-
|
Cross-Site Scripting (XSS) vulnerability was discovered in the GSVoIP web panel version 2.0.90. The `msg` parameter in the `/painel/gateways.php/error` endpoint does not properly sanitize user-suppli…
New
|
-
|
CVE-2025-69606
|
2026-05-2 03:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
26
|
- |
|
-
|
-
|
An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a packet specially crafted to bear a non-valid value in any Boolean field.
New
|
-
|
CVE-2025-63548
|
2026-05-2 03:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
27
|
- |
|
-
|
-
|
An issue in Eprosima Micro-XREC-DDS Agent v.3.0.1 allows a remote attacker to cause a denial of service via a crafted packet to the MTU length field
New
|
-
|
CVE-2025-63547
|
2026-05-2 03:16 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
28
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
Dissection engine zlib decompression crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
New
|
CWE-1325
Improperly Controlled Sequential Memory Allocation
|
CVE-2026-6535
|
2026-05-2 03:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
29
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
DLMS/COSEM protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4
New
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-6536
|
2026-05-2 03:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
30
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
ZigBee protocol dissector crash in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-6537
|
2026-05-2 03:15 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|