|
1811
|
7.1 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
wifi: mac80211: check tdls flag in ieee80211_tdls_oper
When NL80211_TDLS_ENABLE_LINK is called, the code only checks if the
stati…
|
NVD-CWE-noinfo
|
CVE-2026-43052
|
2026-05-8 03:19 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1812
|
8.1 |
HIGH
Adjacent
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq
The wacom_intuos_bt_irq() function processes Bluetooth HID reports
with…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-43051
|
2026-05-8 03:00 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1813
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
vt: discard stale unicode buffer on alt screen exit after resize
When enter_alt_screen() saves vc_uni_lines into vc_saved_uni_lin…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-31742
|
2026-05-8 02:42 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1814
|
9.1 |
CRITICAL
Network
|
torproject
|
tor
|
Tor before 0.4.9.7 has an out-of-bounds read when an END, a TRUNCATE, or a TRUNCATED cell lacks a reason in its payload, aka TROVE-2026-011.
|
CWE-684
Incorrect Provision of Specified Functionality
|
CVE-2026-44597
|
2026-05-8 02:34 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1815
|
5.3 |
MEDIUM
Network
|
torproject
|
tor
|
Tor before 0.4.9.7 can attempt or accept BEGIN_DIR via conflux legs, aka TROVE-2026-008.
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2026-44599
|
2026-05-8 02:31 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1816
|
5.3 |
MEDIUM
Network
|
torproject
|
tor
|
Tor before 0.4.9.7 mishandles accounting of the conflux out-of-order queue during the clearing of a queue, aka TROVE-2026-010.
|
CWE-696
Incorrect Behavior Order
|
CVE-2026-44600
|
2026-05-8 02:26 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1817
|
9.1 |
CRITICAL
Network
|
torproject
|
tor
|
Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.
|
CWE-193
Off-by-one Error
|
CVE-2026-44603
|
2026-05-8 02:24 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1818
|
8.8 |
HIGH
Local
|
-
|
-
|
NanoClaw version 1.2.0 and prior contains a host/container filesystem boundary vulnerability in outbound attachment handling and outbox cleanup that allows a compromised or prompt-injected container …
|
CWE-22
Path Traversal
|
CVE-2026-7875
|
2026-05-8 02:15 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1819
|
5.3 |
MEDIUM
Network
|
kazuho
|
starlet
|
Starlet versions through 0.31 for Perl allows HTTP Request Smuggling via Improper Header Precedence.
Starlet incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both head…
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-40561
|
2026-05-8 02:15 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1820
|
6.3 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.22 contains a time-of-check/time-of-use race condition in the OpenShell filesystem bridge that allows attackers to read files outside the intended mount root. Attackers can exp…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-44113
|
2026-05-8 02:08 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|