boxscore/security
Wednesday, May 27, 2026 · all times UTC← 2026-05-26 · archive · 2026-05-28 →

Edition of May 27, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–715 of 715
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-458677.86.1LinuxLinuxCWE-416power: supply: act8945a: Fix use-after-free in power_supply_changed()
CVE-2026-62687.16.0UnknownEventPressCWE-79EventPress < 22.2 – Reflected Cross-Site Scripting
CVE-2026-458555.56.1LinuxLinuxata: libata-scsi: avoid Non-NCQ command starvation
CVE-2026-458537.86.0LinuxLinuxCWE-787drm/amdgpu: Use kvfree instead of kfree in amdgpu_gmc_get_nps_memranges()
CVE-2026-458617.86.0LinuxLinuxCWE-416gfs2: Fix slab-use-after-free in qd_put
CVE-2026-459897.86.0LinuxLinuxCWE-416of: unittest: fix use-after-free in testdrv_probe()
CVE-2026-458715.56.0LinuxLinuxtpm: st33zp24: Fix missing cleanup on get_burstcount() error
CVE-2026-459185.55.9LinuxLinuxCWE-476ovpn: tcp - don't deref NULL sk_socket member after tcp_close()
CVE-2026-460195.55.9LinuxLinuxCWE-401crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup
CVE-2026-464244.26.0BudibasebudibaseCWE-269Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows R…
CVE-2026-458967.85.8LinuxLinuxCWE-129mtd: intel-dg: Fix accessing regions before setting nregions
CVE-2026-459097.85.8LinuxLinuxclk: mediatek: Drop __initconst from gates
CVE-2026-459475.55.9LinuxLinuxCWE-401drm/amdgpu: Fix memory leak in amdgpu_acpi_enumerate_xcc()
CVE-2026-389315.45.9n/an/aCWE-79A stored cross-site scripting (XSS) vulnerability in the /admin/config-module…
CVE-2026-490474.35.8DearHiveDearFlipCWE-862WordPress DearFlip plugin <= 2.4.27 - Broken Access Control vulnerability
CVE-2026-458667.85.6LinuxLinuxCWE-416serial: caif: fix use-after-free in caif_serial ldisc_close()
CVE-2026-458797.85.6LinuxLinuxCWE-416power: supply: bq25980: Fix use-after-free in power_supply_changed()
CVE-2026-458857.85.6LinuxLinuxCWE-416power: supply: cpcap-battery: Fix use-after-free in power_supply_changed()
CVE-2026-459027.85.6LinuxLinuxCWE-416power: supply: bq256xx: Fix use-after-free in power_supply_changed()
CVE-2026-459167.85.6LinuxLinuxCWE-416power: supply: sbs-battery: Fix use-after-free in power_supply_changed()
CVE-2026-459467.85.6LinuxLinuxCWE-416power: supply: ab8500: Fix use-after-free in power_supply_changed()
CVE-2025-713045.55.7LinuxLinuxsmack: /smack/doi: accept previously used values
CVE-2025-713055.55.7LinuxLinuxdrm/display/dp_mst: Add protection against 0 vcpi
CVE-2026-458475.55.7LinuxLinuxCWE-617net: remove WARN_ON_ONCE when accessing forward path array
CVE-2026-458485.55.7LinuxLinuxCWE-476apparmor: fix NULL sock in aa_sock_file_perm
CVE-2026-458505.55.7LinuxLinuxipvs: skip ipv6 extension headers for csum checks
CVE-2026-458575.55.7LinuxLinuxCWE-476scsi: csiostor: Fix dereference of null pointer rn
CVE-2026-458695.55.7LinuxLinuxCWE-476power: supply: wm97xx: Fix NULL pointer dereference in power_supply_changed()
CVE-2026-458705.55.7LinuxLinuxCWE-401SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths
CVE-2026-458735.55.7LinuxLinuxnetfilter: nft_set_rbtree: check for partial overlaps in anonymous sets
CVE-2026-458775.55.7LinuxLinuxCWE-476HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients
CVE-2026-458865.55.7LinuxLinuxCWE-908bpf: Fix bpf_xdp_store_bytes proto for read-only arg
CVE-2026-458925.55.7LinuxLinuxext4: drop extent cache after doing PARTIAL_VALID1 zeroout
CVE-2026-458995.55.7LinuxLinuxext4: drop extent cache when splitting extent fails
CVE-2026-459155.55.7LinuxLinuxfat: avoid parent link count underflow in rmdir
CVE-2026-459235.55.7LinuxLinuxnet: usb: catc: enable basic endpoint checking
CVE-2026-459485.55.7LinuxLinuxCWE-401ext4: fix memory leak in ext4_ext_shift_extents()
CVE-2026-459625.55.7LinuxLinuxublk: Validate SQE128 flag before accessing the cmd
CVE-2026-459645.55.7LinuxLinuxCWE-401SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path
CVE-2026-459655.55.7LinuxLinuxCWE-476apparmor: fix invalid deref of rawdata when export_binary is unset
CVE-2026-458827.85.5LinuxLinuxCWE-416power: supply: pm8916_bms_vm: Fix use-after-free in power_supply_changed()
CVE-2026-458517.15.6LinuxLinuxCWE-125efi: Fix reservation of unaccepted memory table
CVE-2026-450227.05.6go-gitgo-gitCWE-180go-git: Improper parsing of specially crafted objects may lead to inconsisten…
CVE-2026-458585.55.6LinuxLinuxext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1
CVE-2026-458845.55.6LinuxLinuxCWE-191apparmor: avoid per-cpu hold underflow in aa_get_buffer
CVE-2026-458885.55.6LinuxLinuxCWE-401md/raid1: fix memory leak in raid1_run()
CVE-2026-458955.55.6LinuxLinuxquota: fix livelock between quotactl and freeze_super
CVE-2026-459135.55.6LinuxLinuxnet: bridge: mcast: always update mdb_n_entries for vlan contexts
CVE-2026-459225.55.6LinuxLinuxCWE-401RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler
CVE-2026-459255.55.6LinuxLinuxthermal/of: Fix reference leak in thermal_of_cm_lookup()
CVE-2026-459735.55.6LinuxLinuxRDMA/mlx5: Fix UMR hang in LAG error state unload
CVE-2026-460005.55.6LinuxLinuxrxrpc: Fix conn-level packet handling to unshare RESPONSE packets
CVE-2026-447138.85.4mcdopepam_usbCWE-78pam_usb: Command injection via $TMUX environment variable leads to RCE as root
CVE-2026-459405.55.4LinuxLinuxnet: stmmac: fix oops when split header is enabled
CVE-2026-459297.85.4LinuxLinuxCWE-416ovpn: fix possible use-after-free in ovpn_net_xmit
CVE-2026-459037.15.4LinuxLinuxCWE-125bpf: Fix memory access flags in helper prototypes
CVE-2026-65656.45.3analogwpStyle Kits for ElementorCWE-79Style Kits – Advanced Theme Styles for Elementor <= 2.5.0 - Authenticated (Co…
CVE-2026-87026.45.3garberGBI To PrintCWE-79GBI To Print <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scriptin…
CVE-2026-458645.55.2LinuxLinuxCWE-835fs/ntfs3: prevent infinite loops caused by the next valid being the same
CVE-2026-458655.55.2LinuxLinuxmctp i2c: initialise event handler read bytes
CVE-2026-458685.55.2LinuxLinuxpinctrl: single: fix refcount leak in pcs_add_gpio_func()
CVE-2026-458815.55.2LinuxLinuxCWE-401soc: mediatek: svs: Fix memory leak in svs_enable_debug_write()
CVE-2026-458835.55.2LinuxLinuxCWE-401iio: sca3000: Fix a resource leak in sca3000_probe()
CVE-2026-459045.55.2LinuxLinuxCWE-674powerpc/eeh: fix recursive pci_lock_rescan_remove locking in EEH event handling
CVE-2026-459115.55.2LinuxLinuxCWE-476usb: cdns3: fix role switching during resume
CVE-2026-458635.55.2LinuxLinuxCWE-401i3c: dw: Fix memory leak in dw_i3c_master_i2c_xfers()
CVE-2026-458745.55.2LinuxLinuxCWE-476phy: freescale: imx8qm-hsio: fix NULL pointer dereference
CVE-2026-458805.55.2LinuxLinuxPCI/P2PDMA: Release per-CPU pgmap ref when vm_insert_page() fails
CVE-2026-458975.55.2LinuxLinuxnetfilter: nft_counter: serialize reset with spinlock
CVE-2026-459005.55.2LinuxLinuxCWE-401crypto: caam - fix netdev memory leak in dpaa2_caam_probe
CVE-2026-459015.55.2LinuxLinuxnetfilter: nf_tables: revert commit_mutex usage in reset path
CVE-2026-447128.25.1mcdopepam_usbCWE-78pam_usb: Shell injection via device UUID and username in pamusb-conf and pamu…
CVE-2026-22546.35.0Hitachi VantaraPentaho Data Integration and AnalyticsCWE-732Hitachi Vantara Pentaho Data Integration & Analytics - Incorrect Permission A…
CVE-2026-458545.55.0LinuxLinuxcrypto: inside-secure/eip93 - unregister only available algorithm
CVE-2026-458765.55.0LinuxLinuxCWE-476arm64/gcs: Fix error handling in arch_set_shadow_stack_status()
CVE-2026-458875.55.0LinuxLinuxCWE-401af_unix: Fix memleak of newsk in unix_stream_connect().
CVE-2026-458895.55.0LinuxLinuxCWE-369mptcp: do not account for OoO in mptcp_rcvbuf_grow()
CVE-2026-459085.55.0LinuxLinuxCWE-401accel/amdxdna: Fix memory leak in amdxdna_ubuf_map
CVE-2026-427387.14.8ZAYTECHSmart Online Order for CloverCWE-79WordPress Smart Online Order for Clover plugin <= 1.6.0 - Cross Site Scriptin…
CVE-2026-427397.14.8IniLermAdvanced IP BlockerCWE-79WordPress Advanced IP Blocker plugin <= 8.10.7 - Cross Site Scripting (XSS) v…
CVE-2026-427597.14.8TimoAffiliate Super AssistentCWE-79WordPress Affiliate Super Assistent plugin <= 1.10.1 - Cross Site Scripting (…
CVE-2026-490524.34.9WpmetElementsKit Elementor addons LiteCWE-862WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access C…
CVE-2026-36237.84.8IBMNetezza Performance Server Replication ServicesCWE-250Vulnerabilities exists in IBM Netezza Performance Server Replication Services
CVE-2026-447097.84.8mcdopepam_usbCWE-78pam_usb: PINENTRY_FALLBACK_APP environment variable allows arbitrary command …
CVE-2025-713067.14.7LinuxLinuxCWE-125ima: Fix stack-out-of-bounds in is_bprm_creds_for_exec()
CVE-2026-460557.14.7LinuxLinuxapparmor: Fix string overrun due to missing termination
CVE-2026-453355.44.7LabRedesCefetRJWeGIACWE-601WeGIA: Middleware whitelist bypass → open redirect via InternoControle.nextPage
CVE-2026-458627.84.6LinuxLinuxiommu/vt-d: Flush cache for PASID table before using it
CVE-2026-458947.84.6LinuxLinuxiommu/vt-d: Clear Present bit before tearing down PASID entry
CVE-2026-459357.84.6LinuxLinuxCWE-125fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot
CVE-2026-480656.74.6mcdopepam_usbCWE-122pam_usb: Unchecked integer multiplication before xmalloc() in conf.c allows h…
CVE-2026-444756.14.5ellanetworkscoreCWE-358Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest
CVE-2026-217854.04.6HCLSoftwareBigFix Remote Control ServerCWE-1021HCL BigFix Remote Control Server WebUI is affected by a misconfigured Content…
CVE-2026-460297.04.4LinuxLinuxmm/slab: return NULL early from kmalloc_nolock() in NMI on UP
CVE-2026-459207.84.4LinuxLinuxCWE-415ext4: fix dirtyclusters double decrement on fs shutdown
CVE-2026-457185.44.4BudibasebudibaseCWE-863Budibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allow…
CVE-2026-96744.34.4Jenkins ProjectJenkins Multijob PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin …
CVE-2026-460227.14.3LinuxLinuxCWE-125misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt()
CVE-2026-89116.14.3godlessonsWP AutoBuzzCWE-352WP AutoBuzz <= 1.1.1 - Cross-Site Request Forgery to Stored Cross-Site Script…
CVE-2026-460067.84.1LinuxLinuxCWE-787drm/nouveau: fix u32 overflow in pushbuf reloc bounds check
CVE-2026-459615.54.1LinuxLinuxCWE-401gfs2: fix memory leaks in gfs2_fill_super error path
CVE-2026-460627.84.0LinuxLinuxCWE-190ntfs3: fix integer overflow in run_unpack() volume boundary check
CVE-2026-427627.14.0e4jvikwpVikBooking Hotel Booking Engine & PMSCWE-79WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.9 - Cross Site …
CVE-2026-459935.54.0LinuxLinuxLoongArch: Add spectre boundry for syscall dispatch table
CVE-2026-461007.83.9LinuxLinuxfs: afs: revert mmap_prepare() change
CVE-2026-472746.34.0mcdopepam_usbCWE-427pam_usb: Uncontrolled search path in pam_usb tools allows privilege escalatio…
CVE-2026-89384.33.9nakamura1458auto making JSON-LDCWE-352auto making JSON-LD <= 4.5.3 - Cross-Site Request Forgery to Plugin Certifica…
CVE-2026-89394.33.9simonailieSearch Simple FieldsCWE-352Search Simple Fields <= 0.2 - Cross-Site Request Forgery to Plugin Settings U…
CVE-2026-89414.33.9wmarkCDN Linker liteCWE-352CDN Linker lite <= 1.3.1 - Cross-Site Request Forgery to Plugin Settings Update
CVE-2026-89434.33.9rchmuraGoStats for WordPressCWE-352GoStats for WordPress <= 1.4 - Cross-Site Request Forgery via gostats_manage(…
CVE-2023-529457.83.8SynologyBeeDrive for desktopCWE-427Uncontrolled search path element vulnerability in OpenSSL DLL component in Sy…
CVE-2026-459967.83.8LinuxLinuxCWE-416spi: imx: fix use-after-free on unbind
CVE-2026-460367.83.7LinuxLinuxCWE-416vfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex
CVE-2026-460697.83.8LinuxLinuxCWE-416wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup()
CVE-2026-459947.13.8LinuxLinuxCWE-125ibmasm: fix OOB reads in command_file_write due to missing size checks
CVE-2026-460647.13.8LinuxLinuxCWE-125ibmasm: fix heap over-read in ibmasm_send_i2o_message()
CVE-2026-89034.33.7youtagTwo-factor authentication (formerly IP Vault)CWE-352Two-factor authentication (formerly IP Vault) <= 2.1 - Cross-Site Request For…
CVE-2026-460795.53.7LinuxLinuxCWE-476rbd: fix null-ptr-deref when device_add_disk() fails
CVE-2026-460977.83.6LinuxLinuxCWE-416Input: edt-ft5x06 - fix use-after-free in debugfs teardown
CVE-2025-713075.53.6LinuxLinuxCWE-476drm/panthor: Fix NULL pointer dereference on panthor_fw_unplug
CVE-2025-713085.53.6LinuxLinuxCWE-476accel/amdxdna: Fix potential NULL pointer dereference in context cleanup
CVE-2025-713125.53.6LinuxLinuxCWE-401fs/ntfs3: fix ntfs_mount_options leak in ntfs_fill_super()
CVE-2026-450275.93.5LabRedesCefetRJWeGIACWE-759WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/logi…
CVE-2025-687125.53.5n/an/aCWE-285SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local atta…
CVE-2026-458495.53.5LinuxLinuxCWE-667net: mscc: ocelot: add missing lock protection in ocelot_port_xmit_inj()
CVE-2026-460805.53.5LinuxLinuxocfs2: split transactions in dio completion to avoid credit exhaustion
CVE-2026-460925.53.5LinuxLinuxCWE-476wifi: rtw88: check for PCI upstream bridge existence
CVE-2026-460345.53.5LinuxLinuxCWE-476vfio/cdx: Fix NULL pointer dereference in interrupt trigger path
CVE-2026-460415.53.5LinuxLinuxgreybus: gb-beagleplay: fix sleep in atomic context in hdlc_tx_frames()
CVE-2026-460895.53.5LinuxLinuxzram: do not forget to endio for partial discard requests
CVE-2026-459458.83.4LinuxLinuxCWE-362iommu/vt-d: Fix race condition during PASID entry replacement
CVE-2026-459327.33.3LinuxLinuxbpf: Fix tcx/netkit detach permissions when prog fd isn't given
CVE-2026-444743.73.3ellanetworkscoreCWE-358Ella Core: Handover failures during concurrent Security Mode Command
CVE-2026-408518.43.3MB connect linembNET/mbNET.rokeyCWE-1287Command injection via USB
CVE-2026-458397.83.3LinuxLinuxCWE-129bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec()
CVE-2026-459905.53.3LinuxLinuxCWE-190slub: fix data loss and overflow in krealloc()
CVE-2026-459987.83.2LinuxLinuxCWE-416rxrpc: Fix potential UAF after skb_unshare() failure
CVE-2026-460215.53.2LinuxLinuxCWE-401thermal: core: Fix thermal zone governor cleanup issues
CVE-2026-459997.13.2LinuxLinuxCWE-191erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap()
CVE-2026-460787.13.2LinuxLinuxCWE-125erofs: fix the out-of-bounds nameoff handling for trailing dirents
CVE-2026-460745.53.2LinuxLinuxCWE-401spi: ch341: fix memory leaks on probe failures
CVE-2026-26075.13.1IBMMQ OperatorCWE-532Multiple vulnerabilities in IBM MQ Operator and Queue manager container images
CVE-2026-427506.53.1NexcessWPCompleteCWE-79WordPress WPComplete plugin <= 2.9.5.4 - Cross Site Scripting (XSS) vulnerabi…
CVE-2026-427516.53.1wpdevelopBooking ManagerCWE-79WordPress Booking Manager plugin <= 2.1.18 - Cross Site Scripting (XSS) vulne…
CVE-2026-459195.53.1LinuxLinuxCWE-835sched/rt: Skip currently executing CPU in rto_next_cpu()
CVE-2026-459685.53.1LinuxLinuxCWE-476cpuidle: Skip governor when only one idle state is available
CVE-2026-459825.53.1LinuxLinuxCWE-476ACPICA: Fix NULL pointer dereference in acpi_ev_address_space_dispatch()
CVE-2026-460235.53.1LinuxLinuxCWE-190dm mirror: fix integer overflow in create_dirty_log()
CVE-2026-471045.13.1libusblibusbCWE-125libusb < 1.0.30 Out-of-Bounds Read in parse_iad_array()
CVE-2026-458917.83.0LinuxLinuxCWE-415net: hns3: fix double free issue for tx spare buffer
CVE-2026-460017.82.9LinuxLinuxCWE-787hwmon: (pt5161l) Fix bugs in pt5161l_read_block_data()
CVE-2026-460047.83.0LinuxLinuxCWE-416ALSA: caiaq: Handle probe errors properly
CVE-2026-460157.83.0LinuxLinuxtcp: call sk_data_ready() after listener migration
CVE-2026-460537.83.0LinuxLinuxnet: rds: fix MR cleanup on copy error
CVE-2026-460657.83.0LinuxLinuxCWE-401fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info
CVE-2026-460687.82.9LinuxLinuxCWE-787crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx
CVE-2026-460757.83.0LinuxLinuxCWE-416crypto: atmel-sha204a - Fix potential UAF and memory leak in remove path
CVE-2026-460847.82.9LinuxLinuxCWE-416RDMA/mana_ib: Disable RX steering on RSS QP destroy
CVE-2026-460937.82.9LinuxLinuxmm/vmalloc: take vmap_purge_lock in shrinker
CVE-2026-460337.13.0LinuxLinuxCWE-125crypto: authencesn - reject short ahash digests during instance creation
CVE-2026-458405.53.0LinuxLinuxopenvswitch: cap upcall PID array size and pre-size vport replies
CVE-2026-458445.53.0LinuxLinuxnetfilter: arp_tables: fix IEEE1394 ARP payload parsing
CVE-2026-459305.52.9LinuxLinuxnet: mctp: ensure our nlmsg responses are initialised
CVE-2026-459745.52.9LinuxLinuxbtrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found
CVE-2026-460055.52.9LinuxLinuxCWE-401xfs: fix a resource leak in xfs_alloc_buftarg()
CVE-2026-460265.52.9LinuxLinuxnet: qrtr: ns: Limit the maximum number of lookups
CVE-2026-487924.42.9mcdopepam_usbCWE-390pam_usb: pusb_has_virtual_input_device() silently discards EACCES, disabling …
CVE-2026-76144.32.9mkhfrOld Posts HighlighterCWE-352Old Posts Highlighter <= 1.0.3 - Cross-Site Request Forgery to Settings Update
CVE-2026-87084.32.9shraGenzel breadcrumbsCWE-352Genzel breadcrumbs <= 1.2 - Cross-Site Request Forgery to Settings Update via…
CVE-2026-92364.32.9creativemindssolutionsCM Ad Changer – A simple tool to control and optimize your site's bannersCWE-352CM Ad Changer <= 2.0.7 - Cross-Site Request Forgery to Campaign Deletion via …
CVE-2026-459597.82.8LinuxLinuxCWE-476crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree
CVE-2026-460457.82.8LinuxLinuxCWE-787md/md-llbitmap: skip reading rdevs that are not in_sync
CVE-2026-459447.52.8LinuxLinuxiommu/vt-d: Clear Present bit before tearing down context entry
CVE-2025-156495.52.8PMQSIO::Uncompress::UnzipCWE-248IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught excep…
CVE-2026-458385.52.7LinuxLinuxCWE-476bpf: fix end-of-list detection in cgroup_storage_get_next_key()
CVE-2026-458415.52.7LinuxLinuxCWE-369netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO
CVE-2026-458425.52.7LinuxLinuxCWE-476slip: reject VJ receive packets on instances with no rstate array
CVE-2026-458465.52.8LinuxLinuxCWE-476bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst()
CVE-2026-459285.52.8LinuxLinuxCWE-401media: chips-media: wave5: Fix memory leak on codec_info allocation failure
CVE-2026-459147.82.7LinuxLinuxCWE-416Revert "hwmon: (ibmpex) fix use-after-free in high/low store"
CVE-2026-459367.82.7LinuxLinuxCWE-416power: supply: goldfish: Fix use-after-free in power_supply_changed()
CVE-2026-459567.82.7LinuxLinuxCWE-416drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl()
CVE-2026-459707.82.7LinuxLinuxCWE-416bonding: alb: fix UAF in rlb_arp_recv during bond up/down
CVE-2026-460477.82.7LinuxLinuxCWE-416net: qrtr: ns: Fix use-after-free in driver remove()
CVE-2026-459587.12.7LinuxLinuxCWE-476drm/exynos: vidi: fix to avoid directly dereferencing user pointer
CVE-2026-460707.12.7LinuxLinuxCWE-787md/raid5: validate payload size before accessing journal metadata
CVE-2026-459525.52.7LinuxLinuxeth: fbnic: Add validation for MTU changes
CVE-2026-459815.52.7LinuxLinuxCWE-401s390/cio: Fix device lifecycle handling in css_alloc_subchannel()
CVE-2026-460425.52.7LinuxLinuxCWE-401mm/mempolicy: fix memory leaks in weighted_interleave_auto_store()
CVE-2026-459387.82.6LinuxLinuxCWE-416power: supply: pm8916_lbc: Fix use-after-free in power_supply_changed()
CVE-2026-460117.82.6LinuxLinuxCWE-416media: mtk-jpeg: fix use-after-free in release path due to uncancelled work
CVE-2026-458937.12.6LinuxLinuxCWE-125apparmor: Fix & Optimize table creation from possibly unaligned memory
CVE-2026-459437.12.6LinuxLinuxCWE-125erofs: fix inline data read failure for ztailpacking pclusters
CVE-2026-459577.12.6LinuxLinuxCWE-125rcu: Fix rcu_read_unlock() deadloop due to softirq
CVE-2026-460947.12.6LinuxLinuxCWE-125ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access
CVE-2026-459517.82.5LinuxLinuxCWE-416bpf: Fix a potential use-after-free of BTF object
CVE-2026-459807.82.5LinuxLinuxCWE-416accel/amdxdna: Stop job scheduling across aie2_release_resource()
CVE-2026-459557.12.5LinuxLinuxmd/md-llbitmap: fix percpu_ref not resurrected on suspend timeout
CVE-2026-460207.12.5LinuxLinuxCWE-125mm/damon/core: validate damos_quota_goal->nid for node_mem_{used,free}_bp
CVE-2026-89424.32.5lhughes33472MetaMagic SEO PluginCWE-352MetaMagic SEO Plugin <= 1.6 - Cross-Site Request Forgery to Plugin Settings U…
CVE-2026-460547.12.5LinuxLinuxCWE-280selinux: fix overlayfs mmap() and mprotect() access checks
CVE-2026-458905.52.4LinuxLinuxxen-netback: reject zero-queue configuration from guest
CVE-2026-459125.52.4LinuxLinuxext4: don't cache extent during splitting extent
CVE-2026-459415.52.5LinuxLinuxCWE-401tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure
CVE-2026-459605.52.4LinuxLinuxhfsplus: return error when node already exists in hfs_bnode_create
CVE-2026-459695.52.4LinuxLinuxCWE-476HID: playstation: Add missing check for input_ff_create_memless
CVE-2026-459785.52.4LinuxLinuxCWE-476staging: greybus: lights: avoid NULL deref
CVE-2026-459835.52.4LinuxLinuxnfsd: never defer requests during idmap lookup
CVE-2026-459855.52.4LinuxLinuxext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O
CVE-2026-459865.52.4LinuxLinuxCWE-401crypto: ccree - fix a memory leak in cc_mac_digest()
CVE-2026-459875.52.4LinuxLinuxKVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2
CVE-2026-459975.52.4LinuxLinuxscsi: sd: fix missing put_disk() when device_add(&disk_dev) fails
CVE-2026-460025.52.4LinuxLinuxext2: reject inodes with zero i_nlink and valid mode in ext2_iget()
CVE-2026-460035.52.4LinuxLinuxnet: qrtr: ns: Limit the total number of nodes
CVE-2026-460095.52.4LinuxLinuxPCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown
CVE-2026-460285.52.5LinuxLinuxcrypto: algif_aead - snapshot IV for async AEAD requests
CVE-2026-460385.52.4LinuxLinuxCWE-401net: qrtr: ns: Free the node during ctrl_cmd_bye()
CVE-2026-460405.52.4LinuxLinuxinotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails
CVE-2026-460445.52.4LinuxLinuxipmi:ssif: Clean up kthread on errors
CVE-2026-460465.52.4LinuxLinuxext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all()
CVE-2026-460485.52.4LinuxLinuxALSA: caiaq: fix usb_dev refcount leak on probe failure
CVE-2026-460495.52.4LinuxLinuxALSA: ctxfi: Add fallback to default RSR for S/PDIF
CVE-2026-460725.52.4LinuxLinuxntfs3: add buffer boundary checks to run_unpack()
CVE-2026-460775.52.4LinuxLinuxcrypto: atmel-tdes - fix DMA sync direction
CVE-2026-460825.52.4LinuxLinuxKVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0
CVE-2026-460835.52.4LinuxLinuxCWE-401spi: fix resource leaks on device setup failure
CVE-2026-460865.52.4LinuxLinuxCWE-476net: bridge: use a stable FDB dst snapshot in RCU readers
CVE-2026-460885.52.4LinuxLinuxALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_na…
CVE-2026-460915.52.4LinuxLinuxmedia: rc: igorplugusb: heed coherency rules
CVE-2026-460985.52.4LinuxLinuxCWE-476net: caif: clear client service pointer on teardown
CVE-2026-461015.52.4LinuxLinuxnetfilter: reject zero shift in nft_bitwise
CVE-2026-73657.82.4IBMOperations Analytics - Log AnalysisCWE-1392IBM Operations Analytics - Log Analysis is affected by Information disclosure…
CVE-2026-459175.52.4LinuxLinuxipvs: do not keep dest_dst if dev is going down
CVE-2026-459215.52.4LinuxLinuxCWE-401mtd: parsers: Fix memory leak in mtd_parser_tplink_safeloader_parse()
CVE-2026-459505.52.4LinuxLinuxCWE-401crypto: starfive - Fix memory leak in starfive_aes_aead_do_one_req()
CVE-2026-459545.52.4LinuxLinuxCWE-401fbdev: au1200fb: Fix a memory leak in au1200fb_drv_probe()
CVE-2026-459765.52.3LinuxLinuxCWE-401drm/amdgpu: Fix memory leak in amdgpu_ras_init()
CVE-2026-460075.52.3LinuxLinuxhwmon: (powerz) Avoid cacheline sharing for DMA buffer
CVE-2026-460125.52.3LinuxLinuxCWE-401rxrpc: Fix memory leaks in rxkad_verify_response()
CVE-2026-460165.52.4LinuxLinuxCWE-476remoteproc: xlnx: Only access buffer information if IPI is buffered
CVE-2026-460735.52.4LinuxLinuxhwmon: (powerz) Fix missing usb_kill_urb() on signal interrupt
CVE-2026-472715.12.4mcdopepam_usbCWE-476pam_usb: OOM guards removed by -DNDEBUG cause NULL dereference and authentica…
CVE-2026-460767.92.3LinuxLinuxKVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1
CVE-2026-490007.02.3ZTEZXUniPOS NDS-LTECWE-310Cryptography Implementation Flaw vulnerability in ZTE ZXUniPOS NDS-LTE product
CVE-2026-459345.52.2LinuxLinuxbtrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation
CVE-2026-459375.52.2LinuxLinuxcrypto: inside-secure/eip93 - fix kernel panic in driver detach
CVE-2026-459395.52.2LinuxLinuxCWE-401gpib: Fix memory leak in ni_usb_init()
CVE-2026-459535.52.2LinuxLinuxmd/raid5: fix IO hang with degraded array with llbitmap
CVE-2026-459665.52.2LinuxLinuxCWE-476apparmor: fix NULL pointer dereference in __unix_needs_revalidation
CVE-2026-459715.52.2LinuxLinuxbpf: Limit bpf program signature size
CVE-2026-459775.52.2LinuxLinuxfbnic: close fw_log race between users and teardown
CVE-2026-460305.52.2LinuxLinuxCWE-401EDAC/versalnet: Fix device_node leak in mc_probe()
CVE-2026-460355.52.3LinuxLinuxmm/page_alloc: return NULL early from alloc_frozen_pages_nolock() in NMI on UP
CVE-2026-460595.52.2LinuxLinuxKVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN
CVE-2026-460605.52.2LinuxLinuxcrypto: qat - fix IRQ cleanup on 6xxx probe failure
CVE-2026-460665.52.2LinuxLinuxCWE-193ceph: fix num_ops off-by-one when crypto allocation fails
CVE-2026-460715.52.2LinuxLinuxKVM: nSVM: Avoid clearing VMCB_LBR in vmcb12
CVE-2026-460875.52.2LinuxLinuxCWE-401mm/damon/stat: fix memory leak on damon_start() failure in damon_stat_start()
CVE-2026-460955.52.3LinuxLinuxmd/md-llbitmap: raise barrier before state machine transition
CVE-2026-460965.52.2LinuxLinuxtpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public()
CVE-2026-459067.82.2LinuxLinuxCWE-416power: supply: pf1550: Fix use-after-free in power_supply_changed()
CVE-2026-459957.82.2LinuxLinuxCWE-416io_uring/zcrx: fix user_struct uaf
CVE-2026-423286.22.2ipldgo-ipld-primeCWE-674go-ipld-prime: DAG-CBOR and DAG-JSON decoders unbounded recursion depth
CVE-2026-458455.52.1LinuxLinuxCWE-476net/sched: taprio: fix NULL pointer dereference in class dump
CVE-2026-459245.52.2LinuxLinuxCWE-667ksmbd: call ksmbd_vfs_kern_path_end_removing() on some error paths
CVE-2026-472727.12.0mcdopepam_usbCWE-287pam_usb: OTP pad authentication bypass via missing system pad check and unini…
CVE-2026-89066.12.1rahulbhangaleWP PromoterCWE-352WP Promoter <= 1.3 - Cross-Site Request Forgery to Stored Cross-Site Scriptin…
CVE-2026-459075.52.0LinuxLinuxCWE-667net/mlx5e: Fix deadlocks between devlink and netdev instance locks
CVE-2026-460573.32.0LinuxLinuxlandlock: Fix LOG_SUBDOMAINS_OFF inheritance across fork()
CVE-2026-460677.12.0LinuxLinuxCWE-125mm/damon/core: validate damos_quota_goal->nid for node_memcg_{used,free}_bp
CVE-2026-458377.81.9LinuxLinuxCWE-416bpf: Fix use-after-free in arena_vm_close on fork
CVE-2026-480665.71.9mcdopepam_usbCWE-362pam_usb: Thread-unsafe static pointer in log.c causes data race under concurr…
CVE-2026-459635.51.9LinuxLinuxCWE-476ASoC: nau8821: Cancel delayed work on component remove
CVE-2026-460325.51.9LinuxLinuxKVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT
CVE-2026-481476.51.8BudibasebudibaseCWE-185Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query Stri…
CVE-2026-461035.51.7LinuxLinuxCWE-401can: ucan: fix devres lifetime
CVE-2026-449725.01.6DataDogguarddogCWE-116GuardDog: Unsanitized human-readable scan output allows terminal escape injec…
CVE-2024-113996.81.6SynologyBeeDrive for desktopCWE-552Files or directories accessible to external parties vulnerability in redis-se…
CVE-2026-459265.51.6LinuxLinuxCWE-401rust: pwm: Fix potential memory leak on init error
CVE-2026-459054.71.6LinuxLinuxCWE-362xfrm: fix ip_rt_bug race in icmp_route_lookup reverse path
CVE-2026-490015.31.4ZTEZXUniPOS NDS-LTECWE-352Cross-Site Request Forgery (CSRF) vulnerability in ZTE ZXUniPOS NDS-LTE product
CVE-2026-472706.31.4mcdopepam_usbCWE-362pam_usb: strtok() race condition in multi-threaded PAM hosts can corrupt deny…
CVE-2026-459675.51.3LinuxLinuxbpf: Return proper address for non-zero offsets in insn array
CVE-2026-459755.51.3LinuxLinuxublk: use READ_ONCE() to read struct ublksrv_ctrl_cmd
CVE-2026-459795.51.3LinuxLinuxdrm/amdgpu: clean up the amdgpu_cs_parser_bos
CVE-2026-460135.51.3LinuxLinuxmm/memfd_luo: fix physical address conversion in put_folios cleanup
CVE-2025-713095.51.3LinuxLinuxCWE-667fs/ntfs3: fix deadlock in ni_read_folio_cmpr
CVE-2026-450465.51.3safedepgryphCWE-212Gryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive Content
CVE-2026-460174.71.2LinuxLinuxCWE-362mm: fix deferred split queue races during migration
CVE-2026-489254.31.2Jenkins ProjectJenkins GitHub Integration PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integrati…
CVE-2026-460907.81.1LinuxLinuxCWE-416ALSA: aloop: Fix peer runtime UAF during format-change stop
CVE-2026-459107.81.1LinuxLinuxCWE-362RDMA/rxe: Fix race condition in QP timer handlers
CVE-2026-490147.81.1GDALGDALCWE-121In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver …
CVE-2025-713034.71.1LinuxLinuxCWE-362accel/amdxdna: Fix race condition when checking rpm_on
CVE-2026-55155.51.0IBMApp Connect EnterpriseCWE-922IBM App Connect Enterprise is vulnerable to a confidential disclosure
CVE-2026-459427.80.9LinuxLinuxCWE-362ext4: fix e4b bitmap inconsistency reports
CVE-2026-410094.30.9Cloud Foundry FoundationBOSH DirectorCWE-22Local Blobstore may allow arbitrary reads/deletes
CVE-2026-60535.50.9IBMDb2CWE-770IBM® Db2® is vulnerable to a denial of service when a specially crafted query…
CVE-2026-460587.80.9LinuxLinuxCWE-362media: amphion: Fix race between m2m job_abort and device_run
CVE-2026-304986.30.9n/an/aCWE-352A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delet…
CVE-2026-460505.50.7LinuxLinuxCWE-667md/raid10: fix deadlock with check operation and nowait requests
CVE-2026-460515.50.7LinuxLinuxCWE-667md/raid5: fix soft lockup in retry_aligned_read()
CVE-2026-460615.50.7LinuxLinuxCWE-667jbd2: fix deadlock in jbd2_journal_cancel_revoke()
CVE-2026-460635.50.7LinuxLinuxCWE-667x86/shstk: Prevent deadlock during shstk sigreturn
CVE-2026-460145.50.7LinuxLinuxCWE-667KVM: SVM: Add missing save/restore handling of LBR MSRs
CVE-2026-22375.50.6SynologyStorage ManagerCWE-598A use of get request method with sensitive query strings vulnerability in vol…
CVE-2026-97595.50.6Wireshark FoundationWiresharkCWE-476NULL Pointer Dereference in Wireshark
CVE-2026-459274.70.6LinuxLinuxCWE-367bpf: Require frozen map for calculating map hash
CVE-2026-459494.70.5LinuxLinuxCWE-362hwrng: core - use RCU and work_struct to fix race condition
CVE-2026-460254.70.5LinuxLinuxCWE-362mm/damon/core: fix damon_call() vs kdamond_fn() exit race
CVE-2025-135935.60.4SynologyActiveProtect AgentCWE-346Origin validation error vulnerability in Synology ActiveProtect Agent before …
CVE-2025-665925.60.4SynologySynology Active Backup for Business AgentCWE-346An origin validation error vulnerability in Synology Active Backup for Busine…
CVE-2025-665935.60.4SynologySynology AssistantCWE-346An origin validation error vulnerability in Synology Assistant before 7.0.6-5…
CVE-2026-417046.80.3Cloud Foundry FoundationBOSH DirectorCWE-284Compromised VM can make arbitrary blobstore deletes
CVE-2026-460084.70.2LinuxLinuxCWE-362mm/damon/core: fix damos_walk() vs kdamond_fn() exit race