Edition of May 27, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-45867 | 7.8 | 6.1 | Linux | Linux | CWE-416 | power: supply: act8945a: Fix use-after-free in power_supply_changed() |
| CVE-2026-6268 | 7.1 | 6.0 | Unknown | EventPress | CWE-79 | EventPress < 22.2 – Reflected Cross-Site Scripting |
| CVE-2026-45855 | 5.5 | 6.1 | Linux | Linux | — | ata: libata-scsi: avoid Non-NCQ command starvation |
| CVE-2026-45853 | 7.8 | 6.0 | Linux | Linux | CWE-787 | drm/amdgpu: Use kvfree instead of kfree in amdgpu_gmc_get_nps_memranges() |
| CVE-2026-45861 | 7.8 | 6.0 | Linux | Linux | CWE-416 | gfs2: Fix slab-use-after-free in qd_put |
| CVE-2026-45989 | 7.8 | 6.0 | Linux | Linux | CWE-416 | of: unittest: fix use-after-free in testdrv_probe() |
| CVE-2026-45871 | 5.5 | 6.0 | Linux | Linux | — | tpm: st33zp24: Fix missing cleanup on get_burstcount() error |
| CVE-2026-45918 | 5.5 | 5.9 | Linux | Linux | CWE-476 | ovpn: tcp - don't deref NULL sk_socket member after tcp_close() |
| CVE-2026-46019 | 5.5 | 5.9 | Linux | Linux | CWE-401 | crypto: atmel-aes - Fix 3-page memory leak in atmel_aes_buff_cleanup |
| CVE-2026-46424 | 4.2 | 6.0 | Budibase | budibase | CWE-269 | Budibase: Missing Cache Invalidation on Public API Role Unassignment Allows R… |
| CVE-2026-45896 | 7.8 | 5.8 | Linux | Linux | CWE-129 | mtd: intel-dg: Fix accessing regions before setting nregions |
| CVE-2026-45909 | 7.8 | 5.8 | Linux | Linux | — | clk: mediatek: Drop __initconst from gates |
| CVE-2026-45947 | 5.5 | 5.9 | Linux | Linux | CWE-401 | drm/amdgpu: Fix memory leak in amdgpu_acpi_enumerate_xcc() |
| CVE-2026-38931 | 5.4 | 5.9 | n/a | n/a | CWE-79 | A stored cross-site scripting (XSS) vulnerability in the /admin/config-module… |
| CVE-2026-49047 | 4.3 | 5.8 | DearHive | DearFlip | CWE-862 | WordPress DearFlip plugin <= 2.4.27 - Broken Access Control vulnerability |
| CVE-2026-45866 | 7.8 | 5.6 | Linux | Linux | CWE-416 | serial: caif: fix use-after-free in caif_serial ldisc_close() |
| CVE-2026-45879 | 7.8 | 5.6 | Linux | Linux | CWE-416 | power: supply: bq25980: Fix use-after-free in power_supply_changed() |
| CVE-2026-45885 | 7.8 | 5.6 | Linux | Linux | CWE-416 | power: supply: cpcap-battery: Fix use-after-free in power_supply_changed() |
| CVE-2026-45902 | 7.8 | 5.6 | Linux | Linux | CWE-416 | power: supply: bq256xx: Fix use-after-free in power_supply_changed() |
| CVE-2026-45916 | 7.8 | 5.6 | Linux | Linux | CWE-416 | power: supply: sbs-battery: Fix use-after-free in power_supply_changed() |
| CVE-2026-45946 | 7.8 | 5.6 | Linux | Linux | CWE-416 | power: supply: ab8500: Fix use-after-free in power_supply_changed() |
| CVE-2025-71304 | 5.5 | 5.7 | Linux | Linux | — | smack: /smack/doi: accept previously used values |
| CVE-2025-71305 | 5.5 | 5.7 | Linux | Linux | — | drm/display/dp_mst: Add protection against 0 vcpi |
| CVE-2026-45847 | 5.5 | 5.7 | Linux | Linux | CWE-617 | net: remove WARN_ON_ONCE when accessing forward path array |
| CVE-2026-45848 | 5.5 | 5.7 | Linux | Linux | CWE-476 | apparmor: fix NULL sock in aa_sock_file_perm |
| CVE-2026-45850 | 5.5 | 5.7 | Linux | Linux | — | ipvs: skip ipv6 extension headers for csum checks |
| CVE-2026-45857 | 5.5 | 5.7 | Linux | Linux | CWE-476 | scsi: csiostor: Fix dereference of null pointer rn |
| CVE-2026-45869 | 5.5 | 5.7 | Linux | Linux | CWE-476 | power: supply: wm97xx: Fix NULL pointer dereference in power_supply_changed() |
| CVE-2026-45870 | 5.5 | 5.7 | Linux | Linux | CWE-401 | SUNRPC: auth_gss: fix memory leaks in XDR decoding error paths |
| CVE-2026-45873 | 5.5 | 5.7 | Linux | Linux | — | netfilter: nft_set_rbtree: check for partial overlaps in anonymous sets |
| CVE-2026-45877 | 5.5 | 5.7 | Linux | Linux | CWE-476 | HID: intel-ish-hid: fix NULL-ptr-deref in ishtp_bus_remove_all_clients |
| CVE-2026-45886 | 5.5 | 5.7 | Linux | Linux | CWE-908 | bpf: Fix bpf_xdp_store_bytes proto for read-only arg |
| CVE-2026-45892 | 5.5 | 5.7 | Linux | Linux | — | ext4: drop extent cache after doing PARTIAL_VALID1 zeroout |
| CVE-2026-45899 | 5.5 | 5.7 | Linux | Linux | — | ext4: drop extent cache when splitting extent fails |
| CVE-2026-45915 | 5.5 | 5.7 | Linux | Linux | — | fat: avoid parent link count underflow in rmdir |
| CVE-2026-45923 | 5.5 | 5.7 | Linux | Linux | — | net: usb: catc: enable basic endpoint checking |
| CVE-2026-45948 | 5.5 | 5.7 | Linux | Linux | CWE-401 | ext4: fix memory leak in ext4_ext_shift_extents() |
| CVE-2026-45962 | 5.5 | 5.7 | Linux | Linux | — | ublk: Validate SQE128 flag before accessing the cmd |
| CVE-2026-45964 | 5.5 | 5.7 | Linux | Linux | CWE-401 | SUNRPC: fix gss_auth kref leak in gss_alloc_msg error path |
| CVE-2026-45965 | 5.5 | 5.7 | Linux | Linux | CWE-476 | apparmor: fix invalid deref of rawdata when export_binary is unset |
| CVE-2026-45882 | 7.8 | 5.5 | Linux | Linux | CWE-416 | power: supply: pm8916_bms_vm: Fix use-after-free in power_supply_changed() |
| CVE-2026-45851 | 7.1 | 5.6 | Linux | Linux | CWE-125 | efi: Fix reservation of unaccepted memory table |
| CVE-2026-45022 | 7.0 | 5.6 | go-git | go-git | CWE-180 | go-git: Improper parsing of specially crafted objects may lead to inconsisten… |
| CVE-2026-45858 | 5.5 | 5.6 | Linux | Linux | — | ext4: don't zero the entire extent if EXT4_EXT_DATA_PARTIAL_VALID1 |
| CVE-2026-45884 | 5.5 | 5.6 | Linux | Linux | CWE-191 | apparmor: avoid per-cpu hold underflow in aa_get_buffer |
| CVE-2026-45888 | 5.5 | 5.6 | Linux | Linux | CWE-401 | md/raid1: fix memory leak in raid1_run() |
| CVE-2026-45895 | 5.5 | 5.6 | Linux | Linux | — | quota: fix livelock between quotactl and freeze_super |
| CVE-2026-45913 | 5.5 | 5.6 | Linux | Linux | — | net: bridge: mcast: always update mdb_n_entries for vlan contexts |
| CVE-2026-45922 | 5.5 | 5.6 | Linux | Linux | CWE-401 | RDMA/mlx5: Fix memory leak in GET_DATA_DIRECT_SYSFS_PATH handler |
| CVE-2026-45925 | 5.5 | 5.6 | Linux | Linux | — | thermal/of: Fix reference leak in thermal_of_cm_lookup() |
| CVE-2026-45973 | 5.5 | 5.6 | Linux | Linux | — | RDMA/mlx5: Fix UMR hang in LAG error state unload |
| CVE-2026-46000 | 5.5 | 5.6 | Linux | Linux | — | rxrpc: Fix conn-level packet handling to unshare RESPONSE packets |
| CVE-2026-44713 | 8.8 | 5.4 | mcdope | pam_usb | CWE-78 | pam_usb: Command injection via $TMUX environment variable leads to RCE as root |
| CVE-2026-45940 | 5.5 | 5.4 | Linux | Linux | — | net: stmmac: fix oops when split header is enabled |
| CVE-2026-45929 | 7.8 | 5.4 | Linux | Linux | CWE-416 | ovpn: fix possible use-after-free in ovpn_net_xmit |
| CVE-2026-45903 | 7.1 | 5.4 | Linux | Linux | CWE-125 | bpf: Fix memory access flags in helper prototypes |
| CVE-2026-6565 | 6.4 | 5.3 | analogwp | Style Kits for Elementor | CWE-79 | Style Kits – Advanced Theme Styles for Elementor <= 2.5.0 - Authenticated (Co… |
| CVE-2026-8702 | 6.4 | 5.3 | garber | GBI To Print | CWE-79 | GBI To Print <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scriptin… |
| CVE-2026-45864 | 5.5 | 5.2 | Linux | Linux | CWE-835 | fs/ntfs3: prevent infinite loops caused by the next valid being the same |
| CVE-2026-45865 | 5.5 | 5.2 | Linux | Linux | — | mctp i2c: initialise event handler read bytes |
| CVE-2026-45868 | 5.5 | 5.2 | Linux | Linux | — | pinctrl: single: fix refcount leak in pcs_add_gpio_func() |
| CVE-2026-45881 | 5.5 | 5.2 | Linux | Linux | CWE-401 | soc: mediatek: svs: Fix memory leak in svs_enable_debug_write() |
| CVE-2026-45883 | 5.5 | 5.2 | Linux | Linux | CWE-401 | iio: sca3000: Fix a resource leak in sca3000_probe() |
| CVE-2026-45904 | 5.5 | 5.2 | Linux | Linux | CWE-674 | powerpc/eeh: fix recursive pci_lock_rescan_remove locking in EEH event handling |
| CVE-2026-45911 | 5.5 | 5.2 | Linux | Linux | CWE-476 | usb: cdns3: fix role switching during resume |
| CVE-2026-45863 | 5.5 | 5.2 | Linux | Linux | CWE-401 | i3c: dw: Fix memory leak in dw_i3c_master_i2c_xfers() |
| CVE-2026-45874 | 5.5 | 5.2 | Linux | Linux | CWE-476 | phy: freescale: imx8qm-hsio: fix NULL pointer dereference |
| CVE-2026-45880 | 5.5 | 5.2 | Linux | Linux | — | PCI/P2PDMA: Release per-CPU pgmap ref when vm_insert_page() fails |
| CVE-2026-45897 | 5.5 | 5.2 | Linux | Linux | — | netfilter: nft_counter: serialize reset with spinlock |
| CVE-2026-45900 | 5.5 | 5.2 | Linux | Linux | CWE-401 | crypto: caam - fix netdev memory leak in dpaa2_caam_probe |
| CVE-2026-45901 | 5.5 | 5.2 | Linux | Linux | — | netfilter: nf_tables: revert commit_mutex usage in reset path |
| CVE-2026-44712 | 8.2 | 5.1 | mcdope | pam_usb | CWE-78 | pam_usb: Shell injection via device UUID and username in pamusb-conf and pamu… |
| CVE-2026-2254 | 6.3 | 5.0 | Hitachi Vantara | Pentaho Data Integration and Analytics | CWE-732 | Hitachi Vantara Pentaho Data Integration & Analytics - Incorrect Permission A… |
| CVE-2026-45854 | 5.5 | 5.0 | Linux | Linux | — | crypto: inside-secure/eip93 - unregister only available algorithm |
| CVE-2026-45876 | 5.5 | 5.0 | Linux | Linux | CWE-476 | arm64/gcs: Fix error handling in arch_set_shadow_stack_status() |
| CVE-2026-45887 | 5.5 | 5.0 | Linux | Linux | CWE-401 | af_unix: Fix memleak of newsk in unix_stream_connect(). |
| CVE-2026-45889 | 5.5 | 5.0 | Linux | Linux | CWE-369 | mptcp: do not account for OoO in mptcp_rcvbuf_grow() |
| CVE-2026-45908 | 5.5 | 5.0 | Linux | Linux | CWE-401 | accel/amdxdna: Fix memory leak in amdxdna_ubuf_map |
| CVE-2026-42738 | 7.1 | 4.8 | ZAYTECH | Smart Online Order for Clover | CWE-79 | WordPress Smart Online Order for Clover plugin <= 1.6.0 - Cross Site Scriptin… |
| CVE-2026-42739 | 7.1 | 4.8 | IniLerm | Advanced IP Blocker | CWE-79 | WordPress Advanced IP Blocker plugin <= 8.10.7 - Cross Site Scripting (XSS) v… |
| CVE-2026-42759 | 7.1 | 4.8 | Timo | Affiliate Super Assistent | CWE-79 | WordPress Affiliate Super Assistent plugin <= 1.10.1 - Cross Site Scripting (… |
| CVE-2026-49052 | 4.3 | 4.9 | Wpmet | ElementsKit Elementor addons Lite | CWE-862 | WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access C… |
| CVE-2026-3623 | 7.8 | 4.8 | IBM | Netezza Performance Server Replication Services | CWE-250 | Vulnerabilities exists in IBM Netezza Performance Server Replication Services |
| CVE-2026-44709 | 7.8 | 4.8 | mcdope | pam_usb | CWE-78 | pam_usb: PINENTRY_FALLBACK_APP environment variable allows arbitrary command … |
| CVE-2025-71306 | 7.1 | 4.7 | Linux | Linux | CWE-125 | ima: Fix stack-out-of-bounds in is_bprm_creds_for_exec() |
| CVE-2026-46055 | 7.1 | 4.7 | Linux | Linux | — | apparmor: Fix string overrun due to missing termination |
| CVE-2026-45335 | 5.4 | 4.7 | LabRedesCefetRJ | WeGIA | CWE-601 | WeGIA: Middleware whitelist bypass → open redirect via InternoControle.nextPage |
| CVE-2026-45862 | 7.8 | 4.6 | Linux | Linux | — | iommu/vt-d: Flush cache for PASID table before using it |
| CVE-2026-45894 | 7.8 | 4.6 | Linux | Linux | — | iommu/vt-d: Clear Present bit before tearing down PASID entry |
| CVE-2026-45935 | 7.8 | 4.6 | Linux | Linux | CWE-125 | fs/ntfs3: Fix slab-out-of-bounds read in DeleteIndexEntryRoot |
| CVE-2026-48065 | 6.7 | 4.6 | mcdope | pam_usb | CWE-122 | pam_usb: Unchecked integer multiplication before xmalloc() in conf.c allows h… |
| CVE-2026-44475 | 6.1 | 4.5 | ellanetworks | core | CWE-358 | Ella Core: UE Security Capability bypass on NGAP PathSwitchRequest |
| CVE-2026-21785 | 4.0 | 4.6 | HCLSoftware | BigFix Remote Control Server | CWE-1021 | HCL BigFix Remote Control Server WebUI is affected by a misconfigured Content… |
| CVE-2026-46029 | 7.0 | 4.4 | Linux | Linux | — | mm/slab: return NULL early from kmalloc_nolock() in NMI on UP |
| CVE-2026-45920 | 7.8 | 4.4 | Linux | Linux | CWE-415 | ext4: fix dirtyclusters double decrement on fs shutdown |
| CVE-2026-45718 | 5.4 | 4.4 | Budibase | budibase | CWE-863 | Budibase: Row Action Trigger Bypasses View Row Filter Security Boundary Allow… |
| CVE-2026-9674 | 4.3 | 4.4 | Jenkins Project | Jenkins Multijob Plugin | CWE-352 | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin … |
| CVE-2026-46022 | 7.1 | 4.3 | Linux | Linux | CWE-125 | misc: ibmasm: fix OOB MMIO read in ibmasm_handle_mouse_interrupt() |
| CVE-2026-8911 | 6.1 | 4.3 | godlessons | WP AutoBuzz | CWE-352 | WP AutoBuzz <= 1.1.1 - Cross-Site Request Forgery to Stored Cross-Site Script… |
| CVE-2026-46006 | 7.8 | 4.1 | Linux | Linux | CWE-787 | drm/nouveau: fix u32 overflow in pushbuf reloc bounds check |
| CVE-2026-45961 | 5.5 | 4.1 | Linux | Linux | CWE-401 | gfs2: fix memory leaks in gfs2_fill_super error path |
| CVE-2026-46062 | 7.8 | 4.0 | Linux | Linux | CWE-190 | ntfs3: fix integer overflow in run_unpack() volume boundary check |
| CVE-2026-42762 | 7.1 | 4.0 | e4jvikwp | VikBooking Hotel Booking Engine & PMS | CWE-79 | WordPress VikBooking Hotel Booking Engine & PMS plugin <= 1.8.9 - Cross Site … |
| CVE-2026-45993 | 5.5 | 4.0 | Linux | Linux | — | LoongArch: Add spectre boundry for syscall dispatch table |
| CVE-2026-46100 | 7.8 | 3.9 | Linux | Linux | — | fs: afs: revert mmap_prepare() change |
| CVE-2026-47274 | 6.3 | 4.0 | mcdope | pam_usb | CWE-427 | pam_usb: Uncontrolled search path in pam_usb tools allows privilege escalatio… |
| CVE-2026-8938 | 4.3 | 3.9 | nakamura1458 | auto making JSON-LD | CWE-352 | auto making JSON-LD <= 4.5.3 - Cross-Site Request Forgery to Plugin Certifica… |
| CVE-2026-8939 | 4.3 | 3.9 | simonailie | Search Simple Fields | CWE-352 | Search Simple Fields <= 0.2 - Cross-Site Request Forgery to Plugin Settings U… |
| CVE-2026-8941 | 4.3 | 3.9 | wmark | CDN Linker lite | CWE-352 | CDN Linker lite <= 1.3.1 - Cross-Site Request Forgery to Plugin Settings Update |
| CVE-2026-8943 | 4.3 | 3.9 | rchmura | GoStats for WordPress | CWE-352 | GoStats for WordPress <= 1.4 - Cross-Site Request Forgery via gostats_manage(… |
| CVE-2023-52945 | 7.8 | 3.8 | Synology | BeeDrive for desktop | CWE-427 | Uncontrolled search path element vulnerability in OpenSSL DLL component in Sy… |
| CVE-2026-45996 | 7.8 | 3.8 | Linux | Linux | CWE-416 | spi: imx: fix use-after-free on unbind |
| CVE-2026-46036 | 7.8 | 3.7 | Linux | Linux | CWE-416 | vfio/cdx: Serialize VFIO_DEVICE_SET_IRQS with a per-device mutex |
| CVE-2026-46069 | 7.8 | 3.8 | Linux | Linux | CWE-416 | wifi: mwifiex: fix use-after-free in mwifiex_adapter_cleanup() |
| CVE-2026-45994 | 7.1 | 3.8 | Linux | Linux | CWE-125 | ibmasm: fix OOB reads in command_file_write due to missing size checks |
| CVE-2026-46064 | 7.1 | 3.8 | Linux | Linux | CWE-125 | ibmasm: fix heap over-read in ibmasm_send_i2o_message() |
| CVE-2026-8903 | 4.3 | 3.7 | youtag | Two-factor authentication (formerly IP Vault) | CWE-352 | Two-factor authentication (formerly IP Vault) <= 2.1 - Cross-Site Request For… |
| CVE-2026-46079 | 5.5 | 3.7 | Linux | Linux | CWE-476 | rbd: fix null-ptr-deref when device_add_disk() fails |
| CVE-2026-46097 | 7.8 | 3.6 | Linux | Linux | CWE-416 | Input: edt-ft5x06 - fix use-after-free in debugfs teardown |
| CVE-2025-71307 | 5.5 | 3.6 | Linux | Linux | CWE-476 | drm/panthor: Fix NULL pointer dereference on panthor_fw_unplug |
| CVE-2025-71308 | 5.5 | 3.6 | Linux | Linux | CWE-476 | accel/amdxdna: Fix potential NULL pointer dereference in context cleanup |
| CVE-2025-71312 | 5.5 | 3.6 | Linux | Linux | CWE-401 | fs/ntfs3: fix ntfs_mount_options leak in ntfs_fill_super() |
| CVE-2026-45027 | 5.9 | 3.5 | LabRedesCefetRJ | WeGIA | CWE-759 | WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/logi… |
| CVE-2025-68712 | 5.5 | 3.5 | n/a | n/a | CWE-285 | SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local atta… |
| CVE-2026-45849 | 5.5 | 3.5 | Linux | Linux | CWE-667 | net: mscc: ocelot: add missing lock protection in ocelot_port_xmit_inj() |
| CVE-2026-46080 | 5.5 | 3.5 | Linux | Linux | — | ocfs2: split transactions in dio completion to avoid credit exhaustion |
| CVE-2026-46092 | 5.5 | 3.5 | Linux | Linux | CWE-476 | wifi: rtw88: check for PCI upstream bridge existence |
| CVE-2026-46034 | 5.5 | 3.5 | Linux | Linux | CWE-476 | vfio/cdx: Fix NULL pointer dereference in interrupt trigger path |
| CVE-2026-46041 | 5.5 | 3.5 | Linux | Linux | — | greybus: gb-beagleplay: fix sleep in atomic context in hdlc_tx_frames() |
| CVE-2026-46089 | 5.5 | 3.5 | Linux | Linux | — | zram: do not forget to endio for partial discard requests |
| CVE-2026-45945 | 8.8 | 3.4 | Linux | Linux | CWE-362 | iommu/vt-d: Fix race condition during PASID entry replacement |
| CVE-2026-45932 | 7.3 | 3.3 | Linux | Linux | — | bpf: Fix tcx/netkit detach permissions when prog fd isn't given |
| CVE-2026-44474 | 3.7 | 3.3 | ellanetworks | core | CWE-358 | Ella Core: Handover failures during concurrent Security Mode Command |
| CVE-2026-40851 | 8.4 | 3.3 | MB connect line | mbNET/mbNET.rokey | CWE-1287 | Command injection via USB |
| CVE-2026-45839 | 7.8 | 3.3 | Linux | Linux | CWE-129 | bpf: reject negative CO-RE accessor indices in bpf_core_parse_spec() |
| CVE-2026-45990 | 5.5 | 3.3 | Linux | Linux | CWE-190 | slub: fix data loss and overflow in krealloc() |
| CVE-2026-45998 | 7.8 | 3.2 | Linux | Linux | CWE-416 | rxrpc: Fix potential UAF after skb_unshare() failure |
| CVE-2026-46021 | 5.5 | 3.2 | Linux | Linux | CWE-401 | thermal: core: Fix thermal zone governor cleanup issues |
| CVE-2026-45999 | 7.1 | 3.2 | Linux | Linux | CWE-191 | erofs: fix unsigned underflow in z_erofs_lz4_handle_overlap() |
| CVE-2026-46078 | 7.1 | 3.2 | Linux | Linux | CWE-125 | erofs: fix the out-of-bounds nameoff handling for trailing dirents |
| CVE-2026-46074 | 5.5 | 3.2 | Linux | Linux | CWE-401 | spi: ch341: fix memory leaks on probe failures |
| CVE-2026-2607 | 5.1 | 3.1 | IBM | MQ Operator | CWE-532 | Multiple vulnerabilities in IBM MQ Operator and Queue manager container images |
| CVE-2026-42750 | 6.5 | 3.1 | Nexcess | WPComplete | CWE-79 | WordPress WPComplete plugin <= 2.9.5.4 - Cross Site Scripting (XSS) vulnerabi… |
| CVE-2026-42751 | 6.5 | 3.1 | wpdevelop | Booking Manager | CWE-79 | WordPress Booking Manager plugin <= 2.1.18 - Cross Site Scripting (XSS) vulne… |
| CVE-2026-45919 | 5.5 | 3.1 | Linux | Linux | CWE-835 | sched/rt: Skip currently executing CPU in rto_next_cpu() |
| CVE-2026-45968 | 5.5 | 3.1 | Linux | Linux | CWE-476 | cpuidle: Skip governor when only one idle state is available |
| CVE-2026-45982 | 5.5 | 3.1 | Linux | Linux | CWE-476 | ACPICA: Fix NULL pointer dereference in acpi_ev_address_space_dispatch() |
| CVE-2026-46023 | 5.5 | 3.1 | Linux | Linux | CWE-190 | dm mirror: fix integer overflow in create_dirty_log() |
| CVE-2026-47104 | 5.1 | 3.1 | libusb | libusb | CWE-125 | libusb < 1.0.30 Out-of-Bounds Read in parse_iad_array() |
| CVE-2026-45891 | 7.8 | 3.0 | Linux | Linux | CWE-415 | net: hns3: fix double free issue for tx spare buffer |
| CVE-2026-46001 | 7.8 | 2.9 | Linux | Linux | CWE-787 | hwmon: (pt5161l) Fix bugs in pt5161l_read_block_data() |
| CVE-2026-46004 | 7.8 | 3.0 | Linux | Linux | CWE-416 | ALSA: caiaq: Handle probe errors properly |
| CVE-2026-46015 | 7.8 | 3.0 | Linux | Linux | — | tcp: call sk_data_ready() after listener migration |
| CVE-2026-46053 | 7.8 | 3.0 | Linux | Linux | — | net: rds: fix MR cleanup on copy error |
| CVE-2026-46065 | 7.8 | 3.0 | Linux | Linux | CWE-401 | fbdev: defio: Disconnect deferred I/O from the lifetime of struct fb_info |
| CVE-2026-46068 | 7.8 | 2.9 | Linux | Linux | CWE-787 | crypto: nx - fix bounce buffer leaks in nx842_crypto_{alloc,free}_ctx |
| CVE-2026-46075 | 7.8 | 3.0 | Linux | Linux | CWE-416 | crypto: atmel-sha204a - Fix potential UAF and memory leak in remove path |
| CVE-2026-46084 | 7.8 | 2.9 | Linux | Linux | CWE-416 | RDMA/mana_ib: Disable RX steering on RSS QP destroy |
| CVE-2026-46093 | 7.8 | 2.9 | Linux | Linux | — | mm/vmalloc: take vmap_purge_lock in shrinker |
| CVE-2026-46033 | 7.1 | 3.0 | Linux | Linux | CWE-125 | crypto: authencesn - reject short ahash digests during instance creation |
| CVE-2026-45840 | 5.5 | 3.0 | Linux | Linux | — | openvswitch: cap upcall PID array size and pre-size vport replies |
| CVE-2026-45844 | 5.5 | 3.0 | Linux | Linux | — | netfilter: arp_tables: fix IEEE1394 ARP payload parsing |
| CVE-2026-45930 | 5.5 | 2.9 | Linux | Linux | — | net: mctp: ensure our nlmsg responses are initialised |
| CVE-2026-45974 | 5.5 | 2.9 | Linux | Linux | — | btrfs: fix invalid leaf access in btrfs_quota_enable() if ref key not found |
| CVE-2026-46005 | 5.5 | 2.9 | Linux | Linux | CWE-401 | xfs: fix a resource leak in xfs_alloc_buftarg() |
| CVE-2026-46026 | 5.5 | 2.9 | Linux | Linux | — | net: qrtr: ns: Limit the maximum number of lookups |
| CVE-2026-48792 | 4.4 | 2.9 | mcdope | pam_usb | CWE-390 | pam_usb: pusb_has_virtual_input_device() silently discards EACCES, disabling … |
| CVE-2026-7614 | 4.3 | 2.9 | mkhfr | Old Posts Highlighter | CWE-352 | Old Posts Highlighter <= 1.0.3 - Cross-Site Request Forgery to Settings Update |
| CVE-2026-8708 | 4.3 | 2.9 | shra | Genzel breadcrumbs | CWE-352 | Genzel breadcrumbs <= 1.2 - Cross-Site Request Forgery to Settings Update via… |
| CVE-2026-9236 | 4.3 | 2.9 | creativemindssolutions | CM Ad Changer – A simple tool to control and optimize your site's banners | CWE-352 | CM Ad Changer <= 2.0.7 - Cross-Site Request Forgery to Campaign Deletion via … |
| CVE-2026-45959 | 7.8 | 2.8 | Linux | Linux | CWE-476 | crypto: ccp - Fix a crash due to incorrect cleanup usage of kfree |
| CVE-2026-46045 | 7.8 | 2.8 | Linux | Linux | CWE-787 | md/md-llbitmap: skip reading rdevs that are not in_sync |
| CVE-2026-45944 | 7.5 | 2.8 | Linux | Linux | — | iommu/vt-d: Clear Present bit before tearing down context entry |
| CVE-2025-15649 | 5.5 | 2.8 | PMQS | IO::Uncompress::Unzip | CWE-248 | IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught excep… |
| CVE-2026-45838 | 5.5 | 2.7 | Linux | Linux | CWE-476 | bpf: fix end-of-list detection in cgroup_storage_get_next_key() |
| CVE-2026-45841 | 5.5 | 2.7 | Linux | Linux | CWE-369 | netfilter: nfnetlink_osf: fix divide-by-zero in OSF_WSS_MODULO |
| CVE-2026-45842 | 5.5 | 2.7 | Linux | Linux | CWE-476 | slip: reject VJ receive packets on instances with no rstate array |
| CVE-2026-45846 | 5.5 | 2.8 | Linux | Linux | CWE-476 | bareudp: fix NULL pointer dereference in bareudp_fill_metadata_dst() |
| CVE-2026-45928 | 5.5 | 2.8 | Linux | Linux | CWE-401 | media: chips-media: wave5: Fix memory leak on codec_info allocation failure |
| CVE-2026-45914 | 7.8 | 2.7 | Linux | Linux | CWE-416 | Revert "hwmon: (ibmpex) fix use-after-free in high/low store" |
| CVE-2026-45936 | 7.8 | 2.7 | Linux | Linux | CWE-416 | power: supply: goldfish: Fix use-after-free in power_supply_changed() |
| CVE-2026-45956 | 7.8 | 2.7 | Linux | Linux | CWE-416 | drm/exynos: vidi: use priv->vidi_dev for ctx lookup in vidi_connection_ioctl() |
| CVE-2026-45970 | 7.8 | 2.7 | Linux | Linux | CWE-416 | bonding: alb: fix UAF in rlb_arp_recv during bond up/down |
| CVE-2026-46047 | 7.8 | 2.7 | Linux | Linux | CWE-416 | net: qrtr: ns: Fix use-after-free in driver remove() |
| CVE-2026-45958 | 7.1 | 2.7 | Linux | Linux | CWE-476 | drm/exynos: vidi: fix to avoid directly dereferencing user pointer |
| CVE-2026-46070 | 7.1 | 2.7 | Linux | Linux | CWE-787 | md/raid5: validate payload size before accessing journal metadata |
| CVE-2026-45952 | 5.5 | 2.7 | Linux | Linux | — | eth: fbnic: Add validation for MTU changes |
| CVE-2026-45981 | 5.5 | 2.7 | Linux | Linux | CWE-401 | s390/cio: Fix device lifecycle handling in css_alloc_subchannel() |
| CVE-2026-46042 | 5.5 | 2.7 | Linux | Linux | CWE-401 | mm/mempolicy: fix memory leaks in weighted_interleave_auto_store() |
| CVE-2026-45938 | 7.8 | 2.6 | Linux | Linux | CWE-416 | power: supply: pm8916_lbc: Fix use-after-free in power_supply_changed() |
| CVE-2026-46011 | 7.8 | 2.6 | Linux | Linux | CWE-416 | media: mtk-jpeg: fix use-after-free in release path due to uncancelled work |
| CVE-2026-45893 | 7.1 | 2.6 | Linux | Linux | CWE-125 | apparmor: Fix & Optimize table creation from possibly unaligned memory |
| CVE-2026-45943 | 7.1 | 2.6 | Linux | Linux | CWE-125 | erofs: fix inline data read failure for ztailpacking pclusters |
| CVE-2026-45957 | 7.1 | 2.6 | Linux | Linux | CWE-125 | rcu: Fix rcu_read_unlock() deadloop due to softirq |
| CVE-2026-46094 | 7.1 | 2.6 | Linux | Linux | CWE-125 | ext4: fix bounds check in check_xattrs() to prevent out-of-bounds access |
| CVE-2026-45951 | 7.8 | 2.5 | Linux | Linux | CWE-416 | bpf: Fix a potential use-after-free of BTF object |
| CVE-2026-45980 | 7.8 | 2.5 | Linux | Linux | CWE-416 | accel/amdxdna: Stop job scheduling across aie2_release_resource() |
| CVE-2026-45955 | 7.1 | 2.5 | Linux | Linux | — | md/md-llbitmap: fix percpu_ref not resurrected on suspend timeout |
| CVE-2026-46020 | 7.1 | 2.5 | Linux | Linux | CWE-125 | mm/damon/core: validate damos_quota_goal->nid for node_mem_{used,free}_bp |
| CVE-2026-8942 | 4.3 | 2.5 | lhughes33472 | MetaMagic SEO Plugin | CWE-352 | MetaMagic SEO Plugin <= 1.6 - Cross-Site Request Forgery to Plugin Settings U… |
| CVE-2026-46054 | 7.1 | 2.5 | Linux | Linux | CWE-280 | selinux: fix overlayfs mmap() and mprotect() access checks |
| CVE-2026-45890 | 5.5 | 2.4 | Linux | Linux | — | xen-netback: reject zero-queue configuration from guest |
| CVE-2026-45912 | 5.5 | 2.4 | Linux | Linux | — | ext4: don't cache extent during splitting extent |
| CVE-2026-45941 | 5.5 | 2.5 | Linux | Linux | CWE-401 | tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure |
| CVE-2026-45960 | 5.5 | 2.4 | Linux | Linux | — | hfsplus: return error when node already exists in hfs_bnode_create |
| CVE-2026-45969 | 5.5 | 2.4 | Linux | Linux | CWE-476 | HID: playstation: Add missing check for input_ff_create_memless |
| CVE-2026-45978 | 5.5 | 2.4 | Linux | Linux | CWE-476 | staging: greybus: lights: avoid NULL deref |
| CVE-2026-45983 | 5.5 | 2.4 | Linux | Linux | — | nfsd: never defer requests during idmap lookup |
| CVE-2026-45985 | 5.5 | 2.4 | Linux | Linux | — | ext4: don't set EXT4_GET_BLOCKS_CONVERT when splitting before submitting I/O |
| CVE-2026-45986 | 5.5 | 2.4 | Linux | Linux | CWE-401 | crypto: ccree - fix a memory leak in cc_mac_digest() |
| CVE-2026-45987 | 5.5 | 2.4 | Linux | Linux | — | KVM: nSVM: Sync interrupt shadow to cached vmcb12 after VMRUN of L2 |
| CVE-2026-45997 | 5.5 | 2.4 | Linux | Linux | — | scsi: sd: fix missing put_disk() when device_add(&disk_dev) fails |
| CVE-2026-46002 | 5.5 | 2.4 | Linux | Linux | — | ext2: reject inodes with zero i_nlink and valid mode in ext2_iget() |
| CVE-2026-46003 | 5.5 | 2.4 | Linux | Linux | — | net: qrtr: ns: Limit the total number of nodes |
| CVE-2026-46009 | 5.5 | 2.4 | Linux | Linux | — | PCI: endpoint: pci-epf-ntb: Remove duplicate resource teardown |
| CVE-2026-46028 | 5.5 | 2.5 | Linux | Linux | — | crypto: algif_aead - snapshot IV for async AEAD requests |
| CVE-2026-46038 | 5.5 | 2.4 | Linux | Linux | CWE-401 | net: qrtr: ns: Free the node during ctrl_cmd_bye() |
| CVE-2026-46040 | 5.5 | 2.4 | Linux | Linux | — | inotify: fix watch count leak when fsnotify_add_inode_mark_locked() fails |
| CVE-2026-46044 | 5.5 | 2.4 | Linux | Linux | — | ipmi:ssif: Clean up kthread on errors |
| CVE-2026-46046 | 5.5 | 2.4 | Linux | Linux | — | ext4: fix missing brelse() in ext4_xattr_inode_dec_ref_all() |
| CVE-2026-46048 | 5.5 | 2.4 | Linux | Linux | — | ALSA: caiaq: fix usb_dev refcount leak on probe failure |
| CVE-2026-46049 | 5.5 | 2.4 | Linux | Linux | — | ALSA: ctxfi: Add fallback to default RSR for S/PDIF |
| CVE-2026-46072 | 5.5 | 2.4 | Linux | Linux | — | ntfs3: add buffer boundary checks to run_unpack() |
| CVE-2026-46077 | 5.5 | 2.4 | Linux | Linux | — | crypto: atmel-tdes - fix DMA sync direction |
| CVE-2026-46082 | 5.5 | 2.4 | Linux | Linux | — | KVM: SVM: Inject #UD for INVLPGA if EFER.SVME=0 |
| CVE-2026-46083 | 5.5 | 2.4 | Linux | Linux | CWE-401 | spi: fix resource leaks on device setup failure |
| CVE-2026-46086 | 5.5 | 2.4 | Linux | Linux | CWE-476 | net: bridge: use a stable FDB dst snapshot in RCU readers |
| CVE-2026-46088 | 5.5 | 2.4 | Linux | Linux | — | ALSA: control: Validate buf_len before strnlen() in snd_ctl_elem_init_enum_na… |
| CVE-2026-46091 | 5.5 | 2.4 | Linux | Linux | — | media: rc: igorplugusb: heed coherency rules |
| CVE-2026-46098 | 5.5 | 2.4 | Linux | Linux | CWE-476 | net: caif: clear client service pointer on teardown |
| CVE-2026-46101 | 5.5 | 2.4 | Linux | Linux | — | netfilter: reject zero shift in nft_bitwise |
| CVE-2026-7365 | 7.8 | 2.4 | IBM | Operations Analytics - Log Analysis | CWE-1392 | IBM Operations Analytics - Log Analysis is affected by Information disclosure… |
| CVE-2026-45917 | 5.5 | 2.4 | Linux | Linux | — | ipvs: do not keep dest_dst if dev is going down |
| CVE-2026-45921 | 5.5 | 2.4 | Linux | Linux | CWE-401 | mtd: parsers: Fix memory leak in mtd_parser_tplink_safeloader_parse() |
| CVE-2026-45950 | 5.5 | 2.4 | Linux | Linux | CWE-401 | crypto: starfive - Fix memory leak in starfive_aes_aead_do_one_req() |
| CVE-2026-45954 | 5.5 | 2.4 | Linux | Linux | CWE-401 | fbdev: au1200fb: Fix a memory leak in au1200fb_drv_probe() |
| CVE-2026-45976 | 5.5 | 2.3 | Linux | Linux | CWE-401 | drm/amdgpu: Fix memory leak in amdgpu_ras_init() |
| CVE-2026-46007 | 5.5 | 2.3 | Linux | Linux | — | hwmon: (powerz) Avoid cacheline sharing for DMA buffer |
| CVE-2026-46012 | 5.5 | 2.3 | Linux | Linux | CWE-401 | rxrpc: Fix memory leaks in rxkad_verify_response() |
| CVE-2026-46016 | 5.5 | 2.4 | Linux | Linux | CWE-476 | remoteproc: xlnx: Only access buffer information if IPI is buffered |
| CVE-2026-46073 | 5.5 | 2.4 | Linux | Linux | — | hwmon: (powerz) Fix missing usb_kill_urb() on signal interrupt |
| CVE-2026-47271 | 5.1 | 2.4 | mcdope | pam_usb | CWE-476 | pam_usb: OOM guards removed by -DNDEBUG cause NULL dereference and authentica… |
| CVE-2026-46076 | 7.9 | 2.3 | Linux | Linux | — | KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1 |
| CVE-2026-49000 | 7.0 | 2.3 | ZTE | ZXUniPOS NDS-LTE | CWE-310 | Cryptography Implementation Flaw vulnerability in ZTE ZXUniPOS NDS-LTE product |
| CVE-2026-45934 | 5.5 | 2.2 | Linux | Linux | — | btrfs: fix EEXIST abort due to non-consecutive gaps in chunk allocation |
| CVE-2026-45937 | 5.5 | 2.2 | Linux | Linux | — | crypto: inside-secure/eip93 - fix kernel panic in driver detach |
| CVE-2026-45939 | 5.5 | 2.2 | Linux | Linux | CWE-401 | gpib: Fix memory leak in ni_usb_init() |
| CVE-2026-45953 | 5.5 | 2.2 | Linux | Linux | — | md/raid5: fix IO hang with degraded array with llbitmap |
| CVE-2026-45966 | 5.5 | 2.2 | Linux | Linux | CWE-476 | apparmor: fix NULL pointer dereference in __unix_needs_revalidation |
| CVE-2026-45971 | 5.5 | 2.2 | Linux | Linux | — | bpf: Limit bpf program signature size |
| CVE-2026-45977 | 5.5 | 2.2 | Linux | Linux | — | fbnic: close fw_log race between users and teardown |
| CVE-2026-46030 | 5.5 | 2.2 | Linux | Linux | CWE-401 | EDAC/versalnet: Fix device_node leak in mc_probe() |
| CVE-2026-46035 | 5.5 | 2.3 | Linux | Linux | — | mm/page_alloc: return NULL early from alloc_frozen_pages_nolock() in NMI on UP |
| CVE-2026-46059 | 5.5 | 2.2 | Linux | Linux | — | KVM: nSVM: Always use NextRIP as vmcb02's NextRIP after first L2 VMRUN |
| CVE-2026-46060 | 5.5 | 2.2 | Linux | Linux | — | crypto: qat - fix IRQ cleanup on 6xxx probe failure |
| CVE-2026-46066 | 5.5 | 2.2 | Linux | Linux | CWE-193 | ceph: fix num_ops off-by-one when crypto allocation fails |
| CVE-2026-46071 | 5.5 | 2.2 | Linux | Linux | — | KVM: nSVM: Avoid clearing VMCB_LBR in vmcb12 |
| CVE-2026-46087 | 5.5 | 2.2 | Linux | Linux | CWE-401 | mm/damon/stat: fix memory leak on damon_start() failure in damon_stat_start() |
| CVE-2026-46095 | 5.5 | 2.3 | Linux | Linux | — | md/md-llbitmap: raise barrier before state machine transition |
| CVE-2026-46096 | 5.5 | 2.2 | Linux | Linux | — | tpm2-sessions: Fix missing tpm_buf_destroy() in tpm2_read_public() |
| CVE-2026-45906 | 7.8 | 2.2 | Linux | Linux | CWE-416 | power: supply: pf1550: Fix use-after-free in power_supply_changed() |
| CVE-2026-45995 | 7.8 | 2.2 | Linux | Linux | CWE-416 | io_uring/zcrx: fix user_struct uaf |
| CVE-2026-42328 | 6.2 | 2.2 | ipld | go-ipld-prime | CWE-674 | go-ipld-prime: DAG-CBOR and DAG-JSON decoders unbounded recursion depth |
| CVE-2026-45845 | 5.5 | 2.1 | Linux | Linux | CWE-476 | net/sched: taprio: fix NULL pointer dereference in class dump |
| CVE-2026-45924 | 5.5 | 2.2 | Linux | Linux | CWE-667 | ksmbd: call ksmbd_vfs_kern_path_end_removing() on some error paths |
| CVE-2026-47272 | 7.1 | 2.0 | mcdope | pam_usb | CWE-287 | pam_usb: OTP pad authentication bypass via missing system pad check and unini… |
| CVE-2026-8906 | 6.1 | 2.1 | rahulbhangale | WP Promoter | CWE-352 | WP Promoter <= 1.3 - Cross-Site Request Forgery to Stored Cross-Site Scriptin… |
| CVE-2026-45907 | 5.5 | 2.0 | Linux | Linux | CWE-667 | net/mlx5e: Fix deadlocks between devlink and netdev instance locks |
| CVE-2026-46057 | 3.3 | 2.0 | Linux | Linux | — | landlock: Fix LOG_SUBDOMAINS_OFF inheritance across fork() |
| CVE-2026-46067 | 7.1 | 2.0 | Linux | Linux | CWE-125 | mm/damon/core: validate damos_quota_goal->nid for node_memcg_{used,free}_bp |
| CVE-2026-45837 | 7.8 | 1.9 | Linux | Linux | CWE-416 | bpf: Fix use-after-free in arena_vm_close on fork |
| CVE-2026-48066 | 5.7 | 1.9 | mcdope | pam_usb | CWE-362 | pam_usb: Thread-unsafe static pointer in log.c causes data race under concurr… |
| CVE-2026-45963 | 5.5 | 1.9 | Linux | Linux | CWE-476 | ASoC: nau8821: Cancel delayed work on component remove |
| CVE-2026-46032 | 5.5 | 1.9 | Linux | Linux | — | KVM: nSVM: Triple fault if restore host CR3 fails on nested #VMEXIT |
| CVE-2026-48147 | 6.5 | 1.8 | Budibase | budibase | CWE-185 | Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query Stri… |
| CVE-2026-46103 | 5.5 | 1.7 | Linux | Linux | CWE-401 | can: ucan: fix devres lifetime |
| CVE-2026-44972 | 5.0 | 1.6 | DataDog | guarddog | CWE-116 | GuardDog: Unsanitized human-readable scan output allows terminal escape injec… |
| CVE-2024-11399 | 6.8 | 1.6 | Synology | BeeDrive for desktop | CWE-552 | Files or directories accessible to external parties vulnerability in redis-se… |
| CVE-2026-45926 | 5.5 | 1.6 | Linux | Linux | CWE-401 | rust: pwm: Fix potential memory leak on init error |
| CVE-2026-45905 | 4.7 | 1.6 | Linux | Linux | CWE-362 | xfrm: fix ip_rt_bug race in icmp_route_lookup reverse path |
| CVE-2026-49001 | 5.3 | 1.4 | ZTE | ZXUniPOS NDS-LTE | CWE-352 | Cross-Site Request Forgery (CSRF) vulnerability in ZTE ZXUniPOS NDS-LTE product |
| CVE-2026-47270 | 6.3 | 1.4 | mcdope | pam_usb | CWE-362 | pam_usb: strtok() race condition in multi-threaded PAM hosts can corrupt deny… |
| CVE-2026-45967 | 5.5 | 1.3 | Linux | Linux | — | bpf: Return proper address for non-zero offsets in insn array |
| CVE-2026-45975 | 5.5 | 1.3 | Linux | Linux | — | ublk: use READ_ONCE() to read struct ublksrv_ctrl_cmd |
| CVE-2026-45979 | 5.5 | 1.3 | Linux | Linux | — | drm/amdgpu: clean up the amdgpu_cs_parser_bos |
| CVE-2026-46013 | 5.5 | 1.3 | Linux | Linux | — | mm/memfd_luo: fix physical address conversion in put_folios cleanup |
| CVE-2025-71309 | 5.5 | 1.3 | Linux | Linux | CWE-667 | fs/ntfs3: fix deadlock in ni_read_folio_cmpr |
| CVE-2026-45046 | 5.5 | 1.3 | safedep | gryph | CWE-212 | Gryph Agents Payload Filter Fails to Strip Tool Payload for Sensitive Content |
| CVE-2026-46017 | 4.7 | 1.2 | Linux | Linux | CWE-362 | mm: fix deferred split queue races during migration |
| CVE-2026-48925 | 4.3 | 1.2 | Jenkins Project | Jenkins GitHub Integration Plugin | CWE-352 | A cross-site request forgery (CSRF) vulnerability in Jenkins GitHub Integrati… |
| CVE-2026-46090 | 7.8 | 1.1 | Linux | Linux | CWE-416 | ALSA: aloop: Fix peer runtime UAF during format-change stop |
| CVE-2026-45910 | 7.8 | 1.1 | Linux | Linux | CWE-362 | RDMA/rxe: Fix race condition in QP timer handlers |
| CVE-2026-49014 | 7.8 | 1.1 | GDAL | GDAL | CWE-121 | In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver … |
| CVE-2025-71303 | 4.7 | 1.1 | Linux | Linux | CWE-362 | accel/amdxdna: Fix race condition when checking rpm_on |
| CVE-2026-5515 | 5.5 | 1.0 | IBM | App Connect Enterprise | CWE-922 | IBM App Connect Enterprise is vulnerable to a confidential disclosure |
| CVE-2026-45942 | 7.8 | 0.9 | Linux | Linux | CWE-362 | ext4: fix e4b bitmap inconsistency reports |
| CVE-2026-41009 | 4.3 | 0.9 | Cloud Foundry Foundation | BOSH Director | CWE-22 | Local Blobstore may allow arbitrary reads/deletes |
| CVE-2026-6053 | 5.5 | 0.9 | IBM | Db2 | CWE-770 | IBM® Db2® is vulnerable to a denial of service when a specially crafted query… |
| CVE-2026-46058 | 7.8 | 0.9 | Linux | Linux | CWE-362 | media: amphion: Fix race between m2m job_abort and device_run |
| CVE-2026-30498 | 6.3 | 0.9 | n/a | n/a | CWE-352 | A Cross-Site Request Forgery (CSRF) vulnerability was discovered in the delet… |
| CVE-2026-46050 | 5.5 | 0.7 | Linux | Linux | CWE-667 | md/raid10: fix deadlock with check operation and nowait requests |
| CVE-2026-46051 | 5.5 | 0.7 | Linux | Linux | CWE-667 | md/raid5: fix soft lockup in retry_aligned_read() |
| CVE-2026-46061 | 5.5 | 0.7 | Linux | Linux | CWE-667 | jbd2: fix deadlock in jbd2_journal_cancel_revoke() |
| CVE-2026-46063 | 5.5 | 0.7 | Linux | Linux | CWE-667 | x86/shstk: Prevent deadlock during shstk sigreturn |
| CVE-2026-46014 | 5.5 | 0.7 | Linux | Linux | CWE-667 | KVM: SVM: Add missing save/restore handling of LBR MSRs |
| CVE-2026-2237 | 5.5 | 0.6 | Synology | Storage Manager | CWE-598 | A use of get request method with sensitive query strings vulnerability in vol… |
| CVE-2026-9759 | 5.5 | 0.6 | Wireshark Foundation | Wireshark | CWE-476 | NULL Pointer Dereference in Wireshark |
| CVE-2026-45927 | 4.7 | 0.6 | Linux | Linux | CWE-367 | bpf: Require frozen map for calculating map hash |
| CVE-2026-45949 | 4.7 | 0.5 | Linux | Linux | CWE-362 | hwrng: core - use RCU and work_struct to fix race condition |
| CVE-2026-46025 | 4.7 | 0.5 | Linux | Linux | CWE-362 | mm/damon/core: fix damon_call() vs kdamond_fn() exit race |
| CVE-2025-13593 | 5.6 | 0.4 | Synology | ActiveProtect Agent | CWE-346 | Origin validation error vulnerability in Synology ActiveProtect Agent before … |
| CVE-2025-66592 | 5.6 | 0.4 | Synology | Synology Active Backup for Business Agent | CWE-346 | An origin validation error vulnerability in Synology Active Backup for Busine… |
| CVE-2025-66593 | 5.6 | 0.4 | Synology | Synology Assistant | CWE-346 | An origin validation error vulnerability in Synology Assistant before 7.0.6-5… |
| CVE-2026-41704 | 6.8 | 0.3 | Cloud Foundry Foundation | BOSH Director | CWE-284 | Compromised VM can make arbitrary blobstore deletes |
| CVE-2026-46008 | 4.7 | 0.2 | Linux | Linux | CWE-362 | mm/damon/core: fix damos_walk() vs kdamond_fn() exit race |