boxscore/security
Thursday, May 28, 2026 · all times UTC← 2026-05-27 · archive · 2026-05-29 →

Edition of May 28, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–542 of 542
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-424015.44.0ElasticKibanaCWE-79Improper Neutralization of Input During Web Page Generation in Kibana Leading…
CVE-2026-99913.14.0GoogleChromeCWE-200Inappropriate implementation in Media in Google Chrome on Windows prior to 14…
CVE-2026-461297.83.7LinuxLinuxCWE-415btrfs: fix double free in create_space_info() error path
CVE-2026-461977.83.7LinuxLinuxCWE-787drm/amdkfd: validate SVM ioctl nattr against buffer size
CVE-2026-462067.83.7LinuxLinuxbatman-adv: reject new tp_meter sessions during teardown
CVE-2026-462087.83.7LinuxLinuxbatman-adv: stop tp_meter sessions during mesh teardown
CVE-2026-462097.83.7LinuxLinuxCWE-787drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with…
CVE-2026-461497.13.7LinuxLinuxCWE-674scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show()
CVE-2026-461627.83.7LinuxLinuxCWE-415ice: fix double free in ice_sf_eth_activate() error path
CVE-2026-462017.83.7LinuxLinuxCWE-401drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import()
CVE-2026-96184.33.7peachpayPeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI)CWE-352PeachPay <= 1.120.46 - Cross-Site Request Forgery to Stripe Unlink
CVE-2026-99593.13.6GoogleChromeCWE-362Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a …
CVE-2026-461647.03.6LinuxLinuxCWE-415btrfs: fix double free in create_space_info_sub_group() error path
CVE-2026-461748.83.4LinuxLinuxx86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache
CVE-2026-461807.83.4LinuxLinuxCWE-416wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task
CVE-2026-462197.83.4LinuxLinuxCWE-416spi: mpc52xx: fix use-after-free on unbind
CVE-2026-75334.33.4smubEasy Digital Downloads – eCommerce Payments and Subscriptions made easyCWE-352Easy Digital Downloads <= 3.6.7 - Cross-Site Request Forgery to Payment Accou…
CVE-2026-461177.83.2LinuxLinuxCWE-617RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss()
CVE-2026-461407.13.1LinuxLinuxCWE-125Bluetooth: btmtk: validate WMT event SKB length before struct access
CVE-2026-461907.13.1LinuxLinuxCWE-125mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show()
CVE-2026-461917.13.2LinuxLinuxCWE-125fbcon: Avoid OOB font access if console rotation fails
CVE-2026-461997.13.1LinuxLinuxCWE-125drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg
CVE-2026-462037.13.1LinuxLinuxCWE-125spi: cadence-quadspi: fix unclocked access on unbind
CVE-2026-462047.13.1LinuxLinuxCWE-125drm/amdgpu/vcn4: Prevent OOB reads when parsing IB
CVE-2026-462187.13.2LinuxLinuxdrm/amdgpu: Add bounds checking to ib_{get,set}_value
CVE-2026-461167.83.0LinuxLinuxCWE-416xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete
CVE-2026-461695.53.1LinuxLinuxCWE-908hfsplus: fix uninit-value by validating catalog record size
CVE-2026-461077.83.0LinuxLinuxCWE-191dm-thin: fix metadata refcount underflow
CVE-2026-461227.83.0LinuxLinuxCWE-129wifi: b43: enforce bounds check on firmware key index in b43_rx()
CVE-2026-461367.83.0LinuxLinuxCWE-787wifi: mt76: mt7921: fix a potential clc buffer length underflow
CVE-2026-461637.83.0LinuxLinuxCWE-129wifi: b43legacy: enforce bounds check on firmware key index in RX path
CVE-2026-461787.83.0LinuxLinuxCWE-401RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq()
CVE-2026-462107.83.0LinuxLinuxCWE-416media: iris: fix use-after-free of fmt_src during MBPF check
CVE-2026-462347.83.0LinuxLinuxCWE-787vsock: fix buffer size clamping order
CVE-2026-487356.92.9py-pdfpypdfCWE-770pypdf: Manipulated XMP metadata streams can exhaust RAM
CVE-2026-450786.82.9element-hqsynapseCWE-770Synapse CPU starvation (Denial of Service)
CVE-2026-461275.52.9LinuxLinuxCWE-476RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp()
CVE-2026-461285.52.9LinuxLinuxipmi: Check event message buffer response for bad data
CVE-2026-461325.52.9LinuxLinuxCWE-908net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_v…
CVE-2026-461435.52.9LinuxLinuxCWE-401ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens
CVE-2026-461465.52.9LinuxLinuxCWE-835ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3()
CVE-2026-461605.52.9LinuxLinuxbtrfs: fix missing last_unlink_trans update when removing a directory
CVE-2026-461615.52.9LinuxLinuxCWE-369md/raid10: fix divide-by-zero in setup_geo() with zero far_copies
CVE-2026-461675.52.9LinuxLinuxCWE-908usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl
CVE-2026-461685.52.9LinuxLinuxmptcp: fix scheduling with atomic in timestamp sockopt
CVE-2026-461725.52.9LinuxLinuxipv6: xfrm6: release dst on error in xfrm6_rcv_encap()
CVE-2026-461845.52.9LinuxLinuxCWE-369sound: ua101: fix division by zero at probe
CVE-2026-461935.52.9LinuxLinuxxfrm: ah: account for ESN high bits in async callbacks
CVE-2026-461965.52.9LinuxLinuxtracepoint: balance regfunc() on func_add() failure in tracepoint_add_func()
CVE-2026-462025.52.9LinuxLinuxHID: appletb-kbd: run inactivity autodim from workqueues
CVE-2026-462145.52.9LinuxLinuxvsock/virtio: fix accept queue count leak on transport mismatch
CVE-2026-99795.02.9GoogleChromeCWE-20Insufficient validation of untrusted input in Input in Google Chrome prior to…
CVE-2026-461057.82.8LinuxLinuxscsi: mpt3sas: Limit NVMe request size to 2 MiB
CVE-2026-461265.52.8LinuxLinuxRDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss()
CVE-2026-461315.52.8LinuxLinuxKVM: x86: check for nEPT/nNPT in slow flush hypercalls
CVE-2026-461425.52.8LinuxLinuxnet: libwx: fix VF illegal register access
CVE-2026-461445.52.8LinuxLinuxRDMA/mana: Fix error unwind in mana_ib_create_qp_rss()
CVE-2026-461585.52.8LinuxLinuxmptcp: pm: ADD_ADDR rtx: always decrease sk refcount
CVE-2026-461705.52.8LinuxLinuxmptcp: pm: ADD_ADDR rtx: free sk if last
CVE-2026-461885.52.8LinuxLinuxCWE-476octeon_ep_vf: add NULL check for napi_build_skb()
CVE-2026-462005.52.8LinuxLinuxspi: mpc52xx: fix controller deregistration
CVE-2026-462075.52.8LinuxLinuxCWE-401vsock/virtio: fix empty payload in tap skb for non-linear buffers
CVE-2026-462115.52.8LinuxLinuxCWE-476drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata()
CVE-2026-462165.52.8LinuxLinuxCWE-476drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status()
CVE-2026-485235.42.8jpadillapyjwtCWE-347PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient`…
CVE-2026-481554.82.8py-pdfpypdfCWE-400pypdf: Possible large memory usage for large offsets for layout mode text
CVE-2026-461207.82.7LinuxLinuxCWE-416ip6_gre: Use cached t->net in ip6erspan_changelink().
CVE-2026-461737.82.7LinuxLinuxCWE-787exit: prevent preemption of oopsing TASK_DEAD task
CVE-2026-461345.52.7LinuxLinuxCWE-476platform/chrome: cros_ec_typec: Init mutex in Thunderbolt registration
CVE-2026-461475.52.7LinuxLinuxCWE-401KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu()
CVE-2026-461715.52.7LinuxLinuxCWE-401riscv: kvm: fix vector context allocation leak
CVE-2026-461825.52.7LinuxLinuxCWE-401pseries/papr-hvpipe: Prevent kernel stack memory leak to userspace
CVE-2026-422504.82.7bzip2bzip2CWE-787Off-by-One Leading to Out-of-Bounds Write in bzip2
CVE-2026-461117.82.6LinuxLinuxCWE-416Bluetooth: hci_conn: fix potential UAF in create_big_sync
CVE-2026-461217.82.6LinuxLinuxCWE-416mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock
CVE-2026-462417.82.6LinuxLinuxCWE-416spi: mpc52xx: fix use-after-free on registration failure
CVE-2026-100105.02.6GoogleChromeCWE-346Inappropriate implementation in Input in Google Chrome on Android prior to 14…
CVE-2026-462137.82.5LinuxLinuxCWE-416HID: appletb-kbd: fix UAF in inactivity-timer cleanup path
CVE-2026-462407.82.5LinuxLinuxCWE-416media: iris: Fix use-after-free in iris_release_internal_buffers()
CVE-2026-461307.12.5LinuxLinuxCWE-125dm-verity-fec: fix reading parity bytes split across blocks (take 3)
CVE-2026-461757.12.5LinuxLinuxf2fs: fix fsck inconsistency caused by FGGC of node block
CVE-2026-481565.12.5py-pdfpypdfCWE-834pypdf: Possible long runtimes for zero-only width values in cross-reference s…
CVE-2026-99805.02.6GoogleChromeCWE-20Insufficient validation of untrusted input in Printing in Google Chrome prior…
CVE-2026-461085.52.4LinuxLinuxipmi:si: Return state to normal if message allocation fails
CVE-2026-461095.52.4LinuxLinuxCWE-401usb: ulpi: fix memory leak on ulpi_register() error paths
CVE-2026-461515.52.4LinuxLinuxCWE-401usb: usblp: fix heap leak in IEEE 1284 device ID via short response
CVE-2026-461865.52.4LinuxLinuxCWE-908Bluetooth: virtio_bt: validate rx pkt_type header length
CVE-2026-68915.12.5Canon Inc.My Image Garden for macOSCWE-59Improper handling of symbolic links in the installer of My Image Garden for m…
CVE-2026-462307.12.4LinuxLinuxCWE-125drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg
CVE-2026-461065.52.3LinuxLinuxeventfs: Hold eventfs_mutex and SRCU when remount walks events
CVE-2026-461395.52.4LinuxLinuxCWE-908smb: client: use kzalloc to zero-initialize security descriptor buffer
CVE-2026-461795.52.4LinuxLinuxASoC: SOF: Don't allow pointer operations on unconfigured streams
CVE-2026-453664.72.4universal-tool-calling-protocoltypescript-utcpCWE-918typescript-utcp: SSRF via attacker-controlled OpenAPI servers[0].url in HTTP …
CVE-2026-461045.52.2LinuxLinuxselinux: use sk blob accessor in socket permission helpers
CVE-2026-461185.52.2LinuxLinuxCWE-476pseries/papr-hvpipe: Fix null ptr deref in papr_hvpipe_dev_create_handle()
CVE-2026-461415.52.3LinuxLinuxCWE-401powerpc/xive: fix kmemleak caused by incorrect chip_data lookup
CVE-2026-461485.52.2LinuxLinuxspi: microchip-core-qspi: control built-in cs manually
CVE-2026-461925.52.2LinuxLinuxspi: microchip-core-qspi: don't attempt to transmit during emulated read-only…
CVE-2026-461837.82.2LinuxLinuxCWE-415mm/damon/sysfs-schemes: protect path kfree() with damon_sysfs_lock
CVE-2026-461547.02.2LinuxLinuxCWE-416sched_ext: Read scx_root under scx_cgroup_ops_rwsem in cgroup setters
CVE-2026-462205.52.1LinuxLinuxCWE-617drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission
CVE-2026-462255.52.1LinuxLinuxspi: rspi: fix controller deregistration
CVE-2026-462265.52.0LinuxLinuxspi: fsl: fix controller deregistration
CVE-2026-462295.52.1LinuxLinuxdrm/amdkfd: Clear VRAM on allocation to prevent stale data exposure
CVE-2026-462315.52.1LinuxLinuxbatman-adv: bla: put backbone reference on failed claim hash insert
CVE-2026-462335.52.1LinuxLinuxCWE-476batman-adv: bla: only purge non-released claims
CVE-2026-462355.52.1LinuxLinuxCWE-476media: saa7164: add ioremap return checks and cleanups
CVE-2026-462365.52.1LinuxLinuxmedia: rc: xbox_remote: heed DMA restrictions
CVE-2026-462215.52.0LinuxLinuxCWE-401EDAC/versalnet: Fix device name memory leak
CVE-2026-462245.52.0LinuxLinuxCWE-401drm/xe: Fix bo leak in xe_dma_buf_init_obj() on allocation failure
CVE-2026-462285.52.0LinuxLinuxCWE-401spi: ch341: fix devres lifetime
CVE-2026-352667.91.8Oracle CorporationOracle REST Data ServicesCWE-400Vulnerability in Oracle REST Data Services (component: Core). Supported versi…
CVE-2026-453539.31.8electermelectermCWE-94electerm: Local code through electerm's single-instance socket
CVE-2026-461817.81.7LinuxLinuxCWE-366RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event()
CVE-2026-473317.81.7CanonicalUbuntu LinuxCWE-416Use-after-free in Ubuntu Linux AppArmor notification handling
CVE-2026-461535.51.6LinuxLinux8021q: delete cleared egress QoS mappings
CVE-2026-466856.01.4rustfsrustfsCWE-306RustFS: Reflective CORS with credentials on S3 listener; unauthenticated lice…
CVE-2026-473337.81.3CanonicalUbuntu LinuxCWE-125Out-of-bounds read in Ubuntu Linux AppArmor notification handling
CVE-2026-99896.31.3GoogleChromeCWE-346Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.21…
CVE-2026-473325.51.3CanonicalUbuntu LinuxCWE-125Out-of-bounds read in Ubuntu Linux AppArmor notification handling
CVE-2026-457876.01.2electermelectermCWE-326electerm's encrypt method not safe enough
CVE-2026-462225.51.2LinuxLinuxCWE-476media: rockchip: rkcif: Add missing MUST_CONNECT flag to pads
CVE-2026-462395.51.2LinuxLinuxmedia: i2c: ov5647: Fix runtime PM refcount leak in s_ctrl
CVE-2026-462277.81.2LinuxLinuxCWE-416sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL
CVE-2026-461127.81.0LinuxLinuxCWE-667RDMA/hns: Fix unlocked call to hns_roce_qp_remove()
CVE-2026-99877.80.9GoogleChromeCWE-20Insufficient validation of untrusted input in WebAppInstalls in Google Chrome…
CVE-2026-461577.80.9LinuxLinuxCWE-362ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger
CVE-2026-461655.50.9LinuxLinuxCWE-667openvswitch: vport: fix self-deadlock on release of tunnel ports
CVE-2026-341267.30.8TP-Link Systems Inc.Tapo L535E v1.0, v3.0CWE-319Bluetooth Communication Uses Unencrypted Transmission During Initial Setup on…
CVE-2026-473355.50.9CanonicalUbuntu LinuxCWE-476NULL pointer dereference in Ubuntu Linux AppArmor notification handling
CVE-2026-461565.50.7LinuxLinuxCWE-667LoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang()
CVE-2026-473363.30.7CanonicalUbuntu LinuxCWE-457Use of uninitialized value in Ubuntu Linux AppArmor IPv4/IPv6 socket mediatio…
CVE-2026-473373.30.7CanonicalUbuntu LinuxCWE-476NULL pointer dereference in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation
CVE-2026-473286.10.7CanonicalUbuntu LinuxCWE-590Invalid pointer deallocation in Ubuntu Linux AppArmor notification handling
CVE-2026-473265.50.7CanonicalUbuntu LinuxCWE-401Memory leak in Ubuntu Linux AppArmor large notification response allocation
CVE-2026-461594.70.7LinuxLinuxCWE-367btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-…
CVE-2026-461874.70.7LinuxLinuxCWE-362wifi: rsi: fix kthread lifetime race between self-exit and external-stop
CVE-2026-473293.30.6CanonicalUbuntu LinuxCWE-1284Incorrect validation of field size in Ubuntu Linux AppArmor notification resp…
CVE-2026-473303.30.6CanonicalUbuntu LinuxCWE-457Use of uninitialized value in Ubuntu Linux AppArmor notification handling
CVE-2026-473273.30.6CanonicalUbuntu LinuxCWE-476NULL pointer dereference in Ubuntu Linux AppArmor notification handling
CVE-2026-462235.50.3LinuxLinuxCWE-667cgroup: Defer css percpu_ref kill on rmdir until cgroup is depopulated
CVE-2026-473345.50.1CanonicalUbuntu LinuxCWE-833Deadlock or kernel panic in Ubuntu Linux AppArmor notification handling