Edition of May 28, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-42401 | 5.4 | 4.0 | Elastic | Kibana | CWE-79 | Improper Neutralization of Input During Web Page Generation in Kibana Leading… |
| CVE-2026-9991 | 3.1 | 4.0 | Chrome | CWE-200 | Inappropriate implementation in Media in Google Chrome on Windows prior to 14… | |
| CVE-2026-46129 | 7.8 | 3.7 | Linux | Linux | CWE-415 | btrfs: fix double free in create_space_info() error path |
| CVE-2026-46197 | 7.8 | 3.7 | Linux | Linux | CWE-787 | drm/amdkfd: validate SVM ioctl nattr against buffer size |
| CVE-2026-46206 | 7.8 | 3.7 | Linux | Linux | — | batman-adv: reject new tp_meter sessions during teardown |
| CVE-2026-46208 | 7.8 | 3.7 | Linux | Linux | — | batman-adv: stop tp_meter sessions during mesh teardown |
| CVE-2026-46209 | 7.8 | 3.7 | Linux | Linux | CWE-787 | drm/gem: Fix inconsistent plane dimension calculation in drm_gem_fb_init_with… |
| CVE-2026-46149 | 7.1 | 3.7 | Linux | Linux | CWE-674 | scsi: target: configfs: Bound snprintf() return in tg_pt_gp_members_show() |
| CVE-2026-46162 | 7.8 | 3.7 | Linux | Linux | CWE-415 | ice: fix double free in ice_sf_eth_activate() error path |
| CVE-2026-46201 | 7.8 | 3.7 | Linux | Linux | CWE-401 | drm/xe: Fix dma-buf attachment leak in xe_gem_prime_import() |
| CVE-2026-9618 | 4.3 | 3.7 | peachpay | PeachPay — Payments & Express Checkout for WooCommerce (supports Stripe, PayPal, Square, Authorize.net, NMI) | CWE-352 | PeachPay <= 1.120.46 - Cross-Site Request Forgery to Stripe Unlink |
| CVE-2026-9959 | 3.1 | 3.6 | Chrome | CWE-362 | Race in WebRTC in Google Chrome on Windows prior to 148.0.7778.216 allowed a … | |
| CVE-2026-46164 | 7.0 | 3.6 | Linux | Linux | CWE-415 | btrfs: fix double free in create_space_info_sub_group() error path |
| CVE-2026-46174 | 8.8 | 3.4 | Linux | Linux | — | x86/CPU/AMD: Prevent improper isolation of shared resources in Zen2's op cache |
| CVE-2026-46180 | 7.8 | 3.4 | Linux | Linux | CWE-416 | wifi: brcmfmac: Fix potential use-after-free issue when stopping watchdog task |
| CVE-2026-46219 | 7.8 | 3.4 | Linux | Linux | CWE-416 | spi: mpc52xx: fix use-after-free on unbind |
| CVE-2026-7533 | 4.3 | 3.4 | smub | Easy Digital Downloads – eCommerce Payments and Subscriptions made easy | CWE-352 | Easy Digital Downloads <= 3.6.7 - Cross-Site Request Forgery to Payment Accou… |
| CVE-2026-46117 | 7.8 | 3.2 | Linux | Linux | CWE-617 | RDMA/mana: Remove user triggerable WARN_ON() in mana_ib_create_qp_rss() |
| CVE-2026-46140 | 7.1 | 3.1 | Linux | Linux | CWE-125 | Bluetooth: btmtk: validate WMT event SKB length before struct access |
| CVE-2026-46190 | 7.1 | 3.1 | Linux | Linux | CWE-125 | mtd: spi-nor: debugfs: fix out-of-bounds read in spi_nor_params_show() |
| CVE-2026-46191 | 7.1 | 3.2 | Linux | Linux | CWE-125 | fbcon: Avoid OOB font access if console rotation fails |
| CVE-2026-46199 | 7.1 | 3.1 | Linux | Linux | CWE-125 | drm/amdgpu/vcn4: Prevent OOB reads when parsing dec msg |
| CVE-2026-46203 | 7.1 | 3.1 | Linux | Linux | CWE-125 | spi: cadence-quadspi: fix unclocked access on unbind |
| CVE-2026-46204 | 7.1 | 3.1 | Linux | Linux | CWE-125 | drm/amdgpu/vcn4: Prevent OOB reads when parsing IB |
| CVE-2026-46218 | 7.1 | 3.2 | Linux | Linux | — | drm/amdgpu: Add bounds checking to ib_{get,set}_value |
| CVE-2026-46116 | 7.8 | 3.0 | Linux | Linux | CWE-416 | xfrm: defensively unhash xfrm_state lists in __xfrm_state_delete |
| CVE-2026-46169 | 5.5 | 3.1 | Linux | Linux | CWE-908 | hfsplus: fix uninit-value by validating catalog record size |
| CVE-2026-46107 | 7.8 | 3.0 | Linux | Linux | CWE-191 | dm-thin: fix metadata refcount underflow |
| CVE-2026-46122 | 7.8 | 3.0 | Linux | Linux | CWE-129 | wifi: b43: enforce bounds check on firmware key index in b43_rx() |
| CVE-2026-46136 | 7.8 | 3.0 | Linux | Linux | CWE-787 | wifi: mt76: mt7921: fix a potential clc buffer length underflow |
| CVE-2026-46163 | 7.8 | 3.0 | Linux | Linux | CWE-129 | wifi: b43legacy: enforce bounds check on firmware key index in RX path |
| CVE-2026-46178 | 7.8 | 3.0 | Linux | Linux | CWE-401 | RDMA/mlx4: Fix resource leak on error in mlx4_ib_create_srq() |
| CVE-2026-46210 | 7.8 | 3.0 | Linux | Linux | CWE-416 | media: iris: fix use-after-free of fmt_src during MBPF check |
| CVE-2026-46234 | 7.8 | 3.0 | Linux | Linux | CWE-787 | vsock: fix buffer size clamping order |
| CVE-2026-48735 | 6.9 | 2.9 | py-pdf | pypdf | CWE-770 | pypdf: Manipulated XMP metadata streams can exhaust RAM |
| CVE-2026-45078 | 6.8 | 2.9 | element-hq | synapse | CWE-770 | Synapse CPU starvation (Denial of Service) |
| CVE-2026-46127 | 5.5 | 2.9 | Linux | Linux | CWE-476 | RDMA/ocrdma: Don't NULL deref uctx on errors in ocrdma_copy_pd_uresp() |
| CVE-2026-46128 | 5.5 | 2.9 | Linux | Linux | — | ipmi: Check event message buffer response for bad data |
| CVE-2026-46132 | 5.5 | 2.9 | Linux | Linux | CWE-908 | net: rtnetlink: zero ifla_vf_broadcast to avoid stack infoleak in rtnl_fill_v… |
| CVE-2026-46143 | 5.5 | 2.9 | Linux | Linux | CWE-401 | ASoC: qcom: q6apm-lpass-dai: Fix multiple graph opens |
| CVE-2026-46146 | 5.5 | 2.9 | Linux | Linux | CWE-835 | ALSA: usb-audio: Avoid potential endless loop in convert_chmap_v3() |
| CVE-2026-46160 | 5.5 | 2.9 | Linux | Linux | — | btrfs: fix missing last_unlink_trans update when removing a directory |
| CVE-2026-46161 | 5.5 | 2.9 | Linux | Linux | CWE-369 | md/raid10: fix divide-by-zero in setup_geo() with zero far_copies |
| CVE-2026-46167 | 5.5 | 2.9 | Linux | Linux | CWE-908 | usb: usblp: fix uninitialized heap leak via LPGETSTATUS ioctl |
| CVE-2026-46168 | 5.5 | 2.9 | Linux | Linux | — | mptcp: fix scheduling with atomic in timestamp sockopt |
| CVE-2026-46172 | 5.5 | 2.9 | Linux | Linux | — | ipv6: xfrm6: release dst on error in xfrm6_rcv_encap() |
| CVE-2026-46184 | 5.5 | 2.9 | Linux | Linux | CWE-369 | sound: ua101: fix division by zero at probe |
| CVE-2026-46193 | 5.5 | 2.9 | Linux | Linux | — | xfrm: ah: account for ESN high bits in async callbacks |
| CVE-2026-46196 | 5.5 | 2.9 | Linux | Linux | — | tracepoint: balance regfunc() on func_add() failure in tracepoint_add_func() |
| CVE-2026-46202 | 5.5 | 2.9 | Linux | Linux | — | HID: appletb-kbd: run inactivity autodim from workqueues |
| CVE-2026-46214 | 5.5 | 2.9 | Linux | Linux | — | vsock/virtio: fix accept queue count leak on transport mismatch |
| CVE-2026-9979 | 5.0 | 2.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in Input in Google Chrome prior to… | |
| CVE-2026-46105 | 7.8 | 2.8 | Linux | Linux | — | scsi: mpt3sas: Limit NVMe request size to 2 MiB |
| CVE-2026-46126 | 5.5 | 2.8 | Linux | Linux | — | RDMA/mana: Fix mana_destroy_wq_obj() cleanup in mana_ib_create_qp_rss() |
| CVE-2026-46131 | 5.5 | 2.8 | Linux | Linux | — | KVM: x86: check for nEPT/nNPT in slow flush hypercalls |
| CVE-2026-46142 | 5.5 | 2.8 | Linux | Linux | — | net: libwx: fix VF illegal register access |
| CVE-2026-46144 | 5.5 | 2.8 | Linux | Linux | — | RDMA/mana: Fix error unwind in mana_ib_create_qp_rss() |
| CVE-2026-46158 | 5.5 | 2.8 | Linux | Linux | — | mptcp: pm: ADD_ADDR rtx: always decrease sk refcount |
| CVE-2026-46170 | 5.5 | 2.8 | Linux | Linux | — | mptcp: pm: ADD_ADDR rtx: free sk if last |
| CVE-2026-46188 | 5.5 | 2.8 | Linux | Linux | CWE-476 | octeon_ep_vf: add NULL check for napi_build_skb() |
| CVE-2026-46200 | 5.5 | 2.8 | Linux | Linux | — | spi: mpc52xx: fix controller deregistration |
| CVE-2026-46207 | 5.5 | 2.8 | Linux | Linux | CWE-401 | vsock/virtio: fix empty payload in tap skb for non-linear buffers |
| CVE-2026-46211 | 5.5 | 2.8 | Linux | Linux | CWE-476 | drm/msm/gem: fix error handling in msm_ioctl_gem_info_get_metadata() |
| CVE-2026-46216 | 5.5 | 2.8 | Linux | Linux | CWE-476 | drm/xe/hdcp: Add NULL check for media_gt in intel_hdcp_gsc_check_status() |
| CVE-2026-48523 | 5.4 | 2.8 | jpadilla | pyjwt | CWE-347 | PyJWT: Algorithm allow-list bypass when decoding with `PyJWK` / `PyJWKClient`… |
| CVE-2026-48155 | 4.8 | 2.8 | py-pdf | pypdf | CWE-400 | pypdf: Possible large memory usage for large offsets for layout mode text |
| CVE-2026-46120 | 7.8 | 2.7 | Linux | Linux | CWE-416 | ip6_gre: Use cached t->net in ip6erspan_changelink(). |
| CVE-2026-46173 | 7.8 | 2.7 | Linux | Linux | CWE-787 | exit: prevent preemption of oopsing TASK_DEAD task |
| CVE-2026-46134 | 5.5 | 2.7 | Linux | Linux | CWE-476 | platform/chrome: cros_ec_typec: Init mutex in Thunderbolt registration |
| CVE-2026-46147 | 5.5 | 2.7 | Linux | Linux | CWE-401 | KVM: arm64: Fix pin leak and publication ordering in __pkvm_init_vcpu() |
| CVE-2026-46171 | 5.5 | 2.7 | Linux | Linux | CWE-401 | riscv: kvm: fix vector context allocation leak |
| CVE-2026-46182 | 5.5 | 2.7 | Linux | Linux | CWE-401 | pseries/papr-hvpipe: Prevent kernel stack memory leak to userspace |
| CVE-2026-42250 | 4.8 | 2.7 | bzip2 | bzip2 | CWE-787 | Off-by-One Leading to Out-of-Bounds Write in bzip2 |
| CVE-2026-46111 | 7.8 | 2.6 | Linux | Linux | CWE-416 | Bluetooth: hci_conn: fix potential UAF in create_big_sync |
| CVE-2026-46121 | 7.8 | 2.6 | Linux | Linux | CWE-416 | mm/damon/sysfs-schemes: protect memcg_path kfree() with damon_sysfs_lock |
| CVE-2026-46241 | 7.8 | 2.6 | Linux | Linux | CWE-416 | spi: mpc52xx: fix use-after-free on registration failure |
| CVE-2026-10010 | 5.0 | 2.6 | Chrome | CWE-346 | Inappropriate implementation in Input in Google Chrome on Android prior to 14… | |
| CVE-2026-46213 | 7.8 | 2.5 | Linux | Linux | CWE-416 | HID: appletb-kbd: fix UAF in inactivity-timer cleanup path |
| CVE-2026-46240 | 7.8 | 2.5 | Linux | Linux | CWE-416 | media: iris: Fix use-after-free in iris_release_internal_buffers() |
| CVE-2026-46130 | 7.1 | 2.5 | Linux | Linux | CWE-125 | dm-verity-fec: fix reading parity bytes split across blocks (take 3) |
| CVE-2026-46175 | 7.1 | 2.5 | Linux | Linux | — | f2fs: fix fsck inconsistency caused by FGGC of node block |
| CVE-2026-48156 | 5.1 | 2.5 | py-pdf | pypdf | CWE-834 | pypdf: Possible long runtimes for zero-only width values in cross-reference s… |
| CVE-2026-9980 | 5.0 | 2.6 | Chrome | CWE-20 | Insufficient validation of untrusted input in Printing in Google Chrome prior… | |
| CVE-2026-46108 | 5.5 | 2.4 | Linux | Linux | — | ipmi:si: Return state to normal if message allocation fails |
| CVE-2026-46109 | 5.5 | 2.4 | Linux | Linux | CWE-401 | usb: ulpi: fix memory leak on ulpi_register() error paths |
| CVE-2026-46151 | 5.5 | 2.4 | Linux | Linux | CWE-401 | usb: usblp: fix heap leak in IEEE 1284 device ID via short response |
| CVE-2026-46186 | 5.5 | 2.4 | Linux | Linux | CWE-908 | Bluetooth: virtio_bt: validate rx pkt_type header length |
| CVE-2026-6891 | 5.1 | 2.5 | Canon Inc. | My Image Garden for macOS | CWE-59 | Improper handling of symbolic links in the installer of My Image Garden for m… |
| CVE-2026-46230 | 7.1 | 2.4 | Linux | Linux | CWE-125 | drm/amdgpu/vcn3: Prevent OOB reads when parsing dec msg |
| CVE-2026-46106 | 5.5 | 2.3 | Linux | Linux | — | eventfs: Hold eventfs_mutex and SRCU when remount walks events |
| CVE-2026-46139 | 5.5 | 2.4 | Linux | Linux | CWE-908 | smb: client: use kzalloc to zero-initialize security descriptor buffer |
| CVE-2026-46179 | 5.5 | 2.4 | Linux | Linux | — | ASoC: SOF: Don't allow pointer operations on unconfigured streams |
| CVE-2026-45366 | 4.7 | 2.4 | universal-tool-calling-protocol | typescript-utcp | CWE-918 | typescript-utcp: SSRF via attacker-controlled OpenAPI servers[0].url in HTTP … |
| CVE-2026-46104 | 5.5 | 2.2 | Linux | Linux | — | selinux: use sk blob accessor in socket permission helpers |
| CVE-2026-46118 | 5.5 | 2.2 | Linux | Linux | CWE-476 | pseries/papr-hvpipe: Fix null ptr deref in papr_hvpipe_dev_create_handle() |
| CVE-2026-46141 | 5.5 | 2.3 | Linux | Linux | CWE-401 | powerpc/xive: fix kmemleak caused by incorrect chip_data lookup |
| CVE-2026-46148 | 5.5 | 2.2 | Linux | Linux | — | spi: microchip-core-qspi: control built-in cs manually |
| CVE-2026-46192 | 5.5 | 2.2 | Linux | Linux | — | spi: microchip-core-qspi: don't attempt to transmit during emulated read-only… |
| CVE-2026-46183 | 7.8 | 2.2 | Linux | Linux | CWE-415 | mm/damon/sysfs-schemes: protect path kfree() with damon_sysfs_lock |
| CVE-2026-46154 | 7.0 | 2.2 | Linux | Linux | CWE-416 | sched_ext: Read scx_root under scx_cgroup_ops_rwsem in cgroup setters |
| CVE-2026-46220 | 5.5 | 2.1 | Linux | Linux | CWE-617 | drm/amdgpu/sdma4: replace BUG_ON with WARN_ON in fence emission |
| CVE-2026-46225 | 5.5 | 2.1 | Linux | Linux | — | spi: rspi: fix controller deregistration |
| CVE-2026-46226 | 5.5 | 2.0 | Linux | Linux | — | spi: fsl: fix controller deregistration |
| CVE-2026-46229 | 5.5 | 2.1 | Linux | Linux | — | drm/amdkfd: Clear VRAM on allocation to prevent stale data exposure |
| CVE-2026-46231 | 5.5 | 2.1 | Linux | Linux | — | batman-adv: bla: put backbone reference on failed claim hash insert |
| CVE-2026-46233 | 5.5 | 2.1 | Linux | Linux | CWE-476 | batman-adv: bla: only purge non-released claims |
| CVE-2026-46235 | 5.5 | 2.1 | Linux | Linux | CWE-476 | media: saa7164: add ioremap return checks and cleanups |
| CVE-2026-46236 | 5.5 | 2.1 | Linux | Linux | — | media: rc: xbox_remote: heed DMA restrictions |
| CVE-2026-46221 | 5.5 | 2.0 | Linux | Linux | CWE-401 | EDAC/versalnet: Fix device name memory leak |
| CVE-2026-46224 | 5.5 | 2.0 | Linux | Linux | CWE-401 | drm/xe: Fix bo leak in xe_dma_buf_init_obj() on allocation failure |
| CVE-2026-46228 | 5.5 | 2.0 | Linux | Linux | CWE-401 | spi: ch341: fix devres lifetime |
| CVE-2026-35266 | 7.9 | 1.8 | Oracle Corporation | Oracle REST Data Services | CWE-400 | Vulnerability in Oracle REST Data Services (component: Core). Supported versi… |
| CVE-2026-45353 | 9.3 | 1.8 | electerm | electerm | CWE-94 | electerm: Local code through electerm's single-instance socket |
| CVE-2026-46181 | 7.8 | 1.7 | Linux | Linux | CWE-366 | RDMA/mlx4: Fix mis-use of RCU in mlx4_srq_event() |
| CVE-2026-47331 | 7.8 | 1.7 | Canonical | Ubuntu Linux | CWE-416 | Use-after-free in Ubuntu Linux AppArmor notification handling |
| CVE-2026-46153 | 5.5 | 1.6 | Linux | Linux | — | 8021q: delete cleared egress QoS mappings |
| CVE-2026-46685 | 6.0 | 1.4 | rustfs | rustfs | CWE-306 | RustFS: Reflective CORS with credentials on S3 listener; unauthenticated lice… |
| CVE-2026-47333 | 7.8 | 1.3 | Canonical | Ubuntu Linux | CWE-125 | Out-of-bounds read in Ubuntu Linux AppArmor notification handling |
| CVE-2026-9989 | 6.3 | 1.3 | Chrome | CWE-346 | Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.21… | |
| CVE-2026-47332 | 5.5 | 1.3 | Canonical | Ubuntu Linux | CWE-125 | Out-of-bounds read in Ubuntu Linux AppArmor notification handling |
| CVE-2026-45787 | 6.0 | 1.2 | electerm | electerm | CWE-326 | electerm's encrypt method not safe enough |
| CVE-2026-46222 | 5.5 | 1.2 | Linux | Linux | CWE-476 | media: rockchip: rkcif: Add missing MUST_CONNECT flag to pads |
| CVE-2026-46239 | 5.5 | 1.2 | Linux | Linux | — | media: i2c: ov5647: Fix runtime PM refcount leak in s_ctrl |
| CVE-2026-46227 | 7.8 | 1.2 | Linux | Linux | CWE-416 | sctp: revalidate list cursor after sctp_sendmsg_to_asoc() in SCTP_SENDALL |
| CVE-2026-46112 | 7.8 | 1.0 | Linux | Linux | CWE-667 | RDMA/hns: Fix unlocked call to hns_roce_qp_remove() |
| CVE-2026-9987 | 7.8 | 0.9 | Chrome | CWE-20 | Insufficient validation of untrusted input in WebAppInstalls in Google Chrome… | |
| CVE-2026-46157 | 7.8 | 0.9 | Linux | Linux | CWE-362 | ALSA: pcm: oss: Fix data race at accessing runtime.oss.trigger |
| CVE-2026-46165 | 5.5 | 0.9 | Linux | Linux | CWE-667 | openvswitch: vport: fix self-deadlock on release of tunnel ports |
| CVE-2026-34126 | 7.3 | 0.8 | TP-Link Systems Inc. | Tapo L535E v1.0, v3.0 | CWE-319 | Bluetooth Communication Uses Unencrypted Transmission During Initial Setup on… |
| CVE-2026-47335 | 5.5 | 0.9 | Canonical | Ubuntu Linux | CWE-476 | NULL pointer dereference in Ubuntu Linux AppArmor notification handling |
| CVE-2026-46156 | 5.5 | 0.7 | Linux | Linux | CWE-667 | LoongArch: Fix potential ADE in loongson_gpu_fixup_dma_hang() |
| CVE-2026-47336 | 3.3 | 0.7 | Canonical | Ubuntu Linux | CWE-457 | Use of uninitialized value in Ubuntu Linux AppArmor IPv4/IPv6 socket mediatio… |
| CVE-2026-47337 | 3.3 | 0.7 | Canonical | Ubuntu Linux | CWE-476 | NULL pointer dereference in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation |
| CVE-2026-47328 | 6.1 | 0.7 | Canonical | Ubuntu Linux | CWE-590 | Invalid pointer deallocation in Ubuntu Linux AppArmor notification handling |
| CVE-2026-47326 | 5.5 | 0.7 | Canonical | Ubuntu Linux | CWE-401 | Memory leak in Ubuntu Linux AppArmor large notification response allocation |
| CVE-2026-46159 | 4.7 | 0.7 | Linux | Linux | CWE-367 | btrfs: fix btrfs_ioctl_space_info() slot_count TOCTOU which can lead to info-… |
| CVE-2026-46187 | 4.7 | 0.7 | Linux | Linux | CWE-362 | wifi: rsi: fix kthread lifetime race between self-exit and external-stop |
| CVE-2026-47329 | 3.3 | 0.6 | Canonical | Ubuntu Linux | CWE-1284 | Incorrect validation of field size in Ubuntu Linux AppArmor notification resp… |
| CVE-2026-47330 | 3.3 | 0.6 | Canonical | Ubuntu Linux | CWE-457 | Use of uninitialized value in Ubuntu Linux AppArmor notification handling |
| CVE-2026-47327 | 3.3 | 0.6 | Canonical | Ubuntu Linux | CWE-476 | NULL pointer dereference in Ubuntu Linux AppArmor notification handling |
| CVE-2026-46223 | 5.5 | 0.3 | Linux | Linux | CWE-667 | cgroup: Defer css percpu_ref kill on rmdir until cgroup is depopulated |
| CVE-2026-47334 | 5.5 | 0.1 | Canonical | Ubuntu Linux | CWE-833 | Deadlock or kernel panic in Ubuntu Linux AppArmor notification handling |