boxscore/security
Wednesday, June 24, 2026 · all times UTC← 2026-06-23 · archive · 2026-06-25 →

Edition of June 24, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–520 of 520
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-530225.52.5LinuxLinuxplatform/x86: dell-wmi-sysman: bound enumeration string aggregation
CVE-2026-530235.52.5LinuxLinuxfs/ntfs3: terminate the cached volume label after UTF-8 conversion
CVE-2026-530395.52.5LinuxLinuxCWE-617ocfs2: validate group add input before caching
CVE-2026-530485.52.5LinuxLinuxCWE-476gfs2: prevent NULL pointer dereference during unmount
CVE-2026-530525.52.4LinuxLinuxASoC: qcom: qdsp6: topology: check widget type before accessing data
CVE-2026-530615.52.5LinuxLinuxdm cache: fix dirty mapping checking in passthrough mode switching
CVE-2026-530645.52.5LinuxLinuxCWE-476dm cache: fix null-deref with concurrent writes in passthrough mode
CVE-2026-530935.52.4LinuxLinuxCWE-476wifi: brcmfmac: Fix error pointer dereference
CVE-2026-530817.82.4LinuxLinuxCWE-386bpf: Enforce regsafe base id consistency for BPF_ADD_CONST scalars
CVE-2026-531177.82.4LinuxLinuxCWE-416s390/cio: use generic driver_override infrastructure
CVE-2026-529887.12.4LinuxLinuxnetfilter: nf_tables: join hook list via splice_list_rcu() in commit phase
CVE-2026-530407.12.4LinuxLinuxCWE-416ocfs2: validate bg_bits during freefrag scan
CVE-2026-130067.02.4QOS.CH SarlLogback-coreCWE-20Incomplete protection against CVE-2025-11226
CVE-2026-529805.52.4LinuxLinuxCWE-476sched/fair: Clear rel_deadline when initializing forked entities
CVE-2026-530135.52.3LinuxLinuxmacvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF
CVE-2026-530145.52.3LinuxLinuxnet/sched: act_mirred: fix wrong device for mac_header_xmit check in tcf_bloc…
CVE-2026-530155.52.3LinuxLinuxerofs: unify lcn as u64 for 32-bit platforms
CVE-2026-530275.52.4LinuxLinuxfs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked()
CVE-2026-530325.52.4LinuxLinuxCWE-476bpf: Fix NULL deref in map_kptr_match_type for scalar regs
CVE-2026-530385.52.4LinuxLinuxCWE-125ima_fs: Correctly create securityfs files for unsupported hash algos
CVE-2026-530585.52.3LinuxLinuxCWE-476drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in at…
CVE-2026-531055.52.4LinuxLinuxCWE-476wifi: mt76: mt7925: prevent NULL vif dereference in mt7925_mac_write_txwi
CVE-2026-539465.42.3TryGhostGhostCWE-918Ghost: Mobiledoc image-size fetch SSRF
CVE-2026-529445.52.3LinuxLinuxksmbd: fix FSCTL permission bypass by adding a permission check for FSCTL_SET…
CVE-2026-530185.52.2LinuxLinuxf2fs: avoid reading already updated pages during GC
CVE-2026-530195.52.2LinuxLinuxclk: spacemit: ccu_mix: fix inverted condition in ccu_mix_trigger_fc()
CVE-2026-530285.52.2LinuxLinuxCWE-476usb: typec: Fix error pointer dereference
CVE-2026-530305.52.2LinuxLinuxCWE-401i3c: master: renesas: Fix memory leak in renesas_i3c_i3c_xfers()
CVE-2026-530425.52.2LinuxLinuxCWE-824fwctl: Fix class init ordering to avoid NULL pointer dereference on device re…
CVE-2026-530955.52.3LinuxLinuxbpf: Fix abuse of kprobe_write_ctx via freplace
CVE-2026-531045.52.3LinuxLinuxCWE-401wifi: mt76: Fix memory leak destroying device
CVE-2026-531115.52.3LinuxLinuxCWE-476bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap
CVE-2026-531285.52.3LinuxLinuxdrbd: Balance RCU calls in drbd_adm_dump_devices()
CVE-2026-563704.82.3ImageMagickImageMagickCWE-125ImageMagick - Out-of-bounds Access in ConnectedComponentsImage via connected-…
CVE-2026-424508.42.1AcademySoftwareFoundationOpenColorIOCWE-120OpenColorIO vulnerable to stack buffer overflow via unbounded `sscanf %s` in …
CVE-2026-529277.82.2LinuxLinuxCWE-125netfilter: ebtables: fix OOB read in compat_mtw_from_user
CVE-2026-529337.82.2LinuxLinuxCWE-835io_uring/poll: fix signed comparison in io_poll_get_ownership()
CVE-2026-529357.82.2LinuxLinuxCWE-787xfrm: espintcp: do not reuse an in-progress partial send
CVE-2026-530777.82.2LinuxLinuxnet/rds: Restrict use of RDS/IB to the initial network namespace
CVE-2026-530787.82.1LinuxLinuxCWE-125bpf: Fix same-register dst/src OOB read and pointer leak in sock_ops
CVE-2026-531107.82.1LinuxLinuxs390/bpf: Zero-extend bpf prog return values and kfunc arguments
CVE-2026-531157.82.2LinuxLinuxCWE-416bus: fsl-mc: use generic driver_override infrastructure
CVE-2026-531197.82.2LinuxLinuxCWE-416platform/wmi: use generic driver_override infrastructure
CVE-2026-531207.82.2LinuxLinuxCWE-416PCI: use generic driver_override infrastructure
CVE-2026-530677.82.0LinuxLinuxCWE-415PCI: endpoint: pci-ep-msi: Fix error unwind and prevent double alloc
CVE-2026-530857.82.1LinuxLinuxCWE-416bpf: fix mm lifecycle in open-coded task_vma iterator
CVE-2026-531187.82.1LinuxLinuxCWE-416vdpa: use generic driver_override infrastructure
CVE-2026-529415.52.1LinuxLinuxCWE-476net/smc: avoid NULL deref of conn->lnk in smc_msg_event tracepoint
CVE-2026-530655.52.1LinuxLinuxCWE-401ASoC: sti: use managed regmap_field allocations
CVE-2026-477334.42.0RocketChatRocket.ChatCWE-79Rocket.Chat: Missing URL protocol sanitization in ImageElement allows javascr…
CVE-2026-529197.81.9LinuxLinuxCWE-191batman-adv: fix tp_meter counter underflow during shutdown
CVE-2026-531127.81.9LinuxLinuxCWE-416wifi: rtlwifi: pci: fix possible use-after-free caused by unfinished irq_prep…
CVE-2026-531297.81.9LinuxLinuxCWE-416fs/mbcache: cancel shrink work before destroying the cache
CVE-2026-530687.12.0LinuxLinuxCWE-190drm/komeda: fix integer overflow in AFBC framebuffer size check
CVE-2026-530767.11.9LinuxLinuxCWE-125bpf: Fix OOB in pcpu_init_value
CVE-2026-529395.51.9LinuxLinuxCWE-476net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion
CVE-2026-531235.51.9LinuxLinuxmd: wake raid456 reshape waiters before suspend
CVE-2026-529305.51.8LinuxLinuxipc/shm: serialize orphan cleanup with shm_nattch updates
CVE-2026-529215.51.7LinuxLinuxCWE-835netfilter: ipset: stop hash:* range iteration at end
CVE-2026-529255.51.7LinuxLinuxCWE-476vrf: Fix a potential NPD when removing a port from a VRF
CVE-2026-529265.51.7LinuxLinuxbatman-adv: clear current gateway during teardown
CVE-2026-529285.51.7LinuxLinuxaf_unix: Reject SIOCATMARK on non-stream sockets
CVE-2026-529365.51.7LinuxLinuxcrypto: jitterentropy - replace long-held spinlock with mutex
CVE-2026-530665.51.7LinuxLinuxCWE-476drm/sun4i: backend: fix error pointer dereference
CVE-2026-530735.51.7LinuxLinuxCWE-476Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error
CVE-2026-530745.51.7LinuxLinuxbpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb
CVE-2026-530805.51.7LinuxLinuxCWE-476net/sched: cls_fw: fix NULL dereference of "old" filters before change()
CVE-2026-530825.51.7LinuxLinuxCWE-908net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf
CVE-2026-530835.51.7LinuxLinuxbpf: Fix RCU stall in bpf_fd_array_map_clear()
CVE-2026-530845.51.7LinuxLinuxbpf: return VMA snapshot from task_vma iterator
CVE-2026-531265.51.7LinuxLinuxblk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current()
CVE-2026-531075.51.6LinuxLinuxwifi: libertas: don't kill URBs in interrupt context
CVE-2026-531215.51.6LinuxLinuxCWE-401amd-pstate: Fix memory leak in amd_pstate_epp_cpu_init()
CVE-2026-530897.81.6LinuxLinuxCWE-416bpf: Fix use-after-free in offloaded map/prog info fill
CVE-2026-531167.81.6LinuxLinuxCWE-416s390/ap: use generic driver_override infrastructure
CVE-2026-529375.51.6LinuxLinuxCWE-401tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR
CVE-2026-529405.51.6LinuxLinuxtun: zero the whole vnet header in tun_put_user()
CVE-2026-529495.51.6LinuxLinuxdrm/ttm: Fix ttm_bo_shrink() infinite LRU walk on backup failure
CVE-2026-530175.51.6LinuxLinuxf2fs: fix data loss caused by incorrect use of nat_entry flag
CVE-2026-531145.51.6LinuxLinuxperf/amd/ibs: Avoid calling perf_allow_kernel() from the IBS NMI handler
CVE-2026-573064.21.5Jenkins ProjectJenkins Zowe zDevOps PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins Zowe zDevOps Plu…
CVE-2026-530995.51.4LinuxLinuxbpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI
CVE-2026-531025.51.4LinuxLinuxCWE-401wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()
CVE-2026-531135.51.4LinuxLinuxCWE-401wifi: ath11k: fix memory leaks in beacon template setup
CVE-2026-572894.81.4Jenkins ProjectJenkins Bitbucket Push and Pull Request PluginCWE-295Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditiona…
CVE-2026-529917.81.3LinuxLinuxCWE-362sched/psi: fix race between file release and pressure write
CVE-2026-537666.11.3ChromeDevToolschrome-devtools-mcpCWE-22chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enf…
CVE-2026-530075.51.3LinuxLinuxCWE-476ice: fix potential NULL pointer deref in error path of ice_set_ringparam()
CVE-2026-530295.51.3LinuxLinuxCWE-908fs/ntfs3: prevent uninitialized lcn caused by zero len
CVE-2026-95396.51.3freedesktop.orglibslirpCWE-125libslirp TCP URG OOB Read Information Leak
CVE-2026-549052.01.3ruby-concurrencyconcurrent-rubyCWE-128concurrent-ruby: `ReentrantReadWriteLock` read-count overflow grants a write …
CVE-2026-130377.81.2GoogleChromeCWE-416Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197…
CVE-2026-97214.31.1chuhplBook a Room Event CalendarCWE-352Book a Room Event Calendar <= 1.9 - Cross-Site Request Forgery to Settings Up…
CVE-2026-572925.41.0Jenkins ProjectJenkins Gitee PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 128…
CVE-2026-572985.41.0Jenkins ProjectJenkins Contrast Continuous Application Security PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins Contrast Continu…
CVE-2026-530507.81.0LinuxLinuxCWE-362quota: Fix race of dquot_scan_active() with quota deactivation
CVE-2026-529385.51.0LinuxLinuxCWE-476bpf: Fix NULL pointer dereference in bpf_sk_storage_clone and diag paths
CVE-2026-530795.51.0LinuxLinuxCWE-401net_sched: fix skb memory leak in deferred qdisc drops
CVE-2026-531065.51.0LinuxLinuxCWE-401bpf: Do not allow deleting local storage in NMI
CVE-2026-531245.51.0LinuxLinuxublk: reset per-IO canceled flag on each fetch
CVE-2026-531275.51.0LinuxLinuxCWE-401block: fix zones_cond memory leak on zone revalidation error paths
CVE-2026-530547.80.9LinuxLinuxCWE-667drm/msm: Fix VM_BIND UNMAP locking
CVE-2026-530627.80.8LinuxLinuxCWE-667dm cache policy smq: fix missing locks in invalidating cache blocks
CVE-2026-75397.30.8HP Inc.HP Dock AccessoryCWE-379HP Dock Accessory WMI Provider Installer Security Update
CVE-2026-537656.10.8ChromeDevToolschrome-devtools-mcpCWE-59chrome-devtools-mcp: daemon.pid write follows symlinks in /tmp fallback runti…
CVE-2026-530355.50.7LinuxLinuxCWE-667bpf, sockmap: Fix af_unix iter deadlock
CVE-2026-530375.50.7LinuxLinuxCWE-667HID: usbhid: fix deadlock in hid_post_reset()
CVE-2026-531015.50.7LinuxLinuxCWE-667wifi: mt76: mt7921: fix potential deadlock in mt7921_roc_abort_sync
CVE-2026-531005.50.7LinuxLinuxCWE-667wifi: mt76: fix deadlock in remain-on-channel
CVE-2026-531035.50.7LinuxLinuxCWE-667wifi: mt76: mt7925: fix potential deadlock in mt7925_roc_abort_sync
CVE-2026-529597.80.6LinuxLinuxvirt: sev-guest: Do not use host-controlled page order in cleanup path
CVE-2026-530207.80.6LinuxLinuxCWE-362um: Fix potential race condition in TLB sync
CVE-2026-529795.50.7LinuxLinuxCWE-667net: psp: check for device unregister when creating assoc
CVE-2026-531225.50.6LinuxLinuxCWE-667btrfs: fix deadlock between reflink and transaction commit when using flushon…
CVE-2026-562694.30.7FlowiseFlowiseCWE-798Flowise - Weak Default Token Hash Secret in JWT Token Encryption
CVE-2026-531255.50.6LinuxLinuxCWE-667md: fix array_state=clear sysfs deadlock
CVE-2026-132086.50.5Red HatRed Hat OpenShift Virtualization 4CWE-287Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi…
CVE-2026-530084.70.1LinuxLinuxCWE-362ice: fix race condition in TX timestamp ring cleanup
CVE-2026-531084.70.1LinuxLinuxCWE-362powerpc/64s: Fix unmap race with PMD migration entries
CVE-2026-562725.60.1FlowiseFlowiseCWE-916Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing