Edition of June 25, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-53237 | 5.5 | 2.4 | Linux | Linux | CWE-476 | gpio: mvebu: fix NULL pointer dereference in suspend/resume |
| CVE-2026-53241 | 5.5 | 2.4 | Linux | Linux | — | ALSA: seq: dummy: fix UMP event stack overread |
| CVE-2026-53251 | 5.5 | 2.4 | Linux | Linux | CWE-772 | Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync |
| CVE-2026-53266 | 8.8 | 2.3 | Linux | Linux | — | netfilter: bridge: make ebt_snat ARP rewrite writable |
| CVE-2026-53270 | 7.8 | 2.3 | Linux | Linux | — | ipvs: clear the svc scheduler ptr early on edit |
| CVE-2026-10098 | 6.3 | 2.2 | wolfSSL | wolfSSL | CWE-295 | OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status |
| CVE-2026-6091 | 6.0 | 2.3 | wolfSSL | wolfSSL | CWE-295 | Partial-chain verification accepts untrusted intermediate as trust anchor |
| CVE-2026-53141 | 5.5 | 2.2 | Linux | Linux | — | drm/v3d: Fix global performance monitor reference counting |
| CVE-2026-53164 | 5.5 | 2.2 | Linux | Linux | — | iommu/dma: Do not try to iommu_map a 0 length region in swiotlb |
| CVE-2026-53211 | 5.5 | 2.3 | Linux | Linux | CWE-401 | netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register |
| CVE-2026-53274 | 5.5 | 2.3 | Linux | Linux | — | net/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS |
| CVE-2026-53200 | 8.8 | 2.2 | Linux | Linux | — | KVM: arm64: nv: Fix handling of XN[0] when !FEAT_XNX |
| CVE-2026-53172 | 7.8 | 2.2 | Linux | Linux | CWE-125 | accel/ethosu: fix IFM region index out-of-bounds in command stream parser |
| CVE-2026-53173 | 7.8 | 2.2 | Linux | Linux | CWE-787 | accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate() |
| CVE-2026-53174 | 7.8 | 2.2 | Linux | Linux | — | ovl: keep err zero after successful ovl_cache_get() |
| CVE-2026-53265 | 7.8 | 2.2 | Linux | Linux | — | dm cache policy smq: check allocation under invalidate lock |
| CVE-2026-53267 | 7.8 | 2.1 | Linux | Linux | CWE-674 | netfilter: nft_ct: bail out on template ct in get eval |
| CVE-2021-47986 | 7.7 | 2.2 | parse-community | parse-server | CWE-494 | Parse Server - Unreviewed Code Execution via Malicious Version Tags |
| CVE-2021-47987 | 7.7 | 2.2 | parse-community | parse-server | CWE-494 | Parse Server - Arbitrary Code Execution via Malicious Version Tags |
| CVE-2026-55892 | 5.5 | 2.2 | vim | vim | CWE-787 | Vim: Out-of-bounds Write in Spell File Prefix Dump |
| CVE-2026-46611 | 5.3 | 2.1 | nicolargo | glances | CWE-346 | Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding … |
| CVE-2026-2299 | 4.3 | 2.2 | Mattermost | Mattermost Google Drive Plugin | CWE-862 | Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint |
| CVE-2026-53262 | 7.8 | 2.1 | Linux | Linux | — | l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() |
| CVE-2026-53226 | 5.5 | 2.0 | Linux | Linux | CWE-401 | gpio: rockchip: fix generic IRQ chip leak on remove |
| CVE-2026-55964 | 6.3 | 2.0 | wolfSSL | wolfSSL | CWE-295 | Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temp… |
| CVE-2026-57452 | 5.5 | 2.0 | vim | vim | CWE-125 | Vim: Out-of-bounds Read with libsodium-encrypted Files |
| CVE-2026-57455 | 4.0 | 2.0 | vim | vim | CWE-787 | Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length… |
| CVE-2026-53272 | 7.8 | 1.9 | Linux | Linux | CWE-416 | erofs: fix use-after-free on sbi->sync_decompress |
| CVE-2026-53273 | 7.8 | 2.0 | Linux | Linux | CWE-416 | tee: optee: prevent use-after-free when the client exits before the supplicant |
| CVE-2026-53255 | 7.1 | 2.0 | Linux | Linux | CWE-125 | Bluetooth: MGMT: validate advertising TLV before type checks |
| CVE-2026-57454 | 6.8 | 1.9 | vim | vim | CWE-125 | Vim: Out-of-bounds Read with Text Properties |
| CVE-2026-57589 | 7.8 | 1.9 | OpenBSD | OpenBSD | CWE-416 | sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing loca… |
| CVE-2026-57451 | 6.1 | 1.8 | vim | vim | CWE-125 | Vim: Out-of-bounds Read in Text Property Count |
| CVE-2026-53259 | 7.8 | 1.8 | Linux | Linux | CWE-416 | ipv6: anycast: insert aca into global hash under idev->lock |
| CVE-2026-33612 | 7.5 | 1.8 | PowerDNS | Recursor | CWE-349 | ZoneToCache can poison the cache |
| CVE-2026-53263 | 5.5 | 1.8 | Linux | Linux | CWE-193 | 6lowpan: fix off-by-one in multicast context address compression |
| CVE-2026-53261 | 5.5 | 1.7 | Linux | Linux | CWE-401 | devlink: Release nested relation on devlink free |
| CVE-2026-53269 | 5.5 | 1.8 | Linux | Linux | — | netfilter: synproxy: add mutex to guard hook reference counting |
| CVE-2026-53271 | 5.5 | 1.7 | Linux | Linux | CWE-476 | ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers |
| CVE-2026-55967 | 2.0 | 1.8 | wolfSSL | wolfSSL | CWE-323 | AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enab… |
| CVE-2026-56129 | 6.8 | 1.7 | Dynabook Inc. | Generic IO & Memory Access driver | CWE-782 | Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and… |
| CVE-2026-53276 | 7.8 | 1.6 | Linux | Linux | CWE-416 | Bluetooth: ISO: Fix a use-after-free of the hci_conn pointer |
| CVE-2026-53258 | 5.5 | 1.6 | Linux | Linux | CWE-401 | wifi: fix leak if split 6 GHz scanning fails |
| CVE-2026-8720 | 5.9 | 1.5 | wolfSSL | wolfSSL | CWE-354 | HMAC-BLAKE2 final discards message when key length exceeds block size |
| CVE-2026-9651 | 6.7 | 1.4 | Schneider Electric | EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller | CWE-732 | CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability t… |
| CVE-2026-53277 | 8.8 | 1.3 | Linux | Linux | CWE-662 | KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT… |
| CVE-2026-53155 | 5.5 | 1.3 | Linux | Linux | — | mm/huge_memory: use correct flags for device private PMD entry |
| CVE-2026-53169 | 5.5 | 1.3 | Linux | Linux | CWE-617 | accel/ethosu: reject NPU_OP_RESIZE commands from userspace |
| CVE-2026-53204 | 5.5 | 1.3 | Linux | Linux | CWE-476 | firmware: stratix10-rsu: Fix NULL deref on rsu_send_msg() timeout in probe |
| CVE-2026-53206 | 5.5 | 1.3 | Linux | Linux | — | accel/ivpu: Add bounds check for firmware runtime memory |
| CVE-2026-53222 | 5.5 | 1.3 | Linux | Linux | CWE-401 | ptp: ocp: fix resource freeing order |
| CVE-2026-53243 | 5.5 | 1.3 | Linux | Linux | CWE-908 | rseq: Fix using an uninitialized stack variable in rseq_exit_user_update() |
| CVE-2026-13218 | 4.2 | 1.3 | Red Hat | Red Hat OpenShift Virtualization 4 | CWE-61 | Kubevirt: kubevirt: symlink following in writetocachedfile allows host file o… |
| CVE-2026-53250 | 7.8 | 1.2 | Linux | Linux | CWE-367 | xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata() |
| CVE-2026-54679 | 6.9 | 1.1 | jqlang | jq | CWE-190 | jq: potential integer overflow in jvp_string_append |
| CVE-2026-46733 | 7.8 | 1.1 | Dell | Display and Peripheral Manager | CWE-284 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, co… |
| CVE-2026-4930 | 7.1 | 1.0 | silabs.com | Simplicity SDK | CWE-331 | DPA Countermeasures weakening on Series 3 devices |
| CVE-2026-53257 | 5.5 | 1.0 | Linux | Linux | — | wifi: cfg80211: enforce HE/EHT cap/oper consistency |
| CVE-2026-53145 | 7.8 | 0.9 | Linux | Linux | CWE-367 | drm/gem: Try to fix change_handle ioctl, attempt 4 |
| CVE-2026-53153 | 7.8 | 0.9 | Linux | Linux | CWE-820 | mm/list_lru: drain before clearing xarray entry on reparent |
| CVE-2026-53185 | 7.8 | 0.8 | Linux | Linux | CWE-416 | zram: fix use-after-free in zram_bvec_write_partial() |
| CVE-2026-53207 | 5.5 | 0.7 | Linux | Linux | CWE-667 | mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison |
| CVE-2026-57438 | 2.2 | 0.7 | sparklemotion | nokogiri | CWE-416 | Nokogiri: Possible Use-After-Free in XInclude Processing |
| CVE-2026-53197 | 5.5 | 0.7 | Linux | Linux | CWE-667 | xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state() |
| CVE-2026-53231 | 5.5 | 0.3 | Linux | Linux | CWE-667 | net: phy: don't try to setup PHY-driven SFP cages when using genphy |
| CVE-2026-46732 | 7.0 | 0.1 | Dell | Display and Peripheral Manager | CWE-362 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contai… |
| CVE-2026-6412 | 2.3 | 0.1 | wolfSSL | wolfSSL | CWE-327 | Continued acceptance of SHA-1/MD5 digests in certificate processing |
| CVE-2026-46734 | 7.8 | 0.0 | Dell | Display and Peripheral Manager | CWE-295 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contai… |