boxscore/security
Thursday, June 25, 2026 · all times UTC← 2026-06-24 · archive · 2026-06-26 →

Edition of June 25, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–468 of 468
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-532375.52.4LinuxLinuxCWE-476gpio: mvebu: fix NULL pointer dereference in suspend/resume
CVE-2026-532415.52.4LinuxLinuxALSA: seq: dummy: fix UMP event stack overread
CVE-2026-532515.52.4LinuxLinuxCWE-772Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync
CVE-2026-532668.82.3LinuxLinuxnetfilter: bridge: make ebt_snat ARP rewrite writable
CVE-2026-532707.82.3LinuxLinuxipvs: clear the svc scheduler ptr early on edit
CVE-2026-100986.32.2wolfSSLwolfSSLCWE-295OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_status
CVE-2026-60916.02.3wolfSSLwolfSSLCWE-295Partial-chain verification accepts untrusted intermediate as trust anchor
CVE-2026-531415.52.2LinuxLinuxdrm/v3d: Fix global performance monitor reference counting
CVE-2026-531645.52.2LinuxLinuxiommu/dma: Do not try to iommu_map a 0 length region in swiotlb
CVE-2026-532115.52.3LinuxLinuxCWE-401netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register
CVE-2026-532745.52.3LinuxLinuxnet/smc: fix sleep-inside-lock in __smc_setsockopt() causing local DoS
CVE-2026-532008.82.2LinuxLinuxKVM: arm64: nv: Fix handling of XN[0] when !FEAT_XNX
CVE-2026-531727.82.2LinuxLinuxCWE-125accel/ethosu: fix IFM region index out-of-bounds in command stream parser
CVE-2026-531737.82.2LinuxLinuxCWE-787accel/ethosu: fix OOB write in ethosu_gem_cmdstream_copy_and_validate()
CVE-2026-531747.82.2LinuxLinuxovl: keep err zero after successful ovl_cache_get()
CVE-2026-532657.82.2LinuxLinuxdm cache policy smq: check allocation under invalidate lock
CVE-2026-532677.82.1LinuxLinuxCWE-674netfilter: nft_ct: bail out on template ct in get eval
CVE-2021-479867.72.2parse-communityparse-serverCWE-494Parse Server - Unreviewed Code Execution via Malicious Version Tags
CVE-2021-479877.72.2parse-communityparse-serverCWE-494Parse Server - Arbitrary Code Execution via Malicious Version Tags
CVE-2026-558925.52.2vimvimCWE-787Vim: Out-of-bounds Write in Spell File Prefix Dump
CVE-2026-466115.32.1nicolargoglancesCWE-346Glances: XML-RPC Server Missing Host Header Validation Enables DNS Rebinding …
CVE-2026-22994.32.2MattermostMattermost Google Drive PluginCWE-862Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint
CVE-2026-532627.82.1LinuxLinuxl2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()
CVE-2026-532265.52.0LinuxLinuxCWE-401gpio: rockchip: fix generic IRQ chip leak on remove
CVE-2026-559646.32.0wolfSSLwolfSSLCWE-295Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA (temp…
CVE-2026-574525.52.0vimvimCWE-125Vim: Out-of-bounds Read with libsodium-encrypted Files
CVE-2026-574554.02.0vimvimCWE-787Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length…
CVE-2026-532727.81.9LinuxLinuxCWE-416erofs: fix use-after-free on sbi->sync_decompress
CVE-2026-532737.82.0LinuxLinuxCWE-416tee: optee: prevent use-after-free when the client exits before the supplicant
CVE-2026-532557.12.0LinuxLinuxCWE-125Bluetooth: MGMT: validate advertising TLV before type checks
CVE-2026-574546.81.9vimvimCWE-125Vim: Out-of-bounds Read with Text Properties
CVE-2026-575897.81.9OpenBSDOpenBSDCWE-416sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing loca…
CVE-2026-574516.11.8vimvimCWE-125Vim: Out-of-bounds Read in Text Property Count
CVE-2026-532597.81.8LinuxLinuxCWE-416ipv6: anycast: insert aca into global hash under idev->lock
CVE-2026-336127.51.8PowerDNSRecursorCWE-349ZoneToCache can poison the cache
CVE-2026-532635.51.8LinuxLinuxCWE-1936lowpan: fix off-by-one in multicast context address compression
CVE-2026-532615.51.7LinuxLinuxCWE-401devlink: Release nested relation on devlink free
CVE-2026-532695.51.8LinuxLinuxnetfilter: synproxy: add mutex to guard hook reference counting
CVE-2026-532715.51.7LinuxLinuxCWE-476ksmbd: fix NULL-deref of opinfo->conn in oplock/lease break notifiers
CVE-2026-559672.01.8wolfSSLwolfSSLCWE-323AES-GCM streaming APIs do not reject >64 GiB cumulative single messages, enab…
CVE-2026-561296.81.7Dynabook Inc.Generic IO & Memory Access driverCWE-782Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and…
CVE-2026-532767.81.6LinuxLinuxCWE-416Bluetooth: ISO: Fix a use-after-free of the hci_conn pointer
CVE-2026-532585.51.6LinuxLinuxCWE-401wifi: fix leak if split 6 GHz scanning fails
CVE-2026-87205.91.5wolfSSLwolfSSLCWE-354HMAC-BLAKE2 final discards message when key length exceeds block size
CVE-2026-96516.71.4Schneider ElectricEasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & ControllerCWE-732CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability t…
CVE-2026-532778.81.3LinuxLinuxCWE-662KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT…
CVE-2026-531555.51.3LinuxLinuxmm/huge_memory: use correct flags for device private PMD entry
CVE-2026-531695.51.3LinuxLinuxCWE-617accel/ethosu: reject NPU_OP_RESIZE commands from userspace
CVE-2026-532045.51.3LinuxLinuxCWE-476firmware: stratix10-rsu: Fix NULL deref on rsu_send_msg() timeout in probe
CVE-2026-532065.51.3LinuxLinuxaccel/ivpu: Add bounds check for firmware runtime memory
CVE-2026-532225.51.3LinuxLinuxCWE-401ptp: ocp: fix resource freeing order
CVE-2026-532435.51.3LinuxLinuxCWE-908rseq: Fix using an uninitialized stack variable in rseq_exit_user_update()
CVE-2026-132184.21.3Red HatRed Hat OpenShift Virtualization 4CWE-61Kubevirt: kubevirt: symlink following in writetocachedfile allows host file o…
CVE-2026-532507.81.2LinuxLinuxCWE-367xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata()
CVE-2026-546796.91.1jqlangjqCWE-190jq: potential integer overflow in jvp_string_append
CVE-2026-467337.81.1DellDisplay and Peripheral ManagerCWE-284Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, co…
CVE-2026-49307.11.0silabs.comSimplicity SDKCWE-331DPA Countermeasures weakening on Series 3 devices
CVE-2026-532575.51.0LinuxLinuxwifi: cfg80211: enforce HE/EHT cap/oper consistency
CVE-2026-531457.80.9LinuxLinuxCWE-367drm/gem: Try to fix change_handle ioctl, attempt 4
CVE-2026-531537.80.9LinuxLinuxCWE-820mm/list_lru: drain before clearing xarray entry on reparent
CVE-2026-531857.80.8LinuxLinuxCWE-416zram: fix use-after-free in zram_bvec_write_partial()
CVE-2026-532075.50.7LinuxLinuxCWE-667mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison
CVE-2026-574382.20.7sparklemotionnokogiriCWE-416Nokogiri: Possible Use-After-Free in XInclude Processing
CVE-2026-531975.50.7LinuxLinuxCWE-667xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state()
CVE-2026-532315.50.3LinuxLinuxCWE-667net: phy: don't try to setup PHY-driven SFP cages when using genphy
CVE-2026-467327.00.1DellDisplay and Peripheral ManagerCWE-362Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contai…
CVE-2026-64122.30.1wolfSSLwolfSSLCWE-327Continued acceptance of SHA-1/MD5 digests in certificate processing
CVE-2026-467347.80.0DellDisplay and Peripheral ManagerCWE-295Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contai…