boxscore/security
Sunday, July 19, 2026 · all times UTC← 2026-07-18 · archive · 2026-07-20 →

465 CVEs published July 19, 2026: 58 critical, 212 high, 72 medium, 18 low; 0 in KEV; 0 with a public exploit reference; 105 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 440 in the results table.

Standings

League
MTDYTD2025 same span2025 full
CVEs published51551747313012563
KEV catalog size1670

761 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux4711951178107658912730.27.8.0013+371
google941358150612555387460.47.8.0024-590
microsoft64613579193130612378312.37.8.0039+426
red hat652571410612413400.06.5.0026-10
apple0991236629377.16.5.0031-14
canonical42436105000.05.5.0011+3
suse82141241000.08.5.0033+4
freebsd01601240000.07.8.00150
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco163961690961230.87.5.0050+7
ubiquiti2536142110438.38.8.0036+20
palo alto networks1425021471428.04.7.0021+5
netgear62300221800.04.6.0022-11
fortinet14223610028522.76.7.0036+12
f58175830715.98.6.0057+2
vmware81117212100.08.0.0031+5
ivanti211232033545.58.8.3445-2
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache78231479082114010.47.5.0048-8
mozilla66212183201300.06.5.0025-43
drupal465165355512.05.9.0018+46
gitlab74005276425.04.7.0024-4
github5111280000.06.0.0026+5
docker070520100.08.2.0016-4
jenkins000000600
joomla000000100
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle12711321161844031.18.8.0040-242
adobe942402610210547541.77.5.0021-35
ibm361605254540700.07.5.0026+25
progress101931420900.07.5.0034+5
solarwinds07122011457.17.5.0835-3
veeam042200400.09.0.0046-1
zohocorp031110000.08.4.01700
servicenow111000200.09.5.2673+1
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0025+10
synology02325133000.05.6.0025-5
siemens7161870100.07.6.00190
d-link11405352617.16.0.0058-8
abb170430000.07.2.0018-4
schneider electric060420100.07.8.0024-1
moxa050320000.07.0.0029-5
dahua030111200.06.9.0036-3
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester46117006156000.05.5.0026+9
openclaw441110583914000.07.0.0022-17
dell3793442433211.16.8.0019+10
capgo2283242381000.07.1.0028+19
nvidia40791252150000.07.8.0019+34
imagemagick3273155512300.05.3.0017+4
spring073231391000.06.5.0024-71
itsourcecode1568001949000.02.1.0020-7

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-48282.992499.910.0
CVE-2026-39808.912199.8
CVE-2026-48908.881399.810.0
CVE-2026-34910.869699.710.0
CVE-2026-34908.851999.710.0
CVE-2026-56290.832599.710.0
CVE-2026-20230.832199.78.6
CVE-2026-48939.825099.610.0
CVE-2026-50522.769899.59.8
CVE-2026-15410.763599.57.2
Highest CVSS
CVECVSSEPSSNote
CVE-2026-4828210.0.9924KEV
CVE-2026-4890810.0.8813KEV
CVE-2026-3491010.0.8696KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-5629010.0.8325KEV
CVE-2026-4893910.0.8250KEV
CVE-2026-5629110.0.7607KEV
CVE-2026-1540910.0.7422KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-5016010.0.1775
Most disclosures (vendor)
VendorCVEs
linux885
microsoft647
google500
red hat118
apache113
adobe107
ibm100
capgo80
sourcecodester58
dell48
Most KEV additions (YTD)
VendorKEV
microsoft31
cisco12
apple7
google6
fortinet5
ivanti5
adobe4
solarwinds4
synacor4
linux3
Most-affected ecosystems
EcosystemAdvisories
Maven56
PyPI5
npm5
NuGet3
Packagist1
Fastest to KEV
CVEVendorDays
CVE-2008-4128Cisco0
CVE-2023-4346KNX Association0
CVE-2025-67038Lantronix0
CVE-2026-12569PTC0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-20230Cisco0
CVE-2026-25089Fortinet0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104Accellion2021-11-171705
CVE-2021-27102Accellion2021-11-171705
CVE-2021-27101Accellion2021-11-171705
CVE-2021-27103Accellion2021-11-171705
CVE-2021-21017Adobe2021-11-171705
CVE-2021-28550Adobe2021-11-171705
CVE-2021-42013Apache2021-11-171705
CVE-2021-41773Apache2021-11-171705
CVE-2021-30858Apple2021-11-171705
CVE-2021-30860Apple2021-11-171705

Transactions

EXPLOIT PUBLISHEDCVE-2026-16199 (nextlevelbuilder GoClaw). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16200 (zevorn rt-claw). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16201 (zevorn rt-claw). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16202 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16203 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16204 (zevorn rt-claw). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16205 (Pluck CMS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16209 (Gerapy). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16210 (newpanjing simpleui). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16211 (allegro). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16212 (awesto django-shop). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16214 (geex-arts django-jet). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16215 (geex-arts django-jet). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16216 (geex-arts django-jet). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16217 (guohongze adminset). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16219 (Croogo CMS). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16220 (code-projects Online Examination System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16222 (1Panel-dev CordysCRM). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16223 (1Panel-dev CordysCRM). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16225 (davenardella snap7). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16227 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16228 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.

EXPLOIT PUBLISHEDCVE-2026-16229 (itsourcecode Courier Management System). Public exploit reference added.

DUE DATE PASSEDCVE-2026-46817 (Oracle Corporation Oracle Payments). CISA remediation deadline was July 18, 2026; still in catalog.

Yesterday's Results

465 CVEs published. 25 box scores and 375 table rows below; the remaining 65 continue on page 2 — every CVE is listed, nothing truncated.

Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  N   10.0   .0100   60.1     —
AFFECTED
  Product   Versions            Fixed
  firmware  < 2.7.21.1370b23 –  —
TIMELINE
  May 5   Reserved by CNA
  Jul 19  Published (CNA: GitHub_M)
CWE-94, CWE-829 · CNA: GitHub_M · 4 references · NVD status: Deferred
Linux Linux — scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0075   51.8     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    e48354ce078c079996f89d715dfa44814b4eba01 –  —
  Linux    3.1 –                                       5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Awaiting Analysis
Linux Linux — scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0075   51.8     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    e48354ce078c079996f89d715dfa44814b4eba01 –  —
  Linux    3.1 –                                       5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Awaiting Analysis
Linux Linux — xfrm: esp: restore combined single-frag length gate
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0070   50.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    c075c3ea031757f8ea2d34567565b61a868c08d5 –  —
  Linux    5.18 –                                      5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Awaiting Analysis
Linux Linux — ipv6: exthdrs: refresh nh after handling HAO option
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0069   50.0     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    a831f5bbc89a9978795504be9e1ff412043f8f77 –  —
  Linux    2.6.19 –                                    5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Awaiting Analysis
Linux Linux — ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0069   50.0     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 –  —
  Linux    2.6.12 –                                    5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Awaiting Analysis
Linux Linux — ksmbd: reject non-VALID session in compound request branch
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0069   49.8     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    eb947403518ea3d93f6d89264bb1f5416bb0c7d0 –  —
  Linux    6.4 –                                       5.15.211
TIMELINE
  Jun 9   Reserved by CNA
  Jul 19  Published (CNA: Linux)
CWE-476 · CNA: Linux · 8 references · NVD status: Analyzed
Linux Linux — scsi: target: iscsi: Validate CHAP_R length before base64 decode
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0066   48.8     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    1e5733883421495908f3b90d9d807663038b4136 –  —
  Linux    6.0 –                                       6.1.176
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 6 references · NVD status: Awaiting Analysis
Linux Linux — ipv6: fix possible infinite loop in fib6_select_path()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0065   48.0     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    d0ec61c9f3583b76aebdbb271f5c0d3fcccd48b2 –  —
  Linux    6.13 –                                      6.1.176
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 6 references · NVD status: Awaiting Analysis
Linux Linux — xfrm: input: hold netns during deferred transport reinjection
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  H  H    8.8   .0063   47.4     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    7b3801927e52f8621de311277f7fc727635019e7 –  —
  Linux    5.6 –                                       5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Awaiting Analysis
Linux Linux — ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   L   N  U  H  N  H    8.1   .0063   47.2     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    282cbbb476b9f35793452bc461934af4c7eca169 –  —
  Linux    6.6.140 –                                   —
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 7 references · NVD status: Awaiting Analysis
Linux Linux — net/handshake: Drain pending requests at net namespace exit
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0062   46.7     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    3b3009ea8abb713b022d94fba95ec270cf6e7eae –  —
  Linux    6.4 –                                       6.12.93
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 4 references · NVD status: Awaiting Analysis
Linux Linux — netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  H    8.2   .0062   46.8     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1 –  —
  Linux    2.6.15 –                                    5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Awaiting Analysis
Linux Linux — net/handshake: hand off the pinned file reference to accept_doit
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0060   45.8     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    3b3009ea8abb713b022d94fba95ec270cf6e7eae –  —
  Linux    6.4 –                                       6.18.44
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 3 references · NVD status: Awaiting Analysis
Linux Linux — net: mana: Skip redundant detach on already-detached port
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0058   44.8     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    fb9f98e1041a30dd5766620a2a64cb472b54caa9 –  —
  Linux    7.0 –                                       6.18.35
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 3 references · NVD status: Awaiting Analysis
Linux Linux — net: ethernet: cortina: Make RX SKB per-port
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0055   43.5     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 –  —
  Linux    4.16 –                                      5.10.258
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Awaiting Analysis
Linux Linux — batman-adv: tt: fix negative last_changeset_len
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0055   43.5     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    a73105b8d4c765d9ebfb664d0a66802127d8e4c7 –  —
  Linux    3.1 –                                       5.10.258
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Analyzed
Linux Linux — net: bcmgenet: keep RBUF EEE/PM disabled
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0055   43.5     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    6ef398ea60d931b97d69ed080bd0bd00fac38ec6 –  —
  Linux    3.19 –                                      5.10.258
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Analyzed
Linux Linux — NFSv4/flexfiles: reject zero filehandle version count
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0053   42.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    d67ae825a59d639e4d8b82413af84d854617a87e –  —
  Linux    4.0 –                                       5.10.261
TIMELINE
  Jun 9   Reserved by CNA
  Jul 19  Published (CNA: Linux)
CWE-476 · CNA: Linux · 8 references · NVD status: Analyzed
Linux Linux — nfsd: fix posix_acl leak on SETACL decode failure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0053   42.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    a257cdd0e2179630d3201c32ba14d7fcb3c3a055 –  —
  Linux    2.6.13 –                                    5.10.260
TIMELINE
  Jun 9   Reserved by CNA
  Jul 19  Published (CNA: Linux)
CWE-401 · CNA: Linux · 8 references · NVD status: Analyzed
Linux Linux — tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0052   41.8     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    4cb47a8644cc9eb8ec81190a50e79e6530d0297f –  —
  Linux    5.9 –                                       5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Awaiting Analysis
Linux Linux — NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0052   41.6     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    6b7f3cf96364eaf597940cb5c68a682894829915 –  —
  Linux    4.0 –                                       5.15.211
TIMELINE
  Jun 9   Reserved by CNA
  Jul 19  Published (CNA: Linux)
CWE-476 · CNA: Linux · 7 references · NVD status: Analyzed
Linux Linux — NFSD: Fix SECINFO_NO_NAME decode error cleanup
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0051   41.4     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    5e76b25d7cc82c148d391c0c43b884e6427cb302 –  —
  Linux    6.1 –                                       5.10.260
TIMELINE
  Jun 9   Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Analyzed
Linux Linux — nfsd: release layout stid on setlease failure
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0051   41.4     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    c5c707f96fc9a6e5a57ca5baac892673270abe3d –  —
  Linux    4.0 –                                       5.10.261
TIMELINE
  Jun 9   Reserved by CNA
  Jul 19  Published (CNA: Linux)
CWE-476 · CNA: Linux · 8 references · NVD status: Analyzed
Linux Linux — ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0051   41.4     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3 –  —
  Linux    5.7 –                                       5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · 8 references · NVD status: Awaiting Analysis
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-639939.841.4LinuxLinuxvxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
CVE-2026-640079.841.4LinuxLinuxnetfilter: synproxy: refresh tcphdr after skb_ensure_writable
CVE-2026-640469.841.4LinuxLinuxnet: tls: prevent chain-after-chain in plain text SG
CVE-2026-640479.841.4LinuxLinuxnet: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring
CVE-2026-640559.841.4LinuxLinuxnet: ethernet: cortina: Carry over frag counter
CVE-2026-639929.141.4LinuxLinuxtunnels: do not assume transport header in iptunnel_pmtud_check_icmp()
CVE-2026-641167.541.3LinuxLinuxCWE-476ipv6: ioam: add NULL check for idev in ipv6_hop_ioam()
CVE-2026-638009.840.5LinuxLinuxCWE-416pNFS: Fix use-after-free in pnfs_update_layout()
CVE-2026-638089.840.5LinuxLinuxexfat: fix potential use-after-free in exfat_find_dir_entry()
CVE-2026-641029.840.5LinuxLinuxCWE-125RDMA/siw: Reject MPA FPDU length underflow before signed receive math
CVE-2026-641139.840.5LinuxLinuxCWE-416ixgbevf: fix use-after-free in VEPA multicast source pruning
CVE-2026-640009.840.0LinuxLinuxnet: hsr: fix potential OOB access in supervision frame handling
CVE-2026-641329.840.0LinuxLinuxCWE-416ipv6: ioam: refresh hdr pointer before ioam6_event()
CVE-2026-641369.840.0LinuxLinuxsmb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
CVE-2026-533947.539.9LinuxLinuxCWE-401nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
CVE-2026-533849.839.9LinuxLinuxCWE-416serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
CVE-2026-640339.839.9LinuxLinuxRDMA/rtrs: Fix use-after-free in path file creation cleanup
CVE-2026-638018.839.7LinuxLinuxCWE-416tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
CVE-2026-641429.839.3LinuxLinuxCWE-416ksmbd: close durable scavenger races against m_fp_list lookups
CVE-2026-640487.539.3LinuxLinuxnet/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot
CVE-2026-6379510.039.2LinuxLinuxCWE-4169p: avoid putting oldfid in p9_client_walk() error path
CVE-2026-641487.539.0LinuxLinuxCWE-835pds_core: fix error handling in pdsc_devcmd_wait
CVE-2026-533908.138.7LinuxLinuxCWE-125ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
CVE-2026-639557.538.5LinuxLinuxmm/vmalloc: do not trigger BUG() on BH disabled context
CVE-2026-641229.838.1LinuxLinuxCWE-416net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover
CVE-2026-637968.837.7LinuxLinuxCWE-125ocfs2: reject oversized group bitmap descriptors
CVE-2026-640259.837.0LinuxLinuxbpf, skmsg: fix verdict sk_data_ready racing with ktls rx
CVE-2026-640619.837.0LinuxLinuxnetfs: Fix early put of sink folio in netfs_read_gaps()
CVE-2026-639768.836.9LinuxLinuxBluetooth: l2cap: clear chan->ident on ECRED reconfiguration success
CVE-2026-640169.836.8LinuxLinuxksmbd: fix durable reconnect error path file lifetime
CVE-2026-640359.836.8LinuxLinuxigc: set tx buffer type for SMD frames
CVE-2026-640669.836.8LinuxLinuxnetfs: Fix netfs_read_to_pagecache() to pause on subreq failure
CVE-2026-640699.836.8LinuxLinuxnetfs: Fix cancellation of a DIO and single read subrequests
CVE-2026-641509.836.8LinuxLinuxnetfilter: nft_inner: release local_lock before re-enabling softirqs
CVE-2026-639807.536.7LinuxLinuxnet/handshake: Use spin_lock_bh for hn_lock
CVE-2026-640037.536.7LinuxLinuxscsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues
CVE-2026-641417.536.7LinuxLinuxCWE-476ksmbd: fix null pointer dereference in compare_guid_key()
CVE-2026-640379.835.8LinuxLinuxwifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled
CVE-2026-640919.835.5LinuxLinuxCWE-367batman-adv: tt: fix TOCTOU race for reported vlans
CVE-2026-641388.834.6LinuxLinuxksmbd: validate SID in parent security descriptor during ACL inheritance
CVE-2026-638259.834.6LinuxLinuxgcov: use atomic counter updates to fix concurrent access crashes
CVE-2026-162095.534.2n/aGerapyCWE-287Gerapy Project Upload Endpoint views.py missing authentication
CVE-2026-641609.833.9LinuxLinuxnetfs: Fix potential for tearing in ->remote_i_size and ->zero_point
CVE-2026-162076.333.0n/adjango-tastypieCWE-598django-tastypie authentication.py ApiKeyAuthentication get request method wit…
CVE-2026-162105.532.9newpanjingsimpleuiCWE-287newpanjing simpleui AjaxAdmin AJAX Endpoint admin.py self.get_action missing …
CVE-2026-638938.131.8LinuxLinuxthunderbolt: property: Reject u32 wrap in tb_property_entry_valid()
CVE-2026-640249.431.7LinuxLinuxtcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction
CVE-2026-640679.831.1LinuxLinuxnetfs: Fix missing barriers when accessing stream->subrequests locklessly
CVE-2026-640689.831.1LinuxLinuxnetfs: Fix missing locking around retry adding new subreqs
CVE-2026-641407.529.0LinuxLinuxCWE-476ksmbd: fix null pointer dereference in proc_show_files()
CVE-2026-638309.428.3LinuxLinuxnet: skmsg: preserve sg.copy across SG transforms
CVE-2026-641757.528.0LinuxLinuxwifi: iwlwifi: mld: stop TX during firmware restart
CVE-2026-638579.827.8LinuxLinuxnet: airoha: Do not read uninitialized fragment address in airoha_dev_xmit()
CVE-2026-641629.827.8LinuxLinuxidpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()
CVE-2026-639158.827.5LinuxLinuxnfc: hci: fix out-of-bounds read in HCP header parsing
CVE-2026-639168.827.5LinuxLinuxHID: wacom: Fix OOB write in wacom_hid_set_device_mode()
CVE-2026-639758.827.5LinuxLinuxBluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp
CVE-2026-533957.527.4LinuxLinuxCWE-674nfsd: fix dead ACL conflict guard in nfsd4_create
CVE-2026-640207.527.4LinuxLinuxnvme-pci: fix dma_vecs leak on p2p memory
CVE-2026-162192.127.3CroogoCMSCWE-22Croogo CMS Admin File Manager FileManager.php isEditable path traversal
CVE-2026-639258.127.1LinuxLinuxmacsec: fix replay protection at XPN lower-PN wrap
CVE-2026-639478.826.6LinuxLinuxBluetooth: HIDP: fix missing length checks in hidp_input_report()
CVE-2026-640938.826.6LinuxLinuxbatman-adv: tp_meter: directly shut down timer on cleanup
CVE-2026-638898.126.3LinuxLinuxscsi: scsi_transport_fc: Widen FPIN pname walker counter to u32
CVE-2026-639468.825.6LinuxLinuxBluetooth: ISO: fix UAF in iso_recv_frame
CVE-2026-639448.825.2LinuxLinuxBluetooth: hci_sync: fix UAF in hci_le_create_cis_sync
CVE-2026-638678.224.9LinuxLinuxmptcp: close TOCTOU race while computing rcv_wnd
CVE-2026-162155.524.6geex-artsdjango-jetCWE-862geex-arts django-jet OAuth Credential Revoke authorization
CVE-2026-639748.824.5LinuxLinuxBluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close
CVE-2026-162042.124.1zevornrt-clawCWE-74zevorn rt-claw Telegram-to-AI Tool Execution Flow script.c tool_run_script_ex…
CVE-2026-162015.523.8zevornrt-clawCWE-200zevorn rt-claw http_request net.c claw_net_post information disclosure
CVE-2026-162005.521.3zevornrt-clawCWE-285zevorn rt-claw RPC swarm.c claw_tool_invoke authorization
CVE-2026-640888.820.6LinuxLinuxbatman-adv: tt: fix negative tt_buff_len
CVE-2026-425667.520.4meshtasticfirmwareCWE-20Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh…
CVE-2026-162202.119.7code-projectsOnline Examination SystemCWE-79code-projects Online Examination System account.php cross site scripting
CVE-2026-162292.119.7itsourcecodeCourier Management SystemCWE-79itsourcecode Courier Management System index.php cross site scripting
CVE-2026-533967.119.0LinuxLinuxCWE-401nfsd: fix posix_acl leak and ignored error in nfsd4_create_file
CVE-2026-640957.118.9LinuxLinuxbatman-adv: bla: avoid double decrement of bla.num_requests
CVE-2026-162275.518.2SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System edit_subject.php sql injection
CVE-2026-162285.518.2SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection
CVE-2026-63891await18.3LinuxLinuxthunderbolt: property: Cap recursion depth in __tb_property_parse_dir()
CVE-2026-640108.817.2LinuxLinuxnfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()
CVE-2026-640968.817.2LinuxLinuxCWE-416batman-adv: mcast: fix use-after-free in orig_node RCU release
CVE-2026-162217.517.1fast-urifast-uriCWE-436fast-uri vulnerable to host confusion via literal backslash authority delimiter
CVE-2026-641788.816.5LinuxLinuxCWE-416Bluetooth: bnep: Fix UAF read of dev->name
CVE-2026-63895await15.8LinuxLinuxusb: gadget: f_fs: copy only received bytes on short ep0 read
CVE-2026-638318.815.8LinuxLinuxmac802154: llsec: add skb_cow_data() before in-place crypto
CVE-2026-640308.815.2LinuxLinuxwifi: mac80211: bounds-check link_id in ieee80211_ml_epcs
CVE-2026-641178.814.6LinuxLinuxCWE-416wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb
CVE-2026-162252.113.8davenardellasnap7CWE-119davenardella snap7 s7_peer.cpp NegotiatePDULength out-of-bounds write
CVE-2026-63899await13.5LinuxLinuxUSB: serial: mxuport: fix memory corruption with small endpoint
CVE-2026-63901await13.5LinuxLinuxUSB: serial: digi_acceleport: fix memory corruption with small endpoints
CVE-2026-638328.813.2LinuxLinuxwifi: mt76: add wcid publish check in mt76_sta_add
CVE-2026-638668.813.2LinuxLinuxwifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link()
CVE-2026-162245.313.0jxxghpMoviePilotCWE-266jxxghp MoviePilot Application API improper authorization
CVE-2026-162142.112.7geex-artsdjango-jetCWE-285geex-arts django-jet Dashboard views.py authorization
CVE-2026-162172.112.7guohongzeadminsetCWE-285guohongze adminset Delivery Deployment Endpoint deli.py authorization
CVE-2026-63892await12.7LinuxLinuxthunderbolt: property: Reject dir_len < 4 to prevent size_t underflow
CVE-2026-162265.112.5SourceCodesterPizzafy Ecommerce SystemCWE-284SourceCodester Pizzafy Ecommerce System admin_class_novo.php save_settings un…
CVE-2026-63928await12.3LinuxLinuxUSB: serial: omninet: fix memory corruption with small endpoint
CVE-2026-162222.112.11Panel-devCordysCRMCWE-9181Panel-dev CordysCRM Third Party Endpoint TokenService.java server-side reque…
CVE-2026-162232.112.11Panel-devCordysCRMCWE-9181Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java …
CVE-2026-638697.611.6LinuxLinuxwifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap
CVE-2026-63890await11.6LinuxLinuxscsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker
CVE-2026-63897await11.6LinuxLinuxUSB: serial: mct_u232: fix missing interrupt-in transfer sanity check
CVE-2026-63898await11.6LinuxLinuxUSB: serial: mct_u232: fix memory corruption with small endpoint
CVE-2026-63900await11.6LinuxLinuxUSB: serial: keyspan: fix missing indat transfer sanity check
CVE-2026-63902await11.6LinuxLinuxUSB: serial: cypress_m8: validate interrupt packet headers
CVE-2026-63903await11.6LinuxLinuxUSB: serial: belkin_sa: validate interrupt status length
CVE-2026-63904await11.6LinuxLinuxusb: usbtmc: check URB actual_length for interrupt-IN notifications
CVE-2026-63905await11.6LinuxLinuxusbip: vudc: Fix use after free bug in vudc_remove due to race condition
CVE-2026-63908await11.6LinuxLinuxInput: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem
CVE-2026-63931await11.6LinuxLinuxiio: chemical: scd30: fix division by zero in write_raw
CVE-2026-63933await11.6LinuxLinuxiio: gyro: adis16260: fix division by zero in write_raw
CVE-2026-63948await11.6LinuxLinuxBluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn
CVE-2026-63956await11.6LinuxLinuxUSB: serial: cypress_m8: fix memory corruption with small endpoint
CVE-2026-63957await11.6LinuxLinuxUSB: serial: safe_serial: fix memory corruption with small endpoint
CVE-2026-63958await11.7LinuxLinuxusb: typec: ucsi: validate connector number in ucsi_connector_change()
CVE-2026-63960await11.6LinuxLinuxusb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()
CVE-2026-63961await11.6LinuxLinuxusb: typec: altmodes/displayport: validate count before reading Status Update…
CVE-2026-63964await11.6LinuxLinuxusb: typec: ucsi: ccg: reject firmware images without a ':' record header
CVE-2026-63967await11.6LinuxLinuxiio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer
CVE-2026-63934await11.5LinuxLinuxiio: gyro: itg3200: fix i2c read into the wrong stack location
CVE-2026-641768.111.4LinuxLinuxwifi: iwlwifi: mvm: fix driver-set TX rates on old devices
CVE-2026-162065.311.4django-oauthdjango-oauth-toolkitCWE-613django-oauth django-oauth-toolkit oauth2_validators.py _load_id_token session…
CVE-2026-161992.111.4nextlevelbuilderGoClawCWE-266nextlevelbuilder GoClaw credentialed_exec.go ExecTool.Execute improper author…
CVE-2026-63876await11.3LinuxLinuxserial: zs: Convert to use a platform device
CVE-2026-63877await11.3LinuxLinuxserial: dz: Convert to use a platform device
CVE-2026-63882await10.9LinuxLinuxdrm/amdkfd: fix NULL pointer bug in svm_range_set_attr
CVE-2026-63969await10.9LinuxLinuxipv6: fix possible infinite loop in rt6_fill_node()
CVE-2026-63973await10.9LinuxLinuxnet: mana: Add NULL guards in teardown path to prevent panic on attach failure
CVE-2026-124847.810.7keras-teamkeras-team/kerasCWE-502Unsafe Deserialization in keras.layers.TorchModuleWrapper.from_config
CVE-2026-162051.910.4PluckCMSCWE-79Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting
CVE-2026-162182.110.2hunvreusdevpushCWE-703hunvreus devpush Storage Reset Failure storage.py reset_storage improper chec…
CVE-2026-63896await10.2LinuxLinuxusb: gadget: composite: fix integer underflow in WebUSB GET_URL handling
CVE-2026-63929await10.2LinuxLinuxiio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf()
CVE-2026-63936await10.2LinuxLinuxiio: adc: mt6359: fix unchecked return value in mt6358_read_imp
CVE-2026-63943await10.2LinuxLinuxInput: xpad - fix out-of-bounds access for Share button
CVE-2026-63959await10.2LinuxLinuxusb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
CVE-2026-63962await10.2LinuxLinuxusb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()
CVE-2026-63963await10.2LinuxLinuxusb: typec: tcpm: validate VDO count in Discover Identity ACK handlers
CVE-2026-162022.010.0SourceCodesterClass and Exam Timetabling SystemCWE-79SourceCodester Class and Exam Timetabling System CYS.php cross site scripting
CVE-2026-162032.010.0SourceCodesterClass and Exam Timetabling SystemCWE-79SourceCodester Class and Exam Timetabling System forCYS.php cross site scripting
CVE-2026-63878await9.9LinuxLinuxdrm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO
CVE-2026-63880await9.9LinuxLinuxdrm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO
CVE-2026-63932await9.9LinuxLinuxiio: chemical: mhz19b: reject oversized serial replies
CVE-2026-63965await9.9LinuxLinuxiio: pressure: bmp280: fix stack leak in bmp580 trigger handler
CVE-2026-63966await9.9LinuxLinuxiio: imu: adis16550: fix stack leak in trigger handler
CVE-2026-63982await9.9LinuxLinuxnet/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop
CVE-2026-64043await9.9LinuxLinuxovpn: fix race between deleting interface and adding new peer
CVE-2026-639399.39.8LinuxLinuxKVM: SEV: Compute the correct max length of the in-GHCB scratch area
CVE-2026-63907await8.9LinuxLinuxuio: uio_pci_generic_sva: fix double free of devm_kzalloc() memory
CVE-2026-63935await8.9LinuxLinuxiio: adc: nxp-sar-adc: fix division by zero in write_raw
CVE-2026-63953await8.9LinuxLinuxmm/migrate_device: fix pgtable leak in migrate_vma_insert_huge_pmd_page
CVE-2026-64040await8.9LinuxLinuxcachefiles: Fix error return when vfs_mkdir() fails
CVE-2026-63981await8.7LinuxLinuxnet/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflow
CVE-2026-64028await8.4LinuxLinuxtracing: Avoid NULL return from hist_field_name() on truncation
CVE-2026-641395.58.3LinuxLinuxCWE-401ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow
CVE-2026-64083await8.3LinuxLinuxhwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors
CVE-2026-64085await8.3LinuxLinuxhwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer
CVE-2026-64087await8.3LinuxLinuxhwmon: (pmbus/adm1266) reject implausible blackbox record_count
CVE-2026-162121.38.2awestodjango-shopCWE-362awesto django-shop Purchase Stock inventory.py race condition
CVE-2026-63810await8.2LinuxLinuxblock: Avoid mounting the bdev pseudo-filesystem in userspace
CVE-2026-63990await8.0LinuxLinuxbonding: refuse to enslave CAN devices
CVE-2026-639389.37.9LinuxLinuxKVM: SEV: Check PSC request indices against the actual size of the buffer
CVE-2026-639409.37.9LinuxLinuxKVM: SEV: Ignore Port I/O requests of length '0'
CVE-2026-639268.47.9LinuxLinuxbpf: sockmap: fix tail fragment offset in bpf_msg_push_data
CVE-2026-640397.77.9LinuxLinuxdrm/msm/snapshot: fix dumping of the unaligned regions
CVE-2026-638817.87.5LinuxLinuxdrm/amdkfd: fix a vulnerability of integer overflow in kfd debugger
CVE-2026-63991await7.5LinuxLinuxBluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()
CVE-2026-64012await7.5LinuxLinuxnet/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_p…
CVE-2026-64014await7.5LinuxLinuxInput: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size
CVE-2026-639218.87.4LinuxLinuxip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().
CVE-2026-638847.87.4LinuxLinuxdrm/i915: Fix potential UAF in TTM object purge
CVE-2026-639068.47.3LinuxLinuxusb: musb: omap2430: Fix use-after-free in omap2430_probe()
CVE-2026-639707.87.3LinuxLinuxvsock/virtio: bind uarg before filling zerocopy skb
CVE-2026-640417.87.3LinuxLinuxASoC: codecs: fs210x: fix possible buffer overflow
CVE-2026-63822await7.1LinuxLinuxwifi: ath11k: fix warning when unbinding
CVE-2026-63834await7.2LinuxLinuxbatman-adv: tp_meter: restrict number of unacked list entries
CVE-2026-63835await7.2LinuxLinuxbatman-adv: v: prevent OGM aggregation on disabled hardif
CVE-2026-63836await7.2LinuxLinuxbatman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
CVE-2026-64071await7.1LinuxLinuxnvme-pci: fix use-after-free in nvme_free_host_mem()
CVE-2026-64072await7.1LinuxLinuxnvme: fix bio leak on mapping failure
CVE-2026-640447.86.9LinuxLinuxovpn: respect peer refcount in CMD_NEW_PEER error path
CVE-2026-63821await6.9LinuxLinuxwifi: rtw88: usb: fix memory leaks on USB write failures
CVE-2026-63826await6.9LinuxLinuxfbdev: fix use-after-free in store_modes()
CVE-2026-63949await7.0LinuxLinuxauxdisplay: line-display: fix OOB read on zero-length message_store()
CVE-2026-64006await6.9LinuxLinuxnetfilter: nf_tables: fix dst corruption in same register operation
CVE-2026-639717.86.6LinuxLinuxsctp: fix race between sctp_wait_for_connect and peeloff
CVE-2026-63838await6.6LinuxLinuxASoC: rsnd: Fix potential out-of-bounds access of component_dais[]
CVE-2026-63997await6.5LinuxLinuxethtool: module: avoid leaking a netdev ref on module flash errors
CVE-2026-64001await6.5LinuxLinuxALSA: pcm: oss: Fix setup list UAF on proc write error
CVE-2026-64052await6.5LinuxLinuxblock: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()
CVE-2026-64059await6.5LinuxLinuxnetfs: Fix folio->private handling in netfs_perform_write()
CVE-2026-64062await6.5LinuxLinuxnetfs: Fix potential deadlock in write-through mode
CVE-2026-64063await6.5LinuxLinuxnetfs: Fix streaming write being overwritten
CVE-2026-64064await6.5LinuxLinuxnetfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone
CVE-2026-64065await6.5LinuxLinuxnetfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call
CVE-2026-162082.36.4n/adjango-tastypieCWE-362django-tastypie throttle.py CacheDBThrottle race condition
CVE-2026-63837await6.4LinuxLinuxnet: ena: PHC: Check return code before setting timestamp output
CVE-2026-63983await6.3LinuxLinuxnet/sched: fix packet loop on netem when duplicate is on
CVE-2026-63986await6.3LinuxLinuxethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure
CVE-2026-63988await6.3LinuxLinuxbridge: Fix sleep in atomic context in sysfs path
CVE-2026-63989await6.3LinuxLinuxbridge: Fix sleep in atomic context in netlink path
CVE-2026-63998await6.3LinuxLinuxethtool: module: call ethnl_ops_complete() on module flash errors
CVE-2026-63999await6.3LinuxLinuxethtool: rss: fix indir_table and hkey leak on get_rxfh failure
CVE-2026-64021await6.3LinuxLinuxdrm/xe/oa: Fix exec_queue leak on width check in stream open
CVE-2026-64022await6.3LinuxLinuxgpio: aggregator: remove the software node when deactivating the aggregator
CVE-2026-64038await6.3LinuxLinuxhwmon: (lm90) Stop work before releasing hwmon device
CVE-2026-64049await6.3LinuxLinuxdrm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx
CVE-2026-64054await6.3LinuxLinuxnet: shaper: reject duplicate leaves in GROUP request
CVE-2026-64060await6.3LinuxLinuxnetfs: Fix leak of request in netfs_write_begin() error handling
CVE-2026-64075await6.3LinuxLinuxfprobe: Fix unregister_fprobe() to wait for RCU grace period
CVE-2026-638797.86.2LinuxLinuxdrm/amdgpu: fix amdgpu_hmm_range_get_pages
CVE-2026-639517.86.2LinuxLinuxzram: fix use-after-free in zram_writeback_endio
CVE-2026-63868await6.2LinuxLinuxnet: garp: fix unsigned integer underflow in garp_pdu_parse_attr
CVE-2026-639178.86.1LinuxLinuxip6: vti: Use ip6_tnl.net in vti6_changelink().
CVE-2026-639528.46.1LinuxLinuxmemfd: deny writeable mappings when implying SEAL_WRITE
CVE-2026-638757.86.1LinuxLinuxarm64: tlb: Flush walk cache when unsharing PMD tables
CVE-2026-639277.86.1LinuxLinuxusb: dwc2: Fix use after free in debug code
CVE-2026-639427.86.1LinuxLinuxparport: Fix race between port and client registration
CVE-2026-639547.86.1LinuxLinuxhpfs: fix a crash if hpfs_map_dnode_bitmap fails
CVE-2026-639378.86.0LinuxLinuxKVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer
CVE-2026-639238.85.8LinuxLinuxocteontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify
CVE-2026-639507.85.8LinuxLinuxmm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_one
CVE-2026-638858.85.8LinuxLinuxdrm/gem: fix race between change_handle and handle_delete
CVE-2026-63861await5.8LinuxLinuxspi: mtk-snfi: unregister ECC engine on probe failure and remove() callback
CVE-2026-63862await5.8LinuxLinuxPCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found
CVE-2026-639307.85.6LinuxLinuxiio: buffer: hw-consumer: fix use-after-free in error path
CVE-2026-639457.85.6LinuxLinuxBluetooth: ISO: serialize iso_sock_clear_timer with socket lock
CVE-2026-638947.85.5LinuxLinuxusb: gadget: f_fs: serialize DMABUF cancel against request completion
CVE-2026-639187.85.5LinuxLinuxl2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname
CVE-2026-638837.35.6LinuxLinuxserial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ
CVE-2026-639207.15.6LinuxLinuxipv6: validate extension header length before copying to cmsg
CVE-2026-162162.15.5geex-artsdjango-jetCWE-352geex-arts django-jet OAuth cross-site request forgery
CVE-2026-639117.85.4LinuxLinuxxfrm: iptfs: reset runtime state when cloning SAs
CVE-2026-162111.25.4n/aallegroCWE-362allegro Hostname Allocation assets.py AssetLastHostname.increment_hostname ra…
CVE-2026-63871await5.4LinuxLinuxBluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls
CVE-2026-639147.35.2LinuxLinuxxfrm: route MIGRATE notifications to caller's netns
CVE-2026-63839await5.3LinuxLinuxplatform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int()
CVE-2026-638067.15.2LinuxLinuxCWE-617KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unali…
CVE-2026-640945.55.2LinuxLinuxCWE-476batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface
CVE-2026-63859await5.1LinuxLinuxnet: airoha: Add missing bits in airoha_qdma_cleanup_tx_queue()
CVE-2026-63873await5.2LinuxLinuxaccel/amdxdna: Fix mm_struct reference leak in aie2_populate_range()
CVE-2026-64013await5.2LinuxLinuxACPI: button: Fix ACPI GPE handler leak during removal
CVE-2026-64019await5.2LinuxLinuxnvme-pci: fix dma mapping leak on data setup error
CVE-2026-64070await5.2LinuxLinuxpowerpc/hv-gpci: fix preempt count leak in sysfs show paths
CVE-2026-64079await5.2LinuxLinuxnetfilter: x_tables: allocate hook ops while under mutex
CVE-2026-639418.85.1LinuxLinuxKVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor
CVE-2026-640428.85.1LinuxLinuxvfio/pci: Check BAR resources before exporting a DMABUF
CVE-2026-640458.45.0LinuxLinuxovpn: tcp - use cached peer pointer in ovpn_tcp_close()
CVE-2026-638097.85.1LinuxLinuxbpf: use kvfree() for replaced sysctl write buffer
CVE-2026-639107.85.1LinuxLinuxdma-buf: fix UAF in dma_buf_fd() tracepoint
CVE-2026-641188.44.9LinuxLinuxCWE-415qed: fix double free in qed_cxt_tables_alloc()
CVE-2026-640349.34.8LinuxLinuxnet: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
CVE-2026-641069.04.5LinuxLinuxKVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits
CVE-2026-533698.44.4LinuxLinuxudf: reject descriptors with oversized CRC length
CVE-2026-637978.44.4LinuxLinuxCWE-416rpmsg: char: Fix use-after-free on probe error path
CVE-2026-451385.44.4ci4-cms-erpci4msCWE-79CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
CVE-2026-640809.34.3LinuxLinuxfirmware: arm_ffa: Snapshot notifier callbacks under lock
CVE-2026-63820await4.3LinuxLinuxf2fs: fix missing read bio submission on large folio error
CVE-2026-640097.84.2LinuxLinuxxfrm: Check for underflow in xfrm_state_mtu
CVE-2026-640189.34.0LinuxLinuxnet: mana: validate rx_req_idx to prevent out-of-bounds array access
CVE-2026-637947.84.0LinuxLinuxCWE-787KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
CVE-2026-638188.43.8LinuxLinuxf2fs: validate orphan inode entry count
CVE-2026-640818.43.9LinuxLinuxfirmware: arm_ffa: Validate framework notification message layout
CVE-2026-641538.83.7LinuxLinuxdrm/msm: Fix iommu_map_sgtable() return value check and avoid WARN
CVE-2026-638158.43.8LinuxLinuxf2fs: bound i_inline_xattr_size for non-inline-xattr inodes
CVE-2026-533817.83.7LinuxLinuxCWE-416virtiofs: fix UAF on submount umount
CVE-2026-640847.83.7LinuxLinuxhwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR
CVE-2026-640867.83.7LinuxLinuxhwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer
CVE-2026-638027.83.6LinuxLinuxCWE-416blk-cgroup: fix UAF in __blkcg_rstat_flush()
CVE-2026-638047.83.6LinuxLinuxCWE-416gfs2: fix use-after-free in gfs2_qd_dealloc
CVE-2026-641147.83.5LinuxLinuxCWE-125ipv4: raw: reject IP_HDRINCL packets with ihl < 5
CVE-2026-641158.83.4LinuxLinuxCWE-416vsock/vmci: fix UAF when peer resets connection during handshake
CVE-2026-641267.33.4LinuxLinuxCWE-125Bluetooth: MGMT: validate Add Extended Advertising Data length
CVE-2026-534027.13.5LinuxLinuxCWE-125fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
CVE-2026-641117.13.5LinuxLinuxlsm: hold cred_guard_mutex for lsm_set_self_attr()
CVE-2026-641727.13.5LinuxLinuxKVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235)
CVE-2026-638177.83.3LinuxLinuxf2fs: validate compress cache inode only when enabled
CVE-2026-640997.83.4LinuxLinuxCWE-416drm/v3d: Fix use-after-free of CPU job query arrays on error path
CVE-2026-533935.53.4LinuxLinuxnfsd: reset write verifier on deferred writeback errors
CVE-2026-641048.73.3LinuxLinuxCWE-401virt: sev-guest: Explicitly leak pages in unknown state
CVE-2026-533887.83.2LinuxLinuxCWE-416fuse: re-lock request before replacing page cache folio
CVE-2026-638037.83.2LinuxLinuxCWE-416hdlc_ppp: sync per-proto timers before freeing hdlc state
CVE-2026-638608.43.2LinuxLinuxRDMA/core: Prefer NLA_NUL_STRING
CVE-2026-640737.83.2LinuxLinuxirq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT
CVE-2026-533825.53.2LinuxLinuxCWE-476media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
CVE-2026-533855.53.2LinuxLinuxCWE-476vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write
CVE-2026-638288.43.1LinuxLinuxapparmor: mediate the implicit connect of TCP fast open sendmsg
CVE-2026-638078.83.0LinuxLinuxCWE-125KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
CVE-2026-534035.53.0LinuxLinuxCWE-476fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
CVE-2026-641098.82.9LinuxLinuxCWE-416af_unix: Fix UAF read of tail->len in unix_stream_data_wait()
CVE-2026-533867.82.9LinuxLinuxCWE-129iio: adc: ti-ads1298: add bounds check to pga_settings index
CVE-2026-534017.83.0LinuxLinuxCWE-416fbdev: omap2: fix use-after-free in omapfb_mmap
CVE-2026-638427.83.0LinuxLinuxdrm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring
CVE-2026-638437.83.0LinuxLinuxdrm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring
CVE-2026-638447.83.0LinuxLinuxdrm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring
CVE-2026-638457.83.0LinuxLinuxdrm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring
CVE-2026-638467.83.0LinuxLinuxdrm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring
CVE-2026-638477.82.9LinuxLinuxdrm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring
CVE-2026-638487.83.0LinuxLinuxdrm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring
CVE-2026-638507.83.0LinuxLinuxdrm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring
CVE-2026-639857.83.0LinuxLinuxethtool: eeprom: add more safeties to EEPROM Netlink fallback
CVE-2026-639877.82.9LinuxLinuxethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES
CVE-2026-639957.82.9LinuxLinuxethtool: cmis: validate start_cmd_payload_size from module
CVE-2026-639967.82.9LinuxLinuxethtool: cmis: require exact CDB reply length
CVE-2026-640027.83.0LinuxLinuxipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_…
CVE-2026-640047.83.0LinuxLinuxnet/iucv: fix locking in .getsockopt
CVE-2026-640057.83.0LinuxLinuxnet/smc: Do not re-initialize smc hashtables
CVE-2026-640157.83.0LinuxLinuxsecurity/keys: fix missed RCU read section on lookup
CVE-2026-640267.82.9LinuxLinuxrxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg
CVE-2026-640517.82.9LinuxLinuxaccel/qaic: Add overflow check to remap_pfn_range during mmap
CVE-2026-640537.82.9LinuxLinuxblock: don't overwrite bip_vcnt in bio_integrity_copy_user()
CVE-2026-640977.83.0LinuxLinuxCWE-787drm/amd/display: Validate GPIO pin LUT table size before iterating
CVE-2026-641087.83.0LinuxLinuxcifs: Fix busy dentry used after unmounting
CVE-2026-641337.83.0LinuxLinuxCWE-125ALSA: asihpi: Fix potential OOB array access at reading cache
CVE-2026-641347.82.9LinuxLinuxCWE-476ALSA: pcm: Don't setup bogus iov_iter for silencing
CVE-2026-641377.83.0LinuxLinuxsmb: client: require net admin for CIFS SWN netlink
CVE-2026-638417.82.8LinuxLinuxdrm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.1 ring
CVE-2026-638497.82.8LinuxLinuxdrm/amdgpu/vcn: set no_user_fence for VCN v5.0.1 enc ring
CVE-2026-641817.82.8LinuxLinuxmm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_sp…
CVE-2026-640905.52.9LinuxLinuxbatman-adv: tt: avoid empty VLAN responses
CVE-2026-640925.52.9LinuxLinuxbatman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown
CVE-2026-641285.52.9LinuxLinuxCWE-476Bluetooth: ISO: drop ISO_END frames received without prior ISO_START
CVE-2026-641248.82.8LinuxLinuxnet: devmem: reject dma-buf bind with non-page-aligned size or SG length
CVE-2026-638057.82.8LinuxLinuxcrypto: nx - fix nx_crypto_ctx_exit argument
CVE-2026-638147.82.8LinuxLinuxf2fs: validate ACL entry sizes in f2fs_acl_from_disk()
CVE-2026-638247.82.8LinuxLinuxKEYS: fix overflow in keyctl_pkey_params_get_2()
CVE-2026-640087.82.8LinuxLinuxaccel/rocket: fix UAF via dangling GEM handle in create_bo
CVE-2026-640277.82.8LinuxLinuxnet: shaper: rework the VALID marking (again)
CVE-2026-640317.82.8LinuxLinuxerofs: fix managed cache race for unaligned extents
CVE-2026-640367.82.8LinuxLinuxcgroup/rstat: validate cpu before css_rstat_cpu() access
CVE-2026-640587.82.8LinuxLinuxnetfs: Fix netfs_read_folio() to wait on writeback
CVE-2026-640747.82.8LinuxLinuxfs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap
CVE-2026-640767.82.8LinuxLinuxnetfilter: bridge: eb_tables: close module init race
CVE-2026-640777.82.8LinuxLinuxnetfilter: ebtables: move to two-stage removal scheme
CVE-2026-640787.82.8LinuxLinuxnetfilter: x_tables: add and use xtables_unregister_table_exit
CVE-2026-641457.82.8LinuxLinuxCWE-787wifi: wilc1000: fix dma_buffer leak on bus acquire failure
CVE-2026-641275.52.8LinuxLinuxBluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer
CVE-2026-641445.52.8LinuxLinuxCWE-401Bluetooth: btmtk: fix urb->setup_packet leak in error paths
CVE-2026-641475.52.8LinuxLinuxCWE-401pds_core: fix debugfs_lookup dentry leak and error handling
CVE-2026-638167.82.7LinuxLinuxf2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
CVE-2026-640117.82.7LinuxLinuxnfc: llcp: Fix use-after-free in llcp_sock_release()
CVE-2026-641037.82.7LinuxLinuxCWE-416scsi: isci: Fix use-after-free in device removal path
CVE-2026-641237.82.7LinuxLinuxCWE-416net: hsr: defer node table free until after RCU readers
CVE-2026-641217.12.7LinuxLinuxCWE-125net: ifb: report ethtool stats over num_tx_queues
CVE-2026-637985.52.7LinuxLinuxCWE-401irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
CVE-2026-641015.52.7LinuxLinuxfwctl: pds: Validate RPC input size before parsing
CVE-2026-641495.52.7LinuxLinuxdma-mapping: move dma_map_resource() sanity check into debug code
CVE-2026-533897.82.6LinuxLinuxCWE-416net/tcp-ao: fix use-after-free of key in del_async path
CVE-2026-640297.82.6LinuxLinuxALSA: seq: Serialize UMP output teardown with event_input
CVE-2026-640327.82.6LinuxLinuxbridge: mcast: Fix a possible use-after-free when removing a bridge port
CVE-2026-533877.12.6LinuxLinuxCWE-129iio: light: veml6075: add bounds check to veml6075_it_ms index
CVE-2026-638337.12.6LinuxLinuxntfs3: reject direct userspace writes to reserved $LX* xattrs
CVE-2026-533765.52.6LinuxLinuxdrm/amdkfd: Add upper bound check for num_of_nodes
CVE-2026-638237.82.5LinuxLinuxkeys: Pin request_key_auth payload in instantiate paths
CVE-2026-638277.82.5LinuxLinuxapparmor: fix use-after-free in rawdata dedup loop
CVE-2026-640237.82.5LinuxLinuxgpio: aggregator: fix a potential use-after-free
CVE-2026-640507.82.5LinuxLinuxdrm/msm/dpu: don't mix devm and drmm functions
CVE-2026-533705.52.5LinuxLinuxperf/x86/intel: Improve validation and configuration of ACR masks
CVE-2026-638298.82.5LinuxLinuxnet: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-638648.42.5LinuxLinuxbpf: Propagate error from visit_tailcall_insn
CVE-2026-638707.82.5LinuxLinuxieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit()
CVE-2026-533775.52.5LinuxLinuxdrm/msm: always recover the gpu
CVE-2026-641295.52.5LinuxLinuxCWE-401mm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_page
CVE-2026-641355.52.4LinuxLinuxCWE-674hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX
CVE-2026-641555.52.5LinuxLinuxCWE-401wifi: ath11k: fix error path leaks in some WMI WOW calls
CVE-2026-641055.52.4LinuxLinuxKVM: arm64: vgic: Free private_irqs when init fails after allocation
CVE-2026-641315.52.4LinuxLinuxmm/memory: fix spurious warning when unmapping device-private/exclusive pages
CVE-2026-641575.52.4LinuxLinuxnetfs: Fix partial invalidation of streaming-write folio
CVE-2026-638658.82.3LinuxLinuxbpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks
CVE-2026-637937.82.3LinuxLinuxCWE-416ntfs: serialize volume label accesses
CVE-2026-637997.82.3LinuxLinuxCWE-125sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path
CVE-2026-638407.82.3LinuxLinuxdrm/amdgpu/jpeg: set no_user_fence for JPEG v5.3.0 ring

Results continue: ranks 401–465.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-19 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.