AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H N 10.0 .0100 60.1 —
AFFECTED Product Versions Fixed firmware < 2.7.21.1370b23 – —
TIMELINE May 5 Reserved by CNA Jul 19 Published (CNA: GitHub_M)
465 CVEs published July 19, 2026: 58 critical, 212 high, 72 medium, 18 low; 0 in KEV; 0 with a public exploit reference; 105 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 440 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 5155 | 17473 | 1301 | 2563 |
| KEV catalog size | 1670 | |||
761 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 471 | 1951 | 178 | 1076 | 589 | 1 | 27 | 3 | 0.2 | 7.8 | .0013 | +371 |
| 94 | 1358 | 150 | 612 | 555 | 38 | 74 | 6 | 0.4 | 7.8 | .0024 | -590 | |
| microsoft | 646 | 1357 | 91 | 931 | 306 | 12 | 378 | 31 | 2.3 | 7.8 | .0039 | +426 |
| red hat | 65 | 257 | 14 | 106 | 124 | 13 | 4 | 0 | 0.0 | 6.5 | .0026 | -10 |
| apple | 0 | 99 | 1 | 23 | 66 | 2 | 93 | 7 | 7.1 | 6.5 | .0031 | -14 |
| canonical | 4 | 24 | 3 | 6 | 10 | 5 | 0 | 0 | 0.0 | 5.5 | .0011 | +3 |
| suse | 8 | 21 | 4 | 12 | 4 | 1 | 0 | 0 | 0.0 | 8.5 | .0033 | +4 |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0015 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 16 | 39 | 6 | 16 | 9 | 0 | 96 | 12 | 30.8 | 7.5 | .0050 | +7 |
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 4 | 3 | 8.3 | 8.8 | .0036 | +20 |
| palo alto networks | 14 | 25 | 0 | 2 | 14 | 7 | 14 | 2 | 8.0 | 4.7 | .0021 | +5 |
| netgear | 6 | 23 | 0 | 0 | 22 | 1 | 8 | 0 | 0.0 | 4.6 | .0022 | -11 |
| fortinet | 14 | 22 | 3 | 6 | 10 | 0 | 28 | 5 | 22.7 | 6.7 | .0036 | +12 |
| f5 | 8 | 17 | 5 | 8 | 3 | 0 | 7 | 1 | 5.9 | 8.6 | .0057 | +2 |
| vmware | 8 | 11 | 1 | 7 | 2 | 1 | 21 | 0 | 0.0 | 8.0 | .0031 | +5 |
| ivanti | 2 | 11 | 2 | 3 | 2 | 0 | 33 | 5 | 45.5 | 8.8 | .3445 | -2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 78 | 231 | 47 | 90 | 82 | 11 | 40 | 1 | 0.4 | 7.5 | .0048 | -8 |
| mozilla | 6 | 62 | 12 | 18 | 32 | 0 | 13 | 0 | 0.0 | 6.5 | .0025 | -43 |
| drupal | 46 | 51 | 6 | 5 | 35 | 5 | 5 | 1 | 2.0 | 5.9 | .0018 | +46 |
| gitlab | 7 | 40 | 0 | 5 | 27 | 6 | 4 | 2 | 5.0 | 4.7 | .0024 | -4 |
| github | 5 | 11 | 1 | 2 | 8 | 0 | 0 | 0 | 0.0 | 6.0 | .0026 | +5 |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 1 | 0 | 0.0 | 8.2 | .0016 | -4 |
| jenkins | 0 | 0 | 0 | 0 | 0 | 0 | 6 | 0 | — | — | — | 0 |
| joomla | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1 | 271 | 132 | 116 | 18 | 4 | 40 | 3 | 1.1 | 8.8 | .0040 | -242 |
| adobe | 94 | 240 | 26 | 102 | 105 | 4 | 75 | 4 | 1.7 | 7.5 | .0021 | -35 |
| ibm | 36 | 160 | 52 | 54 | 54 | 0 | 7 | 0 | 0.0 | 7.5 | .0026 | +25 |
| progress | 10 | 19 | 3 | 14 | 2 | 0 | 9 | 0 | 0.0 | 7.5 | .0034 | +5 |
| solarwinds | 0 | 7 | 1 | 2 | 2 | 0 | 11 | 4 | 57.1 | 7.5 | .0835 | -3 |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 4 | 0 | 0.0 | 9.0 | .0046 | -1 |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| servicenow | 1 | 1 | 1 | 0 | 0 | 0 | 2 | 0 | 0.0 | 9.5 | .2673 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rockwell automation | 17 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0025 | +10 |
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 |
| siemens | 7 | 16 | 1 | 8 | 7 | 0 | 1 | 0 | 0.0 | 7.6 | .0019 | 0 |
| d-link | 1 | 14 | 0 | 5 | 3 | 5 | 26 | 1 | 7.1 | 6.0 | .0058 | -8 |
| abb | 1 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -4 |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 1 | 0 | 0.0 | 7.8 | .0024 | -1 |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | -5 |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 2 | 0 | 0.0 | 6.9 | .0036 | -3 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 46 | 117 | 0 | 0 | 61 | 56 | 0 | 0 | 0.0 | 5.5 | .0026 | +9 |
| openclaw | 44 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0022 | -17 |
| dell | 37 | 93 | 4 | 42 | 43 | 3 | 2 | 1 | 1.1 | 6.8 | .0019 | +10 |
| capgo | 22 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0028 | +19 |
| nvidia | 40 | 79 | 12 | 52 | 15 | 0 | 0 | 0 | 0.0 | 7.8 | .0019 | +34 |
| imagemagick | 32 | 73 | 1 | 5 | 55 | 12 | 3 | 0 | 0.0 | 5.3 | .0017 | +4 |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -71 |
| itsourcecode | 15 | 68 | 0 | 0 | 19 | 49 | 0 | 0 | 0.0 | 2.1 | .0020 | -7 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-48282 | .9924 | 99.9 | 10.0 |
| CVE-2026-39808 | .9121 | 99.8 | — |
| CVE-2026-48908 | .8813 | 99.8 | 10.0 |
| CVE-2026-34910 | .8696 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-56290 | .8325 | 99.7 | 10.0 |
| CVE-2026-20230 | .8321 | 99.7 | 8.6 |
| CVE-2026-48939 | .8250 | 99.6 | 10.0 |
| CVE-2026-50522 | .7698 | 99.5 | 9.8 |
| CVE-2026-15410 | .7635 | 99.5 | 7.2 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48282 | 10.0 | .9924 | KEV |
| CVE-2026-48908 | 10.0 | .8813 | KEV |
| CVE-2026-34910 | 10.0 | .8696 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-56290 | 10.0 | .8325 | KEV |
| CVE-2026-48939 | 10.0 | .8250 | KEV |
| CVE-2026-56291 | 10.0 | .7607 | KEV |
| CVE-2026-15409 | 10.0 | .7422 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-50160 | 10.0 | .1775 |
| Vendor | CVEs |
|---|---|
| linux | 885 |
| microsoft | 647 |
| 500 | |
| red hat | 118 |
| apache | 113 |
| adobe | 107 |
| ibm | 100 |
| capgo | 80 |
| sourcecodester | 58 |
| dell | 48 |
| Vendor | KEV |
|---|---|
| microsoft | 31 |
| cisco | 12 |
| apple | 7 |
| 6 | |
| fortinet | 5 |
| ivanti | 5 |
| adobe | 4 |
| solarwinds | 4 |
| synacor | 4 |
| linux | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 56 |
| PyPI | 5 |
| npm | 5 |
| NuGet | 3 |
| Packagist | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4128 | Cisco | 0 |
| CVE-2023-4346 | KNX Association | 0 |
| CVE-2025-67038 | Lantronix | 0 |
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1705 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1705 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1705 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1705 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1705 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1705 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1705 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1705 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1705 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1705 |
EXPLOIT PUBLISHED — CVE-2026-16199 (nextlevelbuilder GoClaw). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16200 (zevorn rt-claw). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16201 (zevorn rt-claw). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16202 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16203 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16204 (zevorn rt-claw). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16205 (Pluck CMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16209 (Gerapy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16210 (newpanjing simpleui). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16211 (allegro). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16212 (awesto django-shop). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16214 (geex-arts django-jet). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16215 (geex-arts django-jet). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16216 (geex-arts django-jet). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16217 (guohongze adminset). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16219 (Croogo CMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16220 (code-projects Online Examination System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16222 (1Panel-dev CordysCRM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16223 (1Panel-dev CordysCRM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16225 (davenardella snap7). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16227 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16228 (SourceCodester Class and Exam Timetabling System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16229 (itsourcecode Courier Management System). Public exploit reference added.
DUE DATE PASSED — CVE-2026-46817 (Oracle Corporation Oracle Payments). CISA remediation deadline was July 18, 2026; still in catalog.
465 CVEs published. 25 box scores and 375 table rows below; the remaining 65 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H N 10.0 .0100 60.1 —
AFFECTED Product Versions Fixed firmware < 2.7.21.1370b23 – —
TIMELINE May 5 Reserved by CNA Jul 19 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0075 51.8 —
AFFECTED Product Versions Fixed Linux e48354ce078c079996f89d715dfa44814b4eba01 – — Linux 3.1 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0075 51.8 —
AFFECTED Product Versions Fixed Linux e48354ce078c079996f89d715dfa44814b4eba01 – — Linux 3.1 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0070 50.3 —
AFFECTED Product Versions Fixed Linux c075c3ea031757f8ea2d34567565b61a868c08d5 – — Linux 5.18 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0069 50.0 —
AFFECTED Product Versions Fixed Linux a831f5bbc89a9978795504be9e1ff412043f8f77 – — Linux 2.6.19 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0069 50.0 —
AFFECTED Product Versions Fixed Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 – — Linux 2.6.12 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0069 49.8 —
AFFECTED Product Versions Fixed Linux eb947403518ea3d93f6d89264bb1f5416bb0c7d0 – — Linux 6.4 – 5.15.211
TIMELINE Jun 9 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0066 48.8 —
AFFECTED Product Versions Fixed Linux 1e5733883421495908f3b90d9d807663038b4136 – — Linux 6.0 – 6.1.176
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0065 48.0 —
AFFECTED Product Versions Fixed Linux d0ec61c9f3583b76aebdbb271f5c0d3fcccd48b2 – — Linux 6.13 – 6.1.176
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0063 47.4 —
AFFECTED Product Versions Fixed Linux 7b3801927e52f8621de311277f7fc727635019e7 – — Linux 5.6 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N H 8.1 .0063 47.2 —
AFFECTED Product Versions Fixed Linux 282cbbb476b9f35793452bc461934af4c7eca169 – — Linux 6.6.140 – —
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0062 46.7 —
AFFECTED Product Versions Fixed Linux 3b3009ea8abb713b022d94fba95ec270cf6e7eae – — Linux 6.4 – 6.12.93
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L H 8.2 .0062 46.8 —
AFFECTED Product Versions Fixed Linux 9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1 – — Linux 2.6.15 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0060 45.8 —
AFFECTED Product Versions Fixed Linux 3b3009ea8abb713b022d94fba95ec270cf6e7eae – — Linux 6.4 – 6.18.44
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0058 44.8 —
AFFECTED Product Versions Fixed Linux fb9f98e1041a30dd5766620a2a64cb472b54caa9 – — Linux 7.0 – 6.18.35
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0055 43.5 —
AFFECTED Product Versions Fixed Linux 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 – — Linux 4.16 – 5.10.258
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0055 43.5 —
AFFECTED Product Versions Fixed Linux a73105b8d4c765d9ebfb664d0a66802127d8e4c7 – — Linux 3.1 – 5.10.258
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0055 43.5 —
AFFECTED Product Versions Fixed Linux 6ef398ea60d931b97d69ed080bd0bd00fac38ec6 – — Linux 3.19 – 5.10.258
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0053 42.3 —
AFFECTED Product Versions Fixed Linux d67ae825a59d639e4d8b82413af84d854617a87e – — Linux 4.0 – 5.10.261
TIMELINE Jun 9 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0053 42.3 —
AFFECTED Product Versions Fixed Linux a257cdd0e2179630d3201c32ba14d7fcb3c3a055 – — Linux 2.6.13 – 5.10.260
TIMELINE Jun 9 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0052 41.8 —
AFFECTED Product Versions Fixed Linux 4cb47a8644cc9eb8ec81190a50e79e6530d0297f – — Linux 5.9 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0052 41.6 —
AFFECTED Product Versions Fixed Linux 6b7f3cf96364eaf597940cb5c68a682894829915 – — Linux 4.0 – 5.15.211
TIMELINE Jun 9 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0051 41.4 —
AFFECTED Product Versions Fixed Linux 5e76b25d7cc82c148d391c0c43b884e6427cb302 – — Linux 6.1 – 5.10.260
TIMELINE Jun 9 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0051 41.4 —
AFFECTED Product Versions Fixed Linux c5c707f96fc9a6e5a57ca5baac892673270abe3d – — Linux 4.0 – 5.10.261
TIMELINE Jun 9 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0051 41.4 —
AFFECTED Product Versions Fixed Linux 8610c7c6e3bd647ff98d21c8bc0580e77bc2f8b3 – — Linux 5.7 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-63993 | 9.8 | 41.4 | Linux | Linux | — | vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() |
| CVE-2026-64007 | 9.8 | 41.4 | Linux | Linux | — | netfilter: synproxy: refresh tcphdr after skb_ensure_writable |
| CVE-2026-64046 | 9.8 | 41.4 | Linux | Linux | — | net: tls: prevent chain-after-chain in plain text SG |
| CVE-2026-64047 | 9.8 | 41.4 | Linux | Linux | — | net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring |
| CVE-2026-64055 | 9.8 | 41.4 | Linux | Linux | — | net: ethernet: cortina: Carry over frag counter |
| CVE-2026-63992 | 9.1 | 41.4 | Linux | Linux | — | tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() |
| CVE-2026-64116 | 7.5 | 41.3 | Linux | Linux | CWE-476 | ipv6: ioam: add NULL check for idev in ipv6_hop_ioam() |
| CVE-2026-63800 | 9.8 | 40.5 | Linux | Linux | CWE-416 | pNFS: Fix use-after-free in pnfs_update_layout() |
| CVE-2026-63808 | 9.8 | 40.5 | Linux | Linux | — | exfat: fix potential use-after-free in exfat_find_dir_entry() |
| CVE-2026-64102 | 9.8 | 40.5 | Linux | Linux | CWE-125 | RDMA/siw: Reject MPA FPDU length underflow before signed receive math |
| CVE-2026-64113 | 9.8 | 40.5 | Linux | Linux | CWE-416 | ixgbevf: fix use-after-free in VEPA multicast source pruning |
| CVE-2026-64000 | 9.8 | 40.0 | Linux | Linux | — | net: hsr: fix potential OOB access in supervision frame handling |
| CVE-2026-64132 | 9.8 | 40.0 | Linux | Linux | CWE-416 | ipv6: ioam: refresh hdr pointer before ioam6_event() |
| CVE-2026-64136 | 9.8 | 40.0 | Linux | Linux | — | smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() |
| CVE-2026-53394 | 7.5 | 39.9 | Linux | Linux | CWE-401 | nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race |
| CVE-2026-53384 | 9.8 | 39.9 | Linux | Linux | CWE-416 | serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails |
| CVE-2026-64033 | 9.8 | 39.9 | Linux | Linux | — | RDMA/rtrs: Fix use-after-free in path file creation cleanup |
| CVE-2026-63801 | 8.8 | 39.7 | Linux | Linux | CWE-416 | tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done |
| CVE-2026-64142 | 9.8 | 39.3 | Linux | Linux | CWE-416 | ksmbd: close durable scavenger races against m_fp_list lookups |
| CVE-2026-64048 | 7.5 | 39.3 | Linux | Linux | — | net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot |
| CVE-2026-63795 | 10.0 | 39.2 | Linux | Linux | CWE-416 | 9p: avoid putting oldfid in p9_client_walk() error path |
| CVE-2026-64148 | 7.5 | 39.0 | Linux | Linux | CWE-835 | pds_core: fix error handling in pdsc_devcmd_wait |
| CVE-2026-53390 | 8.1 | 38.7 | Linux | Linux | CWE-125 | ksmbd: fix out-of-bounds read in smb_check_perm_dacl() |
| CVE-2026-63955 | 7.5 | 38.5 | Linux | Linux | — | mm/vmalloc: do not trigger BUG() on BH disabled context |
| CVE-2026-64122 | 9.8 | 38.1 | Linux | Linux | CWE-416 | net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover |
| CVE-2026-63796 | 8.8 | 37.7 | Linux | Linux | CWE-125 | ocfs2: reject oversized group bitmap descriptors |
| CVE-2026-64025 | 9.8 | 37.0 | Linux | Linux | — | bpf, skmsg: fix verdict sk_data_ready racing with ktls rx |
| CVE-2026-64061 | 9.8 | 37.0 | Linux | Linux | — | netfs: Fix early put of sink folio in netfs_read_gaps() |
| CVE-2026-63976 | 8.8 | 36.9 | Linux | Linux | — | Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success |
| CVE-2026-64016 | 9.8 | 36.8 | Linux | Linux | — | ksmbd: fix durable reconnect error path file lifetime |
| CVE-2026-64035 | 9.8 | 36.8 | Linux | Linux | — | igc: set tx buffer type for SMD frames |
| CVE-2026-64066 | 9.8 | 36.8 | Linux | Linux | — | netfs: Fix netfs_read_to_pagecache() to pause on subreq failure |
| CVE-2026-64069 | 9.8 | 36.8 | Linux | Linux | — | netfs: Fix cancellation of a DIO and single read subrequests |
| CVE-2026-64150 | 9.8 | 36.8 | Linux | Linux | — | netfilter: nft_inner: release local_lock before re-enabling softirqs |
| CVE-2026-63980 | 7.5 | 36.7 | Linux | Linux | — | net/handshake: Use spin_lock_bh for hn_lock |
| CVE-2026-64003 | 7.5 | 36.7 | Linux | Linux | — | scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues |
| CVE-2026-64141 | 7.5 | 36.7 | Linux | Linux | CWE-476 | ksmbd: fix null pointer dereference in compare_guid_key() |
| CVE-2026-64037 | 9.8 | 35.8 | Linux | Linux | — | wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled |
| CVE-2026-64091 | 9.8 | 35.5 | Linux | Linux | CWE-367 | batman-adv: tt: fix TOCTOU race for reported vlans |
| CVE-2026-64138 | 8.8 | 34.6 | Linux | Linux | — | ksmbd: validate SID in parent security descriptor during ACL inheritance |
| CVE-2026-63825 | 9.8 | 34.6 | Linux | Linux | — | gcov: use atomic counter updates to fix concurrent access crashes |
| CVE-2026-16209 | 5.5 | 34.2 | n/a | Gerapy | CWE-287 | Gerapy Project Upload Endpoint views.py missing authentication |
| CVE-2026-64160 | 9.8 | 33.9 | Linux | Linux | — | netfs: Fix potential for tearing in ->remote_i_size and ->zero_point |
| CVE-2026-16207 | 6.3 | 33.0 | n/a | django-tastypie | CWE-598 | django-tastypie authentication.py ApiKeyAuthentication get request method wit… |
| CVE-2026-16210 | 5.5 | 32.9 | newpanjing | simpleui | CWE-287 | newpanjing simpleui AjaxAdmin AJAX Endpoint admin.py self.get_action missing … |
| CVE-2026-63893 | 8.1 | 31.8 | Linux | Linux | — | thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() |
| CVE-2026-64024 | 9.4 | 31.7 | Linux | Linux | — | tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction |
| CVE-2026-64067 | 9.8 | 31.1 | Linux | Linux | — | netfs: Fix missing barriers when accessing stream->subrequests locklessly |
| CVE-2026-64068 | 9.8 | 31.1 | Linux | Linux | — | netfs: Fix missing locking around retry adding new subreqs |
| CVE-2026-64140 | 7.5 | 29.0 | Linux | Linux | CWE-476 | ksmbd: fix null pointer dereference in proc_show_files() |
| CVE-2026-63830 | 9.4 | 28.3 | Linux | Linux | — | net: skmsg: preserve sg.copy across SG transforms |
| CVE-2026-64175 | 7.5 | 28.0 | Linux | Linux | — | wifi: iwlwifi: mld: stop TX during firmware restart |
| CVE-2026-63857 | 9.8 | 27.8 | Linux | Linux | — | net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit() |
| CVE-2026-64162 | 9.8 | 27.8 | Linux | Linux | — | idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() |
| CVE-2026-63915 | 8.8 | 27.5 | Linux | Linux | — | nfc: hci: fix out-of-bounds read in HCP header parsing |
| CVE-2026-63916 | 8.8 | 27.5 | Linux | Linux | — | HID: wacom: Fix OOB write in wacom_hid_set_device_mode() |
| CVE-2026-63975 | 8.8 | 27.5 | Linux | Linux | — | Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp |
| CVE-2026-53395 | 7.5 | 27.4 | Linux | Linux | CWE-674 | nfsd: fix dead ACL conflict guard in nfsd4_create |
| CVE-2026-64020 | 7.5 | 27.4 | Linux | Linux | — | nvme-pci: fix dma_vecs leak on p2p memory |
| CVE-2026-16219 | 2.1 | 27.3 | Croogo | CMS | CWE-22 | Croogo CMS Admin File Manager FileManager.php isEditable path traversal |
| CVE-2026-63925 | 8.1 | 27.1 | Linux | Linux | — | macsec: fix replay protection at XPN lower-PN wrap |
| CVE-2026-63947 | 8.8 | 26.6 | Linux | Linux | — | Bluetooth: HIDP: fix missing length checks in hidp_input_report() |
| CVE-2026-64093 | 8.8 | 26.6 | Linux | Linux | — | batman-adv: tp_meter: directly shut down timer on cleanup |
| CVE-2026-63889 | 8.1 | 26.3 | Linux | Linux | — | scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 |
| CVE-2026-63946 | 8.8 | 25.6 | Linux | Linux | — | Bluetooth: ISO: fix UAF in iso_recv_frame |
| CVE-2026-63944 | 8.8 | 25.2 | Linux | Linux | — | Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync |
| CVE-2026-63867 | 8.2 | 24.9 | Linux | Linux | — | mptcp: close TOCTOU race while computing rcv_wnd |
| CVE-2026-16215 | 5.5 | 24.6 | geex-arts | django-jet | CWE-862 | geex-arts django-jet OAuth Credential Revoke authorization |
| CVE-2026-63974 | 8.8 | 24.5 | Linux | Linux | — | Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close |
| CVE-2026-16204 | 2.1 | 24.1 | zevorn | rt-claw | CWE-74 | zevorn rt-claw Telegram-to-AI Tool Execution Flow script.c tool_run_script_ex… |
| CVE-2026-16201 | 5.5 | 23.8 | zevorn | rt-claw | CWE-200 | zevorn rt-claw http_request net.c claw_net_post information disclosure |
| CVE-2026-16200 | 5.5 | 21.3 | zevorn | rt-claw | CWE-285 | zevorn rt-claw RPC swarm.c claw_tool_invoke authorization |
| CVE-2026-64088 | 8.8 | 20.6 | Linux | Linux | — | batman-adv: tt: fix negative tt_buff_len |
| CVE-2026-42566 | 7.5 | 20.4 | meshtastic | firmware | CWE-20 | Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh… |
| CVE-2026-16220 | 2.1 | 19.7 | code-projects | Online Examination System | CWE-79 | code-projects Online Examination System account.php cross site scripting |
| CVE-2026-16229 | 2.1 | 19.7 | itsourcecode | Courier Management System | CWE-79 | itsourcecode Courier Management System index.php cross site scripting |
| CVE-2026-53396 | 7.1 | 19.0 | Linux | Linux | CWE-401 | nfsd: fix posix_acl leak and ignored error in nfsd4_create_file |
| CVE-2026-64095 | 7.1 | 18.9 | Linux | Linux | — | batman-adv: bla: avoid double decrement of bla.num_requests |
| CVE-2026-16227 | 5.5 | 18.2 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_subject.php sql injection |
| CVE-2026-16228 | 5.5 | 18.2 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection |
| CVE-2026-63891 | await | 18.3 | Linux | Linux | — | thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() |
| CVE-2026-64010 | 8.8 | 17.2 | Linux | Linux | — | nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() |
| CVE-2026-64096 | 8.8 | 17.2 | Linux | Linux | CWE-416 | batman-adv: mcast: fix use-after-free in orig_node RCU release |
| CVE-2026-16221 | 7.5 | 17.1 | fast-uri | fast-uri | CWE-436 | fast-uri vulnerable to host confusion via literal backslash authority delimiter |
| CVE-2026-64178 | 8.8 | 16.5 | Linux | Linux | CWE-416 | Bluetooth: bnep: Fix UAF read of dev->name |
| CVE-2026-63895 | await | 15.8 | Linux | Linux | — | usb: gadget: f_fs: copy only received bytes on short ep0 read |
| CVE-2026-63831 | 8.8 | 15.8 | Linux | Linux | — | mac802154: llsec: add skb_cow_data() before in-place crypto |
| CVE-2026-64030 | 8.8 | 15.2 | Linux | Linux | — | wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs |
| CVE-2026-64117 | 8.8 | 14.6 | Linux | Linux | CWE-416 | wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb |
| CVE-2026-16225 | 2.1 | 13.8 | davenardella | snap7 | CWE-119 | davenardella snap7 s7_peer.cpp NegotiatePDULength out-of-bounds write |
| CVE-2026-63899 | await | 13.5 | Linux | Linux | — | USB: serial: mxuport: fix memory corruption with small endpoint |
| CVE-2026-63901 | await | 13.5 | Linux | Linux | — | USB: serial: digi_acceleport: fix memory corruption with small endpoints |
| CVE-2026-63832 | 8.8 | 13.2 | Linux | Linux | — | wifi: mt76: add wcid publish check in mt76_sta_add |
| CVE-2026-63866 | 8.8 | 13.2 | Linux | Linux | — | wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link() |
| CVE-2026-16224 | 5.3 | 13.0 | jxxghp | MoviePilot | CWE-266 | jxxghp MoviePilot Application API improper authorization |
| CVE-2026-16214 | 2.1 | 12.7 | geex-arts | django-jet | CWE-285 | geex-arts django-jet Dashboard views.py authorization |
| CVE-2026-16217 | 2.1 | 12.7 | guohongze | adminset | CWE-285 | guohongze adminset Delivery Deployment Endpoint deli.py authorization |
| CVE-2026-63892 | await | 12.7 | Linux | Linux | — | thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow |
| CVE-2026-16226 | 5.1 | 12.5 | SourceCodester | Pizzafy Ecommerce System | CWE-284 | SourceCodester Pizzafy Ecommerce System admin_class_novo.php save_settings un… |
| CVE-2026-63928 | await | 12.3 | Linux | Linux | — | USB: serial: omninet: fix memory corruption with small endpoint |
| CVE-2026-16222 | 2.1 | 12.1 | 1Panel-dev | CordysCRM | CWE-918 | 1Panel-dev CordysCRM Third Party Endpoint TokenService.java server-side reque… |
| CVE-2026-16223 | 2.1 | 12.1 | 1Panel-dev | CordysCRM | CWE-918 | 1Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java … |
| CVE-2026-63869 | 7.6 | 11.6 | Linux | Linux | — | wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap |
| CVE-2026-63890 | await | 11.6 | Linux | Linux | — | scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker |
| CVE-2026-63897 | await | 11.6 | Linux | Linux | — | USB: serial: mct_u232: fix missing interrupt-in transfer sanity check |
| CVE-2026-63898 | await | 11.6 | Linux | Linux | — | USB: serial: mct_u232: fix memory corruption with small endpoint |
| CVE-2026-63900 | await | 11.6 | Linux | Linux | — | USB: serial: keyspan: fix missing indat transfer sanity check |
| CVE-2026-63902 | await | 11.6 | Linux | Linux | — | USB: serial: cypress_m8: validate interrupt packet headers |
| CVE-2026-63903 | await | 11.6 | Linux | Linux | — | USB: serial: belkin_sa: validate interrupt status length |
| CVE-2026-63904 | await | 11.6 | Linux | Linux | — | usb: usbtmc: check URB actual_length for interrupt-IN notifications |
| CVE-2026-63905 | await | 11.6 | Linux | Linux | — | usbip: vudc: Fix use after free bug in vudc_remove due to race condition |
| CVE-2026-63908 | await | 11.6 | Linux | Linux | — | Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem |
| CVE-2026-63931 | await | 11.6 | Linux | Linux | — | iio: chemical: scd30: fix division by zero in write_raw |
| CVE-2026-63933 | await | 11.6 | Linux | Linux | — | iio: gyro: adis16260: fix division by zero in write_raw |
| CVE-2026-63948 | await | 11.6 | Linux | Linux | — | Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn |
| CVE-2026-63956 | await | 11.6 | Linux | Linux | — | USB: serial: cypress_m8: fix memory corruption with small endpoint |
| CVE-2026-63957 | await | 11.6 | Linux | Linux | — | USB: serial: safe_serial: fix memory corruption with small endpoint |
| CVE-2026-63958 | await | 11.7 | Linux | Linux | — | usb: typec: ucsi: validate connector number in ucsi_connector_change() |
| CVE-2026-63960 | await | 11.6 | Linux | Linux | — | usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() |
| CVE-2026-63961 | await | 11.6 | Linux | Linux | — | usb: typec: altmodes/displayport: validate count before reading Status Update… |
| CVE-2026-63964 | await | 11.6 | Linux | Linux | — | usb: typec: ucsi: ccg: reject firmware images without a ':' record header |
| CVE-2026-63967 | await | 11.6 | Linux | Linux | — | iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer |
| CVE-2026-63934 | await | 11.5 | Linux | Linux | — | iio: gyro: itg3200: fix i2c read into the wrong stack location |
| CVE-2026-64176 | 8.1 | 11.4 | Linux | Linux | — | wifi: iwlwifi: mvm: fix driver-set TX rates on old devices |
| CVE-2026-16206 | 5.3 | 11.4 | django-oauth | django-oauth-toolkit | CWE-613 | django-oauth django-oauth-toolkit oauth2_validators.py _load_id_token session… |
| CVE-2026-16199 | 2.1 | 11.4 | nextlevelbuilder | GoClaw | CWE-266 | nextlevelbuilder GoClaw credentialed_exec.go ExecTool.Execute improper author… |
| CVE-2026-63876 | await | 11.3 | Linux | Linux | — | serial: zs: Convert to use a platform device |
| CVE-2026-63877 | await | 11.3 | Linux | Linux | — | serial: dz: Convert to use a platform device |
| CVE-2026-63882 | await | 10.9 | Linux | Linux | — | drm/amdkfd: fix NULL pointer bug in svm_range_set_attr |
| CVE-2026-63969 | await | 10.9 | Linux | Linux | — | ipv6: fix possible infinite loop in rt6_fill_node() |
| CVE-2026-63973 | await | 10.9 | Linux | Linux | — | net: mana: Add NULL guards in teardown path to prevent panic on attach failure |
| CVE-2026-12484 | 7.8 | 10.7 | keras-team | keras-team/keras | CWE-502 | Unsafe Deserialization in keras.layers.TorchModuleWrapper.from_config |
| CVE-2026-16205 | 1.9 | 10.4 | Pluck | CMS | CWE-79 | Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting |
| CVE-2026-16218 | 2.1 | 10.2 | hunvreus | devpush | CWE-703 | hunvreus devpush Storage Reset Failure storage.py reset_storage improper chec… |
| CVE-2026-63896 | await | 10.2 | Linux | Linux | — | usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling |
| CVE-2026-63929 | await | 10.2 | Linux | Linux | — | iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() |
| CVE-2026-63936 | await | 10.2 | Linux | Linux | — | iio: adc: mt6359: fix unchecked return value in mt6358_read_imp |
| CVE-2026-63943 | await | 10.2 | Linux | Linux | — | Input: xpad - fix out-of-bounds access for Share button |
| CVE-2026-63959 | await | 10.2 | Linux | Linux | — | usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT |
| CVE-2026-63962 | await | 10.2 | Linux | Linux | — | usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() |
| CVE-2026-63963 | await | 10.2 | Linux | Linux | — | usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers |
| CVE-2026-16202 | 2.0 | 10.0 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System CYS.php cross site scripting |
| CVE-2026-16203 | 2.0 | 10.0 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System forCYS.php cross site scripting |
| CVE-2026-63878 | await | 9.9 | Linux | Linux | — | drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO |
| CVE-2026-63880 | await | 9.9 | Linux | Linux | — | drm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO |
| CVE-2026-63932 | await | 9.9 | Linux | Linux | — | iio: chemical: mhz19b: reject oversized serial replies |
| CVE-2026-63965 | await | 9.9 | Linux | Linux | — | iio: pressure: bmp280: fix stack leak in bmp580 trigger handler |
| CVE-2026-63966 | await | 9.9 | Linux | Linux | — | iio: imu: adis16550: fix stack leak in trigger handler |
| CVE-2026-63982 | await | 9.9 | Linux | Linux | — | net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop |
| CVE-2026-64043 | await | 9.9 | Linux | Linux | — | ovpn: fix race between deleting interface and adding new peer |
| CVE-2026-63939 | 9.3 | 9.8 | Linux | Linux | — | KVM: SEV: Compute the correct max length of the in-GHCB scratch area |
| CVE-2026-63907 | await | 8.9 | Linux | Linux | — | uio: uio_pci_generic_sva: fix double free of devm_kzalloc() memory |
| CVE-2026-63935 | await | 8.9 | Linux | Linux | — | iio: adc: nxp-sar-adc: fix division by zero in write_raw |
| CVE-2026-63953 | await | 8.9 | Linux | Linux | — | mm/migrate_device: fix pgtable leak in migrate_vma_insert_huge_pmd_page |
| CVE-2026-64040 | await | 8.9 | Linux | Linux | — | cachefiles: Fix error return when vfs_mkdir() fails |
| CVE-2026-63981 | await | 8.7 | Linux | Linux | — | net/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflow |
| CVE-2026-64028 | await | 8.4 | Linux | Linux | — | tracing: Avoid NULL return from hist_field_name() on truncation |
| CVE-2026-64139 | 5.5 | 8.3 | Linux | Linux | CWE-401 | ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow |
| CVE-2026-64083 | await | 8.3 | Linux | Linux | — | hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors |
| CVE-2026-64085 | await | 8.3 | Linux | Linux | — | hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer |
| CVE-2026-64087 | await | 8.3 | Linux | Linux | — | hwmon: (pmbus/adm1266) reject implausible blackbox record_count |
| CVE-2026-16212 | 1.3 | 8.2 | awesto | django-shop | CWE-362 | awesto django-shop Purchase Stock inventory.py race condition |
| CVE-2026-63810 | await | 8.2 | Linux | Linux | — | block: Avoid mounting the bdev pseudo-filesystem in userspace |
| CVE-2026-63990 | await | 8.0 | Linux | Linux | — | bonding: refuse to enslave CAN devices |
| CVE-2026-63938 | 9.3 | 7.9 | Linux | Linux | — | KVM: SEV: Check PSC request indices against the actual size of the buffer |
| CVE-2026-63940 | 9.3 | 7.9 | Linux | Linux | — | KVM: SEV: Ignore Port I/O requests of length '0' |
| CVE-2026-63926 | 8.4 | 7.9 | Linux | Linux | — | bpf: sockmap: fix tail fragment offset in bpf_msg_push_data |
| CVE-2026-64039 | 7.7 | 7.9 | Linux | Linux | — | drm/msm/snapshot: fix dumping of the unaligned regions |
| CVE-2026-63881 | 7.8 | 7.5 | Linux | Linux | — | drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger |
| CVE-2026-63991 | await | 7.5 | Linux | Linux | — | Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() |
| CVE-2026-64012 | await | 7.5 | Linux | Linux | — | net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_p… |
| CVE-2026-64014 | await | 7.5 | Linux | Linux | — | Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size |
| CVE-2026-63921 | 8.8 | 7.4 | Linux | Linux | — | ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). |
| CVE-2026-63884 | 7.8 | 7.4 | Linux | Linux | — | drm/i915: Fix potential UAF in TTM object purge |
| CVE-2026-63906 | 8.4 | 7.3 | Linux | Linux | — | usb: musb: omap2430: Fix use-after-free in omap2430_probe() |
| CVE-2026-63970 | 7.8 | 7.3 | Linux | Linux | — | vsock/virtio: bind uarg before filling zerocopy skb |
| CVE-2026-64041 | 7.8 | 7.3 | Linux | Linux | — | ASoC: codecs: fs210x: fix possible buffer overflow |
| CVE-2026-63822 | await | 7.1 | Linux | Linux | — | wifi: ath11k: fix warning when unbinding |
| CVE-2026-63834 | await | 7.2 | Linux | Linux | — | batman-adv: tp_meter: restrict number of unacked list entries |
| CVE-2026-63835 | await | 7.2 | Linux | Linux | — | batman-adv: v: prevent OGM aggregation on disabled hardif |
| CVE-2026-63836 | await | 7.2 | Linux | Linux | — | batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd |
| CVE-2026-64071 | await | 7.1 | Linux | Linux | — | nvme-pci: fix use-after-free in nvme_free_host_mem() |
| CVE-2026-64072 | await | 7.1 | Linux | Linux | — | nvme: fix bio leak on mapping failure |
| CVE-2026-64044 | 7.8 | 6.9 | Linux | Linux | — | ovpn: respect peer refcount in CMD_NEW_PEER error path |
| CVE-2026-63821 | await | 6.9 | Linux | Linux | — | wifi: rtw88: usb: fix memory leaks on USB write failures |
| CVE-2026-63826 | await | 6.9 | Linux | Linux | — | fbdev: fix use-after-free in store_modes() |
| CVE-2026-63949 | await | 7.0 | Linux | Linux | — | auxdisplay: line-display: fix OOB read on zero-length message_store() |
| CVE-2026-64006 | await | 6.9 | Linux | Linux | — | netfilter: nf_tables: fix dst corruption in same register operation |
| CVE-2026-63971 | 7.8 | 6.6 | Linux | Linux | — | sctp: fix race between sctp_wait_for_connect and peeloff |
| CVE-2026-63838 | await | 6.6 | Linux | Linux | — | ASoC: rsnd: Fix potential out-of-bounds access of component_dais[] |
| CVE-2026-63997 | await | 6.5 | Linux | Linux | — | ethtool: module: avoid leaking a netdev ref on module flash errors |
| CVE-2026-64001 | await | 6.5 | Linux | Linux | — | ALSA: pcm: oss: Fix setup list UAF on proc write error |
| CVE-2026-64052 | await | 6.5 | Linux | Linux | — | block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() |
| CVE-2026-64059 | await | 6.5 | Linux | Linux | — | netfs: Fix folio->private handling in netfs_perform_write() |
| CVE-2026-64062 | await | 6.5 | Linux | Linux | — | netfs: Fix potential deadlock in write-through mode |
| CVE-2026-64063 | await | 6.5 | Linux | Linux | — | netfs: Fix streaming write being overwritten |
| CVE-2026-64064 | await | 6.5 | Linux | Linux | — | netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone |
| CVE-2026-64065 | await | 6.5 | Linux | Linux | — | netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call |
| CVE-2026-16208 | 2.3 | 6.4 | n/a | django-tastypie | CWE-362 | django-tastypie throttle.py CacheDBThrottle race condition |
| CVE-2026-63837 | await | 6.4 | Linux | Linux | — | net: ena: PHC: Check return code before setting timestamp output |
| CVE-2026-63983 | await | 6.3 | Linux | Linux | — | net/sched: fix packet loop on netem when duplicate is on |
| CVE-2026-63986 | await | 6.3 | Linux | Linux | — | ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure |
| CVE-2026-63988 | await | 6.3 | Linux | Linux | — | bridge: Fix sleep in atomic context in sysfs path |
| CVE-2026-63989 | await | 6.3 | Linux | Linux | — | bridge: Fix sleep in atomic context in netlink path |
| CVE-2026-63998 | await | 6.3 | Linux | Linux | — | ethtool: module: call ethnl_ops_complete() on module flash errors |
| CVE-2026-63999 | await | 6.3 | Linux | Linux | — | ethtool: rss: fix indir_table and hkey leak on get_rxfh failure |
| CVE-2026-64021 | await | 6.3 | Linux | Linux | — | drm/xe/oa: Fix exec_queue leak on width check in stream open |
| CVE-2026-64022 | await | 6.3 | Linux | Linux | — | gpio: aggregator: remove the software node when deactivating the aggregator |
| CVE-2026-64038 | await | 6.3 | Linux | Linux | — | hwmon: (lm90) Stop work before releasing hwmon device |
| CVE-2026-64049 | await | 6.3 | Linux | Linux | — | drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx |
| CVE-2026-64054 | await | 6.3 | Linux | Linux | — | net: shaper: reject duplicate leaves in GROUP request |
| CVE-2026-64060 | await | 6.3 | Linux | Linux | — | netfs: Fix leak of request in netfs_write_begin() error handling |
| CVE-2026-64075 | await | 6.3 | Linux | Linux | — | fprobe: Fix unregister_fprobe() to wait for RCU grace period |
| CVE-2026-63879 | 7.8 | 6.2 | Linux | Linux | — | drm/amdgpu: fix amdgpu_hmm_range_get_pages |
| CVE-2026-63951 | 7.8 | 6.2 | Linux | Linux | — | zram: fix use-after-free in zram_writeback_endio |
| CVE-2026-63868 | await | 6.2 | Linux | Linux | — | net: garp: fix unsigned integer underflow in garp_pdu_parse_attr |
| CVE-2026-63917 | 8.8 | 6.1 | Linux | Linux | — | ip6: vti: Use ip6_tnl.net in vti6_changelink(). |
| CVE-2026-63952 | 8.4 | 6.1 | Linux | Linux | — | memfd: deny writeable mappings when implying SEAL_WRITE |
| CVE-2026-63875 | 7.8 | 6.1 | Linux | Linux | — | arm64: tlb: Flush walk cache when unsharing PMD tables |
| CVE-2026-63927 | 7.8 | 6.1 | Linux | Linux | — | usb: dwc2: Fix use after free in debug code |
| CVE-2026-63942 | 7.8 | 6.1 | Linux | Linux | — | parport: Fix race between port and client registration |
| CVE-2026-63954 | 7.8 | 6.1 | Linux | Linux | — | hpfs: fix a crash if hpfs_map_dnode_bitmap fails |
| CVE-2026-63937 | 8.8 | 6.0 | Linux | Linux | — | KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer |
| CVE-2026-63923 | 8.8 | 5.8 | Linux | Linux | — | octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify |
| CVE-2026-63950 | 7.8 | 5.8 | Linux | Linux | — | mm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_one |
| CVE-2026-63885 | 8.8 | 5.8 | Linux | Linux | — | drm/gem: fix race between change_handle and handle_delete |
| CVE-2026-63861 | await | 5.8 | Linux | Linux | — | spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback |
| CVE-2026-63862 | await | 5.8 | Linux | Linux | — | PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found |
| CVE-2026-63930 | 7.8 | 5.6 | Linux | Linux | — | iio: buffer: hw-consumer: fix use-after-free in error path |
| CVE-2026-63945 | 7.8 | 5.6 | Linux | Linux | — | Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock |
| CVE-2026-63894 | 7.8 | 5.5 | Linux | Linux | — | usb: gadget: f_fs: serialize DMABUF cancel against request completion |
| CVE-2026-63918 | 7.8 | 5.5 | Linux | Linux | — | l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname |
| CVE-2026-63883 | 7.3 | 5.6 | Linux | Linux | — | serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ |
| CVE-2026-63920 | 7.1 | 5.6 | Linux | Linux | — | ipv6: validate extension header length before copying to cmsg |
| CVE-2026-16216 | 2.1 | 5.5 | geex-arts | django-jet | CWE-352 | geex-arts django-jet OAuth cross-site request forgery |
| CVE-2026-63911 | 7.8 | 5.4 | Linux | Linux | — | xfrm: iptfs: reset runtime state when cloning SAs |
| CVE-2026-16211 | 1.2 | 5.4 | n/a | allegro | CWE-362 | allegro Hostname Allocation assets.py AssetLastHostname.increment_hostname ra… |
| CVE-2026-63871 | await | 5.4 | Linux | Linux | — | Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls |
| CVE-2026-63914 | 7.3 | 5.2 | Linux | Linux | — | xfrm: route MIGRATE notifications to caller's netns |
| CVE-2026-63839 | await | 5.3 | Linux | Linux | — | platform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int() |
| CVE-2026-63806 | 7.1 | 5.2 | Linux | Linux | CWE-617 | KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unali… |
| CVE-2026-64094 | 5.5 | 5.2 | Linux | Linux | CWE-476 | batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface |
| CVE-2026-63859 | await | 5.1 | Linux | Linux | — | net: airoha: Add missing bits in airoha_qdma_cleanup_tx_queue() |
| CVE-2026-63873 | await | 5.2 | Linux | Linux | — | accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range() |
| CVE-2026-64013 | await | 5.2 | Linux | Linux | — | ACPI: button: Fix ACPI GPE handler leak during removal |
| CVE-2026-64019 | await | 5.2 | Linux | Linux | — | nvme-pci: fix dma mapping leak on data setup error |
| CVE-2026-64070 | await | 5.2 | Linux | Linux | — | powerpc/hv-gpci: fix preempt count leak in sysfs show paths |
| CVE-2026-64079 | await | 5.2 | Linux | Linux | — | netfilter: x_tables: allocate hook ops while under mutex |
| CVE-2026-63941 | 8.8 | 5.1 | Linux | Linux | — | KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor |
| CVE-2026-64042 | 8.8 | 5.1 | Linux | Linux | — | vfio/pci: Check BAR resources before exporting a DMABUF |
| CVE-2026-64045 | 8.4 | 5.0 | Linux | Linux | — | ovpn: tcp - use cached peer pointer in ovpn_tcp_close() |
| CVE-2026-63809 | 7.8 | 5.1 | Linux | Linux | — | bpf: use kvfree() for replaced sysctl write buffer |
| CVE-2026-63910 | 7.8 | 5.1 | Linux | Linux | — | dma-buf: fix UAF in dma_buf_fd() tracepoint |
| CVE-2026-64118 | 8.4 | 4.9 | Linux | Linux | CWE-415 | qed: fix double free in qed_cxt_tables_alloc() |
| CVE-2026-64034 | 9.3 | 4.8 | Linux | Linux | — | net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer |
| CVE-2026-64106 | 9.0 | 4.5 | Linux | Linux | — | KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits |
| CVE-2026-53369 | 8.4 | 4.4 | Linux | Linux | — | udf: reject descriptors with oversized CRC length |
| CVE-2026-63797 | 8.4 | 4.4 | Linux | Linux | CWE-416 | rpmsg: char: Fix use-after-free on probe error path |
| CVE-2026-45138 | 5.4 | 4.4 | ci4-cms-erp | ci4ms | CWE-79 | CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule |
| CVE-2026-64080 | 9.3 | 4.3 | Linux | Linux | — | firmware: arm_ffa: Snapshot notifier callbacks under lock |
| CVE-2026-63820 | await | 4.3 | Linux | Linux | — | f2fs: fix missing read bio submission on large folio error |
| CVE-2026-64009 | 7.8 | 4.2 | Linux | Linux | — | xfrm: Check for underflow in xfrm_state_mtu |
| CVE-2026-64018 | 9.3 | 4.0 | Linux | Linux | — | net: mana: validate rx_req_idx to prevent out-of-bounds array access |
| CVE-2026-63794 | 7.8 | 4.0 | Linux | Linux | CWE-787 | KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path |
| CVE-2026-63818 | 8.4 | 3.8 | Linux | Linux | — | f2fs: validate orphan inode entry count |
| CVE-2026-64081 | 8.4 | 3.9 | Linux | Linux | — | firmware: arm_ffa: Validate framework notification message layout |
| CVE-2026-64153 | 8.8 | 3.7 | Linux | Linux | — | drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN |
| CVE-2026-63815 | 8.4 | 3.8 | Linux | Linux | — | f2fs: bound i_inline_xattr_size for non-inline-xattr inodes |
| CVE-2026-53381 | 7.8 | 3.7 | Linux | Linux | CWE-416 | virtiofs: fix UAF on submount umount |
| CVE-2026-64084 | 7.8 | 3.7 | Linux | Linux | — | hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR |
| CVE-2026-64086 | 7.8 | 3.7 | Linux | Linux | — | hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer |
| CVE-2026-63802 | 7.8 | 3.6 | Linux | Linux | CWE-416 | blk-cgroup: fix UAF in __blkcg_rstat_flush() |
| CVE-2026-63804 | 7.8 | 3.6 | Linux | Linux | CWE-416 | gfs2: fix use-after-free in gfs2_qd_dealloc |
| CVE-2026-64114 | 7.8 | 3.5 | Linux | Linux | CWE-125 | ipv4: raw: reject IP_HDRINCL packets with ihl < 5 |
| CVE-2026-64115 | 8.8 | 3.4 | Linux | Linux | CWE-416 | vsock/vmci: fix UAF when peer resets connection during handshake |
| CVE-2026-64126 | 7.3 | 3.4 | Linux | Linux | CWE-125 | Bluetooth: MGMT: validate Add Extended Advertising Data length |
| CVE-2026-53402 | 7.1 | 3.5 | Linux | Linux | CWE-125 | fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font() |
| CVE-2026-64111 | 7.1 | 3.5 | Linux | Linux | — | lsm: hold cred_guard_mutex for lsm_set_self_attr() |
| CVE-2026-64172 | 7.1 | 3.5 | Linux | Linux | — | KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235) |
| CVE-2026-63817 | 7.8 | 3.3 | Linux | Linux | — | f2fs: validate compress cache inode only when enabled |
| CVE-2026-64099 | 7.8 | 3.4 | Linux | Linux | CWE-416 | drm/v3d: Fix use-after-free of CPU job query arrays on error path |
| CVE-2026-53393 | 5.5 | 3.4 | Linux | Linux | — | nfsd: reset write verifier on deferred writeback errors |
| CVE-2026-64104 | 8.7 | 3.3 | Linux | Linux | CWE-401 | virt: sev-guest: Explicitly leak pages in unknown state |
| CVE-2026-53388 | 7.8 | 3.2 | Linux | Linux | CWE-416 | fuse: re-lock request before replacing page cache folio |
| CVE-2026-63803 | 7.8 | 3.2 | Linux | Linux | CWE-416 | hdlc_ppp: sync per-proto timers before freeing hdlc state |
| CVE-2026-63860 | 8.4 | 3.2 | Linux | Linux | — | RDMA/core: Prefer NLA_NUL_STRING |
| CVE-2026-64073 | 7.8 | 3.2 | Linux | Linux | — | irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT |
| CVE-2026-53382 | 5.5 | 3.2 | Linux | Linux | CWE-476 | media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si |
| CVE-2026-53385 | 5.5 | 3.2 | Linux | Linux | CWE-476 | vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write |
| CVE-2026-63828 | 8.4 | 3.1 | Linux | Linux | — | apparmor: mediate the implicit connect of TCP fast open sendmsg |
| CVE-2026-63807 | 8.8 | 3.0 | Linux | Linux | CWE-125 | KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level |
| CVE-2026-53403 | 5.5 | 3.0 | Linux | Linux | CWE-476 | fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var |
| CVE-2026-64109 | 8.8 | 2.9 | Linux | Linux | CWE-416 | af_unix: Fix UAF read of tail->len in unix_stream_data_wait() |
| CVE-2026-53386 | 7.8 | 2.9 | Linux | Linux | CWE-129 | iio: adc: ti-ads1298: add bounds check to pga_settings index |
| CVE-2026-53401 | 7.8 | 3.0 | Linux | Linux | CWE-416 | fbdev: omap2: fix use-after-free in omapfb_mmap |
| CVE-2026-63842 | 7.8 | 3.0 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring |
| CVE-2026-63843 | 7.8 | 3.0 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring |
| CVE-2026-63844 | 7.8 | 3.0 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring |
| CVE-2026-63845 | 7.8 | 3.0 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring |
| CVE-2026-63846 | 7.8 | 3.0 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring |
| CVE-2026-63847 | 7.8 | 2.9 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring |
| CVE-2026-63848 | 7.8 | 3.0 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring |
| CVE-2026-63850 | 7.8 | 3.0 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring |
| CVE-2026-63985 | 7.8 | 3.0 | Linux | Linux | — | ethtool: eeprom: add more safeties to EEPROM Netlink fallback |
| CVE-2026-63987 | 7.8 | 2.9 | Linux | Linux | — | ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES |
| CVE-2026-63995 | 7.8 | 2.9 | Linux | Linux | — | ethtool: cmis: validate start_cmd_payload_size from module |
| CVE-2026-63996 | 7.8 | 2.9 | Linux | Linux | — | ethtool: cmis: require exact CDB reply length |
| CVE-2026-64002 | 7.8 | 3.0 | Linux | Linux | — | ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_… |
| CVE-2026-64004 | 7.8 | 3.0 | Linux | Linux | — | net/iucv: fix locking in .getsockopt |
| CVE-2026-64005 | 7.8 | 3.0 | Linux | Linux | — | net/smc: Do not re-initialize smc hashtables |
| CVE-2026-64015 | 7.8 | 3.0 | Linux | Linux | — | security/keys: fix missed RCU read section on lookup |
| CVE-2026-64026 | 7.8 | 2.9 | Linux | Linux | — | rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg |
| CVE-2026-64051 | 7.8 | 2.9 | Linux | Linux | — | accel/qaic: Add overflow check to remap_pfn_range during mmap |
| CVE-2026-64053 | 7.8 | 2.9 | Linux | Linux | — | block: don't overwrite bip_vcnt in bio_integrity_copy_user() |
| CVE-2026-64097 | 7.8 | 3.0 | Linux | Linux | CWE-787 | drm/amd/display: Validate GPIO pin LUT table size before iterating |
| CVE-2026-64108 | 7.8 | 3.0 | Linux | Linux | — | cifs: Fix busy dentry used after unmounting |
| CVE-2026-64133 | 7.8 | 3.0 | Linux | Linux | CWE-125 | ALSA: asihpi: Fix potential OOB array access at reading cache |
| CVE-2026-64134 | 7.8 | 2.9 | Linux | Linux | CWE-476 | ALSA: pcm: Don't setup bogus iov_iter for silencing |
| CVE-2026-64137 | 7.8 | 3.0 | Linux | Linux | — | smb: client: require net admin for CIFS SWN netlink |
| CVE-2026-63841 | 7.8 | 2.8 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.1 ring |
| CVE-2026-63849 | 7.8 | 2.8 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v5.0.1 enc ring |
| CVE-2026-64181 | 7.8 | 2.8 | Linux | Linux | — | mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_sp… |
| CVE-2026-64090 | 5.5 | 2.9 | Linux | Linux | — | batman-adv: tt: avoid empty VLAN responses |
| CVE-2026-64092 | 5.5 | 2.9 | Linux | Linux | — | batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown |
| CVE-2026-64128 | 5.5 | 2.9 | Linux | Linux | CWE-476 | Bluetooth: ISO: drop ISO_END frames received without prior ISO_START |
| CVE-2026-64124 | 8.8 | 2.8 | Linux | Linux | — | net: devmem: reject dma-buf bind with non-page-aligned size or SG length |
| CVE-2026-63805 | 7.8 | 2.8 | Linux | Linux | — | crypto: nx - fix nx_crypto_ctx_exit argument |
| CVE-2026-63814 | 7.8 | 2.8 | Linux | Linux | — | f2fs: validate ACL entry sizes in f2fs_acl_from_disk() |
| CVE-2026-63824 | 7.8 | 2.8 | Linux | Linux | — | KEYS: fix overflow in keyctl_pkey_params_get_2() |
| CVE-2026-64008 | 7.8 | 2.8 | Linux | Linux | — | accel/rocket: fix UAF via dangling GEM handle in create_bo |
| CVE-2026-64027 | 7.8 | 2.8 | Linux | Linux | — | net: shaper: rework the VALID marking (again) |
| CVE-2026-64031 | 7.8 | 2.8 | Linux | Linux | — | erofs: fix managed cache race for unaligned extents |
| CVE-2026-64036 | 7.8 | 2.8 | Linux | Linux | — | cgroup/rstat: validate cpu before css_rstat_cpu() access |
| CVE-2026-64058 | 7.8 | 2.8 | Linux | Linux | — | netfs: Fix netfs_read_folio() to wait on writeback |
| CVE-2026-64074 | 7.8 | 2.8 | Linux | Linux | — | fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap |
| CVE-2026-64076 | 7.8 | 2.8 | Linux | Linux | — | netfilter: bridge: eb_tables: close module init race |
| CVE-2026-64077 | 7.8 | 2.8 | Linux | Linux | — | netfilter: ebtables: move to two-stage removal scheme |
| CVE-2026-64078 | 7.8 | 2.8 | Linux | Linux | — | netfilter: x_tables: add and use xtables_unregister_table_exit |
| CVE-2026-64145 | 7.8 | 2.8 | Linux | Linux | CWE-787 | wifi: wilc1000: fix dma_buffer leak on bus acquire failure |
| CVE-2026-64127 | 5.5 | 2.8 | Linux | Linux | — | Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer |
| CVE-2026-64144 | 5.5 | 2.8 | Linux | Linux | CWE-401 | Bluetooth: btmtk: fix urb->setup_packet leak in error paths |
| CVE-2026-64147 | 5.5 | 2.8 | Linux | Linux | CWE-401 | pds_core: fix debugfs_lookup dentry leak and error handling |
| CVE-2026-63816 | 7.8 | 2.7 | Linux | Linux | — | f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode |
| CVE-2026-64011 | 7.8 | 2.7 | Linux | Linux | — | nfc: llcp: Fix use-after-free in llcp_sock_release() |
| CVE-2026-64103 | 7.8 | 2.7 | Linux | Linux | CWE-416 | scsi: isci: Fix use-after-free in device removal path |
| CVE-2026-64123 | 7.8 | 2.7 | Linux | Linux | CWE-416 | net: hsr: defer node table free until after RCU readers |
| CVE-2026-64121 | 7.1 | 2.7 | Linux | Linux | CWE-125 | net: ifb: report ethtool stats over num_tx_queues |
| CVE-2026-63798 | 5.5 | 2.7 | Linux | Linux | CWE-401 | irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove |
| CVE-2026-64101 | 5.5 | 2.7 | Linux | Linux | — | fwctl: pds: Validate RPC input size before parsing |
| CVE-2026-64149 | 5.5 | 2.7 | Linux | Linux | — | dma-mapping: move dma_map_resource() sanity check into debug code |
| CVE-2026-53389 | 7.8 | 2.6 | Linux | Linux | CWE-416 | net/tcp-ao: fix use-after-free of key in del_async path |
| CVE-2026-64029 | 7.8 | 2.6 | Linux | Linux | — | ALSA: seq: Serialize UMP output teardown with event_input |
| CVE-2026-64032 | 7.8 | 2.6 | Linux | Linux | — | bridge: mcast: Fix a possible use-after-free when removing a bridge port |
| CVE-2026-53387 | 7.1 | 2.6 | Linux | Linux | CWE-129 | iio: light: veml6075: add bounds check to veml6075_it_ms index |
| CVE-2026-63833 | 7.1 | 2.6 | Linux | Linux | — | ntfs3: reject direct userspace writes to reserved $LX* xattrs |
| CVE-2026-53376 | 5.5 | 2.6 | Linux | Linux | — | drm/amdkfd: Add upper bound check for num_of_nodes |
| CVE-2026-63823 | 7.8 | 2.5 | Linux | Linux | — | keys: Pin request_key_auth payload in instantiate paths |
| CVE-2026-63827 | 7.8 | 2.5 | Linux | Linux | — | apparmor: fix use-after-free in rawdata dedup loop |
| CVE-2026-64023 | 7.8 | 2.5 | Linux | Linux | — | gpio: aggregator: fix a potential use-after-free |
| CVE-2026-64050 | 7.8 | 2.5 | Linux | Linux | — | drm/msm/dpu: don't mix devm and drmm functions |
| CVE-2026-53370 | 5.5 | 2.5 | Linux | Linux | — | perf/x86/intel: Improve validation and configuration of ACR masks |
| CVE-2026-63829 | 8.8 | 2.5 | Linux | Linux | — | net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink |
| CVE-2026-63864 | 8.4 | 2.5 | Linux | Linux | — | bpf: Propagate error from visit_tailcall_insn |
| CVE-2026-63870 | 7.8 | 2.5 | Linux | Linux | — | ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() |
| CVE-2026-53377 | 5.5 | 2.5 | Linux | Linux | — | drm/msm: always recover the gpu |
| CVE-2026-64129 | 5.5 | 2.5 | Linux | Linux | CWE-401 | mm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_page |
| CVE-2026-64135 | 5.5 | 2.4 | Linux | Linux | CWE-674 | hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX |
| CVE-2026-64155 | 5.5 | 2.5 | Linux | Linux | CWE-401 | wifi: ath11k: fix error path leaks in some WMI WOW calls |
| CVE-2026-64105 | 5.5 | 2.4 | Linux | Linux | — | KVM: arm64: vgic: Free private_irqs when init fails after allocation |
| CVE-2026-64131 | 5.5 | 2.4 | Linux | Linux | — | mm/memory: fix spurious warning when unmapping device-private/exclusive pages |
| CVE-2026-64157 | 5.5 | 2.4 | Linux | Linux | — | netfs: Fix partial invalidation of streaming-write folio |
| CVE-2026-63865 | 8.8 | 2.3 | Linux | Linux | — | bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks |
| CVE-2026-63793 | 7.8 | 2.3 | Linux | Linux | CWE-416 | ntfs: serialize volume label accesses |
| CVE-2026-63799 | 7.8 | 2.3 | Linux | Linux | CWE-125 | sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path |
| CVE-2026-63840 | 7.8 | 2.3 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v5.3.0 ring |
Results continue: ranks 401–465.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-19 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.