AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0130 68.1 —
AFFECTED Product Versions Fixed Catalyst::View::Wkhtmltopdf unspecified —
TIMELINE Jul 23 Reserved by CNA Jul 25 Published (CNA: CPANSec)
284 CVEs published July 25, 2026: 25 critical, 111 high, 21 medium, 0 low; 0 in KEV; 1 with a public exploit reference; 127 awaiting enrichment. Elevated volume. 25 rendered as box scores below; the remaining 259 in the results table.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 4239 | 6988 | 1368 | 2563 |
| KEV catalog size | 1670 | |||
133 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; medians are over each vendor's YTD disclosures.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 634 | 1552 | 202 | 1106 | 98 | 0 | 27 | 3 | 0.2 | 7.8 | .0016 | +400 |
| microsoft | 653 | 1356 | 104 | 927 | 300 | 8 | 378 | 32 | 2.4 | 7.8 | .0039 | +434 |
| red hat | 76 | 175 | 9 | 85 | 71 | 10 | 4 | 0 | 0.0 | 7.1 | .0028 | +34 |
| apple | 3 | 80 | 1 | 19 | 52 | 1 | 93 | 7 | 8.8 | 6.5 | .0036 | +3 |
| 26 | 35 | 6 | 24 | 1 | 1 | 73 | 5 | 14.3 | 8.8 | .0030 | +23 | |
| canonical | 3 | 3 | 0 | 2 | 1 | 0 | 0 | 0 | 0.0 | 7.8 | .0013 | +3 |
| android | 0 | 1 | 0 | 1 | 0 | 0 | 16 | 1 | 100.0 | 8.4 | .0171 | -1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 7 | 19 | 4 | 6 | 1 | 0 | 96 | 12 | 63.2 | 8.6 | .2459 | +4 |
| fortinet | 10 | 17 | 2 | 4 | 8 | 0 | 28 | 5 | 29.4 | 6.3 | .0051 | +9 |
| palo alto networks | 10 | 15 | 0 | 1 | 7 | 5 | 14 | 2 | 13.3 | 4.7 | .0028 | +7 |
| vmware | 7 | 7 | 1 | 6 | 0 | 0 | 21 | 0 | 0.0 | 8.7 | .0044 | +7 |
| f5 | 1 | 5 | 4 | 0 | 0 | 0 | 7 | 1 | 20.0 | 9.2 | .0402 | 0 |
| ivanti | 0 | 5 | 1 | 0 | 0 | 0 | 33 | 5 | 100.0 | 10.0 | .8152 | -1 |
| checkpoint | 3 | 4 | 3 | 1 | 0 | 0 | 3 | 2 | 50.0 | 9.2 | .4696 | +2 |
| broadcom | 2 | 4 | 0 | 0 | 2 | 0 | 4 | 2 | 50.0 | 5.1 | .0877 | +2 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| mozilla | 67 | 72 | 42 | 26 | 4 | 0 | 13 | 0 | 0.0 | 9.1 | .0031 | +67 |
| apache | 27 | 59 | 14 | 33 | 12 | 0 | 40 | 1 | 1.7 | 7.5 | .0058 | +12 |
| docker | 0 | 3 | 0 | 1 | 2 | 0 | 1 | 0 | 0.0 | 5.7 | .0015 | -3 |
| wordpress | 2 | 2 | 1 | 0 | 1 | 0 | 5 | 2 | 100.0 | 7.9 | .8435 | +2 |
| gitlab | 0 | 2 | 0 | 0 | 0 | 0 | 4 | 2 | 100.0 | — | .4451 | 0 |
| github | 1 | 1 | 0 | 0 | 1 | 0 | 0 | 0 | 0.0 | 4.7 | .0017 | +1 |
| kubernetes | 1 | 1 | 0 | 0 | 0 | 1 | 0 | 0 | 0.0 | 2.4 | .0024 | +1 |
| drupal | 0 | 1 | 1 | 0 | 0 | 0 | 5 | 1 | 100.0 | 9.8 | .8832 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1109 | 1113 | 212 | 539 | 304 | 57 | 40 | 3 | 0.3 | 7.6 | .0031 | +1107 |
| ibm | 32 | 40 | 16 | 11 | 13 | 0 | 7 | 0 | 0.0 | 8.4 | .0028 | +31 |
| adobe | 16 | 27 | 9 | 10 | 4 | 0 | 75 | 4 | 14.8 | 8.6 | .0144 | +9 |
| solarwinds | 15 | 19 | 15 | 1 | 1 | 0 | 11 | 4 | 21.1 | 9.1 | .0044 | +14 |
| progress | 18 | 18 | 3 | 10 | 5 | 0 | 9 | 0 | 0.0 | 7.8 | .0031 | +18 |
| atlassian | 3 | 3 | 0 | 3 | 0 | 0 | 13 | 0 | 0.0 | 8.0 | .0026 | +3 |
| zohocorp | 3 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 7.1 | .0048 | +3 |
| veeam | 1 | 1 | 0 | 1 | 0 | 0 | 4 | 0 | 0.0 | 8.4 | .0013 | +1 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| d-link | 7 | 8 | 0 | 0 | 6 | 1 | 26 | 1 | 12.5 | 5.5 | .0073 | +7 |
| hikvision | 5 | 6 | 0 | 3 | 2 | 0 | 2 | 1 | 16.7 | 7.2 | .0024 | +5 |
| bosch | 2 | 2 | 0 | 2 | 0 | 0 | 0 | 0 | 0.0 | 8.0 | .0018 | +2 |
| rockwell automation | 1 | 1 | 1 | 0 | 0 | 0 | 0 | 0 | 0.0 | 9.2 | .0030 | +1 |
| siemens | 0 | 1 | 0 | 1 | 0 | 0 | 1 | 0 | 0.0 | 8.7 | .0032 | 0 |
| dahua | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| qnap | 0 | 0 | 0 | 0 | 0 | 0 | 8 | 0 | — | — | — | 0 |
| schneider electric | 0 | 0 | 0 | 0 | 0 | 0 | 1 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| surrealdb | 57 | 57 | 3 | 26 | 25 | 3 | 0 | 0 | 0.0 | 7.1 | .0025 | +57 |
| grafana | 8 | 41 | 2 | 14 | 22 | 3 | 0 | 0 | 0.0 | 6.5 | .0033 | +2 |
| open ises | 0 | 37 | 2 | 14 | 21 | 0 | 0 | 0 | 0.0 | 6.9 | .0021 | 0 |
| netty | 10 | 32 | 6 | 24 | 1 | 1 | 0 | 0 | 0.0 | 7.5 | .0051 | -4 |
| regularlabs.com | 29 | 29 | 6 | 14 | 9 | 0 | 0 | 0 | 0.0 | 7.5 | .0022 | +29 |
| watchguard | 17 | 28 | 1 | 18 | 9 | 0 | 4 | 0 | 0.0 | 7.3 | .0026 | +17 |
| nlnet labs | 24 | 27 | 0 | 4 | 17 | 6 | 0 | 0 | 0.0 | 5.9 | .0024 | +24 |
| mongodb | 26 | 26 | 1 | 17 | 7 | 1 | 2 | 0 | 0.0 | 7.1 | .0023 | +26 |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-48282 | .9924 | 99.9 | — |
| CVE-2026-63030 | .9560 | 99.9 | 9.8 |
| CVE-2026-39808 | .9121 | 99.8 | — |
| CVE-2026-48908 | .8813 | 99.8 | 10.0 |
| CVE-2026-56290 | .8325 | 99.7 | 10.0 |
| CVE-2026-48939 | .8250 | 99.6 | 10.0 |
| CVE-2026-50522 | .7698 | 99.5 | 9.8 |
| CVE-2026-15410 | .7635 | 99.5 | 7.2 |
| CVE-2026-56291 | .7607 | 99.5 | 10.0 |
| CVE-2026-15409 | .7422 | 99.4 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-48908 | 10.0 | .8813 | KEV |
| CVE-2026-56290 | 10.0 | .8325 | KEV |
| CVE-2026-48939 | 10.0 | .8250 | KEV |
| CVE-2026-56291 | 10.0 | .7607 | KEV |
| CVE-2026-15409 | 10.0 | .7422 | KEV |
| CVE-2026-8985 | 10.0 | .0660 | |
| CVE-2026-6516 | 10.0 | .0473 | |
| CVE-2026-47668 | 10.0 | .0434 | |
| CVE-2026-44359 | 10.0 | .0100 | |
| CVE-2025-71389 | 10.0 | .0093 |
| Vendor | CVEs |
|---|---|
| oracle | 1109 |
| microsoft | 653 |
| linux | 641 |
| red hat | 89 |
| mozilla | 67 |
| surrealdb | 57 |
| apple | 40 |
| ibm | 39 |
| regularlabs.com | 29 |
| apache | 28 |
| Vendor | KEV |
|---|---|
| microsoft | 32 |
| cisco | 12 |
| apple | 7 |
| fortinet | 5 |
| 5 | |
| ivanti | 5 |
| adobe | 4 |
| langflow | 4 |
| solarwinds | 4 |
| synacor | 4 |
| Ecosystem | Advisories |
|---|---|
| Maven | 16 |
| crates.io | 1 |
| npm | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2008-4128 | Cisco | 0 |
| CVE-2021-27137 | DD-WRT | 0 |
| CVE-2023-4346 | KNX Association | 0 |
| CVE-2026-0770 | Langflow | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-16232 | checkpoint | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE-2026-39808 | Fortinet | 0 |
| CVE-2026-45659 | Microsoft | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | Accellion | 2021-11-17 | 1711 |
| CVE-2021-27102 | Accellion | 2021-11-17 | 1711 |
| CVE-2021-27101 | Accellion | 2021-11-17 | 1711 |
| CVE-2021-27103 | Accellion | 2021-11-17 | 1711 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1711 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1711 |
| CVE-2021-42013 | Apache | 2021-11-17 | 1711 |
| CVE-2021-41773 | Apache | 2021-11-17 | 1711 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1711 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1711 |
EXPLOIT PUBLISHED — CVE-2026-10681 (zephyrproject zephyr). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65693 (microweber). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-65711 (nuxsmin sysPass). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66004 (ahujasid blender-mcp). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66005 (janhq jan). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-66027 (kortix-ai suna). Public exploit reference added.
DUE DATE PASSED — CVE-2021-27137 (DD-WRT). CISA remediation deadline was July 24, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-0770 (Langflow). CISA remediation deadline was July 24, 2026; still in catalog.
DUE DATE PASSED — CVE-2026-63030 (WordPress). CISA remediation deadline was July 24, 2026; still in catalog.
284 CVEs published. 25 box scores, 259 table rows — nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0130 68.1 —
AFFECTED Product Versions Fixed Catalyst::View::Wkhtmltopdf unspecified —
TIMELINE Jul 23 Reserved by CNA Jul 25 Published (CNA: CPANSec)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N H 9.1 .0073 51.2 —
AFFECTED Product Versions Fixed Linux a07b4970f464f13640e28e16dad6cfa33647cc99 – — Linux 4.8 – 6.12.96
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0069 50.0 —
AFFECTED Product Versions Fixed Linux 8b6a361b8c482f22ac99c3273285ff16b23fba91 – — Linux 5.3 – 5.10.261
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N H 9.1 .0068 49.4 —
AFFECTED Product Versions Fixed Linux 9cb837480424e78ed585376f944088246685aec3 – — Linux 5.8 – 5.15.212
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0067 49.2 —
AFFECTED Product Versions Fixed Linux 09c04466ce7ea494993c0635ba5edb6d2222a806 – — Linux 5.2 – 5.10.261
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N H 9.1 .0067 49.1 —
AFFECTED Product Versions Fixed Linux 31c6312608c60b72a1feb99a5afb680645a3e8a3 – — Linux unspecified —
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N H 9.1 .0054 42.8 —
AFFECTED Product Versions Fixed Linux d7626b5acff9227e2a65da636a53e09bdafdc0aa – — Linux 5.8 – 5.10.261
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H N N 6.5 .0053 42.2 —
AFFECTED Product Versions Fixed Checkout Field Editor for WooCommerce (Pro) unspecified —
TIMELINE Jul 7 Reserved by CNA Jul 25 Published (CNA: Wordfence)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N H 9.1 .0052 42.0 —
AFFECTED Product Versions Fixed Linux db1312dd95488b5e6ff362ff66fcf953a46b1821 – — Linux 6.0 – 6.6.145
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N H L N U H H H 7.5 .0050 40.7 —
AFFECTED Product Versions Fixed Redis unspecified —
TIMELINE Jul 25 Reserved by CNA Jul 25 Published (CNA: mitre)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0050 40.7 —
AFFECTED Product Versions Fixed Linux e624d4ed4aa8cc3c69d1359b0aaea539203ed266 – — Linux 5.14 – 5.15.212
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0050 40.6 —
AFFECTED Product Versions Fixed Linux a92ccd3618e42333ac6f150ecdac14dca298bc7a – — Linux 6.13 – 5.10.261
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0050 40.6 —
AFFECTED Product Versions Fixed Linux b6366f048e0caff28af5335b7af2031266e1b06b – — Linux 4.1 – 5.10.261
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0049 40.0 —
AFFECTED Product Versions Fixed Linux eb817368f50c1cbe1bd07044124aad7db6330e3a – — Linux 5.15 – 6.1.178
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0049 40.0 —
AFFECTED Product Versions Fixed Linux 812ce2f8d14ea791edd88c36ebcc9017bf4c88cb – — Linux 5.12 – 5.15.212
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0048 39.3 —
AFFECTED Product Versions Fixed Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 – — Linux 5.15 – 6.1.178
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0048 39.2 —
AFFECTED Product Versions Fixed Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 – — Linux 5.15 – 6.1.178
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0047 39.0 —
AFFECTED Product Versions Fixed Linux 51e547e8c89c661f6fbede4a28b1d33b13625683 – — Linux 6.18 – 6.18.39
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0047 38.6 —
AFFECTED Product Versions Fixed Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 – — Linux 5.15 – 6.1.178
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N H H 9.1 .0047 38.6 —
AFFECTED Product Versions Fixed Linux f44158485826c076335d6860d35872271a83791d – — Linux 5.15 – 6.6.145
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0047 38.5 —
AFFECTED Product Versions Fixed Linux ccc89b9d1ed233349cfe8d87b842e7351b74d8de – — Linux 7.1 – 7.1.4
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U H H H 8.8 .0047 38.5 —
AFFECTED Product Versions Fixed Linux f5a544e3bab78142207e0242d22442db85ba1eff – — Linux 5.15 – 5.15.212
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L L N U N H H 8.1 .0046 38.3 —
AFFECTED Product Versions Fixed Linux e2f34481b24db2fd634b5edb0a5bd0e4d38cc6e9 – — Linux 5.15 – 6.1.178
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U L N H 8.2 .0046 38.2 —
AFFECTED Product Versions Fixed Linux 093b2bdad3221e3fae3c26d89387e7297a157664 – — Linux 3.6 – 5.10.261
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0046 37.9 —
AFFECTED Product Versions Fixed Linux 433042a91f9373241307725b52de573933ffedbf – — Linux 6.8 – 6.6.145
TIMELINE Jul 19 Reserved by CNA Jul 25 Published (CNA: Linux)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-64384 | 9.8 | 37.9 | Linux | Linux | — | smb: client: fix change notify replay double-free |
| CVE-2026-64385 | 9.8 | 37.9 | Linux | Linux | — | smb: client: fix double-free in SMB2_ioctl() replay |
| CVE-2026-64386 | 9.8 | 37.9 | Linux | Linux | — | smb: client: fix query_info() replay double-free |
| CVE-2026-64387 | 9.8 | 37.9 | Linux | Linux | — | smb: client: fix query directory replay double-free |
| CVE-2026-64391 | 9.8 | 37.9 | Linux | Linux | — | ksmbd: use opener credentials for ADS I/O |
| CVE-2026-64389 | 8.2 | 37.6 | Linux | Linux | — | ksmbd: validate NTLMv2 response before updating session key |
| CVE-2026-64380 | 8.2 | 36.9 | Linux | Linux | — | smb: client: harden POSIX SID length parsing |
| CVE-2026-64414 | 7.5 | 36.7 | Linux | Linux | — | netfilter: handle unreadable frags |
| CVE-2026-66012 | 10.0 | 36.4 | siyuan-note | siyuan | CWE-862 | SiYuan before v3.7.2 Unauthenticated Administrator Takeover via MCP |
| CVE-2026-64396 | 8.8 | 36.2 | Linux | Linux | — | ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation |
| CVE-2026-64437 | 8.8 | 36.2 | Linux | Linux | — | ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL |
| CVE-2026-64439 | 9.8 | 35.8 | Linux | Linux | — | crypto: krb5 - filter out async aead implementations at alloc |
| CVE-2026-64435 | 8.2 | 35.4 | Linux | Linux | — | audit: Fix data races of skb_queue_len() readers on audit_queue |
| CVE-2026-10818 | 8.1 | 35.0 | WPForms | WPForms Pro | CWE-434 | WPForms Pro <= 1.10.1.1 - Unauthenticated Arbitrary File Write via Chunked Up… |
| CVE-2026-64368 | 8.1 | 34.8 | Linux | Linux | — | mm/slab: do not limit zeroing to orig_size when only red zoning is enabled |
| CVE-2026-64395 | 7.5 | 33.8 | Linux | Linux | — | ksmbd: require source read access for duplicate extents |
| CVE-2026-66374 | 8.1 | 32.1 | nic | Knot Resolver | CWE-1284 | Knot Resolver before 6.4.1 allows remote code execution via a heap-based buff… |
| CVE-2026-66013 | 9.3 | 32.0 | openremote | openremote | CWE-639 | OpenRemote before 1.26.2 Authentication Bypass via Console Registration |
| CVE-2026-64410 | 9.8 | 31.1 | Linux | Linux | — | netfilter: flowtable: IPIP tunnel hardware offload is not yet support |
| CVE-2026-64523 | 9.8 | 29.0 | Linux | Linux | — | net/handshake: Take a long-lived file reference at submit |
| CVE-2026-64400 | 8.6 | 28.8 | Linux | Linux | — | ksmbd: prevent path traversal bypass by restricting caseless retry |
| CVE-2026-64382 | 8.8 | 28.5 | Linux | Linux | — | smb: client: fix double-free in SMB2_open() replay |
| CVE-2026-64522 | 8.8 | 27.8 | Linux | Linux | — | net/mlx5e: Fix eswitch mode block underflow on IPsec acquire SA |
| CVE-2026-64313 | 8.8 | 27.5 | Linux | Linux | — | crypto: ecc - Fix carry overflow in vli multiplication |
| CVE-2026-64364 | 8.8 | 27.5 | Linux | Linux | — | HID: multitouch: fix out-of-bounds bit access on mt_io_flags |
| CVE-2026-64445 | 8.8 | 24.4 | Linux | Linux | — | staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth() |
| CVE-2026-64379 | 7.1 | 23.5 | Linux | Linux | — | smb: client: mask server-provided mode to 07777 in modefromsid |
| CVE-2026-64442 | 8.1 | 21.1 | Linux | Linux | — | staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cm… |
| CVE-2026-64443 | 8.1 | 20.4 | Linux | Linux | — | staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop |
| CVE-2026-64444 | 8.1 | 20.4 | Linux | Linux | — | staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop |
| CVE-2026-64406 | 8.0 | 19.8 | Linux | Linux | — | Bluetooth: fix UAF in bt_accept_dequeue() |
| CVE-2026-64440 | 8.1 | 18.6 | Linux | Linux | — | staging: rtl8723bs: fix OOB write in HT_caps_handler() |
| CVE-2026-64403 | 7.1 | 18.5 | Linux | Linux | — | Bluetooth: L2CAP: validate option length before reading conf opt value |
| CVE-2026-64408 | 8.8 | 18.1 | Linux | Linux | — | Bluetooth: bnep: pin L2CAP connection during netdev registration |
| CVE-2026-64441 | 8.8 | 17.4 | Linux | Linux | — | staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and… |
| CVE-2026-64366 | 8.8 | 17.0 | Linux | Linux | — | HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert |
| CVE-2026-64434 | 8.8 | 16.2 | Linux | Linux | — | Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref |
| CVE-2026-64515 | 8.3 | 15.0 | Linux | Linux | — | wifi: mac80211: fix MLE defragmentation |
| CVE-2026-64505 | await | 12.7 | Linux | Linux | — | usb: gadget: function: rndis: add length check for header |
| CVE-2026-64452 | 7.1 | 12.6 | Linux | Linux | — | 6lowpan: fix NHC entry use-after-free on error path |
| CVE-2026-64307 | await | 12.2 | Linux | Linux | — | crypto: ccp - Do not initialize SNP for ioctl(SNP_CONFIG) |
| CVE-2026-64308 | await | 12.2 | Linux | Linux | — | crypto: ccp - Do not initialize SNP for ioctl(SNP_VLEK_LOAD) |
| CVE-2026-64309 | await | 12.2 | Linux | Linux | — | crypto: ccp - Do not initialize SNP for ioctl(SNP_COMMIT) |
| CVE-2026-64310 | await | 12.2 | Linux | Linux | — | crypto: ccp - Do not initialize SNP for SEV ioctls |
| CVE-2026-64306 | await | 11.6 | Linux | Linux | — | crypto: drbg - Fix returning success on failure in CTR_DRBG |
| CVE-2026-64337 | await | 11.6 | Linux | Linux | — | usb: mtu3: unmap request DMA on queue failure |
| CVE-2026-64363 | await | 11.6 | Linux | Linux | — | HID: appleir: fix UAF on pending key_up_timer in remove() |
| CVE-2026-64301 | await | 10.9 | Linux | Linux | — | regulator: scmi: fix of_node refcount leak in scmi_regulator_probe() |
| CVE-2026-64346 | await | 10.9 | Linux | Linux | — | usb: gadget: udc: Fix use-after-free in gadget_match_driver |
| CVE-2026-15425 | 6.4 | 10.3 | yoast | Yoast SEO – Advanced SEO with real-time guidance and built-in AI | CWE-79 | Yoast SEO <= 28.0 - Authenticated (Author+) Stored Cross-Site Scripting via P… |
| CVE-2026-64326 | await | 10.2 | Linux | Linux | — | block: skip sync_blockdev() on surprise removal in bdev_mark_dead() |
| CVE-2026-64327 | await | 10.2 | Linux | Linux | — | usb: gadget: f_fs: Initialize epfile->in early to fix endpoint direction checks |
| CVE-2026-64328 | await | 10.2 | Linux | Linux | — | usb: gadget: f_fs: Fix DMA fence leak |
| CVE-2026-64302 | await | 9.9 | Linux | Linux | — | x86/mm: Fix freeing of PMD-sized vmemmap pages |
| CVE-2026-64314 | await | 9.9 | Linux | Linux | — | crypto: chacha20poly1305 - validate poly1305 template argument |
| CVE-2026-64339 | await | 9.9 | Linux | Linux | — | usb: misc: usbio: bound bulk IN response length to the received transfer |
| CVE-2026-64446 | await | 9.5 | Linux | Linux | — | staging: rtl8723bs: fix heap buffer overflow in rtw_cfg80211_set_wpa_ie() |
| CVE-2026-64495 | await | 9.6 | Linux | Linux | — | iio: gyro: bmg160: bail out when bandwidth/filter is not in table |
| CVE-2026-64325 | await | 8.9 | Linux | Linux | — | wifi: mt76: mt7921/mt7925: fix NULL dereference in CSA beacon |
| CVE-2026-64351 | await | 8.4 | Linux | Linux | — | net: usb: kalmia: bound RX frame length in kalmia_rx_fixup() |
| CVE-2026-64484 | await | 8.4 | Linux | Linux | — | ALSA: es1938: check snd_ctl_new1() return value |
| CVE-2026-64455 | await | 8.3 | Linux | Linux | — | USB: chaoskey: Fix slab-use-after-free in chaoskey_release() |
| CVE-2026-64461 | await | 8.3 | Linux | Linux | — | PCI: mediatek: Fix IRQ domain leak when port fails to enable |
| CVE-2026-64462 | await | 8.3 | Linux | Linux | — | PCI: altera: Fix resource leaks on probe failure |
| CVE-2026-64465 | await | 8.3 | Linux | Linux | — | usb: xhci: Fix sleep in atomic context in xhci_free_streams() |
| CVE-2026-64470 | await | 8.3 | Linux | Linux | — | Bluetooth: btusb: fix use-after-free on marvell probe failure |
| CVE-2026-64471 | await | 8.3 | Linux | Linux | — | Bluetooth: btusb: fix use-after-free on registration failure |
| CVE-2026-64478 | await | 8.3 | Linux | Linux | — | ALSA: usb-audio: avoid kobject path lookup in DualSense match |
| CVE-2026-64483 | await | 8.3 | Linux | Linux | — | ALSA: firewire: isight: bound the sample count to the packet payload |
| CVE-2026-64487 | await | 8.3 | Linux | Linux | — | ALSA: caiaq: fix out-of-bounds read in the Traktor Kontrol S4 input parser |
| CVE-2026-64488 | await | 8.3 | Linux | Linux | — | ALSA: aoa: check snd_ctl_new1() return value |
| CVE-2026-64369 | await | 7.9 | Linux | Linux | — | s390: Revert support for DCACHE_WORD_ACCESS |
| CVE-2026-64472 | await | 7.9 | Linux | Linux | — | vfio/mlx5: Fix racy bitfields and tighten struct layout |
| CVE-2026-64479 | await | 7.9 | Linux | Linux | — | ALSA: seq: Fix uninitialised heap leak in snd_seq_event_dup() |
| CVE-2026-64480 | await | 7.9 | Linux | Linux | — | ALSA: ice1712: check snd_ctl_new1() return value |
| CVE-2026-64482 | await | 7.9 | Linux | Linux | — | ALSA: gus: check snd_ctl_new1() return value |
| CVE-2026-64454 | await | 7.9 | Linux | Linux | — | usb: dwc3: run gadget disconnect from sleepable suspend context |
| CVE-2026-64458 | await | 7.9 | Linux | Linux | — | mm/damon/ops-common: handle extreme intervals in damon_hot_score() |
| CVE-2026-64476 | await | 7.9 | Linux | Linux | — | vfio/pci: Latch disable_idle_d3 per device |
| CVE-2026-64486 | await | 7.9 | Linux | Linux | — | ALSA: cmipci: check snd_ctl_new1() return value |
| CVE-2026-64489 | await | 7.9 | Linux | Linux | — | ALSA: ymfpci: check snd_ctl_new1() return value |
| CVE-2026-64356 | await | 7.7 | Linux | Linux | — | xfs: fix memory leak in xfs_dqinode_metadir_create() |
| CVE-2026-64316 | await | 7.5 | Linux | Linux | — | crypto: caam - use print_hex_dump_devel to guard key hex dumps |
| CVE-2026-64329 | await | 7.5 | Linux | Linux | — | usb: typec: ucsi: ccg: Fix use-after-free of ucsi on remove |
| CVE-2026-64330 | await | 7.5 | Linux | Linux | — | usb: typec: tcpm: Validate SVID index in svdm_consume_modes() |
| CVE-2026-64331 | await | 7.5 | Linux | Linux | — | usbip: vudc: fix NULL deref in vep_dequeue() |
| CVE-2026-64332 | await | 7.5 | Linux | Linux | — | USB: ulpi: fix memory leak on registration failure |
| CVE-2026-64334 | await | 7.5 | Linux | Linux | — | USB: serial: digi_acceleport: fix hard lockup on disconnect |
| CVE-2026-64335 | await | 7.5 | Linux | Linux | — | USB: serial: digi_acceleport: fix broken rx after throttle |
| CVE-2026-64338 | await | 7.5 | Linux | Linux | — | USB: misc: uss720: unregister parport on probe failure |
| CVE-2026-64340 | await | 7.5 | Linux | Linux | — | USB: legousbtower: fix use-after-free on disconnect race |
| CVE-2026-64342 | await | 7.5 | Linux | Linux | — | USB: iowarrior: fix use-after-free on disconnect |
| CVE-2026-64343 | await | 7.5 | Linux | Linux | — | USB: ldusb: fix use-after-free on disconnect race |
| CVE-2026-64344 | await | 7.5 | Linux | Linux | — | USB: idmouse: fix use-after-free on disconnect race |
| CVE-2026-64347 | await | 7.5 | Linux | Linux | — | usb: gadget: composite: fix dead empty check in the USB_DT_OTG handler |
| CVE-2026-64359 | await | 7.5 | Linux | Linux | — | nilfs2: reject CLEAN_SEGMENTS ioctl with out-of-range segment numbers |
| CVE-2026-64360 | await | 7.5 | Linux | Linux | — | hfs/hfsplus: zero-initialize buffer in hfs_bnode_read |
| CVE-2026-64362 | await | 7.5 | Linux | Linux | — | HID: lg-g15: cancel pending work on remove to fix a use-after-free |
| CVE-2026-64370 | await | 7.5 | Linux | Linux | — | posix-cpu-timers: Fix pid refcount leak in do_cpu_nanosleep() error path |
| CVE-2026-64371 | await | 7.5 | Linux | Linux | — | proc: protect ptrace_may_access() with exec_update_lock (part 1) |
| CVE-2026-64373 | await | 7.5 | Linux | Linux | — | cpufreq: Fix hotplug-suspend race during reboot |
| CVE-2026-64381 | await | 7.5 | Linux | Linux | — | smb: client: Fix next buffer leak in receive_encrypted_standard() |
| CVE-2026-64425 | await | 7.5 | Linux | Linux | — | io_uring/io-wq: re-check IO_WQ_BIT_EXIT for each linked work item |
| CVE-2026-64429 | await | 7.5 | Linux | Linux | — | gpio: eic-sprd: use raw_spinlock_t in the irq startup path |
| CVE-2026-64494 | await | 7.5 | Linux | Linux | — | iio: light: gp2ap002: fix runtime PM leak on read error |
| CVE-2026-64497 | await | 7.6 | Linux | Linux | — | iio: chemical: scd30: Cleanup initializations and fix sign-extension bug |
| CVE-2026-64503 | await | 7.5 | Linux | Linux | — | iio: accel: kxsd9: fix runtime PM imbalance on write_raw() error |
| CVE-2026-64514 | await | 7.6 | Linux | Linux | — | userfaultfd: gate must_wait writability check on pte_present() |
| CVE-2026-64474 | await | 7.4 | Linux | Linux | — | vfio: prevent infinite loop in vfio_mig_get_next_state() on blocked arc |
| CVE-2026-64477 | await | 7.4 | Linux | Linux | — | x86,fs/resctrl: Prevent out-of-bounds access while offlining CPU when SNC ena… |
| CVE-2026-64457 | await | 7.3 | Linux | Linux | — | virtio_pci: fix vq info pointer lookup via wrong index |
| CVE-2026-64473 | await | 7.3 | Linux | Linux | — | vfio: Remove device debugfs before releasing devres |
| CVE-2026-64491 | await | 7.1 | Linux | Linux | — | ALSA: usx2y: us144mkii: fix work UAF on disconnect |
| CVE-2026-64336 | await | 7.0 | Linux | Linux | — | USB: serial: keyspan_pda: fix information leak |
| CVE-2026-64345 | await | 7.0 | Linux | Linux | — | usb: gadget: f_printer: take kref only for successful open |
| CVE-2026-64348 | await | 7.0 | Linux | Linux | — | usb: free iso schedules on failed submit |
| CVE-2026-64350 | await | 7.0 | Linux | Linux | — | usb: cdnsp: fix stream context array leak in cdnsp_alloc_stream_info() |
| CVE-2026-64352 | await | 7.0 | Linux | Linux | — | bpf: Allow LPM map access from sleepable BPF programs |
| CVE-2026-64365 | await | 7.0 | Linux | Linux | — | HID: letsketch: fix UAF on inrange_timer at driver unbind |
| CVE-2026-64376 | await | 7.0 | Linux | Linux | — | firmware_loader: fix device reference leak in firmware_upload_register() |
| CVE-2026-64405 | await | 7.0 | Linux | Linux | — | Bluetooth: hci_conn: Fix null ptr deref in hci_abort_conn() |
| CVE-2026-64409 | await | 7.0 | Linux | Linux | — | Bluetooth: btmtksdio: fix infinite loop in btmtksdio_txrx_work() |
| CVE-2026-64417 | await | 7.0 | Linux | Linux | — | mm: shrinker: fix NULL pointer dereference in debugfs |
| CVE-2026-64419 | await | 7.0 | Linux | Linux | — | mm/shrinker: do not hold RCU lock in shrinker_debugfs_count_show() |
| CVE-2026-64428 | await | 7.0 | Linux | Linux | — | gpio: sch: use raw_spinlock_t in the irq startup path |
| CVE-2026-64453 | await | 7.1 | Linux | Linux | — | usb: misc: usbio: fix disconnect UAF in client teardown |
| CVE-2026-64464 | await | 7.1 | Linux | Linux | — | xhci: sideband: fix ring sg table pages leak |
| CVE-2026-64466 | await | 7.1 | Linux | Linux | — | rust_binder: clear freeze listener on node removal |
| CVE-2026-64492 | await | 7.1 | Linux | Linux | — | iio: temperature: tmp006: use devm_iio_trigger_register |
| CVE-2026-64512 | await | 7.0 | Linux | Linux | — | ACPI: CPPC: Suppress UBSAN warning caused by field misuse |
| CVE-2026-64513 | await | 6.8 | Linux | Linux | — | KVM: x86: Unconditionally recompute CR8 intercept on PPR update |
| CVE-2026-64286 | 8.2 | 6.8 | Linux | Linux | — | KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU |
| CVE-2026-64287 | 8.2 | 6.8 | Linux | Linux | — | KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU |
| CVE-2026-64305 | await | 6.5 | Linux | Linux | — | crypto: qat - protect service table iterations with service_lock |
| CVE-2026-64321 | await | 6.5 | Linux | Linux | — | nvme: target: rdma: fix ndev refcount leak on queue connect |
| CVE-2026-64357 | await | 6.5 | Linux | Linux | — | xfs: fix exchmaps reservation limit check |
| CVE-2026-64358 | await | 6.5 | Linux | Linux | — | media: mtk-jpeg: cancel workqueue on release for supported platforms only |
| CVE-2026-64377 | await | 6.5 | Linux | Linux | — | cpufreq: qcom-cpufreq-hw: Fix possible double free |
| CVE-2026-64404 | await | 6.5 | Linux | Linux | — | Bluetooth: ISO: avoid NULL deref of conn in iso_conn_big_sync() |
| CVE-2026-64407 | await | 6.5 | Linux | Linux | — | Bluetooth: btnxpuart: Fix out-of-bounds firmware read in nxp_recv_fw_req_v3() |
| CVE-2026-64415 | await | 6.5 | Linux | Linux | — | mm/swap: add cond_resched() in swap_reclaim_full_clusters to prevent softlockup |
| CVE-2026-64416 | await | 6.5 | Linux | Linux | — | mm: swap_cgroup: fix NULL deref in lookup_swap_cgroup_id on swapless host |
| CVE-2026-64421 | await | 6.5 | Linux | Linux | — | media: nxp: imx8-isi: Fix use-after-free on remove |
| CVE-2026-64424 | await | 6.5 | Linux | Linux | — | netpoll: fix a use-after-free on shutdown path |
| CVE-2026-64427 | await | 6.5 | Linux | Linux | — | HID: logitech-dj: Fix maxfield check in DJ short report validation |
| CVE-2026-64433 | await | 6.5 | Linux | Linux | — | Bluetooth: MGMT: Fix UAF of hci_conn_params in add_device_complete |
| CVE-2026-64493 | await | 6.5 | Linux | Linux | — | iio: pressure: mpl115: fix runtime PM leak on read error |
| CVE-2026-64517 | await | 6.6 | Linux | Linux | — | drm/xe/gsc: Fix double-free of managed BO in error path |
| CVE-2026-64518 | await | 6.5 | Linux | Linux | — | tcp: Fix out-of-bounds access for twsk in tcp_ao_established_key(). |
| CVE-2026-64519 | await | 6.6 | Linux | Linux | — | NFSD: Fix infinite loop in layout state revocation |
| CVE-2026-64528 | await | 6.5 | Linux | Linux | — | tty: serial: samsung: Remove redundant port lock acquisition in rx helpers |
| CVE-2026-64341 | await | 6.3 | Linux | Linux | — | USB: iowarrior: fix use-after-free on disconnect race |
| CVE-2026-64349 | await | 6.3 | Linux | Linux | — | usb: dwc3: fix dwc3_readl() and dwc3_writel() calls in dwc3_ulpi_setup() |
| CVE-2026-64353 | await | 6.3 | Linux | Linux | — | bpf: Keep dynamic inner array lookups nullable |
| CVE-2026-64426 | await | 6.3 | Linux | Linux | — | io_uring/nop: fix file reference leak with IOSQE_FIXED_FILE |
| CVE-2026-64521 | await | 6.3 | Linux | Linux | — | pinctrl: meson: amlogic-a4: fix deadlock issue |
| CVE-2026-64500 | await | 6.2 | Linux | Linux | — | iio: adc: lpc32xx: Initialize completion before requesting IRQ |
| CVE-2026-64504 | await | 6.2 | Linux | Linux | — | iio: accel: bmc150: clamp the device-reported FIFO frame count |
| CVE-2026-64271 | 7.8 | 6.1 | Linux | Linux | CWE-129 | Input: touchwin - reset the packet index on every complete packet |
| CVE-2026-64273 | 7.8 | 6.1 | Linux | Linux | CWE-129 | Input: iforce - bound the device-reported force-feedback effect index |
| CVE-2026-64274 | 7.8 | 6.1 | Linux | Linux | CWE-787 | Input: goodix - clamp the device-reported contact count |
| CVE-2026-64276 | 7.8 | 6.1 | Linux | Linux | CWE-787 | Input: synaptics-rmi4 - bound the F30 keymap to the GPIO/LED count |
| CVE-2026-64277 | 7.8 | 6.1 | Linux | Linux | CWE-125 | Input: synaptics-rmi4 - bound the F3A keymap to the GPIO count |
| CVE-2026-64296 | 7.8 | 6.1 | Linux | Linux | — | exfat: bound uniname advance in exfat_find_dir_entry() |
| CVE-2026-64304 | 7.8 | 6.1 | Linux | Linux | — | crypto: qat - validate RSA CRT component lengths |
| CVE-2026-64322 | 7.8 | 6.1 | Linux | Linux | — | udf: validate sparing table length as an entry count, not a byte count |
| CVE-2026-64333 | 7.8 | 6.1 | Linux | Linux | — | USB: serial: digi_acceleport: fix write buffer corruption |
| CVE-2026-64280 | 8.8 | 6.0 | Linux | Linux | — | fpga: dfl-afu: validate DMA mapping length in afu_dma_map_region() |
| CVE-2026-64270 | 7.8 | 6.0 | Linux | Linux | CWE-787 | Input: mms114 - reject an oversized device packet size |
| CVE-2026-64272 | 7.8 | 6.0 | Linux | Linux | CWE-129 | Input: mms114 - fix touch indexing for MMS134S and MMS136 |
| CVE-2026-64293 | 7.8 | 5.8 | Linux | Linux | — | iommufd: Use sizeof(*hdr) instead of sizeof(hdr) in veventq read |
| CVE-2026-64300 | 7.8 | 5.8 | Linux | Linux | — | perf/aux: Fix page UAF in map_range() |
| CVE-2026-64451 | await | 5.9 | Linux | Linux | — | tracing: Fix NULL pointer dereference in func_set_flag() |
| CVE-2026-64506 | await | 5.8 | Linux | Linux | — | wifi: rtw89: correct drop logic for malformed AMPDU frames |
| CVE-2026-64527 | await | 5.7 | Linux | Linux | — | drm/hyperv: validate VMBus packet size in receive callback |
| CVE-2026-64266 | 7.8 | 5.6 | Linux | Linux | CWE-416 | fuse: re-lock request before returning from fuse_ref_folio() |
| CVE-2026-64298 | 7.1 | 5.7 | Linux | Linux | — | NFSv4: include MAY_WRITE in open permission mask for O_TRUNC |
| CVE-2026-64299 | 7.1 | 5.6 | Linux | Linux | — | tracing: Prevent out-of-bounds read in glob matching |
| CVE-2026-64317 | 7.1 | 5.6 | Linux | Linux | — | isofs: bound Rock Ridge symlink components to the SL record |
| CVE-2026-64318 | 7.1 | 5.6 | Linux | Linux | — | partitions: aix: bound the pp_count scan to the ppe array |
| CVE-2026-64323 | 7.1 | 5.6 | Linux | Linux | — | udf: validate VAT header length against the VAT inode size |
| CVE-2026-64265 | 7.8 | 5.6 | Linux | Linux | CWE-416 | fuse: clear intr_entry in fuse_resend and fuse_remove_pending_req |
| CVE-2026-64295 | 5.5 | 5.4 | Linux | Linux | CWE-476 | mm: page_ext: add count limit to page_ext_iter_next to prevent invalid PFN ac… |
| CVE-2026-64259 | 7.8 | 5.4 | Linux | Linux | CWE-416 | fuse-uring: make a fuse_req on SQE commit only findable after memcpy |
| CVE-2026-64261 | 7.8 | 5.4 | Linux | Linux | CWE-416 | fuse-uring: Avoid use-after-free in fuse_uring_async_stop_queues |
| CVE-2026-64311 | 7.8 | 5.4 | Linux | Linux | — | crypto: loongson - Remove broken and unused loongson-rng |
| CVE-2026-64499 | await | 5.4 | Linux | Linux | — | iio: adc: ti-ads1119: fix PM reference leak in buffer preenable |
| CVE-2026-64507 | await | 5.4 | Linux | Linux | — | x86/bugs: Enable IBPB flush on BPF JIT allocation |
| CVE-2026-64508 | await | 5.4 | Linux | Linux | — | bpf: Support for hardening against JIT spraying |
| CVE-2026-64509 | await | 5.4 | Linux | Linux | — | rust: block: fix GenDisk cleanup paths |
| CVE-2026-64324 | 7.8 | 5.3 | Linux | Linux | — | udf: validate free block extents against the partition length |
| CVE-2026-64275 | 5.5 | 5.2 | Linux | Linux | CWE-369 | Input: elan_i2c - prevent division by zero and arithmetic underflow |
| CVE-2026-64297 | 5.5 | 5.2 | Linux | Linux | CWE-476 | module: decompress: check return value of module_extend_max_pages() |
| CVE-2026-64511 | await | 5.3 | Linux | Linux | — | ACPI: NFIT: core: Fix possible NULL pointer dereference |
| CVE-2026-64525 | await | 5.3 | Linux | Linux | — | xfrm: move policy_bydst RCU sync from per-netns .exit to .pre_exit |
| CVE-2026-64256 | 5.5 | 5.2 | Linux | Linux | — | xfs: don't wrap around quota ids in dqiterate |
| CVE-2026-64289 | 5.5 | 5.2 | Linux | Linux | — | iommufd: Set upper bounds on cache invalidation entry_num and entry_len |
| CVE-2026-64290 | 5.5 | 5.2 | Linux | Linux | CWE-835 | iommufd: Break the loop on failure in iommufd_fault_fops_read() |
| CVE-2026-64294 | 5.5 | 5.2 | Linux | Linux | — | mm: do file ownership checks with the proper mount idmap |
| CVE-2026-64498 | await | 5.2 | Linux | Linux | — | iio: buffer: hw-consumer: free scan_mask on buffer release |
| CVE-2026-64526 | await | 5.1 | Linux | Linux | — | ethtool: tsconfig: fix missing ethnl_ops_complete() |
| CVE-2026-64490 | 8.4 | 4.9 | Linux | Linux | — | ALSA: virtio: Validate control metadata from the device |
| CVE-2026-64258 | 5.5 | 5.0 | Linux | Linux | CWE-476 | fuse-uring: remove request-less entries from ent_w_req_queue to fix NULL deref |
| CVE-2026-64262 | 5.5 | 5.0 | Linux | Linux | — | fuse-uring: end fuse_req on io-uring cancel task work |
| CVE-2026-64263 | 5.5 | 5.0 | Linux | Linux | — | fuse-uring: fix moving cancelled entry to ent_in_userspace list |
| CVE-2026-64264 | 5.5 | 5.0 | Linux | Linux | — | fuse-uring: fix EFAULT clobber in fuse_uring_commit |
| CVE-2026-64267 | 5.5 | 5.0 | Linux | Linux | — | fuse: avoid 32-bit prune notification count wrap |
| CVE-2026-64278 | 5.5 | 5.0 | Linux | Linux | — | i2c: imx-lpi2c: mark I2C adapter when hardware is powered down |
| CVE-2026-64288 | 5.5 | 5.0 | Linux | Linux | CWE-476 | KVM: arm64: nv: Avoid dereferencing NULL VNCR pseudo-TLB |
| CVE-2026-64291 | 5.5 | 5.0 | Linux | Linux | — | iommufd: Set veventq_depth upper bound |
| CVE-2026-64292 | 5.5 | 5.0 | Linux | Linux | CWE-401 | iommufd: Move vevent memory allocation outside spinlock |
| CVE-2026-64456 | 7.7 | 4.5 | Linux | Linux | — | hwrng: virtio: clamp device-reported used.len at copy_data() |
| CVE-2026-64315 | 7.0 | 4.3 | Linux | Linux | — | crypto: caam - use print_hex_dump_devel to guard key hex dumps |
| CVE-2026-64524 | 7.7 | 4.2 | Linux | Linux | — | drm/hyperv: validate resolution_count and fix WIN8 fallback |
| CVE-2026-64367 | 7.8 | 4.0 | Linux | Linux | — | HID: hid-goodix-spi: validate report size to prevent stack buffer overflow |
| CVE-2026-64475 | 8.8 | 3.7 | Linux | Linux | — | vfio/pci: Release the VGA arbiter client on register_device() failure |
| CVE-2026-64449 | 7.8 | 3.7 | Linux | Linux | — | staging: vme_user: bound slave read/write to the kern_buf size |
| CVE-2026-64463 | 7.8 | 3.7 | Linux | Linux | — | usb: typec: tcpci_rt1711h: unregister TCPCI port with devres |
| CVE-2026-64481 | 7.8 | 3.7 | Linux | Linux | — | ALSA: hda/cs35l41: Fix firmware load work teardown |
| CVE-2026-64283 | 7.0 | 3.7 | Linux | Linux | CWE-190 | KVM: guest_memfd: Treat memslot binding offset+size as unsigned values |
| CVE-2026-64467 | 8.8 | 3.6 | Linux | Linux | — | rust_binder: use a u64 stride when cleaning up the offsets array |
| CVE-2026-64485 | 7.8 | 3.6 | Linux | Linux | — | ALSA: compress: Fix task creation error unwind |
| CVE-2026-64285 | 5.5 | 3.6 | Linux | Linux | — | KVM: SEV: Pin source page for write when adding CPUID data for SNP guest |
| CVE-2026-64438 | 8.8 | 3.4 | Linux | Linux | — | crypto: qat - fix VF2PF work teardown race in adf_disable_sriov() |
| CVE-2026-64432 | 7.8 | 3.4 | Linux | Linux | — | fs/ntfs3: validate Dirty Page Table capacity in log_replay copy_lcns |
| CVE-2026-64468 | 7.8 | 3.4 | Linux | Linux | — | binder: fix UAF in binder_free_transaction() |
| CVE-2026-64469 | 7.8 | 3.4 | Linux | Linux | — | binder: fix UAF in binder_thread_release() |
| CVE-2026-64529 | 7.8 | 3.4 | Linux | Linux | — | crypto: qat - remove unused character device and IOCTLs |
| CVE-2026-64447 | 7.8 | 3.3 | Linux | Linux | — | staging: media: ipu7: fix double-free and use-after-free in error paths |
| CVE-2026-64422 | 7.1 | 3.2 | Linux | Linux | — | net: ipv4: bound TCP reordering sysctl writes and MTU probe sizes |
| CVE-2026-64520 | 8.4 | 3.1 | Linux | Linux | — | firmware: arm_ffa: Bound PARTITION_INFO_GET_REGS copies |
| CVE-2026-64354 | 7.8 | 2.9 | Linux | Linux | — | bpf: Validate BTF repeated field counts before expansion |
| CVE-2026-64361 | 7.8 | 3.0 | Linux | Linux | — | hfs/hfsplus: fix u32 overflow in check_and_correct_requested_length |
| CVE-2026-64375 | 7.8 | 3.0 | Linux | Linux | — | proc: protect ptrace_may_access() with exec_update_lock (FD links) |
| CVE-2026-64378 | 7.8 | 3.0 | Linux | Linux | — | writeback: fix race between cgroup_writeback_umount() and inode_switch_wbs() |
| CVE-2026-64402 | 7.8 | 2.9 | Linux | Linux | — | coresight: ultrasoc-smb: Fix OOB write in smb_sync_perf_buffer() |
| CVE-2026-64279 | 7.8 | 2.8 | Linux | Linux | CWE-362 | i2c: core: fix adapter deregistration race |
| CVE-2026-64372 | 7.8 | 2.7 | Linux | Linux | — | cpufreq: pcc: fix use-after-free and double free in _OSC evaluation |
| CVE-2026-64401 | 7.8 | 2.7 | Linux | Linux | — | smb: client: resolve SWN tcon from live registrations |
| CVE-2026-64423 | 7.8 | 2.7 | Linux | Linux | — | ipv4: igmp: remove multicast group from hash table on device destruction |
| CVE-2026-64411 | 7.1 | 2.7 | Linux | Linux | — | netfilter: ebtables: terminate table name before find_table_lock() |
| CVE-2026-64412 | 7.1 | 2.7 | Linux | Linux | — | netfilter: ebtables: module names must be null-terminated |
| CVE-2026-64496 | 7.1 | 2.7 | Linux | Linux | — | iio: event: Fix event FIFO reset race |
| CVE-2026-64260 | 7.8 | 2.6 | Linux | Linux | CWE-362 | fuse-uring: Avoid queue->stopped races and set/read that value under lock |
| CVE-2026-64418 | 7.8 | 2.6 | Linux | Linux | — | mm: shrinker: fix shrinker_info teardown race with expansion |
| CVE-2026-64431 | 7.8 | 2.5 | Linux | Linux | — | ntfs: avoid calling post_write_mst_fixup() for invalid index_block |
| CVE-2026-64284 | 7.1 | 2.5 | Linux | Linux | CWE-367 | KVM: x86: Ensure vendor's exit handler runs before fastpath userspace exits |
| CVE-2026-64413 | 7.0 | 2.3 | Linux | Linux | — | netfilter: ebtables: zero chainstack array |
| CVE-2026-64388 | 7.8 | 2.2 | Linux | Linux | — | smb/client: fix chown/chgrp with SMB3 POSIX Extensions |
| CVE-2026-64502 | 7.8 | 2.1 | Linux | Linux | — | iio: adc: ad_sigma_delta: fix clear_pending_event for registerless devices |
| CVE-2026-64436 | 7.1 | 2.1 | Linux | Linux | — | net: af_key: initialize alg_key_len for IPComp states |
| CVE-2026-64420 | 7.0 | 2.0 | Linux | Linux | — | mfd: cros_ec: Delay dev_set_drvdata() until probe success |
| CVE-2026-64460 | 7.0 | 2.0 | Linux | Linux | — | PCI/IOV: Skip VF Resizable BAR restore on read error |
| CVE-2026-64501 | 7.1 | 1.8 | Linux | Linux | — | iio: adc: ad_sigma_delta: fix CS held asserted and state leaks |
| CVE-2026-64516 | 8.8 | 1.6 | Linux | Linux | — | drm/amdgpu/vce1: Fix VCE 1 firmware size and offsets |
| CVE-2026-64510 | 7.0 | 1.5 | Linux | Linux | — | ACPI: NFIT: core: Fix acpi_nfit_init() error cleanup |
| CVE-2026-64282 | 4.7 | 1.2 | Linux | Linux | CWE-362 | KVM: arm64: Don't leak PFN when kvm_translate_vncr() races MMU notifier |
| CVE-2026-66011 | 4.8 | 0.6 | ImageMagick | ImageMagick | CWE-401 | ImageMagick before 7.1.2-27 Memory Leak via Invalid CLI Options |
| CVE-2026-10681 | 7.0 | 0.4 | zephyrproject | zephyr | CWE-362 | SMP race in `thread_idx_alloc()` lets concurrent `k_object_alloc(K_OBJ_THREAD… |
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-25 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.