Edition of August 10, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-68206 | 7.8 | 7.3 | Linux | Linux | — | media: v4l2-ctrls: validate HEVC active reference counts |
| CVE-2026-68209 | 7.8 | 7.3 | Linux | Linux | — | media: sun4i-csi: Return queued buffers on start_streaming() failure |
| CVE-2026-68210 | 7.8 | 7.3 | Linux | Linux | — | media: stm32: dcmi: unregister notifier on probe failure |
| CVE-2026-68213 | 7.8 | 7.3 | Linux | Linux | — | media: rtl2832_sdr: Return queued buffers on start_streaming() failure |
| CVE-2026-68216 | 7.8 | 7.3 | Linux | Linux | — | media: pwc: Return queued buffers on start_streaming() failure |
| CVE-2026-68219 | 7.8 | 7.3 | Linux | Linux | — | media: nxp: imx8-isi: Fix potential out-of-bounds issues |
| CVE-2026-68338 | 7.8 | 7.3 | Linux | Linux | — | net/packet: avoid fanout hook re-registration after unregister |
| CVE-2026-68126 | await | 7.3 | Linux | Linux | — | mac802154: hold an interface reference across the scan worker |
| CVE-2026-68133 | await | 7.3 | Linux | Linux | — | ice: fix PTP Call Trace during PTP release |
| CVE-2026-68135 | await | 7.3 | Linux | Linux | — | net: hip04: fix RX buffer leak on build_skb failure |
| CVE-2026-68139 | await | 7.3 | Linux | Linux | — | net/mlx5e: Use sender devcom for MPV master-up |
| CVE-2026-68146 | await | 7.3 | Linux | Linux | — | ftrace: Add global mutex to serialize trace_parser access |
| CVE-2026-68151 | await | 7.3 | Linux | Linux | — | binfmt_elf_fdpic: only honour the first PT_INTERP |
| CVE-2026-68252 | await | 7.3 | Linux | Linux | — | drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON() |
| CVE-2026-68256 | await | 7.3 | Linux | Linux | — | drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks p… |
| CVE-2026-68271 | await | 7.3 | Linux | Linux | — | drm/nouveau: fix reversed error cleanup order in ucopy functions |
| CVE-2026-68272 | await | 7.3 | Linux | Linux | — | drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1 |
| CVE-2026-68279 | await | 7.3 | Linux | Linux | — | drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers |
| CVE-2026-68280 | await | 7.3 | Linux | Linux | — | drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS() |
| CVE-2026-68281 | await | 7.3 | Linux | Linux | — | drm/imagination: Count paired job fence as dependency in prepare_job() |
| CVE-2026-68325 | await | 7.3 | Linux | Linux | — | iommu/amd: Bound the early ACPI HID map |
| CVE-2026-68333 | await | 7.3 | Linux | Linux | — | dpaa2-switch: put MAC endpoint device on disconnect |
| CVE-2026-68336 | await | 7.3 | Linux | Linux | — | bonding: fix devconf_all NULL dereference when IPv6 is disabled |
| CVE-2026-68350 | await | 7.3 | Linux | Linux | — | wifi: carl9170: fix OOB read from off-by-two in TX status handler |
| CVE-2026-68355 | await | 7.3 | Linux | Linux | — | wifi: ath11k: fix potential buffer underflow in ath11k_hal_rx_msdu_list_get() |
| CVE-2026-68363 | await | 7.3 | Linux | Linux | — | wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request |
| CVE-2026-68365 | await | 7.3 | Linux | Linux | — | USB: serial: io_edgeport: cap received transmit credits |
| CVE-2026-68366 | await | 7.3 | Linux | Linux | — | usb: gadget: uvc: clamp SEND_RESPONSE length to the response buffer |
| CVE-2026-68367 | await | 7.3 | Linux | Linux | — | usb: gadget: f_tcm: synchronize delayed set_alt with teardown |
| CVE-2026-68406 | await | 7.3 | Linux | Linux | — | wifi: cfg80211: validate PMSR FTM preamble range |
| CVE-2025-30240 | 5.1 | 7.1 | TP-Link Systems Inc. | HB810(US2) V1.0/1.6/2.0/2.6 | CWE-59 | Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in… |
| CVE-2026-68387 | 7.8 | 7.1 | Linux | Linux | — | can: raw: add locking for raw flags bitfield |
| CVE-2026-13701 | 4.8 | 7.1 | Unknown | Advanced Excerpt | CWE-79 | Advanced Excerpt < 4.5 - Admin+ Stored XSS via Ellipsis Setting |
| CVE-2026-68122 | await | 7.1 | Linux | Linux | — | ovpn: fix peer refcount leak in TCP error paths |
| CVE-2026-68132 | await | 7.1 | Linux | Linux | — | super: fix emergency thaw deadlock on frozen block devices |
| CVE-2026-68150 | await | 7.1 | Linux | Linux | — | fs/super: fix emergency thaw double-unlock of s_umount |
| CVE-2026-68211 | await | 7.1 | Linux | Linux | — | media: stm32-dcmipp: Return queued buffers on start_streaming() failure |
| CVE-2026-68275 | await | 7.1 | Linux | Linux | — | drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO |
| CVE-2026-68282 | await | 7.1 | Linux | Linux | — | drm/rockchip: analogix_dp: Add missing error check for platform_get_resource() |
| CVE-2026-68332 | await | 7.1 | Linux | Linux | — | net: airoha: Fix potential use-after-free in airoha_ppe_deinit() |
| CVE-2026-68334 | await | 7.1 | Linux | Linux | — | rxrpc: fix io_thread race in rxrpc_wake_up_io_thread() |
| CVE-2026-68084 | await | 7.0 | Linux | Linux | — | staging: vme_user: fix location monitor leak in tsi148 bridge |
| CVE-2026-72743 | 5.1 | 6.8 | dataease | SQLBot | CWE-79 | SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-html |
| CVE-2026-17023 | 4.8 | 6.8 | Unknown | Salon Booking System | CWE-284 | Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Google Cale… |
| CVE-2026-68200 | 7.8 | 6.8 | Linux | Linux | — | ALSA: timer: don't re-enter an instance callback that is still running |
| CVE-2026-68201 | 7.8 | 6.8 | Linux | Linux | — | ALSA: timer: drain a slave's callback before its master detaches it |
| CVE-2026-68230 | 7.3 | 6.7 | Linux | Linux | — | media: amlogic-c3: Add validations for ae and awb config |
| CVE-2026-6373 | 6.5 | 6.7 | Zyxel Networks | WAH7601 | CWE-497 | Sensitive Data Exposure in Zyxel WAH7601 Router |
| CVE-2026-14941 | 5.4 | 6.5 | Unknown | Customer Reviews for WooCommerce | CWE-862 | Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorizatio… |
| CVE-2026-15238 | 5.4 | 6.5 | Unknown | MotoPress Hotel Booking | CWE-639 | Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR |
| CVE-2026-68092 | await | 6.5 | Linux | Linux | — | time/jiffies: Register jiffies clocksource before usage |
| CVE-2026-68099 | await | 6.5 | Linux | Linux | — | ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL |
| CVE-2026-68102 | await | 6.5 | Linux | Linux | — | drm/amdgpu: fix aperture mapping leak |
| CVE-2026-68110 | await | 6.5 | Linux | Linux | — | drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON() |
| CVE-2026-68111 | await | 6.5 | Linux | Linux | — | drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() |
| CVE-2026-68112 | await | 6.5 | Linux | Linux | — | drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON() |
| CVE-2026-68113 | await | 6.5 | Linux | Linux | — | drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON() |
| CVE-2026-68115 | await | 6.5 | Linux | Linux | — | drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON() |
| CVE-2026-68234 | await | 6.5 | Linux | Linux | — | drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved |
| CVE-2026-68243 | await | 6.5 | Linux | Linux | — | drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU |
| CVE-2026-68244 | await | 6.5 | Linux | Linux | — | drm/i915/gem: Do not leak siblings[] on proto context error |
| CVE-2026-68246 | await | 6.5 | Linux | Linux | — | drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON() |
| CVE-2026-68247 | await | 6.5 | Linux | Linux | — | drm/i915/bios: range check LFP Data Block panel_type2 |
| CVE-2026-68248 | await | 6.5 | Linux | Linux | — | drm/i915: Return NULL on error in active_instance |
| CVE-2026-68249 | await | 6.5 | Linux | Linux | — | drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON() |
| CVE-2026-68254 | await | 6.5 | Linux | Linux | — | drm/i915/vrr: require valid min/max vfreq for VRR |
| CVE-2026-68259 | await | 6.5 | Linux | Linux | — | drm/amdkfd: Check bounds in allocate_event_notification_slot |
| CVE-2026-68267 | await | 6.5 | Linux | Linux | — | drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists |
| CVE-2026-68301 | await | 6.5 | Linux | Linux | — | net: hsr: fix memory leak on slave unregistration by removing synced VLANs |
| CVE-2026-68306 | await | 6.5 | Linux | Linux | — | wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht() |
| CVE-2026-68307 | await | 6.5 | Linux | Linux | — | wifi: mt76: mt7925: fix crash in reset link replay |
| CVE-2026-68308 | await | 6.5 | Linux | Linux | — | wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap() |
| CVE-2026-68309 | await | 6.5 | Linux | Linux | — | wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bs… |
| CVE-2026-68310 | await | 6.5 | Linux | Linux | — | wifi: mt76: mt7915: guard HE capability lookups |
| CVE-2026-68311 | await | 6.5 | Linux | Linux | — | wifi: mt76: mt7925: guard link STA in decap offload |
| CVE-2026-68317 | await | 6.5 | Linux | Linux | — | pds_core: fix auxiliary device add/del races |
| CVE-2026-68318 | await | 6.5 | Linux | Linux | — | pds_core: fix use-after-free on workqueue during remove |
| CVE-2026-68319 | await | 6.5 | Linux | Linux | — | pds_core: fix deadlock between reset thread and remove |
| CVE-2026-68324 | await | 6.5 | Linux | Linux | — | iommu/intel: Fix out-of-bounds memset in dmar_latency_disable() |
| CVE-2026-68327 | await | 6.5 | Linux | Linux | — | wan: wanxl: Only reset hardware after BAR mapping |
| CVE-2026-68328 | await | 6.5 | Linux | Linux | — | nfp: Check resource mutex allocation |
| CVE-2026-68331 | await | 6.5 | Linux | Linux | — | dpaa2-eth: put MAC endpoint device on disconnect |
| CVE-2026-68357 | await | 6.5 | Linux | Linux | — | watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() |
| CVE-2026-68362 | await | 6.5 | Linux | Linux | — | wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin |
| CVE-2026-68372 | await | 6.5 | Linux | Linux | — | usb: core: port: Deattach Type-C connector on component unbind |
| CVE-2026-68403 | await | 6.5 | Linux | Linux | — | wifi: brcmfmac: initialize SDIO data work before cleanup |
| CVE-2026-68407 | await | 6.5 | Linux | Linux | — | wifi: nl80211: free RNR data on MBSSID mismatch |
| CVE-2026-68408 | await | 6.5 | Linux | Linux | — | wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock |
| CVE-2026-68411 | await | 6.5 | Linux | Linux | — | wifi: mac80211_hwsim: clamp virtio RX length before skb_put |
| CVE-2026-59091 | 7.3 | 6.4 | Red Hat | Red Hat Enterprise Linux 6 | CWE-787 | Gimp: gimp: multiple vulnerabilities in file format plugins via crafted image… |
| CVE-2026-18960 | 5.4 | 6.4 | Unknown | Block User Account | CWE-287 | Block User Account < 2.0.1 - Subscriber+ Account Block Bypass via Application… |
| CVE-2026-68087 | await | 6.3 | Linux | Linux | — | HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush() |
| CVE-2026-68089 | await | 6.3 | Linux | Linux | — | iio: core: fix uninitialized data in debugfs |
| CVE-2026-68095 | await | 6.3 | Linux | Linux | — | fuse-uring: fix race between registration and connection abortion |
| CVE-2026-68233 | await | 6.3 | Linux | Linux | — | drm/vc4: Shut down BO cache timer before teardown |
| CVE-2026-68238 | await | 6.3 | Linux | Linux | — | drm/amdgpu: Release VFCT ACPI table reference |
| CVE-2026-68239 | await | 6.3 | Linux | Linux | — | drm/ttm: Account for NULL and handle pages in ttm_pool_backup |
| CVE-2026-68292 | await | 6.3 | Linux | Linux | — | ice: prevent tstamp ring allocation for non-PF VSI types |
| CVE-2026-68356 | await | 6.3 | Linux | Linux | — | watchdog: airoha: Prevent division by zero when clock frequency is zero |
| CVE-2026-68163 | 7.8 | 6.2 | Linux | Linux | — | mm/page_vma_mapped: fix device-private PMD handling |
| CVE-2026-72594 | 7.6 | 6.2 | lobehub | lobe-chat | CWE-79 | lobehub lobe-chat - Stored Cross-Site Scripting via Unrestricted SVG Avatar U… |
| CVE-2026-72576 | 5.4 | 6.2 | Bludit | Bludit | CWE-79 | Bludit - Stored Cross-Site Scripting via Malicious SVG Logo Upload |
| CVE-2026-66410 | 2.3 | 6.2 | ECOVACS ROBOTICS | Android App "ECOVACS PRO" | CWE-295 | Android and iOS apps ECOVACS PRO App improperly validate server certificates.… |
| CVE-2026-68162 | 7.8 | 6.1 | Linux | Linux | — | sctp: avoid auth_enable sysctl UAF during netns teardown |
| CVE-2026-68294 | 8.8 | 6.0 | Linux | Linux | — | net: qrtr: restrict socket creation to the initial network namespace |
| CVE-2026-68178 | 7.8 | 6.0 | Linux | Linux | — | misc: nsm: pin the module while the device is open |
| CVE-2026-68228 | 7.8 | 6.0 | Linux | Linux | — | media: chips-media: wave5: Move src_buf Removal to finish_encode |
| CVE-2026-68245 | 7.8 | 6.0 | Linux | Linux | — | drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid() |
| CVE-2026-68260 | 7.8 | 6.0 | Linux | Linux | — | drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM |
| CVE-2026-17019 | 6.1 | 5.9 | Unknown | JetEngine | CWE-79 | JetEngine < 3.8.13.1 - Unauthenticated Stored XSS via Form File Upload (SVG) |
| CVE-2026-17010 | 5.4 | 5.9 | Unknown | Saitama Addon Pack | CWE-79 | Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta |
| CVE-2026-19075 | 5.0 | 5.8 | Unknown | All-in-One Video Gallery | CWE-918 | All-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery vi… |
| CVE-2026-17020 | 4.3 | 5.8 | Unknown | Salon Booking System | CWE-639 | Salon Booking System – Free Version <= 10.31.0 - Subscriber+ Arbitrary Bookin… |
| CVE-2026-68285 | await | 5.9 | Linux | Linux | — | LoongArch: BPF: Fix memory leak in bpf_jit_free() |
| CVE-2026-68288 | await | 5.9 | Linux | Linux | — | net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD |
| CVE-2026-68289 | await | 5.9 | Linux | Linux | — | tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() |
| CVE-2026-68347 | await | 5.9 | Linux | Linux | — | iommu/amd: Fix IRQ unsafe locking in gdom allocation |
| CVE-2026-68364 | await | 5.9 | Linux | Linux | — | drm/amd/display: Fix ISM dc_lock deadlock during suspend |
| CVE-2026-68375 | await | 5.9 | Linux | Linux | — | bnxt_en: Handle partially initialized auxiliary devices |
| CVE-2026-68240 | 8.8 | 5.8 | Linux | Linux | — | drm/gpusvm: publish dpagemap early to avoid device mapping leak on error |
| CVE-2026-68330 | 7.8 | 5.8 | Linux | Linux | — | net: airoha: Fix DMA direction for NPU mailbox buffer |
| CVE-2026-59088 | 5.5 | 5.7 | Red Hat | Red Hat Enterprise Linux 6 | CWE-190 | Gimp: gimp: denial of service via signed integer overflow in fli file processing |
| CVE-2026-68329 | 8.8 | 5.5 | Linux | Linux | — | iommu/amd: Wait for completion instead of returning early in iommu_completion… |
| CVE-2026-68189 | 7.8 | 5.5 | Linux | Linux | — | Bluetooth: hci_sync: Protect UUID list traversal |
| CVE-2026-68229 | 7.1 | 5.5 | Linux | Linux | — | media: cedrus: skip invalid H.264 reference list entries |
| CVE-2026-68172 | 7.1 | 5.4 | Linux | Linux | — | arm64: make huge_ptep_get handled unaligned addresses |
| CVE-2026-68173 | 7.1 | 5.4 | Linux | Linux | — | ublk: wait on ublk_dev_ready() instead of ub->completion |
| CVE-2026-66484 | 4.6 | 5.4 | GNU | cpio | CWE-22 | Path Traversal in GNU cpio |
| CVE-2026-68416 | await | 5.3 | Linux | Linux | — | mtd: fix double free and WARN_ON in add_mtd_device() error paths |
| CVE-2026-68428 | await | 5.3 | Linux | Linux | — | KVM: x86/mmu: Fix use-after-free on vendor module reload |
| CVE-2026-21063 | 6.8 | 5.2 | Samsung Mobile | Samsung Mobile Devices | CWE-926 | Improper export of android application components in AppLock prior to SMR Aug… |
| CVE-2026-21073 | 5.2 | 5.2 | Samsung Mobile | Samsung Mobile Devices | — | Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 al… |
| CVE-2026-68094 | await | 5.2 | Linux | Linux | — | sched_ext: Preserve rq tracking across local DSQ dispatch |
| CVE-2026-68105 | await | 5.2 | Linux | Linux | — | drm/amdgpu: Fix kernel panic during driver load failure |
| CVE-2026-68109 | await | 5.2 | Linux | Linux | — | drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON() |
| CVE-2026-68114 | await | 5.2 | Linux | Linux | — | drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON() |
| CVE-2026-68237 | await | 5.2 | Linux | Linux | — | drm/amdgpu/userq: fix indefinite fence wait during GPU reset |
| CVE-2026-68291 | await | 5.2 | Linux | Linux | — | idpf: fix max_vport related crash on allocation error during init |
| CVE-2026-68337 | await | 5.2 | Linux | Linux | — | bpf: Reject redirect helpers without a bpf_net_context |
| CVE-2026-68177 | 7.8 | 5.1 | Linux | Linux | — | tracing: Delay module ref count for "enable_event" trigger |
| CVE-2026-68295 | 7.8 | 5.1 | Linux | Linux | — | LoongArch: BPF: Zero-extend signed ALU32 div/mod results |
| CVE-2026-68404 | 7.8 | 5.1 | Linux | Linux | — | wifi: cfg80211: use wiphy work for socket owner autodisconnect |
| CVE-2026-21060 | 6.7 | 5.1 | Samsung Mobile | Samsung Mobile Devices | CWE-20 | Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1… |
| CVE-2025-15680 | 2.4 | 5.1 | TBEA | TBEA TLogger (TBEA Communication Box 3rd Generation) | CWE-497 | Information Disclosure via UART |
| CVE-2026-68418 | await | 5.1 | Linux | Linux | — | RDMA/irdma: Prevent user-triggered null deref on QP create |
| CVE-2026-21083 | 6.8 | 5.0 | Samsung Mobile | Smart Switch | CWE-20 | Improper input validation in Smart Switch prior to version 3.7.72.6 allows ad… |
| CVE-2026-18200 | 4.3 | 4.9 | Unknown | FoodBoxBooker | CWE-639 | FoodBoxBooker < 1.0.8 - Subscriber+ Arbitrary User Profile Update |
| CVE-2026-14211 | 3.8 | 4.9 | Unknown | Booking for Appointments and Events Calendar | CWE-639 | Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modificat… |
| CVE-2026-68274 | 7.8 | 4.8 | Linux | Linux | — | drm/xe/guc: Fix buffer overflow in steered register list allocation |
| CVE-2025-32736 | 4.9 | 4.8 | Ping Identity | PingFederate | CWE-352 | PingFederate Administrative Console CSRF weaknesses |
| CVE-2026-66406 | 2.3 | 4.8 | ECOVACS ROBOTICS | DEEBOT PRO M1 | CWE-295 | DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate v… |
| CVE-2026-68340 | 7.7 | 4.7 | Linux | Linux | — | hwmon: occ: validate poll response sensor blocks |
| CVE-2026-72583 | 5.4 | 4.7 | fastschema | fastschema | CWE-79 | fastschema - Stored Cross-Site Scripting via MIME Type Bypass in File Upload |
| CVE-2026-68086 | await | 4.7 | Linux | Linux | — | mm/khugepaged: write all dirty file folios when collapsing |
| CVE-2026-69112 | 6.9 | 4.5 | huggingface | accelerate | CWE-22 | Hugging Face Accelerate 1.14.0 Path Traversal and DoS via weight_map |
| CVE-2026-72913 | 7.3 | 4.4 | kovidgoyal | kitty | CWE-77 | Kitty: Command injection into the child shell via chained @kitty-echo + @kitt… |
| CVE-2026-21070 | 5.1 | 4.3 | Samsung Mobile | Samsung Mobile Devices | CWE-20 | Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 … |
| CVE-2026-68423 | await | 4.3 | Linux | Linux | — | mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy() |
| CVE-2026-68424 | await | 4.3 | Linux | Linux | — | mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy_joins() |
| CVE-2026-68253 | 7.8 | 4.0 | Linux | Linux | — | drm/i915/hdcp: check streams[] bounds before overflow |
| CVE-2026-68128 | 8.8 | 3.7 | Linux | Linux | — | ice: reject out-of-range ptype in ice_parser_profile_init |
| CVE-2026-68142 | 8.8 | 3.7 | Linux | Linux | — | geneve: require CAP_NET_ADMIN in the device netns for changelink |
| CVE-2026-68121 | 7.8 | 3.7 | Linux | Linux | — | pppoe: reload header pointer after dev_hard_header() |
| CVE-2026-68143 | 7.8 | 3.7 | Linux | Linux | — | net: slip: serialize receive against buffer reallocation |
| CVE-2026-68145 | 7.8 | 3.7 | Linux | Linux | — | iomap: fix out-of-bounds bitmap_set() with zero-length range |
| CVE-2026-68222 | 7.8 | 3.7 | Linux | Linux | — | media: msi2500: Return queued buffers on start_streaming() failure |
| CVE-2026-68257 | 7.8 | 3.7 | Linux | Linux | — | drm/amdkfd: fix 32-bit overflow in CWSR total size calculation |
| CVE-2026-68264 | 7.8 | 3.7 | Linux | Linux | — | drm/xe/pt: Reset current_op in xe_pt_update_ops_init() |
| CVE-2026-68370 | 7.8 | 3.7 | Linux | Linux | — | usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback |
| CVE-2026-68293 | 7.1 | 3.7 | Linux | Linux | — | net/mlx5: Fix MCIA register buffer overflow on 32 dword reads |
| CVE-2026-72570 | 5.4 | 3.7 | cube-root | directory-serve | CWE-79 | cube-root directory-serve - Stored Cross-Site Scripting via Malicious Filename |
| CVE-2026-63105 | 5.1 | 3.7 | Razinsoft | Ready eCommerce | CWE-79 | ReadyEcommerce < 4.5.2 Stored XSS via Chat and Support Ticket Systems |
| CVE-2026-21082 | 6.9 | 3.6 | Samsung Mobile | Samsung Health | CWE-23 | Relative path traversal in Samsung Health prior to version 7.0.0 allows local… |
| CVE-2026-66486 | 4.6 | 3.6 | GNU | cpio | CWE-116 | Improper Output Encoding in GNU cpio |
| CVE-2026-68401 | 7.8 | 3.5 | Linux | Linux | — | firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit() |
| CVE-2026-68108 | 8.8 | 3.4 | Linux | Linux | — | drm/amdgpu/vce: fix integer overflow in image size |
| CVE-2025-30238 | 8.6 | 3.4 | TP-Link Systems Inc. | HB810(US2) V1.0/1.6/2.0/2.6 | CWE-863 | Privilege Escalation via Improper Authorization in User Management in multipl… |
| CVE-2025-30239 | 8.5 | 3.4 | TP-Link Systems Inc. | HB810(US2) V1.0/1.6/2.0/2.6 | CWE-321 | Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Li… |
| CVE-2026-68149 | 8.4 | 3.4 | Linux | Linux | — | fs: preserve ACL_DONT_CACHE state in forget_cached_acl() |
| CVE-2026-71969 | 8.4 | 3.4 | OP-TEE | optee_os | CWE-787 | OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations |
| CVE-2026-68147 | 7.8 | 3.4 | Linux | Linux | — | fscrypt: Avoid dynamic allocation in fscrypt_get_devices() |
| CVE-2026-68152 | 7.8 | 3.4 | Linux | Linux | — | amt: fix use-after-free in AMT delayed works |
| CVE-2026-68266 | 7.8 | 3.4 | Linux | Linux | — | drm/xe: Hold a dma-buf reference for imported BOs |
| CVE-2026-68273 | 7.8 | 3.4 | Linux | Linux | — | drm/amdgpu: Fix context pstate override handling |
| CVE-2026-68284 | 7.8 | 3.4 | Linux | Linux | — | bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() |
| CVE-2026-68335 | 7.8 | 3.4 | Linux | Linux | — | rds: drop incoming messages that cross network namespace boundaries |
| CVE-2026-68384 | 7.8 | 3.4 | Linux | Linux | — | drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves |
| CVE-2026-68415 | 7.8 | 3.3 | Linux | Linux | — | xfrm: clear mode callbacks after failed mode setup |
| CVE-2026-72718 | 7.0 | 3.4 | aaif-goose | goose | CWE-94 | goose: Arbitrary command execution in goose CLI via `goose review` via git co… |
| CVE-2026-68380 | 7.8 | 3.2 | Linux | Linux | — | accel/amdxdna: Fix use-after-free of mm_struct in job scheduler |
| CVE-2026-56619 | 5.4 | 3.3 | HCLSoftware | HCL BigFix Mobile | CWE-79 | HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected … |
| CVE-2026-66485 | 4.6 | 3.2 | GNU | cpio | CWE-789 | Uncontrolled Memory Allocation in GNU cpio |
| CVE-2026-68262 | 7.1 | 3.1 | Linux | Linux | — | drm/imagination: Fix user array stride in pvr_set_uobj_array() |
| CVE-2026-68348 | 7.1 | 3.1 | Linux | Linux | — | ASoC: tas2781: bound firmware description string parsing |
| CVE-2026-18370 | 4.8 | 3.1 | eradman | entr | CWE-122 | Heap-based buffer overflow in entr |
| CVE-2026-63622 | 7.8 | 3.0 | Red Hat | Red Hat Enterprise Linux 10 | CWE-59 | Libvirt: swtpm privilege escalation via symlink following |
| CVE-2026-68138 | 7.8 | 3.0 | Linux | Linux | — | net/sched: serialize qdisc_rtab_list against concurrent get/put |
| CVE-2026-68305 | 7.8 | 3.0 | Linux | Linux | — | drm/xe/vf: Add drm_dev guards when detaching CCS read/write buffers |
| CVE-2026-68382 | 7.8 | 3.0 | Linux | Linux | — | drm/xe/guc: Hold device ref until queue teardown completes |
| CVE-2026-68383 | 7.8 | 3.0 | Linux | Linux | — | drm/xe/guc: Keep scheduler timeline name alive |
| CVE-2026-68399 | 7.8 | 3.0 | Linux | Linux | — | bpf: Fix UAF in sock clone early bailouts |
| CVE-2026-68134 | 7.3 | 3.0 | Linux | Linux | — | ptp: ptp_s390: Add missing facility check |
| CVE-2026-68265 | 7.3 | 3.0 | Linux | Linux | — | drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC |
| CVE-2026-68258 | 7.1 | 3.0 | Linux | Linux | — | drm/amdkfd: Check bounds on CRIU restore queue type and mqd size |
| CVE-2026-68107 | 8.8 | 2.9 | Linux | Linux | — | drm/amdgpu/vcn4: avoid rereading IB param length |
| CVE-2026-68104 | 7.8 | 2.9 | Linux | Linux | — | drm/amdgpu: invoke pm_genpd_remove() before freeing genpd |
| CVE-2026-68106 | 7.8 | 2.9 | Linux | Linux | — | drm/amdgpu: fix division by zero with invalid uvd dimensions |
| CVE-2026-68297 | 7.8 | 2.9 | Linux | Linux | — | tipc: fix u16 MTU truncation in media and bearer MTU validation |
| CVE-2026-68314 | 7.8 | 2.9 | Linux | Linux | — | net: mctp i3c: clean up notifier and buses if driver register fails |
| CVE-2026-68374 | 7.8 | 2.9 | Linux | Linux | — | usb: core: sysfs: add lock to bos_descriptors_read() |
| CVE-2026-68391 | 7.8 | 2.9 | Linux | Linux | — | Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds |
| CVE-2026-68392 | 7.8 | 2.9 | Linux | Linux | — | Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync |
| CVE-2026-68398 | 7.8 | 2.9 | Linux | Linux | — | ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF |
| CVE-2026-68419 | 7.8 | 2.9 | Linux | Linux | — | RDMA/irdma: Prevent rereg_mr for non-mem regions |
| CVE-2026-12570 | 5.5 | 2.8 | keras-team | keras-team/keras | CWE-770 | Denial of Service via HDF5 Shape Bomb in keras.models.load_model() in keras-t… |
| CVE-2026-21068 | 8.4 | 2.7 | Samsung Mobile | Samsung Mobile Devices | CWE-121 | Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 … |
| CVE-2026-68298 | 7.8 | 2.8 | Linux | Linux | — | drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create() |
| CVE-2026-68377 | 7.8 | 2.8 | Linux | Linux | — | net/sched: act_tunnel_key: Defer dst_release to RCU callback |
| CVE-2026-68400 | 7.8 | 2.8 | Linux | Linux | — | firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation |
| CVE-2026-68320 | 7.3 | 2.8 | Linux | Linux | — | sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid |
| CVE-2026-68153 | 7.8 | 2.6 | Linux | Linux | — | libceph: remove debugfs files before client teardown |
| CVE-2026-68236 | 7.8 | 2.6 | Linux | Linux | — | drm/amd/display: set new_stream to NULL after release |
| CVE-2026-68263 | 7.8 | 2.6 | Linux | Linux | — | drm/imagination: Fix double call to drm_sched_entity_fini() |
| CVE-2026-68290 | 7.8 | 2.6 | Linux | Linux | — | rds: tcp: unregister sysctl before tearing down listen socket |
| CVE-2026-68394 | 7.8 | 2.6 | Linux | Linux | — | Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update |
| CVE-2026-68427 | 7.8 | 2.6 | Linux | Linux | — | gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings |
| CVE-2026-71576 | 8.5 | 2.4 | Red Hat | Multicluster Global Hub | CWE-345 | Multicluster-global-hub: multicluster-global-hub: manager trusts self-asserte… |
| CVE-2026-8718 | 8.4 | 2.4 | zephyrproject | zephyr | CWE-787 | Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID… |
| CVE-2026-68116 | 7.9 | 2.3 | Linux | Linux | — | vxlan: mdb: Fix source list corruption on a failed replace |
| CVE-2026-19074 | 5.3 | 2.3 | Unknown | Advanced Classifieds & Directory Pro | CWE-200 | Advanced Classifieds & Directory Pro < 3.4.3 - Unauthenticated Non-Public Lis… |
| CVE-2026-68316 | 7.8 | 2.2 | Linux | Linux | — | accel: ethosu: Fix element size accounting for cmd stream validation |
| CVE-2026-68323 | 7.8 | 2.2 | Linux | Linux | — | tipc: serialize udp bearer replicast list updates |
| CVE-2026-68417 | 7.8 | 2.1 | Linux | Linux | — | RDMA/siw: publish QP after initialization |
| CVE-2026-21058 | 6.9 | 2.1 | Samsung Mobile | Samsung Mobile Devices | CWE-20 | Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1… |
| CVE-2026-71967 | 5.7 | 2.1 | OP-TEE | optee_os | CWE-476 | OP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_session |
| CVE-2026-15059 | 5.5 | 2.1 | systemd | systemd-oomd | CWE-22 | systemd-oomd: unprivileged users can terminate arbitrary processes |
| CVE-2026-21066 | 5.1 | 2.1 | Samsung Mobile | Samsung Mobile Devices | CWE-20 | Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 R… |
| CVE-2026-21067 | 5.1 | 2.1 | Samsung Mobile | Samsung Mobile Devices | — | Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allow… |
| CVE-2026-21072 | 5.1 | 2.1 | Samsung Mobile | Samsung Mobile Devices | CWE-20 | Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 … |
| CVE-2026-18503 | 2.4 | 2.1 | Python Software Foundation | CPython | CWE-1176 | Super-linear CPU usage for unbounded input to csv.Sniffer.sniff() |
| CVE-2026-19382 | 1.8 | 2.0 | Almico | Speedfan | CWE-401 | Almico Speedfan MSR Index speedfan.sys KiSystemCall64 memory leak |
| CVE-2026-19380 | 1.8 | 2.0 | Mullvad | wireguard.sys | CWE-664 | Mullvad wireguard.sys IOCTL AdapterState reference count |
| CVE-2026-13133 | 8.4 | 2.0 | LY Corporation | LINE for Windows | CWE-427 | A vulnerability has been identified in LineInst.exe (LINE for Windows) prior … |
| CVE-2026-59112 | 4.4 | 2.0 | Estonian Information System Authority (RIA) | libdigidocpp | CWE-347 | Signature validation vulnerability affecting DigiDoc applications |
| CVE-2026-68420 | 7.1 | 1.8 | Linux | Linux | — | xfrm: reject optional IPTFS templates in outbound policies |
| CVE-2026-21064 | 7.0 | 1.6 | Samsung Mobile | Samsung Mobile Devices | CWE-284 | Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows loca… |
| CVE-2026-21059 | 6.9 | 1.6 | Samsung Mobile | Samsung Mobile Devices | CWE-926 | Improper export of android application components in Samsung Contacts prior t… |
| CVE-2026-19381 | 7.1 | 1.5 | Kingston | FURY CTRL RGB Control Software | CWE-266 | Kingston FURY CTRL RGB Control Software Driver NTIOLib_KSFX.sys privileges ma… |
| CVE-2026-21069 | 5.1 | 1.5 | Samsung Mobile | Samsung Mobile Devices | CWE-681 | Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior… |
| CVE-2026-21071 | 5.1 | 1.5 | Samsung Mobile | Samsung Mobile Devices | CWE-20 | Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-202… |
| CVE-2026-68103 | 7.1 | 1.5 | Linux | Linux | — | drm/amdgpu: reject mapping a reserved doorbell to a new queue |
| CVE-2026-6368 | 2.1 | 1.3 | glibc | glibc | CWE-908 | wordexp with WRDE_APPEND can return or use invalid memory |
| CVE-2026-21065 | 4.8 | 1.3 | Samsung Mobile | Samsung Mobile Devices | CWE-20 | Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release … |
| CVE-2026-21076 | 6.9 | 1.2 | Samsung Mobile | Samsung Health | CWE-863 | Incorrect authorization in Samsung Health prior to version 7.0.0 allows local… |
| CVE-2026-21077 | 6.9 | 1.2 | Samsung Mobile | Samsung Health | CWE-863 | Incorrect authorization in Samsung Health prior to version 7.0.0 allows local… |
| CVE-2026-21080 | 6.9 | 1.2 | Samsung Mobile | Smart Switch | CWE-312 | Cleartext storage of sensitive information in Smart Switch prior to version 3… |
| CVE-2026-21074 | 7.2 | 1.1 | Samsung Mobile | Bixby | CWE-276 | Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local… |
| CVE-2026-21062 | 4.8 | 1.1 | Samsung Mobile | Samsung Mobile Devices | CWE-939 | Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 a… |
| CVE-2026-71968 | 8.4 | 1.0 | OP-TEE | optee_os | CWE-416 | OP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCUR… |
| CVE-2026-66642 | 5.4 | 0.9 | WP Umbrella | WP Umbrella | CWE-352 | WordPress WP Umbrella plugin 2.24.2-2.26.2 - Cross Site Request Forgery (CSRF… |
| CVE-2026-19411 | 3.9 | 0.9 | Red Hat | Red Hat Enterprise Linux 7 | CWE-476 | Shim/dp.c library: null-pointer dereference in is_removable_media_path() when… |
| CVE-2026-21078 | 4.7 | 0.9 | Samsung Mobile | Smart Switch | CWE-345 | Insufficient verification of data authenticity in Smart Switch trouble scanni… |
| CVE-2026-63623 | 5.5 | 0.8 | Red Hat | Red Hat Enterprise Linux 10 | CWE-732 | Libvirt: information disclosure via world-readable storage volume images duri… |
| CVE-2026-68148 | 7.8 | 0.6 | Linux | Linux | — | fscrypt: Add missing superblock check in find_or_insert_direct_key() |
| CVE-2026-21084 | 6.9 | 0.6 | Samsung Mobile | SmartThings | CWE-284 | Improper access control in SmartThings prior to version 1.8.47.24 allows loca… |
| CVE-2026-21081 | 5.1 | 0.6 | Samsung Mobile | SamsungPassAutofill | CWE-926 | Improper export of android application components in SamsungPassAutofill prio… |
| CVE-2026-11812 | 2.5 | 0.2 | zephyrproject | zephyr | CWE-362 | UpdateHub: race condition on shared context causes out-of-bounds write and DoS |
| CVE-2026-15060 | 4.7 | 0.2 | systemd | systemd-machined | CWE-284 | systemd-machined: unprivileged users can terminate arbitrary processes |
| CVE-2026-21079 | 7.0 | 0.0 | Samsung Mobile | Smart Switch | CWE-311 | Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.… |
| CVE-2026-16742 | 6.7 | 0.0 | systemd | systemd-homed | CWE-269 | systemd-homed: local privilege escalation via missing home-record signature v… |