boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, June 24, 2026 · all times UTC← 2026-06-23 · archive · 2026-06-25 →

Security Box Score — June 24, 2026 — page 2

Edition of June 24, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–520 of 520
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-529905.55.5LinuxLinux—fsnotify: fix inode reference leak in fsnotify_recalc_mask()
CVE-2026-530015.55.6LinuxLinux—netfilter: xtables: restrict several matches to inet family
CVE-2026-530135.55.5LinuxLinux—macvlan: fix macvlan_get_size() not reserving space for IFLA_MACVLAN_BC_CUTOFF
CVE-2026-530145.55.5LinuxLinux—net/sched: act_mirred: fix wrong device for mac_header_xmit check in tcf_bloc…
CVE-2026-530155.55.5LinuxLinux—erofs: unify lcn as u64 for 32-bit platforms
CVE-2026-530225.55.6LinuxLinux—platform/x86: dell-wmi-sysman: bound enumeration string aggregation
CVE-2026-530235.55.6LinuxLinux—fs/ntfs3: terminate the cached volume label after UTF-8 conversion
CVE-2026-530325.55.5LinuxLinuxCWE-476bpf: Fix NULL deref in map_kptr_match_type for scalar regs
CVE-2026-530345.55.6LinuxLinuxCWE-476bpf, sockmap: Fix af_unix null-ptr-deref in proto update
CVE-2026-530385.55.5LinuxLinuxCWE-125ima_fs: Correctly create securityfs files for unsupported hash algos
CVE-2026-530485.55.6LinuxLinuxCWE-476gfs2: prevent NULL pointer dereference during unmount
CVE-2026-530515.55.6LinuxLinux—PCI: tegra194: Fix CBB timeout caused by DBI access before core power-on
CVE-2026-530525.55.6LinuxLinux—ASoC: qcom: qdsp6: topology: check widget type before accessing data
CVE-2026-530565.55.6LinuxLinux—drm/msm/dpu: fix mismatch between power and frequency
CVE-2026-530585.55.6LinuxLinuxCWE-476drm/bridge: cadence: cdns-mhdp8546-core: Set the mhdp connector earlier in at…
CVE-2026-530615.55.6LinuxLinux—dm cache: fix dirty mapping checking in passthrough mode switching
CVE-2026-530655.55.6LinuxLinuxCWE-401ASoC: sti: use managed regmap_field allocations
CVE-2026-530665.55.6LinuxLinuxCWE-476drm/sun4i: backend: fix error pointer dereference
CVE-2026-530735.55.6LinuxLinuxCWE-476Bluetooth: hci_ldisc: Clear HCI_UART_PROTO_INIT on error
CVE-2026-530745.55.6LinuxLinux—bpf: reject short IPv4/IPv6 inputs in bpf_prog_test_run_skb
CVE-2026-530825.55.6LinuxLinuxCWE-908net: hamradio: 6pack: fix uninit-value in sixpack_receive_buf
CVE-2026-530835.55.5LinuxLinux—bpf: Fix RCU stall in bpf_fd_array_map_clear()
CVE-2026-530845.55.5LinuxLinux—bpf: return VMA snapshot from task_vma iterator
CVE-2026-531055.55.5LinuxLinuxCWE-476wifi: mt76: mt7925: prevent NULL vif dereference in mt7925_mac_write_txwi
CVE-2026-531115.55.6LinuxLinuxCWE-476bpf: test_run: Fix the null pointer dereference issue in bpf_lwt_xmit_push_encap
CVE-2026-531235.55.5LinuxLinux—md: wake raid456 reshape waiters before suspend
CVE-2026-531265.55.5LinuxLinux—blk-cgroup: fix disk reference leak in blkcg_maybe_throttle_current()
CVE-2026-531285.55.6LinuxLinux—drbd: Balance RCU calls in drbd_adm_dump_devices()
CVE-2025-604665.05.6n/an/aCWE-416A use-after-free in the gf_filter_pid_get_packet function (/filter_core/filte…
CVE-2026-529375.55.4LinuxLinuxCWE-401tap: fix stack info leak in tap_ioctl() SIOCGIFHWADDR
CVE-2026-529405.55.4LinuxLinux—tun: zero the whole vnet header in tun_put_user()
CVE-2026-529785.55.4LinuxLinux—net: psp: require admin permission for dev-set and key-rotate
CVE-2026-529945.55.4LinuxLinux—vsock/virtio: fix MSG_ZEROCOPY pinned-pages accounting
CVE-2026-529975.55.4LinuxLinuxCWE-476net/sched: sch_dualpi2: drain both C-queue and L-queue in dualpi2_change()
CVE-2026-530185.55.4LinuxLinux—f2fs: avoid reading already updated pages during GC
CVE-2026-530195.55.4LinuxLinux—clk: spacemit: ccu_mix: fix inverted condition in ccu_mix_trigger_fc()
CVE-2026-530285.55.4LinuxLinuxCWE-476usb: typec: Fix error pointer dereference
CVE-2026-530305.55.4LinuxLinuxCWE-401i3c: master: renesas: Fix memory leak in renesas_i3c_i3c_xfers()
CVE-2026-530425.55.4LinuxLinuxCWE-824fwctl: Fix class init ordering to avoid NULL pointer dereference on device re…
CVE-2026-530955.55.4LinuxLinux—bpf: Fix abuse of kprobe_write_ctx via freplace
CVE-2026-531045.55.4LinuxLinuxCWE-401wifi: mt76: Fix memory leak destroying device
CVE-2026-531145.55.4LinuxLinux—perf/amd/ibs: Avoid calling perf_allow_kernel() from the IBS NMI handler
CVE-2026-531215.55.4LinuxLinuxCWE-401amd-pstate: Fix memory leak in amd_pstate_epp_cpu_init()
CVE-2026-529655.55.0LinuxLinuxCWE-835drm/ttm: Fix ttm_bo_swapout() infinite LRU walk on swapout failure
CVE-2026-529887.15.0LinuxLinux—netfilter: nf_tables: join hook list via splice_list_rcu() in commit phase
CVE-2026-572894.85.0Jenkins ProjectJenkins Bitbucket Push and Pull Request PluginCWE-295Jenkins Bitbucket Push and Pull Request Plugin 3.3.8 and earlier unconditiona…
CVE-2026-531135.54.8LinuxLinuxCWE-401wifi: ath11k: fix memory leaks in beacon template setup
CVE-2026-549052.04.7ruby-concurrencyconcurrent-rubyCWE-128concurrent-ruby: `ReentrantReadWriteLock` read-count overflow grants a write …
CVE-2026-130377.84.2GoogleChromeCWE-416Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197…
CVE-2026-132017.34.2Red HatRed Hat Container Native Virtualization 4.13CWE-61Kubevirt: virt-handler-rhel9: kubevirt: safepath symlink following in virt-ha…
CVE-2026-529767.83.9LinuxLinuxCWE-416drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl()
CVE-2026-529385.53.8LinuxLinuxCWE-476bpf: Fix NULL pointer dereference in bpf_sk_storage_clone and diag paths
CVE-2026-529495.53.8LinuxLinux—drm/ttm: Fix ttm_bo_shrink() infinite LRU walk on backup failure
CVE-2026-530075.53.8LinuxLinuxCWE-476ice: fix potential NULL pointer deref in error path of ice_set_ringparam()
CVE-2026-530175.53.8LinuxLinux—f2fs: fix data loss caused by incorrect use of nat_entry flag
CVE-2026-530295.53.8LinuxLinuxCWE-908fs/ntfs3: prevent uninitialized lcn caused by zero len
CVE-2026-530795.53.8LinuxLinuxCWE-401net_sched: fix skb memory leak in deferred qdisc drops
CVE-2026-530995.53.8LinuxLinux—bpf: Switch CONFIG_CFI_CLANG to CONFIG_CFI
CVE-2026-531025.53.8LinuxLinuxCWE-401wifi: mt76: Fix memory leak after mt76_connac_mcu_alloc_sta_req()
CVE-2026-531065.53.8LinuxLinuxCWE-401bpf: Do not allow deleting local storage in NMI
CVE-2026-531245.53.8LinuxLinux—ublk: reset per-IO canceled flag on each fetch
CVE-2026-531275.53.8LinuxLinuxCWE-401block: fix zones_cond memory leak on zone revalidation error paths
CVE-2026-529737.83.7LinuxLinuxCWE-416futex: Drop CLONE_THREAD requirement for private default hash alloc
CVE-2026-530167.83.6LinuxLinuxCWE-787crypto: ccp - copy IV using skcipher ivsize
CVE-2026-530597.83.6LinuxLinuxCWE-787dm log: fix out-of-bounds write due to region_count overflow
CVE-2026-529507.83.5LinuxLinuxCWE-416drm/xe/dma-buf: fix UAF with retry loop
CVE-2026-529757.83.5LinuxLinux—bonding: 3ad: implement proper RCU rules for port->aggregator
CVE-2026-530367.83.5LinuxLinuxCWE-193bpf, arm64: Fix off-by-one in check_imm signed range check
CVE-2026-398942.53.5CacticactiCWE-474Cacti: RRDtool metric shift via LC_NUMERIC locale comma decimal formatting
CVE-2026-572925.43.3Jenkins ProjectJenkins Gitee PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins Gitee Plugin 128…
CVE-2026-572985.43.3Jenkins ProjectJenkins Contrast Continuous Application Security PluginCWE-352A cross-site request forgery (CSRF) vulnerability in Jenkins Contrast Continu…
CVE-2026-529237.83.1LinuxLinuxCWE-401ipc: limit next_id allocation to the valid ID range
CVE-2026-530057.83.1LinuxLinuxCWE-416af_unix: Drop all SCM attributes for SOCKMAP.
CVE-2026-530547.83.1LinuxLinuxCWE-667drm/msm: Fix VM_BIND UNMAP locking
CVE-2026-75397.32.9HP Inc.HP Dock AccessoryCWE-379HP Dock Accessory WMI Provider Installer Security Update
CVE-2026-97214.32.8chuhplBook a Room Event CalendarCWE-352Book a Room Event Calendar <= 1.9 - Cross-Site Request Forgery to Settings Up…
CVE-2026-530007.82.8LinuxLinuxCWE-763netfilter: nat: use kfree_rcu to release ops
CVE-2026-530047.82.8LinuxLinuxCWE-787sctp: fix OOB write to userspace in sctp_getsockopt_peer_auth_chunks
CVE-2026-530097.82.8LinuxLinuxCWE-415ice: fix double-free of tx_buf skb
CVE-2026-529485.52.8LinuxLinuxCWE-190i2c: dev: prevent integer overflow in I2C_TIMEOUT ioctl
CVE-2026-562694.32.8FlowiseFlowiseCWE-798Flowise - Weak Default Token Hash Secret in JWT Token Encryption
CVE-2026-529845.52.7LinuxLinux—net/sched: netem: fix queue limit check to include reordered packets
CVE-2026-530605.52.7LinuxLinuxCWE-401dm cache metadata: fix memory leak on metadata abort retry
CVE-2026-530635.52.7LinuxLinux—dm cache: fix write hang in passthrough mode
CVE-2026-530207.82.6LinuxLinuxCWE-362um: Fix potential race condition in TLB sync
CVE-2026-529157.12.5LinuxLinuxCWE-129netfilter: ip6t_hbh: reject oversized option lists
CVE-2026-132086.52.5Red HatRed Hat OpenShift Virtualization 4CWE-287Kubevirt: virt-handler-rhel9: kubevirt: virt-handler notify server trusts vmi…
CVE-2026-529427.12.5LinuxLinuxCWE-125netfilter: nf_log: validate MAC header was set before dumping it
CVE-2026-530355.52.5LinuxLinuxCWE-667bpf, sockmap: Fix af_unix iter deadlock
CVE-2026-530375.52.5LinuxLinuxCWE-667HID: usbhid: fix deadlock in hid_post_reset()
CVE-2026-531015.52.4LinuxLinuxCWE-667wifi: mt76: mt7921: fix potential deadlock in mt7921_roc_abort_sync
CVE-2026-531225.52.4LinuxLinuxCWE-667btrfs: fix deadlock between reflink and transaction commit when using flushon…
CVE-2026-529795.52.3LinuxLinuxCWE-667net: psp: check for device unregister when creating assoc
CVE-2026-531005.52.3LinuxLinuxCWE-667wifi: mt76: fix deadlock in remain-on-channel
CVE-2026-531035.52.3LinuxLinuxCWE-667wifi: mt76: mt7925: fix potential deadlock in mt7925_roc_abort_sync
CVE-2026-531255.52.3LinuxLinuxCWE-667md: fix array_state=clear sysfs deadlock
CVE-2026-529775.52.3LinuxLinux—futex: Prevent lockup in requeue-PI during signal/ timeout wakeup
CVE-2026-529955.52.2LinuxLinux—net/rds: zero per-item info buffer before handing it to visitors
CVE-2026-530215.52.2LinuxLinuxCWE-190scsi: target: core: Fix integer overflow in UNMAP bounds check
CVE-2026-530395.52.2LinuxLinuxCWE-617ocfs2: validate group add input before caching
CVE-2026-530645.52.3LinuxLinuxCWE-476dm cache: fix null-deref with concurrent writes in passthrough mode
CVE-2026-530935.52.3LinuxLinuxCWE-476wifi: brcmfmac: Fix error pointer dereference
CVE-2026-530275.52.2LinuxLinux—fs/ntfs3: fix missing run load for vcn0 in attr_data_get_block_locked()
CVE-2026-529277.82.0LinuxLinuxCWE-125netfilter: ebtables: fix OOB read in compat_mtw_from_user
CVE-2026-529337.82.0LinuxLinuxCWE-835io_uring/poll: fix signed comparison in io_poll_get_ownership()
CVE-2026-529197.81.8LinuxLinuxCWE-191batman-adv: fix tp_meter counter underflow during shutdown
CVE-2026-531297.81.8LinuxLinuxCWE-416fs/mbcache: cancel shrink work before destroying the cache
CVE-2026-537666.11.8ChromeDevToolschrome-devtools-mcpCWE-22chrome-devtools-mcp: validatePath() does not canonicalize symlinks before enf…
CVE-2026-529917.81.7LinuxLinuxCWE-362sched/psi: fix race between file release and pressure write
CVE-2026-529305.51.7LinuxLinux—ipc/shm: serialize orphan cleanup with shm_nattch updates
CVE-2026-529285.51.7LinuxLinux—af_unix: Reject SIOCATMARK on non-stream sockets
CVE-2026-530805.51.7LinuxLinuxCWE-476net/sched: cls_fw: fix NULL dereference of "old" filters before change()
CVE-2026-529597.81.6LinuxLinux—virt: sev-guest: Do not use host-controlled page order in cleanup path
CVE-2026-531075.51.6LinuxLinux—wifi: libertas: don't kill URBs in interrupt context
CVE-2026-537656.11.1ChromeDevToolschrome-devtools-mcpCWE-59chrome-devtools-mcp: daemon.pid write follows symlinks in /tmp fallback runti…
CVE-2026-530507.80.9LinuxLinuxCWE-362quota: Fix race of dquot_scan_active() with quota deactivation
CVE-2026-530084.70.8LinuxLinuxCWE-362ice: fix race condition in TX timestamp ring cleanup
CVE-2026-531084.70.8LinuxLinuxCWE-362powerpc/64s: Fix unmap race with PMD migration entries
CVE-2026-530627.80.8LinuxLinuxCWE-667dm cache policy smq: fix missing locks in invalidating cache blocks
CVE-2026-562725.60.8FlowiseFlowiseCWE-916Flowise - Insufficient Password Salt Rounds in Bcrypt Hashing