boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, June 25, 2026 · all times UTC← 2026-06-24 · archive · 2026-06-26 →

Security Box Score — June 25, 2026 — page 2

Edition of June 25, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–468 of 468
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-87205.95.2wolfSSLwolfSSLCWE-354HMAC-BLAKE2 final discards message when key length exceeds block size
CVE-2026-124908.25.0NLnet LabsNSDCWE-284Bypass of client certificate verification with transfer over TLS
CVE-2026-532027.85.0LinuxLinuxCWE-787accel/ivpu: Fix signed integer truncation in IPC receive
CVE-2026-96516.75.0Schneider ElectricEasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & ControllerCWE-732CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability t…
CVE-2026-420043.74.9PowerDNSDNSdistCWE-115EDNS options smuggling
CVE-2026-451882.44.7Apache Software FoundationApache KvrocksCWE-23Apache Kvrocks: Replication Fullsync Path Traversal via Unvalidated Filename …
CVE-2026-532778.84.6LinuxLinuxCWE-662KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT…
CVE-2026-531437.84.7LinuxLinuxCWE-787drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11
CVE-2026-400113.74.6PowerDNSDNSdistCWE-116Prometheus denial of service via crafted DNS queries
CVE-2026-532127.84.5LinuxLinuxCWE-416netfilter: nft_tunnel: fix use-after-free on object destroy
CVE-2026-132826.84.5GoogleChromeCWE-416Use after free in Payments in Google Chrome on Android prior to 149.0.7827.20…
CVE-2026-467337.84.3DellDisplay and Peripheral ManagerCWE-284Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, co…
CVE-2026-498397.14.3jqlangjqCWE-787jq --rawfile invalid-state reuse after String too long causes heap-buffer-ove…
CVE-2026-477706.84.2jqlangjqCWE-674jq: stack overflow in deep structural equality
CVE-2026-559618.24.1wolfSSLwolfSSLCWE-347wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 wit…
CVE-2026-574568.44.0vimvimCWE-94Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings
CVE-2026-531555.53.8LinuxLinux—mm/huge_memory: use correct flags for device private PMD entry
CVE-2026-531695.53.8LinuxLinuxCWE-617accel/ethosu: reject NPU_OP_RESIZE commands from userspace
CVE-2026-532045.53.8LinuxLinuxCWE-476firmware: stratix10-rsu: Fix NULL deref on rsu_send_msg() timeout in probe
CVE-2026-532065.53.8LinuxLinux—accel/ivpu: Add bounds check for firmware runtime memory
CVE-2026-532225.53.8LinuxLinuxCWE-401ptp: ocp: fix resource freeing order
CVE-2026-532435.53.8LinuxLinuxCWE-908rseq: Fix using an uninitialized stack variable in rseq_exit_user_update()
CVE-2026-532575.53.8LinuxLinux—wifi: cfg80211: enforce HE/EHT cap/oper consistency
CVE-2026-49307.13.5silabs.comSimplicity SDKCWE-331DPA Countermeasures weakening on Series 3 devices
CVE-2026-132184.23.5Red HatRed Hat OpenShift Virtualization 4CWE-61Kubevirt: kubevirt: symlink following in writetocachedfile allows host file o…
CVE-2026-531457.83.3LinuxLinuxCWE-367drm/gem: Try to fix change_handle ioctl, attempt 4
CVE-2026-531537.83.3LinuxLinuxCWE-820mm/list_lru: drain before clearing xarray entry on reparent
CVE-2026-531857.82.9LinuxLinuxCWE-416zram: fix use-after-free in zram_bvec_write_partial()
CVE-2026-532275.52.8LinuxLinuxCWE-401net: openvswitch: fix possible kfree_skb of ERR_PTR
CVE-2026-532525.52.9LinuxLinuxCWE-401Bluetooth: fix memory leak in error path of hci_alloc_dev()
CVE-2026-531367.82.8LinuxLinuxCWE-787drm/amd/display: Clamp VBIOS HDMI retimer register count to array size
CVE-2026-531897.82.8LinuxLinux—mm/huge_memory: update file PMD counter before folio_put()
CVE-2026-532427.82.8LinuxLinuxCWE-476ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams
CVE-2026-531577.82.5LinuxLinuxCWE-416net: phonet: free phonet_device after RCU grace period
CVE-2026-531387.12.5LinuxLinuxCWE-125drm/amd/display: Bound VBIOS record-chain walk loops
CVE-2026-531497.12.5LinuxLinuxCWE-125thunderbolt: Bound root directory content to block size
CVE-2026-531675.52.5LinuxLinuxCWE-908fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios
CVE-2026-532075.52.5LinuxLinuxCWE-667mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison
CVE-2026-574382.22.4sparklemotionnokogiriCWE-416Nokogiri: Possible Use-After-Free in XInclude Processing
CVE-2026-556935.72.4vimvimCWE-787Vim: Out-of-bounds Write in Spell File Word Count
CVE-2026-531975.52.3LinuxLinuxCWE-667xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state()
CVE-2026-531345.52.3LinuxLinuxCWE-401netfilter: nft_fib: fix stale stack leak via the OIFNAME register
CVE-2026-531395.52.3LinuxLinux—drm/v3d: Skip CSD when it has zeroed workgroups
CVE-2026-531585.52.2LinuxLinuxCWE-476misc: fastrpc: Fix NULL pointer dereference in rpmsg callback
CVE-2026-531635.52.2LinuxLinuxCWE-476locking/rtmutex: Skip remove_waiter() when waiter is not enqueued
CVE-2026-531815.52.3LinuxLinuxCWE-401vsock/vmci: fix sk_ack_backlog leak on failed handshake
CVE-2026-532085.52.3LinuxLinux—Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig
CVE-2026-532135.52.2LinuxLinuxCWE-401drm/vc4: fix krealloc() memory leak
CVE-2026-532185.52.3LinuxLinuxCWE-908netfilter: nft_exthdr: fix register tracking for F_PRESENT flag
CVE-2026-532365.52.3LinuxLinux—tcp: restrict SO_ATTACH_FILTER to priv users
CVE-2026-532455.52.3LinuxLinux—net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr
CVE-2026-532495.52.3LinuxLinux—ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options
CVE-2026-532668.82.1LinuxLinux—netfilter: bridge: make ebt_snat ARP rewrite writable
CVE-2026-532707.82.1LinuxLinux—ipvs: clear the svc scheduler ptr early on edit
CVE-2026-532677.82.0LinuxLinuxCWE-674netfilter: nft_ct: bail out on template ct in get eval
CVE-2026-22994.32.0MattermostMattermost Google Drive PluginCWE-862Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint
CVE-2026-532627.81.9LinuxLinux—l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()
CVE-2026-532265.51.9LinuxLinuxCWE-401gpio: rockchip: fix generic IRQ chip leak on remove
CVE-2026-574554.01.9vimvimCWE-787Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length…
CVE-2026-532737.81.9LinuxLinuxCWE-416tee: optee: prevent use-after-free when the client exits before the supplicant
CVE-2026-532557.11.8LinuxLinuxCWE-125Bluetooth: MGMT: validate advertising TLV before type checks
CVE-2026-336127.51.7PowerDNSRecursorCWE-349ZoneToCache can poison the cache
CVE-2026-532315.51.4LinuxLinuxCWE-667net: phy: don't try to setup PHY-driven SFP cages when using genphy
CVE-2026-64122.31.4wolfSSLwolfSSLCWE-327Continued acceptance of SHA-1/MD5 digests in certificate processing
CVE-2026-532507.81.1LinuxLinuxCWE-367xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata()
CVE-2026-546796.91.1jqlangjqCWE-190jq: potential integer overflow in jvp_string_append
CVE-2026-467327.01.0DellDisplay and Peripheral ManagerCWE-362Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contai…
CVE-2026-467347.80.5DellDisplay and Peripheral ManagerCWE-295Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contai…