Security Box Score — June 25, 2026 — page 2
Edition of June 25, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-8720 | 5.9 | 5.2 | wolfSSL | wolfSSL | CWE-354 | HMAC-BLAKE2 final discards message when key length exceeds block size |
| CVE-2026-12490 | 8.2 | 5.0 | NLnet Labs | NSD | CWE-284 | Bypass of client certificate verification with transfer over TLS |
| CVE-2026-53202 | 7.8 | 5.0 | Linux | Linux | CWE-787 | accel/ivpu: Fix signed integer truncation in IPC receive |
| CVE-2026-9651 | 6.7 | 5.0 | Schneider Electric | EasyLogic T150 (formerly Saitel DR) Remote Terminal Unit & Controller | CWE-732 | CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability t… |
| CVE-2026-42004 | 3.7 | 4.9 | PowerDNS | DNSdist | CWE-115 | EDNS options smuggling |
| CVE-2026-45188 | 2.4 | 4.7 | Apache Software Foundation | Apache Kvrocks | CWE-23 | Apache Kvrocks: Replication Fullsync Path Traversal via Unvalidated Filename … |
| CVE-2026-53277 | 8.8 | 4.6 | Linux | Linux | CWE-662 | KVM: arm64: Take the SRCU lock for page table walks in fault injection and AT… |
| CVE-2026-53143 | 7.8 | 4.7 | Linux | Linux | CWE-787 | drm/amdkfd: Fix buffer overflow in SDMA queue checkpoint/restore on GFX11 |
| CVE-2026-40011 | 3.7 | 4.6 | PowerDNS | DNSdist | CWE-116 | Prometheus denial of service via crafted DNS queries |
| CVE-2026-53212 | 7.8 | 4.5 | Linux | Linux | CWE-416 | netfilter: nft_tunnel: fix use-after-free on object destroy |
| CVE-2026-13282 | 6.8 | 4.5 | Chrome | CWE-416 | Use after free in Payments in Google Chrome on Android prior to 149.0.7827.20… | |
| CVE-2026-46733 | 7.8 | 4.3 | Dell | Display and Peripheral Manager | CWE-284 | Dell Display and Peripheral Manager (DDPM Windows), versions prior to 2.3, co… |
| CVE-2026-49839 | 7.1 | 4.3 | jqlang | jq | CWE-787 | jq --rawfile invalid-state reuse after String too long causes heap-buffer-ove… |
| CVE-2026-47770 | 6.8 | 4.2 | jqlang | jq | CWE-674 | jq: stack overflow in deep structural equality |
| CVE-2026-55961 | 8.2 | 4.1 | wolfSSL | wolfSSL | CWE-347 | wolfSSL_PKCS7_verify() reports success for degenerate (certs-only) PKCS#7 wit… |
| CVE-2026-57456 | 8.4 | 4.0 | vim | vim | CWE-94 | Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings |
| CVE-2026-53155 | 5.5 | 3.8 | Linux | Linux | — | mm/huge_memory: use correct flags for device private PMD entry |
| CVE-2026-53169 | 5.5 | 3.8 | Linux | Linux | CWE-617 | accel/ethosu: reject NPU_OP_RESIZE commands from userspace |
| CVE-2026-53204 | 5.5 | 3.8 | Linux | Linux | CWE-476 | firmware: stratix10-rsu: Fix NULL deref on rsu_send_msg() timeout in probe |
| CVE-2026-53206 | 5.5 | 3.8 | Linux | Linux | — | accel/ivpu: Add bounds check for firmware runtime memory |
| CVE-2026-53222 | 5.5 | 3.8 | Linux | Linux | CWE-401 | ptp: ocp: fix resource freeing order |
| CVE-2026-53243 | 5.5 | 3.8 | Linux | Linux | CWE-908 | rseq: Fix using an uninitialized stack variable in rseq_exit_user_update() |
| CVE-2026-53257 | 5.5 | 3.8 | Linux | Linux | — | wifi: cfg80211: enforce HE/EHT cap/oper consistency |
| CVE-2026-4930 | 7.1 | 3.5 | silabs.com | Simplicity SDK | CWE-331 | DPA Countermeasures weakening on Series 3 devices |
| CVE-2026-13218 | 4.2 | 3.5 | Red Hat | Red Hat OpenShift Virtualization 4 | CWE-61 | Kubevirt: kubevirt: symlink following in writetocachedfile allows host file o… |
| CVE-2026-53145 | 7.8 | 3.3 | Linux | Linux | CWE-367 | drm/gem: Try to fix change_handle ioctl, attempt 4 |
| CVE-2026-53153 | 7.8 | 3.3 | Linux | Linux | CWE-820 | mm/list_lru: drain before clearing xarray entry on reparent |
| CVE-2026-53185 | 7.8 | 2.9 | Linux | Linux | CWE-416 | zram: fix use-after-free in zram_bvec_write_partial() |
| CVE-2026-53227 | 5.5 | 2.8 | Linux | Linux | CWE-401 | net: openvswitch: fix possible kfree_skb of ERR_PTR |
| CVE-2026-53252 | 5.5 | 2.9 | Linux | Linux | CWE-401 | Bluetooth: fix memory leak in error path of hci_alloc_dev() |
| CVE-2026-53136 | 7.8 | 2.8 | Linux | Linux | CWE-787 | drm/amd/display: Clamp VBIOS HDMI retimer register count to array size |
| CVE-2026-53189 | 7.8 | 2.8 | Linux | Linux | — | mm/huge_memory: update file PMD counter before folio_put() |
| CVE-2026-53242 | 7.8 | 2.8 | Linux | Linux | CWE-476 | ALSA: PCM: Fix wait queue list corruption in snd_pcm_drain() on linked streams |
| CVE-2026-53157 | 7.8 | 2.5 | Linux | Linux | CWE-416 | net: phonet: free phonet_device after RCU grace period |
| CVE-2026-53138 | 7.1 | 2.5 | Linux | Linux | CWE-125 | drm/amd/display: Bound VBIOS record-chain walk loops |
| CVE-2026-53149 | 7.1 | 2.5 | Linux | Linux | CWE-125 | thunderbolt: Bound root directory content to block size |
| CVE-2026-53167 | 5.5 | 2.5 | Linux | Linux | CWE-908 | fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios |
| CVE-2026-53207 | 5.5 | 2.5 | Linux | Linux | CWE-667 | mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison |
| CVE-2026-57438 | 2.2 | 2.4 | sparklemotion | nokogiri | CWE-416 | Nokogiri: Possible Use-After-Free in XInclude Processing |
| CVE-2026-55693 | 5.7 | 2.4 | vim | vim | CWE-787 | Vim: Out-of-bounds Write in Spell File Word Count |
| CVE-2026-53197 | 5.5 | 2.3 | Linux | Linux | CWE-667 | xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state() |
| CVE-2026-53134 | 5.5 | 2.3 | Linux | Linux | CWE-401 | netfilter: nft_fib: fix stale stack leak via the OIFNAME register |
| CVE-2026-53139 | 5.5 | 2.3 | Linux | Linux | — | drm/v3d: Skip CSD when it has zeroed workgroups |
| CVE-2026-53158 | 5.5 | 2.2 | Linux | Linux | CWE-476 | misc: fastrpc: Fix NULL pointer dereference in rpmsg callback |
| CVE-2026-53163 | 5.5 | 2.2 | Linux | Linux | CWE-476 | locking/rtmutex: Skip remove_waiter() when waiter is not enqueued |
| CVE-2026-53181 | 5.5 | 2.3 | Linux | Linux | CWE-401 | vsock/vmci: fix sk_ack_backlog leak on failed handshake |
| CVE-2026-53208 | 5.5 | 2.3 | Linux | Linux | — | Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig |
| CVE-2026-53213 | 5.5 | 2.2 | Linux | Linux | CWE-401 | drm/vc4: fix krealloc() memory leak |
| CVE-2026-53218 | 5.5 | 2.3 | Linux | Linux | CWE-908 | netfilter: nft_exthdr: fix register tracking for F_PRESENT flag |
| CVE-2026-53236 | 5.5 | 2.3 | Linux | Linux | — | tcp: restrict SO_ATTACH_FILTER to priv users |
| CVE-2026-53245 | 5.5 | 2.3 | Linux | Linux | — | net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr |
| CVE-2026-53249 | 5.5 | 2.3 | Linux | Linux | — | ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options |
| CVE-2026-53266 | 8.8 | 2.1 | Linux | Linux | — | netfilter: bridge: make ebt_snat ARP rewrite writable |
| CVE-2026-53270 | 7.8 | 2.1 | Linux | Linux | — | ipvs: clear the svc scheduler ptr early on edit |
| CVE-2026-53267 | 7.8 | 2.0 | Linux | Linux | CWE-674 | netfilter: nft_ct: bail out on template ct in get eval |
| CVE-2026-2299 | 4.3 | 2.0 | Mattermost | Mattermost Google Drive Plugin | CWE-862 | Improper Access Control in Mattermost Google Drive Plugin File Creation Endpoint |
| CVE-2026-53262 | 7.8 | 1.9 | Linux | Linux | — | l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() |
| CVE-2026-53226 | 5.5 | 1.9 | Linux | Linux | CWE-401 | gpio: rockchip: fix generic IRQ chip leak on remove |
| CVE-2026-57455 | 4.0 | 1.9 | vim | vim | CWE-787 | Vim: Stack out-of-bounds write in `spell_soundfold_sofo()` via an over-length… |
| CVE-2026-53273 | 7.8 | 1.9 | Linux | Linux | CWE-416 | tee: optee: prevent use-after-free when the client exits before the supplicant |
| CVE-2026-53255 | 7.1 | 1.8 | Linux | Linux | CWE-125 | Bluetooth: MGMT: validate advertising TLV before type checks |
| CVE-2026-33612 | 7.5 | 1.7 | PowerDNS | Recursor | CWE-349 | ZoneToCache can poison the cache |
| CVE-2026-53231 | 5.5 | 1.4 | Linux | Linux | CWE-667 | net: phy: don't try to setup PHY-driven SFP cages when using genphy |
| CVE-2026-6412 | 2.3 | 1.4 | wolfSSL | wolfSSL | CWE-327 | Continued acceptance of SHA-1/MD5 digests in certificate processing |
| CVE-2026-53250 | 7.8 | 1.1 | Linux | Linux | CWE-367 | xsk: cache csum_start/csum_offset to fix TOCTOU in xsk_skb_metadata() |
| CVE-2026-54679 | 6.9 | 1.1 | jqlang | jq | CWE-190 | jq: potential integer overflow in jvp_string_append |
| CVE-2026-46732 | 7.0 | 1.0 | Dell | Display and Peripheral Manager | CWE-362 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contai… |
| CVE-2026-46734 | 7.8 | 0.5 | Dell | Display and Peripheral Manager | CWE-295 | Dell Display and Peripheral Manager (DDPM Mac), versions prior to 2.3, contai… |