boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, July 19, 2026 · all times UTC← 2026-07-18 · archive · 2026-07-20 →

Security Box Score — July 19, 2026

464 CVEs published, led by Linux (429).

464 CVEs published July 19, 2026: 58 critical, 211 high, 72 medium, 18 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 105 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 64 on continuation pages.

Standings

League
MTDYTD2025 same span2025 full
CVEs published515117554——
KEV catalog size1675

Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.

Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.

763 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.

Operating Systems & Platforms
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
linux4701950178107559111120.17.8.0016+371 ▲
microsoft64614039697531814286231.67.8.0047+426 ▲
google941359150616555387760.47.8.0024-590 ▼
red hat652871411514018200.06.5.0032-10 ▼
apple01042287228876.76.5.0032-14 ▼
canonical42436105000.05.5.0013+3 ▲
suse82141241000.08.5.0039+4 ▲
freebsd01601240000.07.8.00160
Network & Infrastructure
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
cisco1537818110561129.77.5.0057+6 ▲
ubiquiti2536142110338.38.8.0049+20 ▲
palo alto networks1425131471328.04.7.0028+5 ▲
netgear62300221000.04.6.0024-11 ▼
fortinet13226610028522.77.3.0039+11 ▲
f58165830416.38.6.0057+2 ▲
vmware8121821718.38.2.0039+5 ▲
ivanti211452025545.58.8.3445-2 ▼
Open Source Ecosystems
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
apache78233479084113310.47.5.0058-8 ▼
mozilla6621218320900.06.5.0026-43 ▼
drupal465165355412.05.9.0026+46 ▲
gitlab73805276425.34.7.0032-4 ▼
github5111280000.06.0.0042+5 ▲
docker070520000.08.2.0016-4 ▼
wordpress00000020———0
Enterprise Applications
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
oracle12711331161842731.18.8.0040-241 ▼
adobe942382610310541931.37.6.0026-35 ▼
ibm361605254540600.07.5.0036+25 ▲
progress101931420600.07.5.0037+5 ▲
solarwinds07232010457.17.5.4001-3 ▼
veeam042200100.09.0.0052-1 ▼
zohocorp031110000.08.4.01700
servicenow111000200.09.5.7758+1 ▲
Industrial & Embedded
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
rockwell automation172441820000.08.7.0029+10 ▲
synology02325133000.05.6.0025-5 ▼
siemens7161870000.07.6.00240
d-link1130535300.06.0.0059-8 ▼
abb170430000.07.2.0018-4 ▼
schneider electric060420000.07.8.0042-1 ▼
moxa050320000.07.0.0029-5 ▼
dahua030111000.06.9.0036-3 ▼
Other
VendorMTDYTDCHMLKEVKEV YTDKEV/100Med CVSSMed EPSSΔ
sourcecodester46117006156000.05.5.0033+9 ▲
openclaw441110583914000.07.0.0026-17 ▼
dell3793542433211.17.0.0021+10 ▲
capgo2283242381000.07.1.0037+19 ▲
nvidia40791252150000.07.8.0037+34 ▲
imagemagick3273155512000.05.3.0019+4 ▲
spring073231391000.06.5.0024-71 ▼
itsourcecode1568001949000.02.1.0033-7 ▼

Leaders (trailing 30 days unless noted)

Highest EPSS
CVEEPSS%ileCVSS
CVE-2026-20230.882099.88.6
CVE-2026-34910.874799.710.0
CVE-2026-34908.851999.710.0
CVE-2026-50522.846199.79.8
CVE-2026-15409.836699.710.0
CVE-2026-6875.775899.59.5
CVE-2026-25089.761199.59.8
CVE-2026-45659.760899.58.8
CVE-2026-34909.639099.210.0
CVE-2026-48282.423998.610.0
Highest CVSS
CVECVSSEPSSNote
CVE-2026-3491010.0.8747KEV
CVE-2026-3490810.0.8519KEV
CVE-2026-1540910.0.8366KEV
CVE-2026-3490910.0.6390KEV
CVE-2026-4828210.0.4239KEV
CVE-2026-5629010.0.3038KEV
CVE-2026-4893910.0.1973KEV
CVE-2026-4890810.0.1482KEV
CVE-2026-5629110.0.1459KEV
CVE-2026-5972610.0.0688
Most disclosures (vendor)
VendorCVEs
linux884
microsoft647
google500
red hat118
apache113
adobe107
ibm100
capgo80
sourcecodester58
dell48
Most KEV additions (YTD)
VendorKEV
microsoft23
cisco11
apple7
google6
fortinet5
ivanti5
solarwinds4
adobe3
berriai3
oracle3
Most-affected ecosystems
EcosystemAdvisories
Maven56
PyPI5
npm5
NuGet3
Packagist1
Fastest to KEV
CVEVendorDays
CVE-2026-12569PTC0
CVE-2026-15409SonicWall0
CVE-2026-15410SonicWall0
CVE-2026-20230Cisco0
CVE-2026-25089Fortinet0
CVE-2026-34908Ubiquiti Inc0
CVE-2026-34909Ubiquiti Inc0
CVE-2026-34910Ubiquiti Inc0
CVE-2026-45659Microsoft0
CVE-2026-46817Oracle Corporation0
Longest unpatched (KEV due date passed)
CVEVendorDueDays over
CVE-2021-27104n/a2021-11-171705
CVE-2021-27102n/a2021-11-171705
CVE-2021-27101n/a2021-11-171705
CVE-2021-27103n/a2021-11-171705
CVE-2021-21017Adobe2021-11-171705
CVE-2021-28550Adobe2021-11-171705
CVE-2021-42013Apache Software Foundation2021-11-171705
CVE-2021-41773Apache Software Foundation2021-11-171705
CVE-2021-30858Apple2021-11-171705
CVE-2021-30860Apple2021-11-171705

Transactions

EXPLOIT PUBLISHED — SourceCodester Class and Exam Timetabling System: 4 CVEs (CVE-2026-16202, CVE-2026-16203, CVE-2026-16227, CVE-2026-16228). Public exploit references added.

EXPLOIT PUBLISHED — geex-arts django-jet: 3 CVEs (CVE-2026-16214, CVE-2026-16215, CVE-2026-16216). Public exploit references added.

EXPLOIT PUBLISHED — zevorn rt-claw: 3 CVEs (CVE-2026-16200, CVE-2026-16201, CVE-2026-16204). Public exploit references added.

EXPLOIT PUBLISHED — CVE-2026-16199 (nextlevelbuilder GoClaw). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16205 (Pluck CMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16209 (Gerapy). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16210 (newpanjing simpleui). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16211 (allegro). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16212 (awesto django-shop). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16217 (guohongze adminset). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16219 (Croogo CMS). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16220 (code-projects Online Examination System). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16222 (1Panel-dev CordysCRM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16223 (1Panel-dev CordysCRM). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16225 (davenardella snap7). Public exploit reference added.

EXPLOIT PUBLISHED — CVE-2026-16229 (itsourcecode Courier Management System). Public exploit reference added.

DUE DATE PASSED — CVE-2026-46817 (Oracle Corporation Oracle Payments). CISA remediation deadline was July 18, 2026; still in catalog.

Yesterday's Results

How to read these box scores · glossary

464 CVEs published. 25 box scores and 375 table rows below; the remaining 64 continue on page 2 — every CVE is listed, nothing truncated.

Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  C  H  H  N   10.0   .0180   76.8     —
AFFECTED
  Product   Versions            Fixed
  firmware  < 2.7.21.1370b23 –  —
TIMELINE
  May 5   Reserved by CNA
  Jul 19  Published (CNA: GitHub_M)
CWE-94, CWE-829 · CNA: GitHub_M · CVSS v3.1 · 4 references · NVD status: Deferred
Linux Linux — netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  L  H    8.2   .0097   59.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1 –  —
  Linux    2.6.15 –                                    5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Awaiting Analysis
Linux Linux — scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0078   53.1     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    e48354ce078c079996f89d715dfa44814b4eba01 –  —
  Linux    3.1 –                                       5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Awaiting Analysis
Linux Linux — scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0078   53.1     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    e48354ce078c079996f89d715dfa44814b4eba01 –  —
  Linux    3.1 –                                       5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Awaiting Analysis
Linux Linux — gcov: use atomic counter updates to fix concurrent access crashes
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0077   53.0     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    2521f2c228ad750701ba4702484e31d876dbc386 –  —
  Linux    2.6.31 –                                    6.18.38
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 3 references · NVD status: Awaiting Analysis
Linux Linux — vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0076   52.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    4cb47a8644cc9eb8ec81190a50e79e6530d0297f –  —
  Linux    5.9 –                                       5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Awaiting Analysis
Linux Linux — net: tls: prevent chain-after-chain in plain text SG
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0076   52.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    9aaaa56845a06aeabdd597cbe19492dc01f281ec –  —
  Linux    5.5 –                                       5.10.258
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Awaiting Analysis
Linux Linux — net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0076   52.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    9aaaa56845a06aeabdd597cbe19492dc01f281ec –  —
  Linux    5.5 –                                       5.10.258
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Awaiting Analysis
Linux Linux — net: ethernet: cortina: Carry over frag counter
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0076   52.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 –  —
  Linux    4.16 –                                      5.10.258
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Awaiting Analysis
Linux Linux — tunnels: do not assume transport header in iptunnel_pmtud_check_icmp()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  N  H    9.1   .0073   51.7     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    4cb47a8644cc9eb8ec81190a50e79e6530d0297f –  —
  Linux    5.9 –                                       5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Awaiting Analysis
Linux Linux — RDMA/siw: Reject MPA FPDU length underflow before signed receive math
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0073   51.6     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    8b6a361b8c482f22ac99c3273285ff16b23fba91 –  —
  Linux    5.3 –                                       5.10.258
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CWE-125 · CNA: Linux · CVSS v3.1 · 8 references · NVD status: Analyzed
Linux Linux — ixgbevf: fix use-after-free in VEPA multicast source pruning
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0073   51.6     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    bad17234ba702a50aeec50ab04724ee58af89607 –  —
  Linux    3.19 –                                      5.10.258
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CWE-416 · CNA: Linux · CVSS v3.1 · 8 references · NVD status: Analyzed
Linux Linux — net: hsr: fix potential OOB access in supervision frame handling
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0072   51.2     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    eafaa88b3eb7f28aecb222281655473431d3ef2e –  —
  Linux    5.16 –                                      6.1.176
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 6 references · NVD status: Awaiting Analysis
Linux Linux — RDMA/rtrs: Fix use-after-free in path file creation cleanup
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0072   51.0     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    bab17b761c8974a869b04462be5d4dd9aad366b4 –  —
  Linux    5.17 –                                      5.15.209
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 7 references · NVD status: Awaiting Analysis
Linux Linux — xfrm: esp: restore combined single-frag length gate
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0071   50.9     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    c075c3ea031757f8ea2d34567565b61a868c08d5 –  —
  Linux    5.18 –                                      5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Awaiting Analysis
Linux Linux — ipv6: exthdrs: refresh nh after handling HAO option
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0071   50.9     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    a831f5bbc89a9978795504be9e1ff412043f8f77 –  —
  Linux    2.6.19 –                                    5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Awaiting Analysis
Linux Linux — ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0071   50.9     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 –  —
  Linux    2.6.12 –                                    5.10.259
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 8 references · NVD status: Awaiting Analysis
Linux Linux — scsi: target: iscsi: Validate CHAP_R length before base64 decode
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0071   50.8     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    1e5733883421495908f3b90d9d807663038b4136 –  —
  Linux    6.0 –                                       6.1.176
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 6 references · NVD status: Awaiting Analysis
n/a Gerapy — Gerapy Project Upload Endpoint views.py missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0071   50.7     —
AFFECTED
  Product  Versions  Fixed
  Gerapy   0.9.0 –   —
TIMELINE
  Jul 18  Reserved by CNA
  Jul 19  Public exploit reference published
  Jul 19  Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · CVSS v4.0 · 8 references · NVD status: Deferred
Linux Linux — ksmbd: close durable scavenger races against m_fp_list lookups
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0070   50.6     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    7f0cb478703cbeaddfe5c9101c5c73cd975d1073 –  —
  Linux    6.11 –                                      6.12.92
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CWE-416 · CNA: Linux · CVSS v3.1 · 5 references · NVD status: Analyzed
Linux Linux — ipv6: ioam: add NULL check for idev in ipv6_hop_ioam()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0070   50.4     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    9ee11f0fff205b4b3df9750bff5e94f97c71b6a0 –  —
  Linux    5.15 –                                      5.15.210
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CWE-476 · CNA: Linux · CVSS v3.1 · 7 references · NVD status: Analyzed
newpanjing simpleui AjaxAdmin AJAX Endpoint admin.py self.get_action missing authentication
  AV  AC  AT  PR  UI  VC  VI  VA   CVSS    EPSS   %ile   KEV
   N   L   N   N   N   L   L   L    5.5   .0069   49.9     —
AFFECTED
  Product   Versions      Fixed
  simpleui  2026.01.13 –  —
TIMELINE
  Jul 18  Reserved by CNA
  Jul 19  Public exploit reference published
  Jul 19  Published (CNA: VulDB)
CWE-287, CWE-306 · CNA: VulDB · CVSS v4.0 · 6 references · NVD status: Deferred
Linux Linux — ipv6: ioam: refresh hdr pointer before ioam6_event()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0067   49.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    f655c78d6225f585ef60a9d93ffb79d507ff3ad3 –  —
  Linux    6.9 –                                       6.12.92
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CWE-416 · CNA: Linux · CVSS v3.1 · 4 references · NVD status: Analyzed
Linux Linux — smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .0067   49.3     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    953953abb66e52c224057ab91e404284fefeab62 –  —
  Linux    7.0 –                                       6.6.142
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CNA: Linux · CVSS v3.1 · 5 references · NVD status: Analyzed
Linux Linux — pds_core: fix error handling in pdsc_devcmd_wait
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  H    7.5   .0067   49.2     —
AFFECTED
  Product  Versions                                    Fixed
  Linux    45d76f492938cdc27ddadc16e1e75103f4cfbf56 –  —
  Linux    6.4 –                                       6.6.142
TIMELINE
  Jul 19  Reserved by CNA
  Jul 19  Published (CNA: Linux)
CWE-835 · CNA: Linux · CVSS v3.1 · 5 references · NVD status: Analyzed
Remainder (ranked, continued)
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-639687.549.0LinuxLinux—ipv6: fix possible infinite loop in fib6_select_path()
CVE-2026-533837.549.0LinuxLinuxCWE-476ksmbd: reject non-VALID session in compound request branch
CVE-2026-640259.848.5LinuxLinux—bpf, skmsg: fix verdict sk_data_ready racing with ktls rx
CVE-2026-640619.848.5LinuxLinux—netfs: Fix early put of sink folio in netfs_read_gaps()
CVE-2026-639198.848.4LinuxLinux—xfrm: input: hold netns during deferred transport reinjection
CVE-2026-638579.848.4LinuxLinux—net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit()
CVE-2026-639799.848.4LinuxLinux—net/handshake: hand off the pinned file reference to accept_doit
CVE-2026-640169.848.4LinuxLinux—ksmbd: fix durable reconnect error path file lifetime
CVE-2026-640359.848.4LinuxLinux—igc: set tx buffer type for SMD frames
CVE-2026-640669.848.4LinuxLinux—netfs: Fix netfs_read_to_pagecache() to pause on subreq failure
CVE-2026-640699.848.4LinuxLinux—netfs: Fix cancellation of a DIO and single read subrequests
CVE-2026-641509.848.4LinuxLinux—netfilter: nft_inner: release local_lock before re-enabling softirqs
CVE-2026-641629.848.4LinuxLinux—idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()
CVE-2026-640379.847.5LinuxLinux—wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled
CVE-2026-641229.847.5LinuxLinuxCWE-416net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover
CVE-2026-639807.547.4LinuxLinux—net/handshake: Use spin_lock_bh for hn_lock
CVE-2026-640037.547.4LinuxLinux—scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues
CVE-2026-641417.547.4LinuxLinuxCWE-476ksmbd: fix null pointer dereference in compare_guid_key()
CVE-2026-639098.147.4LinuxLinux—ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops
CVE-2026-162076.347.1n/adjango-tastypieCWE-598django-tastypie authentication.py ApiKeyAuthentication get request method wit…
CVE-2026-639789.846.9LinuxLinux—net/handshake: Drain pending requests at net namespace exit
CVE-2026-641757.546.5LinuxLinux—wifi: iwlwifi: mld: stop TX during firmware restart
CVE-2026-641388.846.1LinuxLinux—ksmbd: validate SID in parent security descriptor during ACL inheritance
CVE-2026-638678.245.7LinuxLinux—mptcp: close TOCTOU race while computing rcv_wnd
CVE-2026-639727.545.6LinuxLinux—net: mana: Skip redundant detach on already-detached port
CVE-2026-640249.444.4LinuxLinux—tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction
CVE-2026-640679.843.7LinuxLinux—netfs: Fix missing barriers when accessing stream->subrequests locklessly
CVE-2026-640689.843.7LinuxLinux—netfs: Fix missing locking around retry adding new subreqs
CVE-2026-641609.843.7LinuxLinux—netfs: Fix potential for tearing in ->remote_i_size and ->zero_point
CVE-2026-640569.843.6LinuxLinux—net: ethernet: cortina: Make RX SKB per-port
CVE-2026-640899.843.6LinuxLinux—batman-adv: tt: fix negative last_changeset_len
CVE-2026-641259.843.6LinuxLinux—net: bcmgenet: keep RBUF EEE/PM disabled
CVE-2026-162155.543.4geex-artsdjango-jetCWE-862geex-arts django-jet OAuth Credential Revoke authorization
CVE-2026-162042.143.4zevornrt-clawCWE-74zevorn rt-claw Telegram-to-AI Tool Execution Flow script.c tool_run_script_ex…
CVE-2026-533989.843.1LinuxLinux—NFSD: Fix SECINFO_NO_NAME decode error cleanup
CVE-2026-533999.843.1LinuxLinuxCWE-476nfsd: release layout stid on setlease failure
CVE-2026-162015.542.5zevornrt-clawCWE-200zevorn rt-claw http_request net.c claw_net_post information disclosure
CVE-2026-639768.842.4LinuxLinux—Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success
CVE-2026-533927.542.4LinuxLinuxCWE-476NFSv4/flexfiles: reject zero filehandle version count
CVE-2026-533977.542.4LinuxLinuxCWE-401nfsd: fix posix_acl leak on SETACL decode failure
CVE-2026-638009.842.3LinuxLinuxCWE-416pNFS: Fix use-after-free in pnfs_update_layout()
CVE-2026-638089.842.3LinuxLinux—exfat: fix potential use-after-free in exfat_find_dir_entry()
CVE-2026-533917.541.6LinuxLinuxCWE-476NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr
CVE-2026-533849.841.5LinuxLinuxCWE-416serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails
CVE-2026-639849.841.4LinuxLinux—ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()
CVE-2026-639949.841.4LinuxLinux—tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()
CVE-2026-640079.841.4LinuxLinux—netfilter: synproxy: refresh tcphdr after skb_ensure_writable
CVE-2026-638018.841.3LinuxLinuxCWE-416tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
CVE-2026-6379510.040.7LinuxLinuxCWE-4169p: avoid putting oldfid in p9_client_walk() error path
CVE-2026-640487.540.6LinuxLinux—net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot
CVE-2026-162005.540.2zevornrt-clawCWE-285zevorn rt-claw RPC swarm.c claw_tool_invoke authorization
CVE-2026-425667.539.8meshtasticfirmwareCWE-20Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh…
CVE-2026-533957.539.8LinuxLinuxCWE-674nfsd: fix dead ACL conflict guard in nfsd4_create
CVE-2026-639557.539.8LinuxLinux—mm/vmalloc: do not trigger BUG() on BH disabled context
CVE-2026-640207.539.8LinuxLinux—nvme-pci: fix dma_vecs leak on p2p memory
CVE-2026-641407.539.8LinuxLinuxCWE-476ksmbd: fix null pointer dereference in proc_show_files()
CVE-2026-533947.539.4LinuxLinuxCWE-401nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race
CVE-2026-637968.839.3LinuxLinuxCWE-125ocfs2: reject oversized group bitmap descriptors
CVE-2026-533908.138.5LinuxLinuxCWE-125ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
CVE-2026-162202.138.6code-projectsOnline Examination SystemCWE-79code-projects Online Examination System account.php cross site scripting
CVE-2026-162292.138.6itsourcecodeCourier Management SystemCWE-79itsourcecode Courier Management System index.php cross site scripting
CVE-2026-162217.536.1fast-urifast-uriCWE-436fast-uri vulnerable to host confusion via literal backslash authority delimiter
CVE-2026-162275.535.7SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System edit_subject.php sql injection
CVE-2026-162285.535.7SourceCodesterClass and Exam Timetabling SystemCWE-74SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection
CVE-2026-640919.835.3LinuxLinuxCWE-367batman-adv: tt: fix TOCTOU race for reported vlans
CVE-2026-162192.135.2CroogoCMSCWE-22Croogo CMS Admin File Manager FileManager.php isEditable path traversal
CVE-2026-639168.834.0LinuxLinux—HID: wacom: Fix OOB write in wacom_hid_set_device_mode()
CVE-2026-640888.834.0LinuxLinux—batman-adv: tt: fix negative tt_buff_len
CVE-2026-641788.834.0LinuxLinuxCWE-416Bluetooth: bnep: Fix UAF read of dev->name
CVE-2026-640957.133.7LinuxLinux—batman-adv: bla: avoid double decrement of bla.num_requests
CVE-2026-639478.833.1LinuxLinux—Bluetooth: HIDP: fix missing length checks in hidp_input_report()
CVE-2026-640938.833.1LinuxLinux—batman-adv: tp_meter: directly shut down timer on cleanup
CVE-2026-639258.133.0LinuxLinux—macsec: fix replay protection at XPN lower-PN wrap
CVE-2026-640108.832.9LinuxLinux—nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc()
CVE-2026-640968.832.9LinuxLinuxCWE-416batman-adv: mcast: fix use-after-free in orig_node RCU release
CVE-2026-162252.132.7davenardellasnap7CWE-119davenardella snap7 s7_peer.cpp NegotiatePDULength out-of-bounds write
CVE-2026-124847.832.1keras-teamkeras-team/kerasCWE-502Unsafe Deserialization in keras.layers.TorchModuleWrapper.from_config
CVE-2026-638898.131.7LinuxLinux—scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32
CVE-2026-639448.831.5LinuxLinux—Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync
CVE-2026-638938.131.4LinuxLinux—thunderbolt: property: Reject u32 wrap in tb_property_entry_valid()
CVE-2026-162245.331.3jxxghpMoviePilotCWE-266jxxghp MoviePilot Application API improper authorization
CVE-2026-162142.131.2geex-artsdjango-jetCWE-285geex-arts django-jet Dashboard views.py authorization
CVE-2026-162172.131.2guohongzeadminsetCWE-285guohongze adminset Delivery Deployment Endpoint deli.py authorization
CVE-2026-533967.130.7LinuxLinuxCWE-401nfsd: fix posix_acl leak and ignored error in nfsd4_create_file
CVE-2026-639748.830.7LinuxLinux—Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close
CVE-2026-162265.130.4SourceCodesterPizzafy Ecommerce SystemCWE-284SourceCodester Pizzafy Ecommerce System admin_class_novo.php save_settings un…
CVE-2026-638328.830.2LinuxLinux—wifi: mt76: add wcid publish check in mt76_sta_add
CVE-2026-638668.830.2LinuxLinux—wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link()
CVE-2026-640308.830.2LinuxLinux—wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs
CVE-2026-162222.130.21Panel-devCordysCRMCWE-9181Panel-dev CordysCRM Third Party Endpoint TokenService.java server-side reque…
CVE-2026-162232.130.21Panel-devCordysCRMCWE-9181Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java …
CVE-2026-638309.429.9LinuxLinux—net: skmsg: preserve sg.copy across SG transforms
CVE-2026-162065.329.3django-oauthdjango-oauth-toolkitCWE-613django-oauth django-oauth-toolkit oauth2_validators.py _load_id_token session…
CVE-2026-161992.129.3nextlevelbuilderGoClawCWE-266nextlevelbuilder GoClaw credentialed_exec.go ExecTool.Execute improper author…
CVE-2026-639158.828.1LinuxLinux—nfc: hci: fix out-of-bounds read in HCP header parsing
CVE-2026-639758.828.1LinuxLinux—Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp
CVE-2026-162051.927.6PluckCMSCWE-79Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting
CVE-2026-162022.027.4SourceCodesterClass and Exam Timetabling SystemCWE-79SourceCodester Class and Exam Timetabling System CYS.php cross site scripting
CVE-2026-162032.027.4SourceCodesterClass and Exam Timetabling SystemCWE-79SourceCodester Class and Exam Timetabling System forCYS.php cross site scripting
CVE-2026-641768.126.8LinuxLinux—wifi: iwlwifi: mvm: fix driver-set TX rates on old devices
CVE-2026-641178.826.5LinuxLinuxCWE-416wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb
CVE-2026-638697.626.2LinuxLinux—wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap
CVE-2026-639468.826.1LinuxLinux—Bluetooth: ISO: fix UAF in iso_recv_frame
CVE-2026-162182.121.4hunvreusdevpushCWE-703hunvreus devpush Storage Reset Failure storage.py reset_storage improper chec…
CVE-2026-162121.320.9awestodjango-shopCWE-362awesto django-shop Purchase Stock inventory.py race condition
CVE-2026-162082.317.9n/adjango-tastypieCWE-362django-tastypie throttle.py CacheDBThrottle race condition
CVE-2026-63891await17.8LinuxLinux—thunderbolt: property: Cap recursion depth in __tb_property_parse_dir()
CVE-2026-63895await16.6LinuxLinux—usb: gadget: f_fs: copy only received bytes on short ep0 read
CVE-2026-638318.816.3LinuxLinux—mac802154: llsec: add skb_cow_data() before in-place crypto
CVE-2026-451385.414.2ci4-cms-erpci4msCWE-79CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule
CVE-2026-64028await13.7LinuxLinux—tracing: Avoid NULL return from hist_field_name() on truncation
CVE-2026-162162.113.6geex-artsdjango-jetCWE-352geex-arts django-jet OAuth cross-site request forgery
CVE-2026-63981await13.4LinuxLinux—net/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflow
CVE-2026-63899await13.0LinuxLinux—USB: serial: mxuport: fix memory corruption with small endpoint
CVE-2026-63901await13.0LinuxLinux—USB: serial: digi_acceleport: fix memory corruption with small endpoints
CVE-2026-63990await13.0LinuxLinux—bonding: refuse to enslave CAN devices
CVE-2026-162111.212.8n/aallegroCWE-362allegro Hostname Allocation assets.py AssetLastHostname.increment_hostname ra…
CVE-2026-63868await12.3LinuxLinux—net: garp: fix unsigned integer underflow in garp_pdu_parse_attr
CVE-2026-63890await12.3LinuxLinux—scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker
CVE-2026-63892await12.3LinuxLinux—thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow
CVE-2026-63897await12.3LinuxLinux—USB: serial: mct_u232: fix missing interrupt-in transfer sanity check
CVE-2026-63898await12.3LinuxLinux—USB: serial: mct_u232: fix memory corruption with small endpoint
CVE-2026-63900await12.3LinuxLinux—USB: serial: keyspan: fix missing indat transfer sanity check
CVE-2026-63902await12.3LinuxLinux—USB: serial: cypress_m8: validate interrupt packet headers
CVE-2026-63903await12.3LinuxLinux—USB: serial: belkin_sa: validate interrupt status length
CVE-2026-63904await12.3LinuxLinux—usb: usbtmc: check URB actual_length for interrupt-IN notifications
CVE-2026-63905await12.3LinuxLinux—usbip: vudc: Fix use after free bug in vudc_remove due to race condition
CVE-2026-63908await12.3LinuxLinux—Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem
CVE-2026-63931await12.2LinuxLinux—iio: chemical: scd30: fix division by zero in write_raw
CVE-2026-63933await12.3LinuxLinux—iio: gyro: adis16260: fix division by zero in write_raw
CVE-2026-63934await12.3LinuxLinux—iio: gyro: itg3200: fix i2c read into the wrong stack location
CVE-2026-63948await12.3LinuxLinux—Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn
CVE-2026-63956await12.2LinuxLinux—USB: serial: cypress_m8: fix memory corruption with small endpoint
CVE-2026-63957await12.2LinuxLinux—USB: serial: safe_serial: fix memory corruption with small endpoint
CVE-2026-63960await12.3LinuxLinux—usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()
CVE-2026-63961await12.3LinuxLinux—usb: typec: altmodes/displayport: validate count before reading Status Update…
CVE-2026-63964await12.3LinuxLinux—usb: typec: ucsi: ccg: reject firmware images without a ':' record header
CVE-2026-63967await12.3LinuxLinux—iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer
CVE-2026-63991await12.3LinuxLinux—Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt()
CVE-2026-64012await12.3LinuxLinux—net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_p…
CVE-2026-64014await12.3LinuxLinux—Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size
CVE-2026-64083await12.3LinuxLinux—hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors
CVE-2026-64085await12.3LinuxLinux—hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer
CVE-2026-64087await12.3LinuxLinux—hwmon: (pmbus/adm1266) reject implausible blackbox record_count
CVE-2026-63928await11.9LinuxLinux—USB: serial: omninet: fix memory corruption with small endpoint
CVE-2026-63861await11.7LinuxLinux—spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback
CVE-2026-63862await11.7LinuxLinux—PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found
CVE-2026-63882await11.7LinuxLinux—drm/amdkfd: fix NULL pointer bug in svm_range_set_attr
CVE-2026-63949await11.7LinuxLinux—auxdisplay: line-display: fix OOB read on zero-length message_store()
CVE-2026-63969await11.7LinuxLinux—ipv6: fix possible infinite loop in rt6_fill_node()
CVE-2026-63973await11.7LinuxLinux—net: mana: Add NULL guards in teardown path to prevent panic on attach failure
CVE-2026-639399.311.3LinuxLinux—KVM: SEV: Compute the correct max length of the in-GHCB scratch area
CVE-2026-63958await11.3LinuxLinux—usb: typec: ucsi: validate connector number in ucsi_connector_change()
CVE-2026-63838await10.9LinuxLinux—ASoC: rsnd: Fix potential out-of-bounds access of component_dais[]
CVE-2026-63871await10.9LinuxLinux—Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls
CVE-2026-63876await10.9LinuxLinux—serial: zs: Convert to use a platform device
CVE-2026-63877await10.9LinuxLinux—serial: dz: Convert to use a platform device
CVE-2026-63896await10.9LinuxLinux—usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling
CVE-2026-63929await10.9LinuxLinux—iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf()
CVE-2026-63936await10.9LinuxLinux—iio: adc: mt6359: fix unchecked return value in mt6358_read_imp
CVE-2026-63943await10.9LinuxLinux—Input: xpad - fix out-of-bounds access for Share button
CVE-2026-63959await10.9LinuxLinux—usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT
CVE-2026-63962await10.9LinuxLinux—usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()
CVE-2026-63963await10.9LinuxLinux—usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers
CVE-2026-63997await10.9LinuxLinux—ethtool: module: avoid leaking a netdev ref on module flash errors
CVE-2026-64001await10.9LinuxLinux—ALSA: pcm: oss: Fix setup list UAF on proc write error
CVE-2026-64006await10.9LinuxLinux—netfilter: nf_tables: fix dst corruption in same register operation
CVE-2026-64052await10.9LinuxLinux—block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()
CVE-2026-64059await10.9LinuxLinux—netfs: Fix folio->private handling in netfs_perform_write()
CVE-2026-64062await10.9LinuxLinux—netfs: Fix potential deadlock in write-through mode
CVE-2026-64063await10.9LinuxLinux—netfs: Fix streaming write being overwritten
CVE-2026-64064await10.9LinuxLinux—netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone
CVE-2026-64065await10.9LinuxLinux—netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call
CVE-2026-63837await10.6LinuxLinux—net: ena: PHC: Check return code before setting timestamp output
CVE-2026-63859await10.6LinuxLinux—net: airoha: Add missing bits in airoha_qdma_cleanup_tx_queue()
CVE-2026-63873await10.6LinuxLinux—accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range()
CVE-2026-63878await10.6LinuxLinux—drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO
CVE-2026-63880await10.6LinuxLinux—drm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO
CVE-2026-63932await10.6LinuxLinux—iio: chemical: mhz19b: reject oversized serial replies
CVE-2026-63965await10.6LinuxLinux—iio: pressure: bmp280: fix stack leak in bmp580 trigger handler
CVE-2026-63966await10.6LinuxLinux—iio: imu: adis16550: fix stack leak in trigger handler
CVE-2026-63982await10.6LinuxLinux—net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop
CVE-2026-63983await10.6LinuxLinux—net/sched: fix packet loop on netem when duplicate is on
CVE-2026-63986await10.6LinuxLinux—ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure
CVE-2026-63988await10.6LinuxLinux—bridge: Fix sleep in atomic context in sysfs path
CVE-2026-63989await10.6LinuxLinux—bridge: Fix sleep in atomic context in netlink path
CVE-2026-63998await10.6LinuxLinux—ethtool: module: call ethnl_ops_complete() on module flash errors
CVE-2026-63999await10.6LinuxLinux—ethtool: rss: fix indir_table and hkey leak on get_rxfh failure
CVE-2026-64021await10.6LinuxLinux—drm/xe/oa: Fix exec_queue leak on width check in stream open
CVE-2026-64022await10.6LinuxLinux—gpio: aggregator: remove the software node when deactivating the aggregator
CVE-2026-64038await10.6LinuxLinux—hwmon: (lm90) Stop work before releasing hwmon device
CVE-2026-64043await10.6LinuxLinux—ovpn: fix race between deleting interface and adding new peer
CVE-2026-64049await10.6LinuxLinux—drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx
CVE-2026-64054await10.6LinuxLinux—net: shaper: reject duplicate leaves in GROUP request
CVE-2026-64060await10.6LinuxLinux—netfs: Fix leak of request in netfs_write_begin() error handling
CVE-2026-64071await10.6LinuxLinux—nvme-pci: fix use-after-free in nvme_free_host_mem()
CVE-2026-64072await10.6LinuxLinux—nvme: fix bio leak on mapping failure
CVE-2026-64075await10.6LinuxLinux—fprobe: Fix unregister_fprobe() to wait for RCU grace period
CVE-2026-640349.310.4LinuxLinux—net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer
CVE-2026-640097.89.9LinuxLinux—xfrm: Check for underflow in xfrm_state_mtu
CVE-2026-640809.39.6LinuxLinux—firmware: arm_ffa: Snapshot notifier callbacks under lock
CVE-2026-63820await9.5LinuxLinux—f2fs: fix missing read bio submission on large folio error
CVE-2026-63839await9.5LinuxLinux—platform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int()
CVE-2026-63907await9.5LinuxLinux—uio: uio_pci_generic_sva: fix double free of devm_kzalloc() memory
CVE-2026-63935await9.5LinuxLinux—iio: adc: nxp-sar-adc: fix division by zero in write_raw
CVE-2026-63953await9.5LinuxLinux—mm/migrate_device: fix pgtable leak in migrate_vma_insert_huge_pmd_page
CVE-2026-64013await9.5LinuxLinux—ACPI: button: Fix ACPI GPE handler leak during removal
CVE-2026-64019await9.5LinuxLinux—nvme-pci: fix dma mapping leak on data setup error
CVE-2026-64040await9.5LinuxLinux—cachefiles: Fix error return when vfs_mkdir() fails
CVE-2026-64070await9.5LinuxLinux—powerpc/hv-gpci: fix preempt count leak in sysfs show paths
CVE-2026-64079await9.5LinuxLinux—netfilter: x_tables: allocate hook ops while under mutex
CVE-2026-639389.39.3LinuxLinux—KVM: SEV: Check PSC request indices against the actual size of the buffer
CVE-2026-639409.39.3LinuxLinux—KVM: SEV: Ignore Port I/O requests of length '0'
CVE-2026-640189.39.3LinuxLinux—net: mana: validate rx_req_idx to prevent out-of-bounds array access
CVE-2026-638608.49.3LinuxLinux—RDMA/core: Prefer NLA_NUL_STRING
CVE-2026-639268.49.3LinuxLinux—bpf: sockmap: fix tail fragment offset in bpf_msg_push_data
CVE-2026-641188.49.3LinuxLinuxCWE-415qed: fix double free in qed_cxt_tables_alloc()
CVE-2026-641727.19.2LinuxLinux—KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235)
CVE-2026-640458.49.0LinuxLinux—ovpn: tcp - use cached peer pointer in ovpn_tcp_close()
CVE-2026-640818.49.0LinuxLinux—firmware: arm_ffa: Validate framework notification message layout
CVE-2026-639068.48.7LinuxLinux—usb: musb: omap2430: Fix use-after-free in omap2430_probe()
CVE-2026-638817.88.6LinuxLinux—drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger
CVE-2026-640417.88.3LinuxLinux—ASoC: codecs: fs210x: fix possible buffer overflow
CVE-2026-641147.88.0LinuxLinuxCWE-125ipv4: raw: reject IP_HDRINCL packets with ihl < 5
CVE-2026-640447.88.0LinuxLinux—ovpn: respect peer refcount in CMD_NEW_PEER error path
CVE-2026-63810await7.9LinuxLinux—block: Avoid mounting the bdev pseudo-filesystem in userspace
CVE-2026-638648.47.5LinuxLinux—bpf: Propagate error from visit_tailcall_insn
CVE-2026-640737.87.6LinuxLinux—irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT
CVE-2026-640397.77.6LinuxLinux—drm/msm/snapshot: fix dumping of the unaligned regions
CVE-2026-534017.87.2LinuxLinuxCWE-416fbdev: omap2: fix use-after-free in omapfb_mmap
CVE-2026-639517.87.2LinuxLinux—zram: fix use-after-free in zram_writeback_endio
CVE-2026-638658.87.1LinuxLinux—bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks
CVE-2026-639218.87.1LinuxLinux—ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().
CVE-2026-641538.87.1LinuxLinux—drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN
CVE-2026-638707.87.1LinuxLinux—ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit()
CVE-2026-638757.87.1LinuxLinux—arm64: tlb: Flush walk cache when unsharing PMD tables
CVE-2026-638847.87.1LinuxLinux—drm/i915: Fix potential UAF in TTM object purge
CVE-2026-639427.87.1LinuxLinux—parport: Fix race between port and client registration
CVE-2026-639547.87.1LinuxLinux—hpfs: fix a crash if hpfs_map_dnode_bitmap fails
CVE-2026-639857.87.1LinuxLinux—ethtool: eeprom: add more safeties to EEPROM Netlink fallback
CVE-2026-640027.87.1LinuxLinux—ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_…
CVE-2026-640047.87.1LinuxLinux—net/iucv: fix locking in .getsockopt
CVE-2026-640057.87.1LinuxLinux—net/smc: Do not re-initialize smc hashtables
CVE-2026-640157.87.1LinuxLinux—security/keys: fix missed RCU read section on lookup
CVE-2026-640847.87.1LinuxLinux—hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR
CVE-2026-640867.87.1LinuxLinux—hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer
CVE-2026-640977.87.1LinuxLinuxCWE-787drm/amd/display: Validate GPIO pin LUT table size before iterating
CVE-2026-641087.87.1LinuxLinux—cifs: Fix busy dentry used after unmounting
CVE-2026-641337.87.1LinuxLinuxCWE-125ALSA: asihpi: Fix potential OOB array access at reading cache
CVE-2026-641377.87.1LinuxLinux—smb: client: require net admin for CIFS SWN netlink
CVE-2026-639378.87.0LinuxLinux—KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer
CVE-2026-641098.87.0LinuxLinuxCWE-416af_unix: Fix UAF read of tail->len in unix_stream_data_wait()
CVE-2026-533867.87.0LinuxLinuxCWE-129iio: adc: ti-ads1298: add bounds check to pga_settings index
CVE-2026-638127.87.0LinuxLinux—f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()
CVE-2026-638427.87.0LinuxLinux—drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring
CVE-2026-638437.87.0LinuxLinux—drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring
CVE-2026-638447.87.0LinuxLinux—drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring
CVE-2026-638457.87.0LinuxLinux—drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring
CVE-2026-638467.87.0LinuxLinux—drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring
CVE-2026-638477.87.0LinuxLinux—drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring
CVE-2026-638487.87.0LinuxLinux—drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring
CVE-2026-638507.87.0LinuxLinux—drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring
CVE-2026-638517.87.0LinuxLinux—drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring
CVE-2026-638527.87.0LinuxLinux—drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring
CVE-2026-638547.87.0LinuxLinux—drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings
CVE-2026-638557.87.0LinuxLinux—drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings
CVE-2026-638567.87.0LinuxLinux—drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings
CVE-2026-639707.87.0LinuxLinux—vsock/virtio: bind uarg before filling zerocopy skb
CVE-2026-639877.87.0LinuxLinux—ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES
CVE-2026-639957.87.0LinuxLinux—ethtool: cmis: validate start_cmd_payload_size from module
CVE-2026-639967.87.0LinuxLinux—ethtool: cmis: require exact CDB reply length
CVE-2026-640267.87.0LinuxLinux—rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg
CVE-2026-640517.87.0LinuxLinux—accel/qaic: Add overflow check to remap_pfn_range during mmap
CVE-2026-640537.87.0LinuxLinux—block: don't overwrite bip_vcnt in bio_integrity_copy_user()
CVE-2026-641347.87.0LinuxLinuxCWE-476ALSA: pcm: Don't setup bogus iov_iter for silencing
CVE-2026-63822await6.8LinuxLinux—wifi: ath11k: fix warning when unbinding
CVE-2026-63834await6.9LinuxLinux—batman-adv: tp_meter: restrict number of unacked list entries
CVE-2026-63835await6.9LinuxLinux—batman-adv: v: prevent OGM aggregation on disabled hardif
CVE-2026-63836await6.9LinuxLinux—batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd
CVE-2026-638858.86.8LinuxLinux—drm/gem: fix race between change_handle and handle_delete
CVE-2026-639238.86.8LinuxLinux—octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify
CVE-2026-641248.86.8LinuxLinux—net: devmem: reject dma-buf bind with non-page-aligned size or SG length
CVE-2026-638057.86.8LinuxLinux—crypto: nx - fix nx_crypto_ctx_exit argument
CVE-2026-638137.86.8LinuxLinux—Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block"
CVE-2026-638197.86.8LinuxLinux—f2fs: fix to do sanity check on f2fs_get_node_folio_ra()
CVE-2026-638417.86.8LinuxLinux—drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.1 ring
CVE-2026-638497.86.8LinuxLinux—drm/amdgpu/vcn: set no_user_fence for VCN v5.0.1 enc ring
CVE-2026-638537.86.8LinuxLinux—drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring
CVE-2026-638747.86.8LinuxLinux—net: mctp: usb: fix race between urb completion and rx_retry cancellation
CVE-2026-639507.86.8LinuxLinux—mm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_one
CVE-2026-640087.86.8LinuxLinux—accel/rocket: fix UAF via dangling GEM handle in create_bo
CVE-2026-640277.86.8LinuxLinux—net: shaper: rework the VALID marking (again)
CVE-2026-640317.86.8LinuxLinux—erofs: fix managed cache race for unaligned extents
CVE-2026-640367.86.8LinuxLinux—cgroup/rstat: validate cpu before css_rstat_cpu() access
CVE-2026-640587.86.8LinuxLinux—netfs: Fix netfs_read_folio() to wait on writeback
CVE-2026-640747.86.8LinuxLinux—fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap
CVE-2026-640767.86.8LinuxLinux—netfilter: bridge: eb_tables: close module init race
CVE-2026-640777.86.8LinuxLinux—netfilter: ebtables: move to two-stage removal scheme
CVE-2026-640787.86.8LinuxLinux—netfilter: x_tables: add and use xtables_unregister_table_exit
CVE-2026-641817.86.8LinuxLinux—mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_sp…
CVE-2026-638797.86.7LinuxLinux—drm/amdgpu: fix amdgpu_hmm_range_get_pages
CVE-2026-63821await6.7LinuxLinux—wifi: rtw88: usb: fix memory leaks on USB write failures
CVE-2026-641158.86.5LinuxLinuxCWE-416vsock/vmci: fix UAF when peer resets connection during handshake
CVE-2026-639307.86.5LinuxLinux—iio: buffer: hw-consumer: fix use-after-free in error path
CVE-2026-639457.86.5LinuxLinux—Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock
CVE-2026-640117.86.5LinuxLinux—nfc: llcp: Fix use-after-free in llcp_sock_release()
CVE-2026-640327.86.5LinuxLinux—bridge: mcast: Fix a possible use-after-free when removing a bridge port
CVE-2026-641237.86.5LinuxLinuxCWE-416net: hsr: defer node table free until after RCU readers
CVE-2026-638837.36.5LinuxLinux—serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ
CVE-2026-641267.36.6LinuxLinuxCWE-125Bluetooth: MGMT: validate Add Extended Advertising Data length
CVE-2026-641117.16.6LinuxLinux—lsm: hold cred_guard_mutex for lsm_set_self_attr()
CVE-2026-533897.86.5LinuxLinuxCWE-416net/tcp-ao: fix use-after-free of key in del_async path
CVE-2026-638947.86.5LinuxLinux—usb: gadget: f_fs: serialize DMABUF cancel against request completion
CVE-2026-639187.86.5LinuxLinux—l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname
CVE-2026-640297.86.5LinuxLinux—ALSA: seq: Serialize UMP output teardown with event_input
CVE-2026-640997.86.5LinuxLinuxCWE-416drm/v3d: Fix use-after-free of CPU job query arrays on error path
CVE-2026-639178.86.3LinuxLinux—ip6: vti: Use ip6_tnl.net in vti6_changelink().
CVE-2026-641048.76.3LinuxLinuxCWE-401virt: sev-guest: Explicitly leak pages in unknown state
CVE-2026-639717.86.3LinuxLinux—sctp: fix race between sctp_wait_for_connect and peeloff
CVE-2026-533687.16.3LinuxLinux—f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage
CVE-2026-639117.86.3LinuxLinux—xfrm: iptfs: reset runtime state when cloning SAs
CVE-2026-640237.86.3LinuxLinux—gpio: aggregator: fix a potential use-after-free
CVE-2026-640507.86.3LinuxLinux—drm/msm/dpu: don't mix devm and drmm functions
CVE-2026-639207.16.1LinuxLinux—ipv6: validate extension header length before copying to cmsg
CVE-2026-533877.16.0LinuxLinuxCWE-129iio: light: veml6075: add bounds check to veml6075_it_ms index
CVE-2026-63826await6.0LinuxLinux—fbdev: fix use-after-free in store_modes()
CVE-2026-638638.85.9LinuxLinux—drm/gpusvm: Fix unbalanced unlock in drm_gpusvm_scan_mm()
CVE-2026-639418.85.9LinuxLinux—KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor
CVE-2026-640428.85.9LinuxLinux—vfio/pci: Check BAR resources before exporting a DMABUF
CVE-2026-533737.85.9LinuxLinux—mm/vma: do not try to unmap a VMA if mmap_prepare() invoked from mmap()
CVE-2026-533807.85.9LinuxLinuxCWE-787media: rzv2h-ivc: Fix concurrent buffer list access
CVE-2026-637937.85.9LinuxLinuxCWE-416ntfs: serialize volume label accesses
CVE-2026-637997.85.9LinuxLinuxCWE-125sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path
CVE-2026-638407.85.9LinuxLinux—drm/amdgpu/jpeg: set no_user_fence for JPEG v5.3.0 ring
CVE-2026-638587.85.9LinuxLinux—netfilter: nf_tables: add hook transactions for device deletions
CVE-2026-639107.85.9LinuxLinux—dma-buf: fix UAF in dma_buf_fd() tracepoint
CVE-2026-639777.85.9LinuxLinux—dpll: zl3073x: use __dpll_device_change_ntf() and remove change_work
CVE-2026-640577.85.9LinuxLinux—afs: Fix the locking used by afs_get_link()
CVE-2026-640827.85.9LinuxLinux—riscv: Fix register corruption from uninitialized cregs on error
CVE-2026-639528.45.8LinuxLinux—memfd: deny writeable mappings when implying SEAL_WRITE
CVE-2026-639277.85.8LinuxLinux—usb: dwc2: Fix use after free in debug code
CVE-2026-641518.45.7LinuxLinux—iommupt: Check for missing PAGE_SIZE in the pgsize_bitmap
CVE-2026-639147.35.6LinuxLinux—xfrm: route MIGRATE notifications to caller's netns
CVE-2026-641055.55.5LinuxLinux—KVM: arm64: vgic: Free private_irqs when init fails after allocation
CVE-2026-641275.55.5LinuxLinux—Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer
CVE-2026-641285.55.6LinuxLinuxCWE-476Bluetooth: ISO: drop ISO_END frames received without prior ISO_START
CVE-2026-641445.55.6LinuxLinuxCWE-401Bluetooth: btmtk: fix urb->setup_packet leak in error paths
CVE-2026-641575.55.5LinuxLinux—netfs: Fix partial invalidation of streaming-write folio
CVE-2026-641635.55.6LinuxLinux—test_kprobes: clear kprobes between test runs
CVE-2026-641705.55.6LinuxLinuxCWE-476spi: qup: fix error pointer deref after DMA setup failure
CVE-2026-641775.55.6LinuxLinux—phonet/pep: disable BH around forwarded sk_receive_skb()
CVE-2026-641795.55.6LinuxLinuxCWE-401net: wwan: iosm: fix potential memory leaks in ipc_imem_init()
CVE-2026-641805.55.6LinuxLinux—mm/memory_hotplug: fix memory block reference leak on remove
CVE-2026-641825.55.5LinuxLinux—drivers/base/memory: fix memory block reference leak in poison accounting
CVE-2026-641835.55.6LinuxLinuxCWE-476efi: Allocate runtime workqueue before ACPI init
CVE-2026-641845.55.6LinuxLinux—mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()
CVE-2026-533675.55.4LinuxLinux—selinux: fix avdcache auditing
CVE-2026-533715.55.4LinuxLinux—RDMA/ionic: bound node_desc sysfs read with %.64s
CVE-2026-533725.55.4LinuxLinux—iommu/vt-d: Block PASID attachment to nested domain with dirty tracking
CVE-2026-641105.55.4LinuxLinuxCWE-401igc: fix potential skb leak in igc_fpe_xmit_smd_frame()
CVE-2026-641205.55.4LinuxLinuxCWE-476net: ethtool: fix NULL pointer dereference in phy_reply_size
CVE-2026-641305.55.4LinuxLinuxCWE-908mm/page_alloc: fix initialization of tags of the huge zero folio with init_on…
CVE-2026-641495.55.4LinuxLinux—dma-mapping: move dma_map_resource() sanity check into debug code
CVE-2026-641565.55.4LinuxLinux—netfs, afs: Fix write skipping in dir/link writepages
CVE-2026-638067.14.9LinuxLinuxCWE-617KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unali…
CVE-2026-640945.54.9LinuxLinuxCWE-476batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface
CVE-2026-638097.84.8LinuxLinux—bpf: use kvfree() for replaced sysctl write buffer
CVE-2026-640987.84.7LinuxLinuxCWE-667drm/virtio: use uninterruptible resv lock for plane updates
CVE-2026-641069.04.2LinuxLinux—KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits
CVE-2026-533698.44.2LinuxLinux—udf: reject descriptors with oversized CRC length
CVE-2026-637978.44.1LinuxLinuxCWE-416rpmsg: char: Fix use-after-free on probe error path
CVE-2026-533785.53.8LinuxLinuxCWE-401drm/colorop: Fix blob property reference tracking in state lifecycle
CVE-2026-641075.53.8LinuxLinuxCWE-476ASoC: codecs: pcm512x: fix null-ptr dereference in pcm512x_overclock_xxx_put()
CVE-2026-641465.53.8LinuxLinuxCWE-401erofs: fix metabuf leak in inode xattr initialization
CVE-2026-641595.53.8LinuxLinux—netfs: Fix zeropoint update where i_size > remote_i_size

Results continue: ranks 401–464.

Methodology

Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.

Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.

Day boundary. A day is a UTC calendar day. This page covers 2026-07-19 00:00:00–23:59:59 UTC. All times shown are UTC.

Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.

Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.

Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.