AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H N 10.0 .0180 76.8 —
AFFECTED Product Versions Fixed firmware < 2.7.21.1370b23 – —
TIMELINE May 5 Reserved by CNA Jul 19 Published (CNA: GitHub_M)
A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?
464 CVEs published, led by Linux (429).
464 CVEs published July 19, 2026: 58 critical, 211 high, 72 medium, 18 low; 0 in the KEV catalog at press time; 0 with a public exploit reference; 105 awaiting enrichment. Elevated volume. 25 rendered as box scores below; 375 more in the results table on this page; the remaining 64 on continuation pages.
| MTD | YTD | 2025 same span | 2025 full | |
|---|---|---|---|---|
| CVEs published | 5151 | 17554 | — | — |
| KEV catalog size | 1675 | |||
Publication counts reflect the record since May 20, 2026 (archive start); KEV figures are catalog-wide.
Prior-year comparisons begin when the archive covers a full year; archive begins May 20, 2026.
763 disclosures carry no usable vendor attribution (upstream records marked n/a or unknown) and are excluded from the vendor tables. C/H/M/L = YTD disclosures by severity band. KEV = catalog entries all-time / YTD. KEV/100 = KEV additions YTD ÷ CVEs YTD × 100. Med CVSS / Med EPSS = medians over the vendor's YTD disclosures. Δ = this month-to-date minus the same day-span of last month.
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| linux | 470 | 1950 | 178 | 1075 | 591 | 1 | 11 | 2 | 0.1 | 7.8 | .0016 | +371 ▲ |
| microsoft | 646 | 1403 | 96 | 975 | 318 | 14 | 286 | 23 | 1.6 | 7.8 | .0047 | +426 ▲ |
| 94 | 1359 | 150 | 616 | 555 | 38 | 77 | 6 | 0.4 | 7.8 | .0024 | -590 ▼ | |
| red hat | 65 | 287 | 14 | 115 | 140 | 18 | 2 | 0 | 0.0 | 6.5 | .0032 | -10 ▼ |
| apple | 0 | 104 | 2 | 28 | 72 | 2 | 88 | 7 | 6.7 | 6.5 | .0032 | -14 ▼ |
| canonical | 4 | 24 | 3 | 6 | 10 | 5 | 0 | 0 | 0.0 | 5.5 | .0013 | +3 ▲ |
| suse | 8 | 21 | 4 | 12 | 4 | 1 | 0 | 0 | 0.0 | 8.5 | .0039 | +4 ▲ |
| freebsd | 0 | 16 | 0 | 12 | 4 | 0 | 0 | 0 | 0.0 | 7.8 | .0016 | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| cisco | 15 | 37 | 8 | 18 | 11 | 0 | 56 | 11 | 29.7 | 7.5 | .0057 | +6 ▲ |
| ubiquiti | 25 | 36 | 14 | 21 | 1 | 0 | 3 | 3 | 8.3 | 8.8 | .0049 | +20 ▲ |
| palo alto networks | 14 | 25 | 1 | 3 | 14 | 7 | 13 | 2 | 8.0 | 4.7 | .0028 | +5 ▲ |
| netgear | 6 | 23 | 0 | 0 | 22 | 1 | 0 | 0 | 0.0 | 4.6 | .0024 | -11 ▼ |
| fortinet | 13 | 22 | 6 | 6 | 10 | 0 | 28 | 5 | 22.7 | 7.3 | .0039 | +11 ▲ |
| f5 | 8 | 16 | 5 | 8 | 3 | 0 | 4 | 1 | 6.3 | 8.6 | .0057 | +2 ▲ |
| vmware | 8 | 12 | 1 | 8 | 2 | 1 | 7 | 1 | 8.3 | 8.2 | .0039 | +5 ▲ |
| ivanti | 2 | 11 | 4 | 5 | 2 | 0 | 25 | 5 | 45.5 | 8.8 | .3445 | -2 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| apache | 78 | 233 | 47 | 90 | 84 | 11 | 33 | 1 | 0.4 | 7.5 | .0058 | -8 ▼ |
| mozilla | 6 | 62 | 12 | 18 | 32 | 0 | 9 | 0 | 0.0 | 6.5 | .0026 | -43 ▼ |
| drupal | 46 | 51 | 6 | 5 | 35 | 5 | 4 | 1 | 2.0 | 5.9 | .0026 | +46 ▲ |
| gitlab | 7 | 38 | 0 | 5 | 27 | 6 | 4 | 2 | 5.3 | 4.7 | .0032 | -4 ▼ |
| github | 5 | 11 | 1 | 2 | 8 | 0 | 0 | 0 | 0.0 | 6.0 | .0042 | +5 ▲ |
| docker | 0 | 7 | 0 | 5 | 2 | 0 | 0 | 0 | 0.0 | 8.2 | .0016 | -4 ▼ |
| wordpress | 0 | 0 | 0 | 0 | 0 | 0 | 2 | 0 | — | — | — | 0 |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| oracle | 1 | 271 | 133 | 116 | 18 | 4 | 27 | 3 | 1.1 | 8.8 | .0040 | -241 ▼ |
| adobe | 94 | 238 | 26 | 103 | 105 | 4 | 19 | 3 | 1.3 | 7.6 | .0026 | -35 ▼ |
| ibm | 36 | 160 | 52 | 54 | 54 | 0 | 6 | 0 | 0.0 | 7.5 | .0036 | +25 ▲ |
| progress | 10 | 19 | 3 | 14 | 2 | 0 | 6 | 0 | 0.0 | 7.5 | .0037 | +5 ▲ |
| solarwinds | 0 | 7 | 2 | 3 | 2 | 0 | 10 | 4 | 57.1 | 7.5 | .4001 | -3 ▼ |
| veeam | 0 | 4 | 2 | 2 | 0 | 0 | 1 | 0 | 0.0 | 9.0 | .0052 | -1 ▼ |
| zohocorp | 0 | 3 | 1 | 1 | 1 | 0 | 0 | 0 | 0.0 | 8.4 | .0170 | 0 |
| servicenow | 1 | 1 | 1 | 0 | 0 | 0 | 2 | 0 | 0.0 | 9.5 | .7758 | +1 ▲ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| rockwell automation | 17 | 24 | 4 | 18 | 2 | 0 | 0 | 0 | 0.0 | 8.7 | .0029 | +10 ▲ |
| synology | 0 | 23 | 2 | 5 | 13 | 3 | 0 | 0 | 0.0 | 5.6 | .0025 | -5 ▼ |
| siemens | 7 | 16 | 1 | 8 | 7 | 0 | 0 | 0 | 0.0 | 7.6 | .0024 | 0 |
| d-link | 1 | 13 | 0 | 5 | 3 | 5 | 3 | 0 | 0.0 | 6.0 | .0059 | -8 ▼ |
| abb | 1 | 7 | 0 | 4 | 3 | 0 | 0 | 0 | 0.0 | 7.2 | .0018 | -4 ▼ |
| schneider electric | 0 | 6 | 0 | 4 | 2 | 0 | 0 | 0 | 0.0 | 7.8 | .0042 | -1 ▼ |
| moxa | 0 | 5 | 0 | 3 | 2 | 0 | 0 | 0 | 0.0 | 7.0 | .0029 | -5 ▼ |
| dahua | 0 | 3 | 0 | 1 | 1 | 1 | 0 | 0 | 0.0 | 6.9 | .0036 | -3 ▼ |
| Vendor | MTD | YTD | C | H | M | L | KEV | KEV YTD | KEV/100 | Med CVSS | Med EPSS | Δ |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| sourcecodester | 46 | 117 | 0 | 0 | 61 | 56 | 0 | 0 | 0.0 | 5.5 | .0033 | +9 ▲ |
| openclaw | 44 | 111 | 0 | 58 | 39 | 14 | 0 | 0 | 0.0 | 7.0 | .0026 | -17 ▼ |
| dell | 37 | 93 | 5 | 42 | 43 | 3 | 2 | 1 | 1.1 | 7.0 | .0021 | +10 ▲ |
| capgo | 22 | 83 | 2 | 42 | 38 | 1 | 0 | 0 | 0.0 | 7.1 | .0037 | +19 ▲ |
| nvidia | 40 | 79 | 12 | 52 | 15 | 0 | 0 | 0 | 0.0 | 7.8 | .0037 | +34 ▲ |
| imagemagick | 32 | 73 | 1 | 5 | 55 | 12 | 0 | 0 | 0.0 | 5.3 | .0019 | +4 ▲ |
| spring | 0 | 73 | 2 | 31 | 39 | 1 | 0 | 0 | 0.0 | 6.5 | .0024 | -71 ▼ |
| itsourcecode | 15 | 68 | 0 | 0 | 19 | 49 | 0 | 0 | 0.0 | 2.1 | .0033 | -7 ▼ |
| CVE | EPSS | %ile | CVSS |
|---|---|---|---|
| CVE-2026-20230 | .8820 | 99.8 | 8.6 |
| CVE-2026-34910 | .8747 | 99.7 | 10.0 |
| CVE-2026-34908 | .8519 | 99.7 | 10.0 |
| CVE-2026-50522 | .8461 | 99.7 | 9.8 |
| CVE-2026-15409 | .8366 | 99.7 | 10.0 |
| CVE-2026-6875 | .7758 | 99.5 | 9.5 |
| CVE-2026-25089 | .7611 | 99.5 | 9.8 |
| CVE-2026-45659 | .7608 | 99.5 | 8.8 |
| CVE-2026-34909 | .6390 | 99.2 | 10.0 |
| CVE-2026-48282 | .4239 | 98.6 | 10.0 |
| CVE | CVSS | EPSS | Note |
|---|---|---|---|
| CVE-2026-34910 | 10.0 | .8747 | KEV |
| CVE-2026-34908 | 10.0 | .8519 | KEV |
| CVE-2026-15409 | 10.0 | .8366 | KEV |
| CVE-2026-34909 | 10.0 | .6390 | KEV |
| CVE-2026-48282 | 10.0 | .4239 | KEV |
| CVE-2026-56290 | 10.0 | .3038 | KEV |
| CVE-2026-48939 | 10.0 | .1973 | KEV |
| CVE-2026-48908 | 10.0 | .1482 | KEV |
| CVE-2026-56291 | 10.0 | .1459 | KEV |
| CVE-2026-59726 | 10.0 | .0688 |
| Vendor | CVEs |
|---|---|
| linux | 884 |
| microsoft | 647 |
| 500 | |
| red hat | 118 |
| apache | 113 |
| adobe | 107 |
| ibm | 100 |
| capgo | 80 |
| sourcecodester | 58 |
| dell | 48 |
| Vendor | KEV |
|---|---|
| microsoft | 23 |
| cisco | 11 |
| apple | 7 |
| 6 | |
| fortinet | 5 |
| ivanti | 5 |
| solarwinds | 4 |
| adobe | 3 |
| berriai | 3 |
| oracle | 3 |
| Ecosystem | Advisories |
|---|---|
| Maven | 56 |
| PyPI | 5 |
| npm | 5 |
| NuGet | 3 |
| Packagist | 1 |
| CVE | Vendor | Days |
|---|---|---|
| CVE-2026-12569 | PTC | 0 |
| CVE-2026-15409 | SonicWall | 0 |
| CVE-2026-15410 | SonicWall | 0 |
| CVE-2026-20230 | Cisco | 0 |
| CVE-2026-25089 | Fortinet | 0 |
| CVE-2026-34908 | Ubiquiti Inc | 0 |
| CVE-2026-34909 | Ubiquiti Inc | 0 |
| CVE-2026-34910 | Ubiquiti Inc | 0 |
| CVE-2026-45659 | Microsoft | 0 |
| CVE-2026-46817 | Oracle Corporation | 0 |
| CVE | Vendor | Due | Days over |
|---|---|---|---|
| CVE-2021-27104 | n/a | 2021-11-17 | 1705 |
| CVE-2021-27102 | n/a | 2021-11-17 | 1705 |
| CVE-2021-27101 | n/a | 2021-11-17 | 1705 |
| CVE-2021-27103 | n/a | 2021-11-17 | 1705 |
| CVE-2021-21017 | Adobe | 2021-11-17 | 1705 |
| CVE-2021-28550 | Adobe | 2021-11-17 | 1705 |
| CVE-2021-42013 | Apache Software Foundation | 2021-11-17 | 1705 |
| CVE-2021-41773 | Apache Software Foundation | 2021-11-17 | 1705 |
| CVE-2021-30858 | Apple | 2021-11-17 | 1705 |
| CVE-2021-30860 | Apple | 2021-11-17 | 1705 |
EXPLOIT PUBLISHED — SourceCodester Class and Exam Timetabling System: 4 CVEs (CVE-2026-16202, CVE-2026-16203, CVE-2026-16227, CVE-2026-16228). Public exploit references added.
EXPLOIT PUBLISHED — geex-arts django-jet: 3 CVEs (CVE-2026-16214, CVE-2026-16215, CVE-2026-16216). Public exploit references added.
EXPLOIT PUBLISHED — zevorn rt-claw: 3 CVEs (CVE-2026-16200, CVE-2026-16201, CVE-2026-16204). Public exploit references added.
EXPLOIT PUBLISHED — CVE-2026-16199 (nextlevelbuilder GoClaw). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16205 (Pluck CMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16209 (Gerapy). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16210 (newpanjing simpleui). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16211 (allegro). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16212 (awesto django-shop). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16217 (guohongze adminset). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16219 (Croogo CMS). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16220 (code-projects Online Examination System). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16222 (1Panel-dev CordysCRM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16223 (1Panel-dev CordysCRM). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16225 (davenardella snap7). Public exploit reference added.
EXPLOIT PUBLISHED — CVE-2026-16229 (itsourcecode Courier Management System). Public exploit reference added.
DUE DATE PASSED — CVE-2026-46817 (Oracle Corporation Oracle Payments). CISA remediation deadline was July 18, 2026; still in catalog.
How to read these box scores · glossary
464 CVEs published. 25 box scores and 375 table rows below; the remaining 64 continue on page 2 — every CVE is listed, nothing truncated.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N C H H N 10.0 .0180 76.8 —
AFFECTED Product Versions Fixed firmware < 2.7.21.1370b23 – —
TIMELINE May 5 Reserved by CNA Jul 19 Published (CNA: GitHub_M)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N L H 8.2 .0097 59.3 —
AFFECTED Product Versions Fixed Linux 9fb9cbb1082d6b31fb45aa1a14432449a0df6cf1 – — Linux 2.6.15 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0078 53.1 —
AFFECTED Product Versions Fixed Linux e48354ce078c079996f89d715dfa44814b4eba01 – — Linux 3.1 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0078 53.1 —
AFFECTED Product Versions Fixed Linux e48354ce078c079996f89d715dfa44814b4eba01 – — Linux 3.1 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0077 53.0 —
AFFECTED Product Versions Fixed Linux 2521f2c228ad750701ba4702484e31d876dbc386 – — Linux 2.6.31 – 6.18.38
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0076 52.3 —
AFFECTED Product Versions Fixed Linux 4cb47a8644cc9eb8ec81190a50e79e6530d0297f – — Linux 5.9 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0076 52.3 —
AFFECTED Product Versions Fixed Linux 9aaaa56845a06aeabdd597cbe19492dc01f281ec – — Linux 5.5 – 5.10.258
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0076 52.3 —
AFFECTED Product Versions Fixed Linux 9aaaa56845a06aeabdd597cbe19492dc01f281ec – — Linux 5.5 – 5.10.258
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0076 52.3 —
AFFECTED Product Versions Fixed Linux 4d5ae32f5e1e13f7f36d6439ec3257993b9f5b88 – — Linux 4.16 – 5.10.258
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H N H 9.1 .0073 51.7 —
AFFECTED Product Versions Fixed Linux 4cb47a8644cc9eb8ec81190a50e79e6530d0297f – — Linux 5.9 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0073 51.6 —
AFFECTED Product Versions Fixed Linux 8b6a361b8c482f22ac99c3273285ff16b23fba91 – — Linux 5.3 – 5.10.258
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0073 51.6 —
AFFECTED Product Versions Fixed Linux bad17234ba702a50aeec50ab04724ee58af89607 – — Linux 3.19 – 5.10.258
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0072 51.2 —
AFFECTED Product Versions Fixed Linux eafaa88b3eb7f28aecb222281655473431d3ef2e – — Linux 5.16 – 6.1.176
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0072 51.0 —
AFFECTED Product Versions Fixed Linux bab17b761c8974a869b04462be5d4dd9aad366b4 – — Linux 5.17 – 5.15.209
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0071 50.9 —
AFFECTED Product Versions Fixed Linux c075c3ea031757f8ea2d34567565b61a868c08d5 – — Linux 5.18 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0071 50.9 —
AFFECTED Product Versions Fixed Linux a831f5bbc89a9978795504be9e1ff412043f8f77 – — Linux 2.6.19 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0071 50.9 —
AFFECTED Product Versions Fixed Linux 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 – — Linux 2.6.12 – 5.10.259
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0071 50.8 —
AFFECTED Product Versions Fixed Linux 1e5733883421495908f3b90d9d807663038b4136 – — Linux 6.0 – 6.1.176
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0071 50.7 —
AFFECTED Product Versions Fixed Gerapy 0.9.0 – —
TIMELINE Jul 18 Reserved by CNA Jul 19 Public exploit reference published Jul 19 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0070 50.6 —
AFFECTED Product Versions Fixed Linux 7f0cb478703cbeaddfe5c9101c5c73cd975d1073 – — Linux 6.11 – 6.12.92
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0070 50.4 —
AFFECTED Product Versions Fixed Linux 9ee11f0fff205b4b3df9750bff5e94f97c71b6a0 – — Linux 5.15 – 5.15.210
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV N L N N N L L L 5.5 .0069 49.9 —
AFFECTED Product Versions Fixed simpleui 2026.01.13 – —
TIMELINE Jul 18 Reserved by CNA Jul 19 Public exploit reference published Jul 19 Published (CNA: VulDB)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0067 49.3 —
AFFECTED Product Versions Fixed Linux f655c78d6225f585ef60a9d93ffb79d507ff3ad3 – — Linux 6.9 – 6.12.92
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .0067 49.3 —
AFFECTED Product Versions Fixed Linux 953953abb66e52c224057ab91e404284fefeab62 – — Linux 7.0 – 6.6.142
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U N N H 7.5 .0067 49.2 —
AFFECTED Product Versions Fixed Linux 45d76f492938cdc27ddadc16e1e75103f4cfbf56 – — Linux 6.4 – 6.6.142
TIMELINE Jul 19 Reserved by CNA Jul 19 Published (CNA: Linux)
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-63968 | 7.5 | 49.0 | Linux | Linux | — | ipv6: fix possible infinite loop in fib6_select_path() |
| CVE-2026-53383 | 7.5 | 49.0 | Linux | Linux | CWE-476 | ksmbd: reject non-VALID session in compound request branch |
| CVE-2026-64025 | 9.8 | 48.5 | Linux | Linux | — | bpf, skmsg: fix verdict sk_data_ready racing with ktls rx |
| CVE-2026-64061 | 9.8 | 48.5 | Linux | Linux | — | netfs: Fix early put of sink folio in netfs_read_gaps() |
| CVE-2026-63919 | 8.8 | 48.4 | Linux | Linux | — | xfrm: input: hold netns during deferred transport reinjection |
| CVE-2026-63857 | 9.8 | 48.4 | Linux | Linux | — | net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit() |
| CVE-2026-63979 | 9.8 | 48.4 | Linux | Linux | — | net/handshake: hand off the pinned file reference to accept_doit |
| CVE-2026-64016 | 9.8 | 48.4 | Linux | Linux | — | ksmbd: fix durable reconnect error path file lifetime |
| CVE-2026-64035 | 9.8 | 48.4 | Linux | Linux | — | igc: set tx buffer type for SMD frames |
| CVE-2026-64066 | 9.8 | 48.4 | Linux | Linux | — | netfs: Fix netfs_read_to_pagecache() to pause on subreq failure |
| CVE-2026-64069 | 9.8 | 48.4 | Linux | Linux | — | netfs: Fix cancellation of a DIO and single read subrequests |
| CVE-2026-64150 | 9.8 | 48.4 | Linux | Linux | — | netfilter: nft_inner: release local_lock before re-enabling softirqs |
| CVE-2026-64162 | 9.8 | 48.4 | Linux | Linux | — | idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init() |
| CVE-2026-64037 | 9.8 | 47.5 | Linux | Linux | — | wifi: iwlwifi: mld: fix TSO segmentation explosion when AMSDU is disabled |
| CVE-2026-64122 | 9.8 | 47.5 | Linux | Linux | CWE-416 | net/mlx5e: Fix use-after-free in mlx5e_tx_reporter_timeout_recover |
| CVE-2026-63980 | 7.5 | 47.4 | Linux | Linux | — | net/handshake: Use spin_lock_bh for hn_lock |
| CVE-2026-64003 | 7.5 | 47.4 | Linux | Linux | — | scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues |
| CVE-2026-64141 | 7.5 | 47.4 | Linux | Linux | CWE-476 | ksmbd: fix null pointer dereference in compare_guid_key() |
| CVE-2026-63909 | 8.1 | 47.4 | Linux | Linux | — | ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops |
| CVE-2026-16207 | 6.3 | 47.1 | n/a | django-tastypie | CWE-598 | django-tastypie authentication.py ApiKeyAuthentication get request method wit… |
| CVE-2026-63978 | 9.8 | 46.9 | Linux | Linux | — | net/handshake: Drain pending requests at net namespace exit |
| CVE-2026-64175 | 7.5 | 46.5 | Linux | Linux | — | wifi: iwlwifi: mld: stop TX during firmware restart |
| CVE-2026-64138 | 8.8 | 46.1 | Linux | Linux | — | ksmbd: validate SID in parent security descriptor during ACL inheritance |
| CVE-2026-63867 | 8.2 | 45.7 | Linux | Linux | — | mptcp: close TOCTOU race while computing rcv_wnd |
| CVE-2026-63972 | 7.5 | 45.6 | Linux | Linux | — | net: mana: Skip redundant detach on already-detached port |
| CVE-2026-64024 | 9.4 | 44.4 | Linux | Linux | — | tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction |
| CVE-2026-64067 | 9.8 | 43.7 | Linux | Linux | — | netfs: Fix missing barriers when accessing stream->subrequests locklessly |
| CVE-2026-64068 | 9.8 | 43.7 | Linux | Linux | — | netfs: Fix missing locking around retry adding new subreqs |
| CVE-2026-64160 | 9.8 | 43.7 | Linux | Linux | — | netfs: Fix potential for tearing in ->remote_i_size and ->zero_point |
| CVE-2026-64056 | 9.8 | 43.6 | Linux | Linux | — | net: ethernet: cortina: Make RX SKB per-port |
| CVE-2026-64089 | 9.8 | 43.6 | Linux | Linux | — | batman-adv: tt: fix negative last_changeset_len |
| CVE-2026-64125 | 9.8 | 43.6 | Linux | Linux | — | net: bcmgenet: keep RBUF EEE/PM disabled |
| CVE-2026-16215 | 5.5 | 43.4 | geex-arts | django-jet | CWE-862 | geex-arts django-jet OAuth Credential Revoke authorization |
| CVE-2026-16204 | 2.1 | 43.4 | zevorn | rt-claw | CWE-74 | zevorn rt-claw Telegram-to-AI Tool Execution Flow script.c tool_run_script_ex… |
| CVE-2026-53398 | 9.8 | 43.1 | Linux | Linux | — | NFSD: Fix SECINFO_NO_NAME decode error cleanup |
| CVE-2026-53399 | 9.8 | 43.1 | Linux | Linux | CWE-476 | nfsd: release layout stid on setlease failure |
| CVE-2026-16201 | 5.5 | 42.5 | zevorn | rt-claw | CWE-200 | zevorn rt-claw http_request net.c claw_net_post information disclosure |
| CVE-2026-63976 | 8.8 | 42.4 | Linux | Linux | — | Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success |
| CVE-2026-53392 | 7.5 | 42.4 | Linux | Linux | CWE-476 | NFSv4/flexfiles: reject zero filehandle version count |
| CVE-2026-53397 | 7.5 | 42.4 | Linux | Linux | CWE-401 | nfsd: fix posix_acl leak on SETACL decode failure |
| CVE-2026-63800 | 9.8 | 42.3 | Linux | Linux | CWE-416 | pNFS: Fix use-after-free in pnfs_update_layout() |
| CVE-2026-63808 | 9.8 | 42.3 | Linux | Linux | — | exfat: fix potential use-after-free in exfat_find_dir_entry() |
| CVE-2026-53391 | 7.5 | 41.6 | Linux | Linux | CWE-476 | NFSv4/pNFS: reject zero-length r_addr in nfs4_decode_mp_ds_addr |
| CVE-2026-53384 | 9.8 | 41.5 | Linux | Linux | CWE-416 | serial: 8250_dw: unregister 8250 port if clk_notifier_register() fails |
| CVE-2026-63984 | 9.8 | 41.4 | Linux | Linux | — | ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() |
| CVE-2026-63994 | 9.8 | 41.4 | Linux | Linux | — | tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() |
| CVE-2026-64007 | 9.8 | 41.4 | Linux | Linux | — | netfilter: synproxy: refresh tcphdr after skb_ensure_writable |
| CVE-2026-63801 | 8.8 | 41.3 | Linux | Linux | CWE-416 | tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done |
| CVE-2026-63795 | 10.0 | 40.7 | Linux | Linux | CWE-416 | 9p: avoid putting oldfid in p9_client_walk() error path |
| CVE-2026-64048 | 7.5 | 40.6 | Linux | Linux | — | net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot |
| CVE-2026-16200 | 5.5 | 40.2 | zevorn | rt-claw | CWE-285 | zevorn rt-claw RPC swarm.c claw_tool_invoke authorization |
| CVE-2026-42566 | 7.5 | 39.8 | meshtastic | firmware | CWE-20 | Meshtastic: Malformed UTF-8 in User.long_name broadcast over LoRa causes mesh… |
| CVE-2026-53395 | 7.5 | 39.8 | Linux | Linux | CWE-674 | nfsd: fix dead ACL conflict guard in nfsd4_create |
| CVE-2026-63955 | 7.5 | 39.8 | Linux | Linux | — | mm/vmalloc: do not trigger BUG() on BH disabled context |
| CVE-2026-64020 | 7.5 | 39.8 | Linux | Linux | — | nvme-pci: fix dma_vecs leak on p2p memory |
| CVE-2026-64140 | 7.5 | 39.8 | Linux | Linux | CWE-476 | ksmbd: fix null pointer dereference in proc_show_files() |
| CVE-2026-53394 | 7.5 | 39.4 | Linux | Linux | CWE-401 | nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race |
| CVE-2026-63796 | 8.8 | 39.3 | Linux | Linux | CWE-125 | ocfs2: reject oversized group bitmap descriptors |
| CVE-2026-53390 | 8.1 | 38.5 | Linux | Linux | CWE-125 | ksmbd: fix out-of-bounds read in smb_check_perm_dacl() |
| CVE-2026-16220 | 2.1 | 38.6 | code-projects | Online Examination System | CWE-79 | code-projects Online Examination System account.php cross site scripting |
| CVE-2026-16229 | 2.1 | 38.6 | itsourcecode | Courier Management System | CWE-79 | itsourcecode Courier Management System index.php cross site scripting |
| CVE-2026-16221 | 7.5 | 36.1 | fast-uri | fast-uri | CWE-436 | fast-uri vulnerable to host confusion via literal backslash authority delimiter |
| CVE-2026-16227 | 5.5 | 35.7 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_subject.php sql injection |
| CVE-2026-16228 | 5.5 | 35.7 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection |
| CVE-2026-64091 | 9.8 | 35.3 | Linux | Linux | CWE-367 | batman-adv: tt: fix TOCTOU race for reported vlans |
| CVE-2026-16219 | 2.1 | 35.2 | Croogo | CMS | CWE-22 | Croogo CMS Admin File Manager FileManager.php isEditable path traversal |
| CVE-2026-63916 | 8.8 | 34.0 | Linux | Linux | — | HID: wacom: Fix OOB write in wacom_hid_set_device_mode() |
| CVE-2026-64088 | 8.8 | 34.0 | Linux | Linux | — | batman-adv: tt: fix negative tt_buff_len |
| CVE-2026-64178 | 8.8 | 34.0 | Linux | Linux | CWE-416 | Bluetooth: bnep: Fix UAF read of dev->name |
| CVE-2026-64095 | 7.1 | 33.7 | Linux | Linux | — | batman-adv: bla: avoid double decrement of bla.num_requests |
| CVE-2026-63947 | 8.8 | 33.1 | Linux | Linux | — | Bluetooth: HIDP: fix missing length checks in hidp_input_report() |
| CVE-2026-64093 | 8.8 | 33.1 | Linux | Linux | — | batman-adv: tp_meter: directly shut down timer on cleanup |
| CVE-2026-63925 | 8.1 | 33.0 | Linux | Linux | — | macsec: fix replay protection at XPN lower-PN wrap |
| CVE-2026-64010 | 8.8 | 32.9 | Linux | Linux | — | nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() |
| CVE-2026-64096 | 8.8 | 32.9 | Linux | Linux | CWE-416 | batman-adv: mcast: fix use-after-free in orig_node RCU release |
| CVE-2026-16225 | 2.1 | 32.7 | davenardella | snap7 | CWE-119 | davenardella snap7 s7_peer.cpp NegotiatePDULength out-of-bounds write |
| CVE-2026-12484 | 7.8 | 32.1 | keras-team | keras-team/keras | CWE-502 | Unsafe Deserialization in keras.layers.TorchModuleWrapper.from_config |
| CVE-2026-63889 | 8.1 | 31.7 | Linux | Linux | — | scsi: scsi_transport_fc: Widen FPIN pname walker counter to u32 |
| CVE-2026-63944 | 8.8 | 31.5 | Linux | Linux | — | Bluetooth: hci_sync: fix UAF in hci_le_create_cis_sync |
| CVE-2026-63893 | 8.1 | 31.4 | Linux | Linux | — | thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() |
| CVE-2026-16224 | 5.3 | 31.3 | jxxghp | MoviePilot | CWE-266 | jxxghp MoviePilot Application API improper authorization |
| CVE-2026-16214 | 2.1 | 31.2 | geex-arts | django-jet | CWE-285 | geex-arts django-jet Dashboard views.py authorization |
| CVE-2026-16217 | 2.1 | 31.2 | guohongze | adminset | CWE-285 | guohongze adminset Delivery Deployment Endpoint deli.py authorization |
| CVE-2026-53396 | 7.1 | 30.7 | Linux | Linux | CWE-401 | nfsd: fix posix_acl leak and ignored error in nfsd4_create_file |
| CVE-2026-63974 | 8.8 | 30.7 | Linux | Linux | — | Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close |
| CVE-2026-16226 | 5.1 | 30.4 | SourceCodester | Pizzafy Ecommerce System | CWE-284 | SourceCodester Pizzafy Ecommerce System admin_class_novo.php save_settings un… |
| CVE-2026-63832 | 8.8 | 30.2 | Linux | Linux | — | wifi: mt76: add wcid publish check in mt76_sta_add |
| CVE-2026-63866 | 8.8 | 30.2 | Linux | Linux | — | wifi: mt76: mt7996: Clear wcid pointer in mt7996_mac_sta_deinit_link() |
| CVE-2026-64030 | 8.8 | 30.2 | Linux | Linux | — | wifi: mac80211: bounds-check link_id in ieee80211_ml_epcs |
| CVE-2026-16222 | 2.1 | 30.2 | 1Panel-dev | CordysCRM | CWE-918 | 1Panel-dev CordysCRM Third Party Endpoint TokenService.java server-side reque… |
| CVE-2026-16223 | 2.1 | 30.2 | 1Panel-dev | CordysCRM | CWE-918 | 1Panel-dev CordysCRM Third Party Edit Endpoint IntegrationConfigService.java … |
| CVE-2026-63830 | 9.4 | 29.9 | Linux | Linux | — | net: skmsg: preserve sg.copy across SG transforms |
| CVE-2026-16206 | 5.3 | 29.3 | django-oauth | django-oauth-toolkit | CWE-613 | django-oauth django-oauth-toolkit oauth2_validators.py _load_id_token session… |
| CVE-2026-16199 | 2.1 | 29.3 | nextlevelbuilder | GoClaw | CWE-266 | nextlevelbuilder GoClaw credentialed_exec.go ExecTool.Execute improper author… |
| CVE-2026-63915 | 8.8 | 28.1 | Linux | Linux | — | nfc: hci: fix out-of-bounds read in HCP header parsing |
| CVE-2026-63975 | 8.8 | 28.1 | Linux | Linux | — | Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp |
| CVE-2026-16205 | 1.9 | 27.6 | Pluck | CMS | CWE-79 | Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting |
| CVE-2026-16202 | 2.0 | 27.4 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System CYS.php cross site scripting |
| CVE-2026-16203 | 2.0 | 27.4 | SourceCodester | Class and Exam Timetabling System | CWE-79 | SourceCodester Class and Exam Timetabling System forCYS.php cross site scripting |
| CVE-2026-64176 | 8.1 | 26.8 | Linux | Linux | — | wifi: iwlwifi: mvm: fix driver-set TX rates on old devices |
| CVE-2026-64117 | 8.8 | 26.5 | Linux | Linux | CWE-416 | wifi: mac80211: capture fast-RX rate before mesh reuses skb->cb |
| CVE-2026-63869 | 7.6 | 26.2 | Linux | Linux | — | wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap |
| CVE-2026-63946 | 8.8 | 26.1 | Linux | Linux | — | Bluetooth: ISO: fix UAF in iso_recv_frame |
| CVE-2026-16218 | 2.1 | 21.4 | hunvreus | devpush | CWE-703 | hunvreus devpush Storage Reset Failure storage.py reset_storage improper chec… |
| CVE-2026-16212 | 1.3 | 20.9 | awesto | django-shop | CWE-362 | awesto django-shop Purchase Stock inventory.py race condition |
| CVE-2026-16208 | 2.3 | 17.9 | n/a | django-tastypie | CWE-362 | django-tastypie throttle.py CacheDBThrottle race condition |
| CVE-2026-63891 | await | 17.8 | Linux | Linux | — | thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() |
| CVE-2026-63895 | await | 16.6 | Linux | Linux | — | usb: gadget: f_fs: copy only received bytes on short ep0 read |
| CVE-2026-63831 | 8.8 | 16.3 | Linux | Linux | — | mac802154: llsec: add skb_cow_data() before in-place crypto |
| CVE-2026-45138 | 5.4 | 14.2 | ci4-cms-erp | ci4ms | CWE-79 | CI4MS: Stored XSS in Blog Content via Broken `html_purify` Validation Rule |
| CVE-2026-64028 | await | 13.7 | Linux | Linux | — | tracing: Avoid NULL return from hist_field_name() on truncation |
| CVE-2026-16216 | 2.1 | 13.6 | geex-arts | django-jet | CWE-352 | geex-arts django-jet OAuth cross-site request forgery |
| CVE-2026-63981 | await | 13.4 | Linux | Linux | — | net/sched: act_mirred: Fix blockcast recursion bypass leading to stack overflow |
| CVE-2026-63899 | await | 13.0 | Linux | Linux | — | USB: serial: mxuport: fix memory corruption with small endpoint |
| CVE-2026-63901 | await | 13.0 | Linux | Linux | — | USB: serial: digi_acceleport: fix memory corruption with small endpoints |
| CVE-2026-63990 | await | 13.0 | Linux | Linux | — | bonding: refuse to enslave CAN devices |
| CVE-2026-16211 | 1.2 | 12.8 | n/a | allegro | CWE-362 | allegro Hostname Allocation assets.py AssetLastHostname.increment_hostname ra… |
| CVE-2026-63868 | await | 12.3 | Linux | Linux | — | net: garp: fix unsigned integer underflow in garp_pdu_parse_attr |
| CVE-2026-63890 | await | 12.3 | Linux | Linux | — | scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker |
| CVE-2026-63892 | await | 12.3 | Linux | Linux | — | thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow |
| CVE-2026-63897 | await | 12.3 | Linux | Linux | — | USB: serial: mct_u232: fix missing interrupt-in transfer sanity check |
| CVE-2026-63898 | await | 12.3 | Linux | Linux | — | USB: serial: mct_u232: fix memory corruption with small endpoint |
| CVE-2026-63900 | await | 12.3 | Linux | Linux | — | USB: serial: keyspan: fix missing indat transfer sanity check |
| CVE-2026-63902 | await | 12.3 | Linux | Linux | — | USB: serial: cypress_m8: validate interrupt packet headers |
| CVE-2026-63903 | await | 12.3 | Linux | Linux | — | USB: serial: belkin_sa: validate interrupt status length |
| CVE-2026-63904 | await | 12.3 | Linux | Linux | — | usb: usbtmc: check URB actual_length for interrupt-IN notifications |
| CVE-2026-63905 | await | 12.3 | Linux | Linux | — | usbip: vudc: Fix use after free bug in vudc_remove due to race condition |
| CVE-2026-63908 | await | 12.3 | Linux | Linux | — | Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem |
| CVE-2026-63931 | await | 12.2 | Linux | Linux | — | iio: chemical: scd30: fix division by zero in write_raw |
| CVE-2026-63933 | await | 12.3 | Linux | Linux | — | iio: gyro: adis16260: fix division by zero in write_raw |
| CVE-2026-63934 | await | 12.3 | Linux | Linux | — | iio: gyro: itg3200: fix i2c read into the wrong stack location |
| CVE-2026-63948 | await | 12.3 | Linux | Linux | — | Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn |
| CVE-2026-63956 | await | 12.2 | Linux | Linux | — | USB: serial: cypress_m8: fix memory corruption with small endpoint |
| CVE-2026-63957 | await | 12.2 | Linux | Linux | — | USB: serial: safe_serial: fix memory corruption with small endpoint |
| CVE-2026-63960 | await | 12.3 | Linux | Linux | — | usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() |
| CVE-2026-63961 | await | 12.3 | Linux | Linux | — | usb: typec: altmodes/displayport: validate count before reading Status Update… |
| CVE-2026-63964 | await | 12.3 | Linux | Linux | — | usb: typec: ucsi: ccg: reject firmware images without a ':' record header |
| CVE-2026-63967 | await | 12.3 | Linux | Linux | — | iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer |
| CVE-2026-63991 | await | 12.3 | Linux | Linux | — | Bluetooth: 6lowpan: check skb_clone() return value in send_mcast_pkt() |
| CVE-2026-64012 | await | 12.3 | Linux | Linux | — | net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_p… |
| CVE-2026-64014 | await | 12.3 | Linux | Linux | — | Input: usbtouchscreen - clamp NEXIO data_len/x_len to URB buffer size |
| CVE-2026-64083 | await | 12.3 | Linux | Linux | — | hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors |
| CVE-2026-64085 | await | 12.3 | Linux | Linux | — | hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer |
| CVE-2026-64087 | await | 12.3 | Linux | Linux | — | hwmon: (pmbus/adm1266) reject implausible blackbox record_count |
| CVE-2026-63928 | await | 11.9 | Linux | Linux | — | USB: serial: omninet: fix memory corruption with small endpoint |
| CVE-2026-63861 | await | 11.7 | Linux | Linux | — | spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback |
| CVE-2026-63862 | await | 11.7 | Linux | Linux | — | PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found |
| CVE-2026-63882 | await | 11.7 | Linux | Linux | — | drm/amdkfd: fix NULL pointer bug in svm_range_set_attr |
| CVE-2026-63949 | await | 11.7 | Linux | Linux | — | auxdisplay: line-display: fix OOB read on zero-length message_store() |
| CVE-2026-63969 | await | 11.7 | Linux | Linux | — | ipv6: fix possible infinite loop in rt6_fill_node() |
| CVE-2026-63973 | await | 11.7 | Linux | Linux | — | net: mana: Add NULL guards in teardown path to prevent panic on attach failure |
| CVE-2026-63939 | 9.3 | 11.3 | Linux | Linux | — | KVM: SEV: Compute the correct max length of the in-GHCB scratch area |
| CVE-2026-63958 | await | 11.3 | Linux | Linux | — | usb: typec: ucsi: validate connector number in ucsi_connector_change() |
| CVE-2026-63838 | await | 10.9 | Linux | Linux | — | ASoC: rsnd: Fix potential out-of-bounds access of component_dais[] |
| CVE-2026-63871 | await | 10.9 | Linux | Linux | — | Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls |
| CVE-2026-63876 | await | 10.9 | Linux | Linux | — | serial: zs: Convert to use a platform device |
| CVE-2026-63877 | await | 10.9 | Linux | Linux | — | serial: dz: Convert to use a platform device |
| CVE-2026-63896 | await | 10.9 | Linux | Linux | — | usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling |
| CVE-2026-63929 | await | 10.9 | Linux | Linux | — | iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() |
| CVE-2026-63936 | await | 10.9 | Linux | Linux | — | iio: adc: mt6359: fix unchecked return value in mt6358_read_imp |
| CVE-2026-63943 | await | 10.9 | Linux | Linux | — | Input: xpad - fix out-of-bounds access for Share button |
| CVE-2026-63959 | await | 10.9 | Linux | Linux | — | usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT |
| CVE-2026-63962 | await | 10.9 | Linux | Linux | — | usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() |
| CVE-2026-63963 | await | 10.9 | Linux | Linux | — | usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers |
| CVE-2026-63997 | await | 10.9 | Linux | Linux | — | ethtool: module: avoid leaking a netdev ref on module flash errors |
| CVE-2026-64001 | await | 10.9 | Linux | Linux | — | ALSA: pcm: oss: Fix setup list UAF on proc write error |
| CVE-2026-64006 | await | 10.9 | Linux | Linux | — | netfilter: nf_tables: fix dst corruption in same register operation |
| CVE-2026-64052 | await | 10.9 | Linux | Linux | — | block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() |
| CVE-2026-64059 | await | 10.9 | Linux | Linux | — | netfs: Fix folio->private handling in netfs_perform_write() |
| CVE-2026-64062 | await | 10.9 | Linux | Linux | — | netfs: Fix potential deadlock in write-through mode |
| CVE-2026-64063 | await | 10.9 | Linux | Linux | — | netfs: Fix streaming write being overwritten |
| CVE-2026-64064 | await | 10.9 | Linux | Linux | — | netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone |
| CVE-2026-64065 | await | 10.9 | Linux | Linux | — | netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call |
| CVE-2026-63837 | await | 10.6 | Linux | Linux | — | net: ena: PHC: Check return code before setting timestamp output |
| CVE-2026-63859 | await | 10.6 | Linux | Linux | — | net: airoha: Add missing bits in airoha_qdma_cleanup_tx_queue() |
| CVE-2026-63873 | await | 10.6 | Linux | Linux | — | accel/amdxdna: Fix mm_struct reference leak in aie2_populate_range() |
| CVE-2026-63878 | await | 10.6 | Linux | Linux | — | drm/amdgpu: check num_entries in GEM_OP GET_MAPPING_INFO |
| CVE-2026-63880 | await | 10.6 | Linux | Linux | — | drm/amdgpu: fix lock leak on ENOMEM in AMDGPU_GEM_OP_GET_MAPPING_INFO |
| CVE-2026-63932 | await | 10.6 | Linux | Linux | — | iio: chemical: mhz19b: reject oversized serial replies |
| CVE-2026-63965 | await | 10.6 | Linux | Linux | — | iio: pressure: bmp280: fix stack leak in bmp580 trigger handler |
| CVE-2026-63966 | await | 10.6 | Linux | Linux | — | iio: imu: adis16550: fix stack leak in trigger handler |
| CVE-2026-63982 | await | 10.6 | Linux | Linux | — | net/sched: Fix ethx:ingress -> ethy:egress -> ethx:ingress mirred loop |
| CVE-2026-63983 | await | 10.6 | Linux | Linux | — | net/sched: fix packet loop on netem when duplicate is on |
| CVE-2026-63986 | await | 10.6 | Linux | Linux | — | ethtool: tsinfo: don't pass ERR_PTR to genlmsg_cancel on prepare failure |
| CVE-2026-63988 | await | 10.6 | Linux | Linux | — | bridge: Fix sleep in atomic context in sysfs path |
| CVE-2026-63989 | await | 10.6 | Linux | Linux | — | bridge: Fix sleep in atomic context in netlink path |
| CVE-2026-63998 | await | 10.6 | Linux | Linux | — | ethtool: module: call ethnl_ops_complete() on module flash errors |
| CVE-2026-63999 | await | 10.6 | Linux | Linux | — | ethtool: rss: fix indir_table and hkey leak on get_rxfh failure |
| CVE-2026-64021 | await | 10.6 | Linux | Linux | — | drm/xe/oa: Fix exec_queue leak on width check in stream open |
| CVE-2026-64022 | await | 10.6 | Linux | Linux | — | gpio: aggregator: remove the software node when deactivating the aggregator |
| CVE-2026-64038 | await | 10.6 | Linux | Linux | — | hwmon: (lm90) Stop work before releasing hwmon device |
| CVE-2026-64043 | await | 10.6 | Linux | Linux | — | ovpn: fix race between deleting interface and adding new peer |
| CVE-2026-64049 | await | 10.6 | Linux | Linux | — | drm/msm/adreno: fix userspace-triggered crash on a2xx-a4xx |
| CVE-2026-64054 | await | 10.6 | Linux | Linux | — | net: shaper: reject duplicate leaves in GROUP request |
| CVE-2026-64060 | await | 10.6 | Linux | Linux | — | netfs: Fix leak of request in netfs_write_begin() error handling |
| CVE-2026-64071 | await | 10.6 | Linux | Linux | — | nvme-pci: fix use-after-free in nvme_free_host_mem() |
| CVE-2026-64072 | await | 10.6 | Linux | Linux | — | nvme: fix bio leak on mapping failure |
| CVE-2026-64075 | await | 10.6 | Linux | Linux | — | fprobe: Fix unregister_fprobe() to wait for RCU grace period |
| CVE-2026-64034 | 9.3 | 10.4 | Linux | Linux | — | net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer |
| CVE-2026-64009 | 7.8 | 9.9 | Linux | Linux | — | xfrm: Check for underflow in xfrm_state_mtu |
| CVE-2026-64080 | 9.3 | 9.6 | Linux | Linux | — | firmware: arm_ffa: Snapshot notifier callbacks under lock |
| CVE-2026-63820 | await | 9.5 | Linux | Linux | — | f2fs: fix missing read bio submission on large folio error |
| CVE-2026-63839 | await | 9.5 | Linux | Linux | — | platform/x86: lenovo-wmi-helpers: Fix memory leak in lwmi_dev_evaluate_int() |
| CVE-2026-63907 | await | 9.5 | Linux | Linux | — | uio: uio_pci_generic_sva: fix double free of devm_kzalloc() memory |
| CVE-2026-63935 | await | 9.5 | Linux | Linux | — | iio: adc: nxp-sar-adc: fix division by zero in write_raw |
| CVE-2026-63953 | await | 9.5 | Linux | Linux | — | mm/migrate_device: fix pgtable leak in migrate_vma_insert_huge_pmd_page |
| CVE-2026-64013 | await | 9.5 | Linux | Linux | — | ACPI: button: Fix ACPI GPE handler leak during removal |
| CVE-2026-64019 | await | 9.5 | Linux | Linux | — | nvme-pci: fix dma mapping leak on data setup error |
| CVE-2026-64040 | await | 9.5 | Linux | Linux | — | cachefiles: Fix error return when vfs_mkdir() fails |
| CVE-2026-64070 | await | 9.5 | Linux | Linux | — | powerpc/hv-gpci: fix preempt count leak in sysfs show paths |
| CVE-2026-64079 | await | 9.5 | Linux | Linux | — | netfilter: x_tables: allocate hook ops while under mutex |
| CVE-2026-63938 | 9.3 | 9.3 | Linux | Linux | — | KVM: SEV: Check PSC request indices against the actual size of the buffer |
| CVE-2026-63940 | 9.3 | 9.3 | Linux | Linux | — | KVM: SEV: Ignore Port I/O requests of length '0' |
| CVE-2026-64018 | 9.3 | 9.3 | Linux | Linux | — | net: mana: validate rx_req_idx to prevent out-of-bounds array access |
| CVE-2026-63860 | 8.4 | 9.3 | Linux | Linux | — | RDMA/core: Prefer NLA_NUL_STRING |
| CVE-2026-63926 | 8.4 | 9.3 | Linux | Linux | — | bpf: sockmap: fix tail fragment offset in bpf_msg_push_data |
| CVE-2026-64118 | 8.4 | 9.3 | Linux | Linux | CWE-415 | qed: fix double free in qed_cxt_tables_alloc() |
| CVE-2026-64172 | 7.1 | 9.2 | Linux | Linux | — | KVM: SVM: Disable AVIC IPI virtualization on Hygon Family 18h (erratum #1235) |
| CVE-2026-64045 | 8.4 | 9.0 | Linux | Linux | — | ovpn: tcp - use cached peer pointer in ovpn_tcp_close() |
| CVE-2026-64081 | 8.4 | 9.0 | Linux | Linux | — | firmware: arm_ffa: Validate framework notification message layout |
| CVE-2026-63906 | 8.4 | 8.7 | Linux | Linux | — | usb: musb: omap2430: Fix use-after-free in omap2430_probe() |
| CVE-2026-63881 | 7.8 | 8.6 | Linux | Linux | — | drm/amdkfd: fix a vulnerability of integer overflow in kfd debugger |
| CVE-2026-64041 | 7.8 | 8.3 | Linux | Linux | — | ASoC: codecs: fs210x: fix possible buffer overflow |
| CVE-2026-64114 | 7.8 | 8.0 | Linux | Linux | CWE-125 | ipv4: raw: reject IP_HDRINCL packets with ihl < 5 |
| CVE-2026-64044 | 7.8 | 8.0 | Linux | Linux | — | ovpn: respect peer refcount in CMD_NEW_PEER error path |
| CVE-2026-63810 | await | 7.9 | Linux | Linux | — | block: Avoid mounting the bdev pseudo-filesystem in userspace |
| CVE-2026-63864 | 8.4 | 7.5 | Linux | Linux | — | bpf: Propagate error from visit_tailcall_insn |
| CVE-2026-64073 | 7.8 | 7.6 | Linux | Linux | — | irq_work: Fix use-after-free in irq_work_single() on PREEMPT_RT |
| CVE-2026-64039 | 7.7 | 7.6 | Linux | Linux | — | drm/msm/snapshot: fix dumping of the unaligned regions |
| CVE-2026-53401 | 7.8 | 7.2 | Linux | Linux | CWE-416 | fbdev: omap2: fix use-after-free in omapfb_mmap |
| CVE-2026-63951 | 7.8 | 7.2 | Linux | Linux | — | zram: fix use-after-free in zram_writeback_endio |
| CVE-2026-63865 | 8.8 | 7.1 | Linux | Linux | — | bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks |
| CVE-2026-63921 | 8.8 | 7.1 | Linux | Linux | — | ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). |
| CVE-2026-64153 | 8.8 | 7.1 | Linux | Linux | — | drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN |
| CVE-2026-63870 | 7.8 | 7.1 | Linux | Linux | — | ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() |
| CVE-2026-63875 | 7.8 | 7.1 | Linux | Linux | — | arm64: tlb: Flush walk cache when unsharing PMD tables |
| CVE-2026-63884 | 7.8 | 7.1 | Linux | Linux | — | drm/i915: Fix potential UAF in TTM object purge |
| CVE-2026-63942 | 7.8 | 7.1 | Linux | Linux | — | parport: Fix race between port and client registration |
| CVE-2026-63954 | 7.8 | 7.1 | Linux | Linux | — | hpfs: fix a crash if hpfs_map_dnode_bitmap fails |
| CVE-2026-63985 | 7.8 | 7.1 | Linux | Linux | — | ethtool: eeprom: add more safeties to EEPROM Netlink fallback |
| CVE-2026-64002 | 7.8 | 7.1 | Linux | Linux | — | ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_… |
| CVE-2026-64004 | 7.8 | 7.1 | Linux | Linux | — | net/iucv: fix locking in .getsockopt |
| CVE-2026-64005 | 7.8 | 7.1 | Linux | Linux | — | net/smc: Do not re-initialize smc hashtables |
| CVE-2026-64015 | 7.8 | 7.1 | Linux | Linux | — | security/keys: fix missed RCU read section on lookup |
| CVE-2026-64084 | 7.8 | 7.1 | Linux | Linux | — | hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR |
| CVE-2026-64086 | 7.8 | 7.1 | Linux | Linux | — | hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer |
| CVE-2026-64097 | 7.8 | 7.1 | Linux | Linux | CWE-787 | drm/amd/display: Validate GPIO pin LUT table size before iterating |
| CVE-2026-64108 | 7.8 | 7.1 | Linux | Linux | — | cifs: Fix busy dentry used after unmounting |
| CVE-2026-64133 | 7.8 | 7.1 | Linux | Linux | CWE-125 | ALSA: asihpi: Fix potential OOB array access at reading cache |
| CVE-2026-64137 | 7.8 | 7.1 | Linux | Linux | — | smb: client: require net admin for CIFS SWN netlink |
| CVE-2026-63937 | 8.8 | 7.0 | Linux | Linux | — | KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer |
| CVE-2026-64109 | 8.8 | 7.0 | Linux | Linux | CWE-416 | af_unix: Fix UAF read of tail->len in unix_stream_data_wait() |
| CVE-2026-53386 | 7.8 | 7.0 | Linux | Linux | CWE-129 | iio: adc: ti-ads1298: add bounds check to pga_settings index |
| CVE-2026-63812 | 7.8 | 7.0 | Linux | Linux | — | f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() |
| CVE-2026-63842 | 7.8 | 7.0 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring |
| CVE-2026-63843 | 7.8 | 7.0 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring |
| CVE-2026-63844 | 7.8 | 7.0 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring |
| CVE-2026-63845 | 7.8 | 7.0 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring |
| CVE-2026-63846 | 7.8 | 7.0 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring |
| CVE-2026-63847 | 7.8 | 7.0 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring |
| CVE-2026-63848 | 7.8 | 7.0 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring |
| CVE-2026-63850 | 7.8 | 7.0 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring |
| CVE-2026-63851 | 7.8 | 7.0 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring |
| CVE-2026-63852 | 7.8 | 7.0 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring |
| CVE-2026-63854 | 7.8 | 7.0 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings |
| CVE-2026-63855 | 7.8 | 7.0 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings |
| CVE-2026-63856 | 7.8 | 7.0 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings |
| CVE-2026-63970 | 7.8 | 7.0 | Linux | Linux | — | vsock/virtio: bind uarg before filling zerocopy skb |
| CVE-2026-63987 | 7.8 | 7.0 | Linux | Linux | — | ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES |
| CVE-2026-63995 | 7.8 | 7.0 | Linux | Linux | — | ethtool: cmis: validate start_cmd_payload_size from module |
| CVE-2026-63996 | 7.8 | 7.0 | Linux | Linux | — | ethtool: cmis: require exact CDB reply length |
| CVE-2026-64026 | 7.8 | 7.0 | Linux | Linux | — | rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg |
| CVE-2026-64051 | 7.8 | 7.0 | Linux | Linux | — | accel/qaic: Add overflow check to remap_pfn_range during mmap |
| CVE-2026-64053 | 7.8 | 7.0 | Linux | Linux | — | block: don't overwrite bip_vcnt in bio_integrity_copy_user() |
| CVE-2026-64134 | 7.8 | 7.0 | Linux | Linux | CWE-476 | ALSA: pcm: Don't setup bogus iov_iter for silencing |
| CVE-2026-63822 | await | 6.8 | Linux | Linux | — | wifi: ath11k: fix warning when unbinding |
| CVE-2026-63834 | await | 6.9 | Linux | Linux | — | batman-adv: tp_meter: restrict number of unacked list entries |
| CVE-2026-63835 | await | 6.9 | Linux | Linux | — | batman-adv: v: prevent OGM aggregation on disabled hardif |
| CVE-2026-63836 | await | 6.9 | Linux | Linux | — | batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd |
| CVE-2026-63885 | 8.8 | 6.8 | Linux | Linux | — | drm/gem: fix race between change_handle and handle_delete |
| CVE-2026-63923 | 8.8 | 6.8 | Linux | Linux | — | octeontx2-af: validate body pcifunc in rvu_mbox_handler_rep_event_notify |
| CVE-2026-64124 | 8.8 | 6.8 | Linux | Linux | — | net: devmem: reject dma-buf bind with non-page-aligned size or SG length |
| CVE-2026-63805 | 7.8 | 6.8 | Linux | Linux | — | crypto: nx - fix nx_crypto_ctx_exit argument |
| CVE-2026-63813 | 7.8 | 6.8 | Linux | Linux | — | Revert "f2fs: remove non-uptodate folio from the page cache in move_data_block" |
| CVE-2026-63819 | 7.8 | 6.8 | Linux | Linux | — | f2fs: fix to do sanity check on f2fs_get_node_folio_ra() |
| CVE-2026-63841 | 7.8 | 6.8 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.1 ring |
| CVE-2026-63849 | 7.8 | 6.8 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v5.0.1 enc ring |
| CVE-2026-63853 | 7.8 | 6.8 | Linux | Linux | — | drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring |
| CVE-2026-63874 | 7.8 | 6.8 | Linux | Linux | — | net: mctp: usb: fix race between urb completion and rx_retry cancellation |
| CVE-2026-63950 | 7.8 | 6.8 | Linux | Linux | — | mm/rmap: initialize nr_pages to 1 at loop start in try_to_unmap_one |
| CVE-2026-64008 | 7.8 | 6.8 | Linux | Linux | — | accel/rocket: fix UAF via dangling GEM handle in create_bo |
| CVE-2026-64027 | 7.8 | 6.8 | Linux | Linux | — | net: shaper: rework the VALID marking (again) |
| CVE-2026-64031 | 7.8 | 6.8 | Linux | Linux | — | erofs: fix managed cache race for unaligned extents |
| CVE-2026-64036 | 7.8 | 6.8 | Linux | Linux | — | cgroup/rstat: validate cpu before css_rstat_cpu() access |
| CVE-2026-64058 | 7.8 | 6.8 | Linux | Linux | — | netfs: Fix netfs_read_folio() to wait on writeback |
| CVE-2026-64074 | 7.8 | 6.8 | Linux | Linux | — | fs/statmount: fix slab out-of-bounds write in statmount_mnt_idmap |
| CVE-2026-64076 | 7.8 | 6.8 | Linux | Linux | — | netfilter: bridge: eb_tables: close module init race |
| CVE-2026-64077 | 7.8 | 6.8 | Linux | Linux | — | netfilter: ebtables: move to two-stage removal scheme |
| CVE-2026-64078 | 7.8 | 6.8 | Linux | Linux | — | netfilter: x_tables: add and use xtables_unregister_table_exit |
| CVE-2026-64181 | 7.8 | 6.8 | Linux | Linux | — | mm: fix __vm_normal_page() to handle missing support for pmd_special()/pud_sp… |
| CVE-2026-63879 | 7.8 | 6.7 | Linux | Linux | — | drm/amdgpu: fix amdgpu_hmm_range_get_pages |
| CVE-2026-63821 | await | 6.7 | Linux | Linux | — | wifi: rtw88: usb: fix memory leaks on USB write failures |
| CVE-2026-64115 | 8.8 | 6.5 | Linux | Linux | CWE-416 | vsock/vmci: fix UAF when peer resets connection during handshake |
| CVE-2026-63930 | 7.8 | 6.5 | Linux | Linux | — | iio: buffer: hw-consumer: fix use-after-free in error path |
| CVE-2026-63945 | 7.8 | 6.5 | Linux | Linux | — | Bluetooth: ISO: serialize iso_sock_clear_timer with socket lock |
| CVE-2026-64011 | 7.8 | 6.5 | Linux | Linux | — | nfc: llcp: Fix use-after-free in llcp_sock_release() |
| CVE-2026-64032 | 7.8 | 6.5 | Linux | Linux | — | bridge: mcast: Fix a possible use-after-free when removing a bridge port |
| CVE-2026-64123 | 7.8 | 6.5 | Linux | Linux | CWE-416 | net: hsr: defer node table free until after RCU readers |
| CVE-2026-63883 | 7.3 | 6.5 | Linux | Linux | — | serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ |
| CVE-2026-64126 | 7.3 | 6.6 | Linux | Linux | CWE-125 | Bluetooth: MGMT: validate Add Extended Advertising Data length |
| CVE-2026-64111 | 7.1 | 6.6 | Linux | Linux | — | lsm: hold cred_guard_mutex for lsm_set_self_attr() |
| CVE-2026-53389 | 7.8 | 6.5 | Linux | Linux | CWE-416 | net/tcp-ao: fix use-after-free of key in del_async path |
| CVE-2026-63894 | 7.8 | 6.5 | Linux | Linux | — | usb: gadget: f_fs: serialize DMABUF cancel against request completion |
| CVE-2026-63918 | 7.8 | 6.5 | Linux | Linux | — | l2tp: use refcount_inc_not_zero in l2tp_session_get_by_ifname |
| CVE-2026-64029 | 7.8 | 6.5 | Linux | Linux | — | ALSA: seq: Serialize UMP output teardown with event_input |
| CVE-2026-64099 | 7.8 | 6.5 | Linux | Linux | CWE-416 | drm/v3d: Fix use-after-free of CPU job query arrays on error path |
| CVE-2026-63917 | 8.8 | 6.3 | Linux | Linux | — | ip6: vti: Use ip6_tnl.net in vti6_changelink(). |
| CVE-2026-64104 | 8.7 | 6.3 | Linux | Linux | CWE-401 | virt: sev-guest: Explicitly leak pages in unknown state |
| CVE-2026-63971 | 7.8 | 6.3 | Linux | Linux | — | sctp: fix race between sctp_wait_for_connect and peeloff |
| CVE-2026-53368 | 7.1 | 6.3 | Linux | Linux | — | f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage |
| CVE-2026-63911 | 7.8 | 6.3 | Linux | Linux | — | xfrm: iptfs: reset runtime state when cloning SAs |
| CVE-2026-64023 | 7.8 | 6.3 | Linux | Linux | — | gpio: aggregator: fix a potential use-after-free |
| CVE-2026-64050 | 7.8 | 6.3 | Linux | Linux | — | drm/msm/dpu: don't mix devm and drmm functions |
| CVE-2026-63920 | 7.1 | 6.1 | Linux | Linux | — | ipv6: validate extension header length before copying to cmsg |
| CVE-2026-53387 | 7.1 | 6.0 | Linux | Linux | CWE-129 | iio: light: veml6075: add bounds check to veml6075_it_ms index |
| CVE-2026-63826 | await | 6.0 | Linux | Linux | — | fbdev: fix use-after-free in store_modes() |
| CVE-2026-63863 | 8.8 | 5.9 | Linux | Linux | — | drm/gpusvm: Fix unbalanced unlock in drm_gpusvm_scan_mm() |
| CVE-2026-63941 | 8.8 | 5.9 | Linux | Linux | — | KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor |
| CVE-2026-64042 | 8.8 | 5.9 | Linux | Linux | — | vfio/pci: Check BAR resources before exporting a DMABUF |
| CVE-2026-53373 | 7.8 | 5.9 | Linux | Linux | — | mm/vma: do not try to unmap a VMA if mmap_prepare() invoked from mmap() |
| CVE-2026-53380 | 7.8 | 5.9 | Linux | Linux | CWE-787 | media: rzv2h-ivc: Fix concurrent buffer list access |
| CVE-2026-63793 | 7.8 | 5.9 | Linux | Linux | CWE-416 | ntfs: serialize volume label accesses |
| CVE-2026-63799 | 7.8 | 5.9 | Linux | Linux | CWE-125 | sched/mmcid: Fix OOB clear_bit when CID is MM_CID_UNSET in fixup path |
| CVE-2026-63840 | 7.8 | 5.9 | Linux | Linux | — | drm/amdgpu/jpeg: set no_user_fence for JPEG v5.3.0 ring |
| CVE-2026-63858 | 7.8 | 5.9 | Linux | Linux | — | netfilter: nf_tables: add hook transactions for device deletions |
| CVE-2026-63910 | 7.8 | 5.9 | Linux | Linux | — | dma-buf: fix UAF in dma_buf_fd() tracepoint |
| CVE-2026-63977 | 7.8 | 5.9 | Linux | Linux | — | dpll: zl3073x: use __dpll_device_change_ntf() and remove change_work |
| CVE-2026-64057 | 7.8 | 5.9 | Linux | Linux | — | afs: Fix the locking used by afs_get_link() |
| CVE-2026-64082 | 7.8 | 5.9 | Linux | Linux | — | riscv: Fix register corruption from uninitialized cregs on error |
| CVE-2026-63952 | 8.4 | 5.8 | Linux | Linux | — | memfd: deny writeable mappings when implying SEAL_WRITE |
| CVE-2026-63927 | 7.8 | 5.8 | Linux | Linux | — | usb: dwc2: Fix use after free in debug code |
| CVE-2026-64151 | 8.4 | 5.7 | Linux | Linux | — | iommupt: Check for missing PAGE_SIZE in the pgsize_bitmap |
| CVE-2026-63914 | 7.3 | 5.6 | Linux | Linux | — | xfrm: route MIGRATE notifications to caller's netns |
| CVE-2026-64105 | 5.5 | 5.5 | Linux | Linux | — | KVM: arm64: vgic: Free private_irqs when init fails after allocation |
| CVE-2026-64127 | 5.5 | 5.5 | Linux | Linux | — | Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer |
| CVE-2026-64128 | 5.5 | 5.6 | Linux | Linux | CWE-476 | Bluetooth: ISO: drop ISO_END frames received without prior ISO_START |
| CVE-2026-64144 | 5.5 | 5.6 | Linux | Linux | CWE-401 | Bluetooth: btmtk: fix urb->setup_packet leak in error paths |
| CVE-2026-64157 | 5.5 | 5.5 | Linux | Linux | — | netfs: Fix partial invalidation of streaming-write folio |
| CVE-2026-64163 | 5.5 | 5.6 | Linux | Linux | — | test_kprobes: clear kprobes between test runs |
| CVE-2026-64170 | 5.5 | 5.6 | Linux | Linux | CWE-476 | spi: qup: fix error pointer deref after DMA setup failure |
| CVE-2026-64177 | 5.5 | 5.6 | Linux | Linux | — | phonet/pep: disable BH around forwarded sk_receive_skb() |
| CVE-2026-64179 | 5.5 | 5.6 | Linux | Linux | CWE-401 | net: wwan: iosm: fix potential memory leaks in ipc_imem_init() |
| CVE-2026-64180 | 5.5 | 5.6 | Linux | Linux | — | mm/memory_hotplug: fix memory block reference leak on remove |
| CVE-2026-64182 | 5.5 | 5.5 | Linux | Linux | — | drivers/base/memory: fix memory block reference leak in poison accounting |
| CVE-2026-64183 | 5.5 | 5.6 | Linux | Linux | CWE-476 | efi: Allocate runtime workqueue before ACPI init |
| CVE-2026-64184 | 5.5 | 5.6 | Linux | Linux | — | mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() |
| CVE-2026-53367 | 5.5 | 5.4 | Linux | Linux | — | selinux: fix avdcache auditing |
| CVE-2026-53371 | 5.5 | 5.4 | Linux | Linux | — | RDMA/ionic: bound node_desc sysfs read with %.64s |
| CVE-2026-53372 | 5.5 | 5.4 | Linux | Linux | — | iommu/vt-d: Block PASID attachment to nested domain with dirty tracking |
| CVE-2026-64110 | 5.5 | 5.4 | Linux | Linux | CWE-401 | igc: fix potential skb leak in igc_fpe_xmit_smd_frame() |
| CVE-2026-64120 | 5.5 | 5.4 | Linux | Linux | CWE-476 | net: ethtool: fix NULL pointer dereference in phy_reply_size |
| CVE-2026-64130 | 5.5 | 5.4 | Linux | Linux | CWE-908 | mm/page_alloc: fix initialization of tags of the huge zero folio with init_on… |
| CVE-2026-64149 | 5.5 | 5.4 | Linux | Linux | — | dma-mapping: move dma_map_resource() sanity check into debug code |
| CVE-2026-64156 | 5.5 | 5.4 | Linux | Linux | — | netfs, afs: Fix write skipping in dir/link writepages |
| CVE-2026-63806 | 7.1 | 4.9 | Linux | Linux | CWE-617 | KVM: Replace guest-triggerable BUG_ON() in ioeventfd datamatch with get_unali… |
| CVE-2026-64094 | 5.5 | 4.9 | Linux | Linux | CWE-476 | batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface |
| CVE-2026-63809 | 7.8 | 4.8 | Linux | Linux | — | bpf: use kvfree() for replaced sysctl write buffer |
| CVE-2026-64098 | 7.8 | 4.7 | Linux | Linux | CWE-667 | drm/virtio: use uninterruptible resv lock for plane updates |
| CVE-2026-64106 | 9.0 | 4.2 | Linux | Linux | — | KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits |
| CVE-2026-53369 | 8.4 | 4.2 | Linux | Linux | — | udf: reject descriptors with oversized CRC length |
| CVE-2026-63797 | 8.4 | 4.1 | Linux | Linux | CWE-416 | rpmsg: char: Fix use-after-free on probe error path |
| CVE-2026-53378 | 5.5 | 3.8 | Linux | Linux | CWE-401 | drm/colorop: Fix blob property reference tracking in state lifecycle |
| CVE-2026-64107 | 5.5 | 3.8 | Linux | Linux | CWE-476 | ASoC: codecs: pcm512x: fix null-ptr dereference in pcm512x_overclock_xxx_put() |
| CVE-2026-64146 | 5.5 | 3.8 | Linux | Linux | CWE-401 | erofs: fix metabuf leak in inode xattr initialization |
| CVE-2026-64159 | 5.5 | 3.8 | Linux | Linux | — | netfs: Fix zeropoint update where i_size > remote_i_size |
Results continue: ranks 401–464.
Ranking. Sort: (1) KEV membership, descending. (2) EPSS score, descending. (3) CVSS base score, descending. (4) CVE ID, ascending. CVEs lacking EPSS or CVSS data sort below those that have it within their KEV tier and are labeled AWAITING ENRICHMENT. Missing scores are never imputed.
Standings. Vendor tables exclude records whose vendor field is a placeholder (n/a, unknown); the excluded count is stated under the standings. Rate stats are arithmetic over published figures: KEV/100 = KEV additions YTD ÷ CVEs YTD × 100; Med CVSS and Med EPSS are medians over the vendor's year-to-date disclosures.
Day boundary. A day is a UTC calendar day. This page covers 2026-07-19 00:00:00–23:59:59 UTC. All times shown are UTC.
Feed status for this edition. cvelist: ok · kev: ok · epss: ok · nvd: ok.
Sources. CVE records from the CVE Program (cvelistV5). Enrichment from the National Vulnerability Database (NIST). Known-exploited status from the CISA KEV catalog. Exploit probability from FIRST EPSS. Open-source advisories from OSV.dev. This page reports the public record; it does not analyze, rank by opinion, or editorialize. See full methodology.
Machine-readable. This edition as JSON or CSV — the ranked results, transactions, and counts, for citation or ingestion. Frozen at publication; later changes appear as transactions on later editions.