boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Sunday, July 19, 2026 · all times UTC← 2026-07-18 · archive · 2026-07-20 →

Security Box Score — July 19, 2026 — page 2

Edition of July 19, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–464 of 464
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-637947.83.7LinuxLinuxCWE-787KVM: SVM: Fix page overflow in sev_dbg_crypt() for ENCRYPT path
CVE-2026-641527.83.7LinuxLinux—iommu: Handle unmap error when iommu_debug is enabled
CVE-2026-638188.43.6LinuxLinux—f2fs: validate orphan inode entry count
CVE-2026-638158.43.5LinuxLinux—f2fs: bound i_inline_xattr_size for non-inline-xattr inodes
CVE-2026-533817.83.5LinuxLinuxCWE-416virtiofs: fix UAF on submount umount
CVE-2026-638078.83.3LinuxLinuxCWE-125KVM: x86/mmu: Ensure hugepage is in by slot before checking max mapping level
CVE-2026-638047.83.3LinuxLinuxCWE-416gfs2: fix use-after-free in gfs2_qd_dealloc
CVE-2026-641395.53.3LinuxLinuxCWE-401ksmbd: fix SID memory leak in set_posix_acl_entries_dacl() on overflow
CVE-2026-641127.83.2LinuxLinuxCWE-367rbd: eliminate a race in lock_dwork draining on unmap
CVE-2026-534027.13.2LinuxLinuxCWE-125fbdev: fbcon: fix out-of-bounds read in err_out of fbcon_do_set_font()
CVE-2026-638177.83.1LinuxLinux—f2fs: validate compress cache inode only when enabled
CVE-2026-533887.83.0LinuxLinuxCWE-416fuse: re-lock request before replacing page cache folio
CVE-2026-638037.83.0LinuxLinuxCWE-416hdlc_ppp: sync per-proto timers before freeing hdlc state
CVE-2026-638027.83.0LinuxLinuxCWE-416blk-cgroup: fix UAF in __blkcg_rstat_flush()
CVE-2026-533825.53.0LinuxLinuxCWE-476media: vidtv: fix NULL pointer dereference in vidtv_mux_push_si
CVE-2026-533855.53.0LinuxLinuxCWE-476vc_screen: fix null-ptr-deref in vcs_notifier() during concurrent vcs_write
CVE-2026-638288.42.9LinuxLinux—apparmor: mediate the implicit connect of TCP fast open sendmsg
CVE-2026-638247.82.8LinuxLinux—KEYS: fix overflow in keyctl_pkey_params_get_2()
CVE-2026-534035.52.8LinuxLinuxCWE-476fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var
CVE-2026-533935.52.8LinuxLinux—nfsd: reset write verifier on deferred writeback errors
CVE-2026-640905.52.7LinuxLinux—batman-adv: tt: avoid empty VLAN responses
CVE-2026-640925.52.7LinuxLinux—batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown
CVE-2026-63811await2.7LinuxLinux—f2fs: read COW data with the original inode during atomic write
CVE-2026-533748.82.6LinuxLinux—drm/amdgpu: zero-initialize GART table on allocation
CVE-2026-533758.82.6LinuxLinux—drm/amdgpu/vce: Prevent partial address patches
CVE-2026-638298.82.6LinuxLinux—net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-638147.82.6LinuxLinux—f2fs: validate ACL entry sizes in f2fs_acl_from_disk()
CVE-2026-641457.82.6LinuxLinuxCWE-787wifi: wilc1000: fix dma_buffer leak on bus acquire failure
CVE-2026-641475.52.6LinuxLinuxCWE-401pds_core: fix debugfs_lookup dentry leak and error handling
CVE-2026-638167.82.5LinuxLinux—f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode
CVE-2026-641037.82.5LinuxLinuxCWE-416scsi: isci: Fix use-after-free in device removal path
CVE-2026-641217.12.5LinuxLinuxCWE-125net: ifb: report ethtool stats over num_tx_queues
CVE-2026-637985.52.5LinuxLinuxCWE-401irqchip/imgpdc: Fix resource leak, add missing chained handler cleanup on remove
CVE-2026-641015.52.5LinuxLinux—fwctl: pds: Validate RPC input size before parsing
CVE-2026-640177.82.4LinuxLinux—blk-mq: pop cached request if it is usable
CVE-2026-638337.12.4LinuxLinux—ntfs3: reject direct userspace writes to reserved $LX* xattrs
CVE-2026-638237.82.4LinuxLinux—keys: Pin request_key_auth payload in instantiate paths
CVE-2026-638277.82.4LinuxLinux—apparmor: fix use-after-free in rawdata dedup loop
CVE-2026-533705.52.4LinuxLinux—perf/x86/intel: Improve validation and configuration of ACR masks
CVE-2026-533775.52.3LinuxLinux—drm/msm: always recover the gpu
CVE-2026-641295.52.3LinuxLinuxCWE-401mm/migrate_device: fix spinlock leak in migrate_vma_insert_huge_pmd_page
CVE-2026-641355.52.2LinuxLinuxCWE-674hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX
CVE-2026-641555.52.3LinuxLinuxCWE-401wifi: ath11k: fix error path leaks in some WMI WOW calls
CVE-2026-641315.52.2LinuxLinux—mm/memory: fix spurious warning when unmapping device-private/exclusive pages
CVE-2026-641195.52.1LinuxLinux—l2tp: use list_del_rcu in l2tp_session_unhash
CVE-2026-641615.52.1LinuxLinuxCWE-401net: ti: icssm-prueth: fix eth_ports_node leak in probe
CVE-2026-533765.52.0LinuxLinux—drm/amdkfd: Add upper bound check for num_of_nodes
CVE-2026-533795.52.1LinuxLinuxCWE-908media: i2c: ov8856: free control handler on error in ov8856_init_controls()
CVE-2026-641665.52.0LinuxLinuxCWE-476firmware: arm_ffa: Check for NULL FF-A ID table while driver registration
CVE-2026-641745.52.0LinuxLinux—wifi: cfg80211: advance loop vars in cfg80211_merge_profile()
CVE-2026-641655.52.0LinuxLinuxCWE-476ARM: integrator: Fix early initialization
CVE-2026-641545.51.9LinuxLinux—drm/msm/adreno: Fix a reference leak in a6xx_gpu_init()
CVE-2026-641855.51.8LinuxLinux—sysfs: don't remove existing directory on update failure
CVE-2026-641867.11.8LinuxLinuxCWE-125iommu/amd: Remove latent out-of-bounds access in IOMMU debugfs
CVE-2026-641685.51.7LinuxLinuxCWE-476spi: sprd: fix error pointer deref after DMA setup failure
CVE-2026-641645.51.7LinuxLinuxCWE-476btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()
CVE-2026-641695.51.6LinuxLinuxCWE-476spi: ep93xx: fix error pointer deref after DMA setup failure
CVE-2026-641735.51.7LinuxLinux—tracing: Do not call map->ops->elt_free() if elt_alloc() fails
CVE-2026-641435.51.5LinuxLinux—platform/x86: uniwill-laptop: Do not enable the charging limit even when forced
CVE-2026-162134.81.4Fantomas42django-blog-zinniaCWE-310Fantomas42 django-blog-zinnia Protected Entry Password entry_protection.py cl…
CVE-2026-534007.81.1LinuxLinuxCWE-362i2c: core: fix adapter registration race
CVE-2026-641675.51.0LinuxLinuxCWE-476kho: skip KHO for crash kernel
CVE-2026-641005.50.8LinuxLinuxCWE-667drm/msm: Fix shrinker deadlock
CVE-2026-641715.50.2LinuxLinuxCWE-667i2c: tegra: fix pm_runtime leak on mutex_lock failure