boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Monday, August 10, 2026 · all times UTC← 2026-08-09 · archive · 2026-08-11 →

Security Box Score — August 10, 2026 — page 2

Edition of August 10, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–670 of 670
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-68406await8.0LinuxLinux—wifi: cfg80211: validate PMSR FTM preamble range
CVE-2026-129712.27.9UnknownLearnPressCWE-918LearnPress < 4.4.4 - Instructor+ Server-Side Request Forgery via openai_apply…
CVE-2026-725788.87.8FreePBXFreePBX FrameworkCWE-352FreePBX Framework - Missing CSRF Protection in Admin Panel Ajax Dispatcher
CVE-2026-683718.47.8LinuxLinux—usb: musb: omap2430: Do not put borrowed of_node in probe
CVE-2026-152295.37.7UnknownPinpoint Booking SystemCWE-863Pinpoint Booking System <= 2.9.9.7.1 - Unauthenticated Arbitrary Booking Pric…
CVE-2026-170215.37.7UnknownSalon Booking SystemCWE-862Salon Booking System – Free Version < 10.30.34 - Unauthenticated Arbitrary Bo…
CVE-2026-572796.07.6Cybozu, IncCybozu GaroonCWE-79Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerab…
CVE-2026-681798.47.6LinuxLinux—misc: nsm: only unlock nsm_dev on post-lock error paths
CVE-2026-68280await7.6LinuxLinux—drm/bridge: cdns-dsi: Replace deprecated UNIVERSAL_DEV_PM_OPS()
CVE-2026-68333await7.6LinuxLinux—dpaa2-switch: put MAC endpoint device on disconnect
CVE-2026-68336await7.6LinuxLinux—bonding: fix devconf_all NULL dereference when IPv6 is disabled
CVE-2026-189345.57.4UnknownRSS Aggregator by FeedzyCWE-863RSS Aggregator by Feedzy < 5.2.6 - Author+ Cross-User Import Job Manipulation…
CVE-2025-302405.17.3TP-Link Systems Inc.HB810(US2) V1.0/1.6/2.0/2.6CWE-59Arbitrary File Read via Improper Symlink Handling in USB HTTPS Access Path in…
CVE-2026-68088await7.2LinuxLinux—usb: gadget: function: rndis: add length check to response query
CVE-2026-68090await7.2LinuxLinux—debugobjects: Plug race against a concurrent OOM disable
CVE-2026-68342await7.3LinuxLinux—ovpn: avoid putting unrelated P2P peer on socket release
CVE-2026-682027.87.1LinuxLinux—ALSA: seq: close a re-opened queue timer in the destructor
CVE-2026-682047.87.1LinuxLinux—media: vivid: check for vb2_is_busy() when toggling caps
CVE-2026-682067.87.1LinuxLinux—media: v4l2-ctrls: validate HEVC active reference counts
CVE-2026-682097.87.1LinuxLinux—media: sun4i-csi: Return queued buffers on start_streaming() failure
CVE-2026-682107.87.1LinuxLinux—media: stm32: dcmi: unregister notifier on probe failure
CVE-2026-682137.87.1LinuxLinux—media: rtl2832_sdr: Return queued buffers on start_streaming() failure
CVE-2026-682167.87.1LinuxLinux—media: pwc: Return queued buffers on start_streaming() failure
CVE-2026-683387.87.1LinuxLinux—net/packet: avoid fanout hook re-registration after unregister
CVE-2026-725226.27.2libexpat projectlibexpatCWE-125libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop b…
CVE-2026-68111await7.2LinuxLinux—drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON()
CVE-2026-68115await7.2LinuxLinux—drm/amdgpu/gfx10: replace BUG_ON() with WARN_ON()
CVE-2026-68234await7.2LinuxLinux—drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved
CVE-2026-68249await7.2LinuxLinux—drm/amdgpu/sdma5.0: replace BUG_ON() with WARN_ON()
CVE-2026-68327await7.2LinuxLinux—wan: wanxl: Only reset hardware after BAR mapping
CVE-2026-68328await7.2LinuxLinux—nfp: Check resource mutex allocation
CVE-2026-68357await7.2LinuxLinux—watchdog: pretimeout: Fix UAF in watchdog_unregister_governor()
CVE-2026-68403await7.2LinuxLinux—wifi: brcmfmac: initialize SDIO data work before cleanup
CVE-2026-68411await7.2LinuxLinux—wifi: mac80211_hwsim: clamp virtio RX length before skb_put
CVE-2026-682197.87.0LinuxLinux—media: nxp: imx8-isi: Fix potential out-of-bounds issues
CVE-2026-68126await7.0LinuxLinux—mac802154: hold an interface reference across the scan worker
CVE-2026-68133await7.0LinuxLinux—ice: fix PTP Call Trace during PTP release
CVE-2026-68139await7.0LinuxLinux—net/mlx5e: Use sender devcom for MPV master-up
CVE-2026-68150await7.0LinuxLinux—fs/super: fix emergency thaw double-unlock of s_umount
CVE-2026-68252await7.0LinuxLinux—drm/amdgpu/sdma7.0: replace BUG_ON() with WARN_ON()
CVE-2026-68256await7.0LinuxLinux—drm/amd/display: detect_link_and_local_sink: DP alt mode timeout path leaks p…
CVE-2026-68271await7.0LinuxLinux—drm/nouveau: fix reversed error cleanup order in ucopy functions
CVE-2026-68272await7.0LinuxLinux—drm/amdgpu: validate CP_GFX_SHADOW chunk size in CS pass1
CVE-2026-68281await7.0LinuxLinux—drm/imagination: Count paired job fence as dependency in prepare_job()
CVE-2026-683877.86.8LinuxLinux—can: raw: add locking for raw flags bitfield
CVE-2026-68122await6.8LinuxLinux—ovpn: fix peer refcount leak in TCP error paths
CVE-2026-68211await6.8LinuxLinux—media: stm32-dcmipp: Return queued buffers on start_streaming() failure
CVE-2026-68275await6.8LinuxLinux—drm/amdgpu: check amdgpu_vm_bo_find() result in GET_MAPPING_INFO
CVE-2026-68282await6.8LinuxLinux—drm/rockchip: analogix_dp: Add missing error check for platform_get_resource()
CVE-2026-68332await6.8LinuxLinux—net: airoha: Fix potential use-after-free in airoha_ppe_deinit()
CVE-2026-68334await6.8LinuxLinux—rxrpc: fix io_thread race in rxrpc_wake_up_io_thread()
CVE-2026-68084await6.7LinuxLinux—staging: vme_user: fix location monitor leak in tsi148 bridge
CVE-2026-68099await6.7LinuxLinux—ksmbd: restore DACL size on check_add_overflow() to avoid malformed ACL
CVE-2026-68243await6.7LinuxLinux—drm/i915/gem: Fix NULL deref in I915_CONTEXT_PARAM_SSEU
CVE-2026-68244await6.7LinuxLinux—drm/i915/gem: Do not leak siblings[] on proto context error
CVE-2026-68246await6.7LinuxLinux—drm/amdgpu/gfx11: replace BUG_ON() with WARN_ON()
CVE-2026-68248await6.7LinuxLinux—drm/i915: Return NULL on error in active_instance
CVE-2026-68254await6.7LinuxLinux—drm/i915/vrr: require valid min/max vfreq for VRR
CVE-2026-68259await6.7LinuxLinux—drm/amdkfd: Check bounds in allocate_event_notification_slot
CVE-2026-68301await6.7LinuxLinux—net: hsr: fix memory leak on slave unregistration by removing synced VLANs
CVE-2026-68309await6.7LinuxLinux—wifi: mt76: connac: fix possible NULL-pointer deref in mt76_connac_mcu_uni_bs…
CVE-2026-68310await6.7LinuxLinux—wifi: mt76: mt7915: guard HE capability lookups
CVE-2026-68324await6.7LinuxLinux—iommu/intel: Fix out-of-bounds memset in dmar_latency_disable()
CVE-2026-68331await6.7LinuxLinux—dpaa2-eth: put MAC endpoint device on disconnect
CVE-2026-68362await6.7LinuxLinux—wifi: ath11k: fix NULL pointer dereference in ath11k_hal_srng_access_begin
CVE-2026-68407await6.7LinuxLinux—wifi: nl80211: free RNR data on MBSSID mismatch
CVE-2026-681627.86.6LinuxLinux—sctp: avoid auth_enable sysctl UAF during netns teardown
CVE-2026-727435.16.6dataeaseSQLBotCWE-79SQLBot 1.10.0 SQText Dashboard Component Stored XSS via v-html
CVE-2026-170234.86.5UnknownSalon Booking SystemCWE-284Salon Booking System – Free Version <= 10.30.33 - Unauthenticated Google Cale…
CVE-2026-682007.86.5LinuxLinux—ALSA: timer: don't re-enter an instance callback that is still running
CVE-2026-682017.86.5LinuxLinux—ALSA: timer: drain a slave's callback before its master detaches it
CVE-2026-682307.36.4LinuxLinux—media: amlogic-c3: Add validations for ae and awb config
CVE-2026-63736.56.4Zyxel NetworksWAH7601CWE-497Sensitive Data Exposure in Zyxel WAH7601 Router
CVE-2026-149415.46.2UnknownCustomer Reviews for WooCommerceCWE-862Customer Reviews for WooCommerce < 5.116.0 - Subscriber+ Missing Authorizatio…
CVE-2026-152385.46.2UnknownMotoPress Hotel BookingCWE-639Hotel Booking Lite < 6.2.3 - Subscriber+ Customer Data Modification via IDOR
CVE-2026-137014.86.3UnknownAdvanced ExcerptCWE-79Advanced Excerpt < 4.5 - Admin+ Stored XSS via Ellipsis Setting
CVE-2026-68092await6.2LinuxLinux—time/jiffies: Register jiffies clocksource before usage
CVE-2026-68102await6.2LinuxLinux—drm/amdgpu: fix aperture mapping leak
CVE-2026-68110await6.2LinuxLinux—drm/amdgpu/sdma4.4.2: replace BUG_ON() with WARN_ON()
CVE-2026-68112await6.2LinuxLinux—drm/amdgpu/gfx9.4.3: replace BUG_ON() with WARN_ON()
CVE-2026-68113await6.2LinuxLinux—drm/amdgpu/gfx12: replace BUG_ON() with WARN_ON()
CVE-2026-68247await6.2LinuxLinux—drm/i915/bios: range check LFP Data Block panel_type2
CVE-2026-68267await6.2LinuxLinux—drm/xe/rtp: Add RING_FORCE_TO_NONPRIV_DENY to OA whitelists
CVE-2026-68306await6.2LinuxLinux—wifi: mt76: mt7996: fix possible NULL-pointer deref in mt7996_mcu_sta_bfer_eht()
CVE-2026-68307await6.2LinuxLinux—wifi: mt76: mt7925: fix crash in reset link replay
CVE-2026-68308await6.2LinuxLinux—wifi: mt76: mt7996: check pointer returned by mt76_connac_get_he_phy_cap()
CVE-2026-68311await6.2LinuxLinux—wifi: mt76: mt7925: guard link STA in decap offload
CVE-2026-68317await6.2LinuxLinux—pds_core: fix auxiliary device add/del races
CVE-2026-68318await6.2LinuxLinux—pds_core: fix use-after-free on workqueue during remove
CVE-2026-68319await6.2LinuxLinux—pds_core: fix deadlock between reset thread and remove
CVE-2026-68372await6.2LinuxLinux—usb: core: port: Deattach Type-C connector on component unbind
CVE-2026-68408await6.2LinuxLinux—wifi: cfg80211: convert pmsr_free_wk to wiphy_work to fix deadlock
CVE-2026-189605.46.2UnknownBlock User AccountCWE-287Block User Account < 2.0.1 - Subscriber+ Account Block Bypass via Application…
CVE-2026-68087await6.0LinuxLinux—HID: wacom: use GFP_ATOMIC in wacom_wac_queue_flush()
CVE-2026-68089await6.0LinuxLinux—iio: core: fix uninitialized data in debugfs
CVE-2026-68095await6.0LinuxLinux—fuse-uring: fix race between registration and connection abortion
CVE-2026-68233await6.0LinuxLinux—drm/vc4: Shut down BO cache timer before teardown
CVE-2026-68238await6.0LinuxLinux—drm/amdgpu: Release VFCT ACPI table reference
CVE-2026-68239await6.0LinuxLinux—drm/ttm: Account for NULL and handle pages in ttm_pool_backup
CVE-2026-68292await6.0LinuxLinux—ice: prevent tstamp ring allocation for non-PF VSI types
CVE-2026-68356await6.0LinuxLinux—watchdog: airoha: Prevent division by zero when clock frequency is zero
CVE-2026-681637.85.9LinuxLinux—mm/page_vma_mapped: fix device-private PMD handling
CVE-2026-725947.65.9lobehublobe-chatCWE-79lobehub lobe-chat - Stored Cross-Site Scripting via Unrestricted SVG Avatar U…
CVE-2026-725765.45.9BluditBluditCWE-79Bludit - Stored Cross-Site Scripting via Malicious SVG Logo Upload
CVE-2026-682948.85.8LinuxLinux—net: qrtr: restrict socket creation to the initial network namespace
CVE-2026-68428await5.8LinuxLinux—KVM: x86/mmu: Fix use-after-free on vendor module reload
CVE-2026-681787.85.7LinuxLinux—misc: nsm: pin the module while the device is open
CVE-2026-682287.85.7LinuxLinux—media: chips-media: wave5: Move src_buf Removal to finish_encode
CVE-2026-682457.85.7LinuxLinux—drm/amdgpu: fix lifetime issue of amdgpu_vm_get_task_info_pasid()
CVE-2026-682607.85.7LinuxLinux—drm/imagination: acquire vm_ctx->lock before mapping memory to GPU VM
CVE-2026-210836.85.6Samsung MobileSmart SwitchCWE-20Improper input validation in Smart Switch prior to version 3.7.72.6 allows ad…
CVE-2026-682408.85.5LinuxLinux—drm/gpusvm: publish dpagemap early to avoid device mapping leak on error
CVE-2026-683307.85.5LinuxLinux—net: airoha: Fix DMA direction for NPU mailbox buffer
CVE-2026-170196.15.6UnknownJetEngineCWE-79JetEngine < 3.8.13.1 - Unauthenticated Stored XSS via Form File Upload (SVG)
CVE-2026-170204.35.5UnknownSalon Booking SystemCWE-639Salon Booking System – Free Version <= 10.31.0 - Subscriber+ Arbitrary Bookin…
CVE-2026-68285await5.6LinuxLinux—LoongArch: BPF: Fix memory leak in bpf_jit_free()
CVE-2026-68288await5.6LinuxLinux—net: drop_monitor: fix info leak in NET_DM_ATTR_PAYLOAD
CVE-2026-68289await5.6LinuxLinux—tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream()
CVE-2026-68347await5.6LinuxLinux—iommu/amd: Fix IRQ unsafe locking in gdom allocation
CVE-2026-68364await5.6LinuxLinux—drm/amd/display: Fix ISM dc_lock deadlock during suspend
CVE-2026-68375await5.6LinuxLinux—bnxt_en: Handle partially initialized auxiliary devices
CVE-2026-683298.85.2LinuxLinux—iommu/amd: Wait for completion instead of returning early in iommu_completion…
CVE-2026-681897.85.3LinuxLinux—Bluetooth: hci_sync: Protect UUID list traversal
CVE-2026-682297.15.3LinuxLinux—media: cedrus: skip invalid H.264 reference list entries
CVE-2026-681737.15.1LinuxLinux—ublk: wait on ublk_dev_ready() instead of ub->completion
CVE-2026-681727.15.1LinuxLinux—arm64: make huge_ptep_get handled unaligned addresses
CVE-2026-170105.45.1UnknownSaitama Addon PackCWE-79Saitama Addon Pack <= 1.0.8 - Contributor+ Stored XSS via Post Meta
CVE-2026-190755.05.1UnknownAll-in-One Video GalleryCWE-918All-in-One Video Gallery < 4.9.2 - Subscriber+ Server-Side Request Forgery vi…
CVE-2026-664844.65.0GNUcpioCWE-22Path Traversal in GNU cpio
CVE-2026-68416await5.0LinuxLinux—mtd: fix double free and WARN_ON in add_mtd_device() error paths
CVE-2026-210606.74.9Samsung MobileSamsung Mobile DevicesCWE-20Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1…
CVE-2026-210735.24.9Samsung MobileSamsung Mobile Devices—Improper input validation in Galaxy Themes prior to SMR Aug-2026 Release 1 al…
CVE-2026-68094await4.9LinuxLinux—sched_ext: Preserve rq tracking across local DSQ dispatch
CVE-2026-68105await4.9LinuxLinux—drm/amdgpu: Fix kernel panic during driver load failure
CVE-2026-68109await4.9LinuxLinux—drm/amdgpu/sdma7.1: replace BUG_ON() with WARN_ON()
CVE-2026-68114await4.9LinuxLinux—drm/amdgpu/gfx12.1: replace BUG_ON() with WARN_ON()
CVE-2026-68237await4.9LinuxLinux—drm/amdgpu/userq: fix indefinite fence wait during GPU reset
CVE-2026-68291await4.9LinuxLinux—idpf: fix max_vport related crash on allocation error during init
CVE-2026-68337await4.9LinuxLinux—bpf: Reject redirect helpers without a bpf_net_context
CVE-2026-681777.84.8LinuxLinux—tracing: Delay module ref count for "enable_event" trigger
CVE-2026-682957.84.8LinuxLinux—LoongArch: BPF: Zero-extend signed ALU32 div/mod results
CVE-2026-684047.84.7LinuxLinux—wifi: cfg80211: use wiphy work for socket owner autodisconnect
CVE-2025-156802.44.8TBEATBEA TLogger (TBEA Communication Box 3rd Generation)CWE-497Information Disclosure via UART
CVE-2026-68418await4.8LinuxLinux—RDMA/irdma: Prevent user-triggered null deref on QP create
CVE-2026-182004.34.6UnknownFoodBoxBookerCWE-639FoodBoxBooker < 1.0.8 - Subscriber+ Arbitrary User Profile Update
CVE-2026-142113.84.6UnknownBooking for Appointments and Events CalendarCWE-639Amelia Pro < 9.7 - Provider+ Arbitrary Customer Data Disclosure and Modificat…
CVE-2026-682747.84.5LinuxLinux—drm/xe/guc: Fix buffer overflow in steered register list allocation
CVE-2025-327364.94.5Ping IdentityPingFederateCWE-352PingFederate Administrative Console CSRF weaknesses
CVE-2026-683407.74.4LinuxLinux—hwmon: occ: validate poll response sensor blocks
CVE-2026-725835.44.4fastschemafastschemaCWE-79fastschema - Stored Cross-Site Scripting via MIME Type Bypass in File Upload
CVE-2026-68086await4.4LinuxLinux—mm/khugepaged: write all dirty file folios when collapsing
CVE-2026-691126.94.2huggingfaceaccelerateCWE-22Hugging Face Accelerate 1.14.0 Path Traversal and DoS via weight_map
CVE-2026-210636.84.3Samsung MobileSamsung Mobile DevicesCWE-926Improper export of android application components in AppLock prior to SMR Aug…
CVE-2026-210705.14.0Samsung MobileSamsung Mobile DevicesCWE-20Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 …
CVE-2026-68423await4.0LinuxLinux—mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy()
CVE-2026-68424await4.0LinuxLinux—mtd: virt_concat: fix use-after-free in mtd_virt_concat_destroy_joins()
CVE-2025-302388.63.9TP-Link Systems Inc.HB810(US2) V1.0/1.6/2.0/2.6CWE-863Privilege Escalation via Improper Authorization in User Management in multipl…
CVE-2025-302398.53.9TP-Link Systems Inc.HB810(US2) V1.0/1.6/2.0/2.6CWE-321Sensitive Data Exposure due to Hardcoded Cryptographic Keys in Multiple TP-Li…
CVE-2026-729137.33.9kovidgoyalkittyCWE-77Kitty: Command injection into the child shell via chained @kitty-echo + @kitt…
CVE-2026-682537.83.8LinuxLinux—drm/i915/hdcp: check streams[] bounds before overflow
CVE-2026-664085.13.8ECOVACS ROBOTICSDEEBOT PRO M1CWE-1391The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with w…
CVE-2026-681288.83.4LinuxLinux—ice: reject out-of-range ptype in ice_parser_profile_init
CVE-2026-681428.83.4LinuxLinux—geneve: require CAP_NET_ADMIN in the device netns for changelink
CVE-2026-681217.83.4LinuxLinux—pppoe: reload header pointer after dev_hard_header()
CVE-2026-681437.83.4LinuxLinux—net: slip: serialize receive against buffer reallocation
CVE-2026-681457.83.4LinuxLinux—iomap: fix out-of-bounds bitmap_set() with zero-length range
CVE-2026-682227.83.4LinuxLinux—media: msi2500: Return queued buffers on start_streaming() failure
CVE-2026-682577.83.4LinuxLinux—drm/amdkfd: fix 32-bit overflow in CWSR total size calculation
CVE-2026-682647.83.4LinuxLinux—drm/xe/pt: Reset current_op in xe_pt_update_ops_init()
CVE-2026-683707.83.4LinuxLinux—usb: gadget: dummy_hcd: prevent fifo_req reuse during giveback
CVE-2026-682937.13.4LinuxLinux—net/mlx5: Fix MCIA register buffer overflow on 32 dword reads
CVE-2026-725705.43.4cube-rootdirectory-serveCWE-79cube-root directory-serve - Stored Cross-Site Scripting via Malicious Filename
CVE-2026-631055.13.4RazinsoftReady eCommerceCWE-79ReadyEcommerce < 4.5.2 Stored XSS via Chat and Support Ticket Systems
CVE-2026-664864.63.3GNUcpioCWE-116Improper Output Encoding in GNU cpio
CVE-2026-684017.83.3LinuxLinux—firmware: arm_ffa: Fix out-of-bound writes in ffa_setup_and_transmit()
CVE-2026-681088.83.2LinuxLinux—drm/amdgpu/vce: fix integer overflow in image size
CVE-2026-681498.43.2LinuxLinux—fs: preserve ACL_DONT_CACHE state in forget_cached_acl()
CVE-2026-681477.83.2LinuxLinux—fscrypt: Avoid dynamic allocation in fscrypt_get_devices()
CVE-2026-682847.83.2LinuxLinux—bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg()
CVE-2026-683357.83.2LinuxLinux—rds: drop incoming messages that cross network namespace boundaries
CVE-2026-719698.43.1OP-TEEoptee_osCWE-787OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations
CVE-2026-681527.83.1LinuxLinux—amt: fix use-after-free in AMT delayed works
CVE-2026-682667.83.1LinuxLinux—drm/xe: Hold a dma-buf reference for imported BOs
CVE-2026-682737.83.1LinuxLinux—drm/amdgpu: Fix context pstate override handling
CVE-2026-683847.83.1LinuxLinux—drm/xe/vf: Fix VF CCS attach/detach race with in-flight BO moves
CVE-2026-684157.83.1LinuxLinux—xfrm: clear mode callbacks after failed mode setup
CVE-2026-727187.03.1aaif-goosegooseCWE-94goose: Arbitrary command execution in goose CLI via `goose review` via git co…
CVE-2026-683807.83.0LinuxLinux—accel/amdxdna: Fix use-after-free of mm_struct in job scheduler
CVE-2026-566195.43.0HCLSoftwareHCL BigFix MobileCWE-79HCL BigFix Mobile is vulnerable to Reflected Cross-Site Scripting (Reflected …
CVE-2026-664854.63.0GNUcpioCWE-789Uncontrolled Memory Allocation in GNU cpio
CVE-2026-682627.12.9LinuxLinux—drm/imagination: Fix user array stride in pvr_set_uobj_array()
CVE-2026-683487.12.9LinuxLinux—ASoC: tas2781: bound firmware description string parsing
CVE-2026-183704.82.9eradmanentrCWE-122Heap-based buffer overflow in entr
CVE-2026-636227.82.8Red HatRed Hat Enterprise Linux 10CWE-59Libvirt: swtpm privilege escalation via symlink following
CVE-2026-681047.82.8LinuxLinux—drm/amdgpu: invoke pm_genpd_remove() before freeing genpd
CVE-2026-681067.82.8LinuxLinux—drm/amdgpu: fix division by zero with invalid uvd dimensions
CVE-2026-682977.82.8LinuxLinux—tipc: fix u16 MTU truncation in media and bearer MTU validation
CVE-2026-683057.82.8LinuxLinux—drm/xe/vf: Add drm_dev guards when detaching CCS read/write buffers
CVE-2026-683147.82.7LinuxLinux—net: mctp i3c: clean up notifier and buses if driver register fails
CVE-2026-683827.82.8LinuxLinux—drm/xe/guc: Hold device ref until queue teardown completes
CVE-2026-683837.82.8LinuxLinux—drm/xe/guc: Keep scheduler timeline name alive
CVE-2026-683927.82.8LinuxLinux—Bluetooth: mgmt: fix locking in unpair_device/disconnect_sync
CVE-2026-683997.82.8LinuxLinux—bpf: Fix UAF in sock clone early bailouts
CVE-2026-684197.82.7LinuxLinux—RDMA/irdma: Prevent rereg_mr for non-mem regions
CVE-2026-681347.32.8LinuxLinux—ptp: ptp_s390: Add missing facility check
CVE-2026-682657.32.8LinuxLinux—drm/xe/vm: Fix BO prefetch with CONSULT_MEM_ADVISE_PREF_LOC
CVE-2026-682587.12.8LinuxLinux—drm/amdkfd: Check bounds on CRIU restore queue type and mqd size
CVE-2026-681078.82.7LinuxLinux—drm/amdgpu/vcn4: avoid rereading IB param length
CVE-2026-683747.82.7LinuxLinux—usb: core: sysfs: add lock to bos_descriptors_read()
CVE-2026-683777.82.6LinuxLinux—net/sched: act_tunnel_key: Defer dst_release to RCU callback
CVE-2026-683917.82.7LinuxLinux—Bluetooth: mgmt: hold reference for hci_conn in mgmt_pending_cmds
CVE-2026-125705.52.7keras-teamkeras-team/kerasCWE-770Denial of Service via HDF5 Shape Bomb in keras.models.load_model() in keras-t…
CVE-2026-682987.82.6LinuxLinux—drm/xe/vm: Fix SVM leak on resv obj alloc failure in xe_vm_create()
CVE-2026-684007.82.6LinuxLinux—firmware: arm_ffa: Fix Endpoint Memory Access Descriptor offset calculation
CVE-2026-683207.32.6LinuxLinux—sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid
CVE-2026-210688.42.5Samsung MobileSamsung Mobile DevicesCWE-121Stack-based buffer overflow in libril_sem.so prior to SMR Aug-2026 Release 1 …
CVE-2026-681537.82.5LinuxLinux—libceph: remove debugfs files before client teardown
CVE-2026-682367.82.4LinuxLinux—drm/amd/display: set new_stream to NULL after release
CVE-2026-682637.82.4LinuxLinux—drm/imagination: Fix double call to drm_sched_entity_fini()
CVE-2026-682907.82.4LinuxLinux—rds: tcp: unregister sysctl before tearing down listen socket
CVE-2026-683947.82.4LinuxLinux—Bluetooth: MGMT: revalidate LOAD_CONN_PARAM queued update
CVE-2026-684277.82.5LinuxLinux—gpu: host1x: Fix use-after-free in host1x_bo_clear_cached_mappings
CVE-2026-664046.02.4ECOVACS ROBOTICSDEEBOT PRO M1CWE-295DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQT…
CVE-2026-210826.92.4Samsung MobileSamsung HealthCWE-23Relative path traversal in Samsung Health prior to version 7.0.0 allows local…
CVE-2026-715768.52.2Red HatMulticluster Global HubCWE-345Multicluster-global-hub: multicluster-global-hub: manager trusts self-asserte…
CVE-2026-87188.42.2zephyrprojectzephyrCWE-787Out-of-bounds write in DTLS peer Connection ID getsockopt (`TLS_DTLS_PEER_CID…
CVE-2026-681167.92.1LinuxLinux—vxlan: mdb: Fix source list corruption on a failed replace
CVE-2026-683167.82.1LinuxLinux—accel: ethosu: Fix element size accounting for cmd stream validation
CVE-2026-683237.82.0LinuxLinux—tipc: serialize udp bearer replicast list updates
CVE-2026-684177.82.0LinuxLinux—RDMA/siw: publish QP after initialization
CVE-2026-719675.72.0OP-TEEoptee_osCWE-476OP-TEE OS 4.10.0 NULL Pointer Dereference DoS via Widevine PTA open_session
CVE-2026-150595.52.0systemdsystemd-oomdCWE-22systemd-oomd: unprivileged users can terminate arbitrary processes
CVE-2026-185032.42.0Python Software FoundationCPythonCWE-1176Super-linear CPU usage for unbounded input to csv.Sniffer.sniff()
CVE-2026-193821.81.9AlmicoSpeedfanCWE-401Almico Speedfan MSR Index speedfan.sys KiSystemCall64 memory leak
CVE-2026-190745.31.9UnknownAdvanced Classifieds & Directory ProCWE-200Advanced Classifieds & Directory Pro < 3.4.3 - Unauthenticated Non-Public Lis…
CVE-2026-193801.81.9Mullvadwireguard.sysCWE-664Mullvad wireguard.sys IOCTL AdapterState reference count
CVE-2026-131338.41.9LY CorporationLINE for WindowsCWE-427A vulnerability has been identified in LineInst.exe (LINE for Windows) prior …
CVE-2026-684207.11.7LinuxLinux—xfrm: reject optional IPTFS templates in outbound policies
CVE-2026-591124.41.7Estonian Information System Authority (RIA)libdigidocppCWE-347Signature validation vulnerability affecting DigiDoc applications
CVE-2026-210665.11.6Samsung MobileSamsung Mobile DevicesCWE-20Improper input validation in libcodec2_sec_flacdec.so prior to SMR Aug-2026 R…
CVE-2026-210675.11.6Samsung MobileSamsung Mobile Devices—Improper input validation in libsmsd.so prior to SMR Aug-2026 Release 1 allow…
CVE-2026-210725.11.6Samsung MobileSamsung Mobile DevicesCWE-20Improper input validation in VC1 codec in libsavsvc.so prior to SMR Aug-2026 …
CVE-2026-210806.91.5Samsung MobileSmart SwitchCWE-312Cleartext storage of sensitive information in Smart Switch prior to version 3…
CVE-2026-210654.81.5Samsung MobileSamsung Mobile DevicesCWE-20Out-of-bounds write in libcodec2secqcelpdec.so prior to SMR Aug-2026 Release …
CVE-2026-193817.11.4KingstonFURY CTRL RGB Control SoftwareCWE-266Kingston FURY CTRL RGB Control Software Driver NTIOLib_KSFX.sys privileges ma…
CVE-2026-681037.11.4LinuxLinux—drm/amdgpu: reject mapping a reserved doorbell to a new queue
CVE-2026-63682.11.2glibcglibcCWE-908wordexp with WRDE_APPEND can return or use invalid memory
CVE-2026-210695.11.2Samsung MobileSamsung Mobile DevicesCWE-681Incorrect conversion between numeric types in VC1 codec in libsavsvc.so prior…
CVE-2026-210715.11.2Samsung MobileSamsung Mobile DevicesCWE-20Improper input validation in MPEG4 codec in libsavsvc.so prior to SMR Aug-202…
CVE-2026-210586.91.1Samsung MobileSamsung Mobile DevicesCWE-20Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1…
CVE-2026-210747.21.1Samsung MobileBixbyCWE-276Incorrect default permissions in Bixby prior to version 4.0.86.0 allows local…
CVE-2026-664102.31.1ECOVACS ROBOTICSAndroid App "ECOVACS PRO"CWE-295Android and iOS apps ECOVACS PRO App improperly validate server certificates.…
CVE-2026-210784.71.0Samsung MobileSmart SwitchCWE-345Insufficient verification of data authenticity in Smart Switch trouble scanni…
CVE-2026-719688.40.9OP-TEEoptee_osCWE-416OP-TEE OS 4.10.0 Use-After-Free via Trusted Application Loader TA_FLAG_CONCUR…
CVE-2026-666425.40.9WP UmbrellaWP UmbrellaCWE-352WordPress WP Umbrella plugin 2.24.2-2.26.2 - Cross Site Request Forgery (CSRF…
CVE-2026-194113.90.8Red HatRed Hat Enterprise Linux 7CWE-476Shim/dp.c library: null-pointer dereference in is_removable_media_path() when…
CVE-2026-636235.50.7Red HatRed Hat Enterprise Linux 10CWE-732Libvirt: information disclosure via world-readable storage volume images duri…
CVE-2026-210624.80.7Samsung MobileSamsung Mobile DevicesCWE-939Authorization bypass in SemClipboardService prior to SMR Aug-2026 Release 1 a…
CVE-2026-664062.30.7ECOVACS ROBOTICSDEEBOT PRO M1CWE-295DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate v…
CVE-2026-210647.00.6Samsung MobileSamsung Mobile DevicesCWE-284Improper access control in Weaver prior to SMR Aug-2026 Release 1 allows loca…
CVE-2026-210596.90.6Samsung MobileSamsung Mobile DevicesCWE-926Improper export of android application components in Samsung Contacts prior t…
CVE-2026-210766.90.6Samsung MobileSamsung HealthCWE-863Incorrect authorization in Samsung Health prior to version 7.0.0 allows local…
CVE-2026-210776.90.6Samsung MobileSamsung HealthCWE-863Incorrect authorization in Samsung Health prior to version 7.0.0 allows local…
CVE-2026-681487.80.6LinuxLinux—fscrypt: Add missing superblock check in find_or_insert_direct_key()
CVE-2026-210846.90.5Samsung MobileSmartThingsCWE-284Improper access control in SmartThings prior to version 1.8.47.24 allows loca…
CVE-2026-210815.10.6Samsung MobileSamsungPassAutofillCWE-926Improper export of android application components in SamsungPassAutofill prio…
CVE-2026-118122.50.2zephyrprojectzephyrCWE-362UpdateHub: race condition on shared context causes out-of-bounds write and DoS
CVE-2026-150604.70.2systemdsystemd-machinedCWE-284systemd-machined: unprivileged users can terminate arbitrary processes
CVE-2026-210797.00.0Samsung MobileSmart SwitchCWE-311Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.…
CVE-2026-167426.70.0systemdsystemd-homedCWE-269systemd-homed: local privilege escalation via missing home-record signature v…