| CVE-2026-68477 | 9.8 | 50.5 | Linux | Linux | — | ipvs: fix more places with wrong ipv6 transport offsets |
| CVE-2026-72129 | 9.8 | 50.5 | Linux | Linux | — | nvmet-rdma: handle inline data with a nonzero offset |
| CVE-2026-72226 | 9.8 | 50.5 | Linux | Linux | — | batman-adv: tt: prevent TVLV OOB check overflow |
| CVE-2026-72398 | 9.8 | 50.5 | Linux | Linux | — | sctp: add INIT verification after cookie unpacking |
| CVE-2026-74280 | 10.0 | 50.2 | Linux | Linux | — | crypto: marvell/octeontx - fix DMA cleanup using wrong loop index |
| CVE-2026-72020 | 9.8 | 50.2 | Linux | Linux | — | ipvs: reset full ip_vs_seq structs in ip_vs_conn_new |
| CVE-2026-72041 | 9.8 | 50.2 | Linux | Linux | — | espintcp: use sk_msg_free_partial to fix partial send |
| CVE-2026-72251 | 9.8 | 50.2 | Linux | Linux | — | netfilter: nf_nat_sip: reload possible stale data pointer |
| CVE-2026-74267 | 9.8 | 50.2 | Linux | Linux | — | net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek befor… |
| CVE-2026-72296 | 9.1 | 50.2 | Linux | Linux | — | net: ife: require ETH_HLEN to be pullable in ife_decode() |
| CVE-2026-72247 | 7.5 | 49.9 | Linux | Linux | — | netfilter: nf_conncount: fix zone comparison in tuple dedup |
| CVE-2026-72409 | 7.5 | 49.9 | Linux | Linux | — | net: mvneta: re-enable percpu interrupt on resume |
| CVE-2026-72502 | 7.5 | 49.9 | Linux | Linux | — | tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) |
| CVE-2026-72191 | 9.8 | 49.6 | Linux | Linux | — | ntfs3: validate split-point offset in indx_insert_into_buffer |
| CVE-2026-72231 | 7.5 | 49.5 | Linux | Linux | — | batman-adv: tt: avoid request storms during pending request |
| CVE-2026-72242 | 7.5 | 49.5 | Linux | Linux | — | selinux: avoid sk_socket dereference in selinux_sctp_bind_connect() |
| CVE-2026-72253 | 7.5 | 49.5 | Linux | Linux | — | netfilter: nf_conntrack_sip: validate skb_dst() before accessing it |
| CVE-2026-74282 | 7.5 | 49.5 | Linux | Linux | — | tipc: prevent snt_unacked underflow on CONN_ACK |
| CVE-2026-72234 | 9.8 | 49.4 | Linux | Linux | — | batman-adv: access unicast_ttvn skb->data only after skb realloc |
| CVE-2026-72464 | 7.5 | 49.4 | Linux | Linux | — | xprtrdma: Repost Receive buffers for malformed replies |
| CVE-2026-72399 | 9.8 | 49.3 | Linux | Linux | — | net: enetc: check the number of BDs needed for xdp_frame |
| CVE-2026-72014 | 9.8 | 49.0 | Linux | Linux | — | drbd: reject data replies with an out-of-range payload size |
| CVE-2026-72473 | 9.8 | 49.0 | Linux | Linux | — | xprtrdma: Decouple req recycling from RPC completion |
| CVE-2026-72451 | 9.8 | 48.9 | Linux | Linux | — | xfrm: Fix xfrm state cache insertion race |
| CVE-2026-74281 | 7.5 | 48.9 | Linux | Linux | — | tipc: reject inverted service ranges from peer bindings |
| CVE-2026-72422 | 9.8 | 48.8 | Linux | Linux | — | ksmbd: fix use-after-free of conn->preauth_info in concurrent SMB2 NEGOTIATE |
| CVE-2026-72465 | 7.5 | 48.6 | Linux | Linux | — | xprtrdma: Sanitize the reply credit grant after parsing |
| CVE-2026-72149 | 7.5 | 48.2 | Linux | Linux | — | dmaengine: tegra: Fix burst size calculation |
| CVE-2026-72098 | 9.8 | 48.2 | Linux | Linux | — | dm-verity: fix buffer overflow in FEC calculation |
| CVE-2026-72317 | 9.8 | 48.1 | Linux | Linux | — | SUNRPC: pin upper rpc_clnt across the TLS connect_worker |
| CVE-2026-72323 | 9.8 | 48.1 | Linux | Linux | — | ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() |
| CVE-2026-72381 | 9.8 | 48.1 | Linux | Linux | — | ksmbd: fix use-after-free of fp->owner.name in durable handle owner check |
| CVE-2026-72472 | 9.8 | 48.1 | Linux | Linux | — | nfs: use nfsi->rwsem to protect traversal of the file lock list |
| CVE-2026-72310 | 8.1 | 48.0 | Linux | Linux | — | smb: client: fix overflow in passthrough ioctl bounds check |
| CVE-2026-72366 | 9.8 | 47.9 | Linux | Linux | — | netfs: Fix netfs_create_write_req() to handle async cache object creation |
| CVE-2026-72160 | 8.8 | 47.6 | Linux | Linux | — | ocfs2: reject dinodes with non-canonical i_mode type |
| CVE-2026-72107 | 8.8 | 47.6 | Linux | Linux | — | dm era: fix out-of-bounds memory access for non-zero start sector |
| CVE-2026-72330 | 7.5 | 47.4 | Linux | Linux | — | net/tls: Consume empty data records in tls_sw_read_sock() |
| CVE-2026-72185 | 9.8 | 47.3 | Linux | Linux | — | ntfs: fix WARN_ON for resident attribute in ntfs_map_runlist_nolock() |
| CVE-2026-72221 | 9.8 | 47.3 | Linux | Linux | — | sunrpc: wait for in-flight TLS handshake callback when cancel loses race |
| CVE-2026-72348 | 9.1 | 47.3 | Linux | Linux | — | netfilter: ip6tables: mark malformed IPv6 extension headers for hotdrop |
| CVE-2026-72356 | 7.5 | 47.1 | Linux | Linux | — | cifs: Fix missing credit release on failure in cifs_issue_read() |
| CVE-2026-72373 | 7.5 | 47.1 | Linux | Linux | — | afs: Fix missing NULL pointer check in afs_break_some_callbacks() |
| CVE-2026-68476 | 9.8 | 46.9 | Linux | Linux | — | ipvs: reload ip header after head reallocation |
| CVE-2026-72046 | 9.8 | 46.9 | Linux | Linux | — | gve: fix header buffer corruption with header-split and HW-GRO |
| CVE-2026-72137 | 9.8 | 46.9 | Linux | Linux | — | xfrm: nat_keepalive: avoid double free on send error |
| CVE-2026-72217 | 9.8 | 46.9 | Linux | Linux | — | SUNRPC: Bound-check xdr_buf_to_bvec() stores before writing |
| CVE-2026-72222 | 9.8 | 46.9 | Linux | Linux | — | sunrpc: pin svc_xprt across the asynchronous TLS handshake callback |
| CVE-2026-15689 | 9.8 | 46.4 | ABEVERLEY | Dancer2::Plugin::Auth::Extensible | CWE-640 | Dancer2::Plugin::Auth::Extensible versions through 0.713 for Perl allow passw… |
| CVE-2026-72429 | 9.8 | 46.3 | Linux | Linux | — | ipv6: ioam: fix type confusion of dst_entry |
| CVE-2026-72200 | 9.8 | 45.9 | Linux | Linux | — | ntfs: detect mapping-pairs LCN accumulator overflow |
| CVE-2026-74268 | 9.8 | 45.9 | Linux | Linux | — | tcp: clear sock_ops cb flags before force-closing a child socket |
| CVE-2026-72254 | 7.5 | 45.8 | Linux | Linux | — | netfilter: nft_fib: reject fib expression on the netdev egress hook |
| CVE-2026-72382 | 8.8 | 45.5 | Linux | Linux | — | ksmbd: reject undersized DACLs before parsing ACEs |
| CVE-2026-72220 | 9.8 | 45.5 | Linux | Linux | — | sunrpc: harden rq_procinfo lifecycle to prevent double-free |
| CVE-2026-72318 | 9.4 | 45.4 | Linux | Linux | — | cifs: validate DFS referral string offsets |
| CVE-2026-72057 | 8.2 | 45.3 | Linux | Linux | — | net/sched: act_ct: preserve tc_skb_cb across defragmentation |
| CVE-2026-72367 | 8.8 | 45.2 | Linux | Linux | — | iomap: guard io_size EOF trim against concurrent truncate underflow |
| CVE-2026-72139 | 9.8 | 45.1 | Linux | Linux | — | tcp: defer md5sig_info kfree past RCU grace period in tcp_connect |
| CVE-2026-72393 | 9.8 | 45.1 | Linux | Linux | — | eth: fbnic: don't cache shinfo across skb realloc |
| CVE-2026-15965 | 8.8 | 45.1 | sadathimel | MaxUpload – Big File Uploads – Increase Maximum File Upload Size | CWE-434 | MaxUpload <= 1.4.0 - Unauthenticated Arbitrary File Upload via 'resumableFile… |
| CVE-2026-72141 | 7.5 | 44.9 | Linux | Linux | — | i2c: imx: fix locked bus on SMBus block-read of 0 (IRQ) |
| CVE-2026-72203 | 7.5 | 44.9 | Linux | Linux | — | ntfs: skip extent mft records in writeback to prevent deadlock |
| CVE-2026-74478 | 9.8 | 44.7 | Linux | Linux | — | um: vector: fix use-after-free in vector_mmsg_rx() |
| CVE-2026-72021 | 8.2 | 44.7 | Linux | Linux | — | ipvs: use parsed transport offset in SCTP state lookup |
| CVE-2026-72035 | 8.2 | 44.7 | Linux | Linux | — | net/sched: sch_taprio: Replace direct dequeue call with peek and qdisc_dequeu… |
| CVE-2026-72100 | 8.8 | 44.1 | Linux | Linux | — | dm-integrity: fix a bug if the bio is out of limits |
| CVE-2026-72421 | 10.0 | 43.8 | Linux | Linux | — | ipv4: fib: Don't ignore error route in local/main tables. |
| CVE-2026-72355 | 9.8 | 43.7 | Linux | Linux | — | netfs: Fix barriering when walking subrequest list |
| CVE-2026-72417 | 9.8 | 43.7 | Linux | Linux | — | netfilter: flowtable: Validate iph->ihl in nf_flow_ip4_tunnel_proto() |
| CVE-2026-72442 | 9.8 | 43.7 | Linux | Linux | — | netfilter: flowtable: fix and simplify IP6IP6 tunnel handling |
| CVE-2026-72064 | 9.8 | 43.7 | Linux | Linux | — | net: mana: Sync page pool RX frags for CPU |
| CVE-2026-74394 | 9.8 | 43.0 | Linux | Linux | — | RDMA/srpt: fix integer overflow in immediate data length check |
| CVE-2026-72099 | 7.1 | 42.5 | Linux | Linux | — | dm-integrity: don't increment hash_offset twice |
| CVE-2026-74473 | 9.8 | 42.1 | Linux | Linux | — | vxlan: use pskb_network_may_pull() in route_shortcircuit() |
| CVE-2026-74480 | 9.8 | 42.1 | Linux | Linux | — | net: bridge: stop fast-leave after deleting a port group |
| CVE-2026-72320 | 9.1 | 42.0 | Linux | Linux | — | netfilter: nft_lookup: fix catchall element handling with inverted lookups |
| CVE-2026-74279 | 10.0 | 41.9 | Linux | Linux | — | crypto: cavium/cpt - fix DMA cleanup using wrong loop index |
| CVE-2026-74384 | 9.8 | 41.9 | Linux | Linux | — | nvme-multipath: fix flex array size in struct nvme_ns_head |
| CVE-2026-74287 | 9.1 | 41.9 | Linux | Linux | — | sctp: validate embedded address parameter length |
| CVE-2026-72407 | 10.0 | 41.6 | Linux | Linux | — | geneve: validate inner network offset in geneve_gro_complete() |
| CVE-2026-72199 | 9.8 | 41.6 | Linux | Linux | — | ntfs: validate resident index root values on lookup |
| CVE-2026-72201 | 9.8 | 41.6 | Linux | Linux | — | ntfs: validate index entries on reading |
| CVE-2026-72206 | 9.8 | 41.6 | Linux | Linux | — | ntfs: validate index block header more strictly |
| CVE-2026-72207 | 9.8 | 41.6 | Linux | Linux | — | ntfs: not change 0-byte $DATA attribute to non-resident |
| CVE-2026-72208 | 9.8 | 41.6 | Linux | Linux | — | ntfs: add bounds check before accessing EA entries |
| CVE-2026-72209 | 9.8 | 41.6 | Linux | Linux | — | ntfs: validate attribute values on lookup |
| CVE-2026-72210 | 9.8 | 41.6 | Linux | Linux | — | ntfs: fix off-by-one in mapping pairs decoding bounds checks |
| CVE-2026-72211 | 9.8 | 41.6 | Linux | Linux | — | ntfs: grow index root value before reparent header update |
| CVE-2026-72248 | 9.8 | 41.6 | Linux | Linux | — | netfilter: flowtable: support IPIP tunnel with direct xmit |
| CVE-2026-72249 | 9.8 | 41.6 | Linux | Linux | — | netfilter: flowtable: use dst in this direction when pushing IPIP header |
| CVE-2026-72477 | 9.8 | 41.6 | Linux | Linux | — | fs/ntfs3: call _ntfs_bad_inode() when failing to rename |
| CVE-2026-74398 | 9.8 | 41.4 | Linux | Linux | — | ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD |
| CVE-2026-74495 | 9.8 | 41.4 | Linux | Linux | — | igbvf: Fix leak in TX DMA error cleanup |
| CVE-2026-74396 | 7.5 | 41.3 | Linux | Linux | — | RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure |
| CVE-2026-74376 | 9.8 | 41.1 | Linux | Linux | — | md/raid10: reset read_slot when reusing r10bio for discard |
| CVE-2026-72353 | 8.8 | 41.0 | Linux | Linux | — | ntfs: avoid stale runlist element dereference in fallocate |
| CVE-2026-72354 | 8.8 | 41.1 | Linux | Linux | — | ntfs: avoid stale runlist element dereference in MFT writeback |
| CVE-2026-74321 | 7.5 | 41.0 | Linux | Linux | — | btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs() |
| CVE-2026-74255 | 9.8 | 40.9 | Linux | Linux | — | tipc: fix UAF in tipc_l2_send_msg() |
| CVE-2026-74523 | 7.5 | 40.6 | Linux | Linux | — | qede: sync udp_tunnel ports outside qede_lock in the recovery path |
| CVE-2026-74493 | 9.8 | 40.5 | Linux | Linux | — | net/smc: fix socket use-after-free during link group termination |
| CVE-2026-73194 | 9.1 | 40.1 | — | DBI | CWE-1284 | DBI versions before 1.652 for Perl allow a heap out-of-bounds write via an un… |
| CVE-2026-74406 | 9.8 | 40.0 | Linux | Linux | — | vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). |
| CVE-2026-74476 | 9.1 | 40.0 | Linux | Linux | — | veth: convert frag_list skbs before running XDP |
| CVE-2026-19898 | 2.9 | 39.4 | n/a | VictoriaMetrics | CWE-307 | VictoriaMetrics VMAuth Authentication Endpoint main.go requestHandler excessi… |
| CVE-2026-68457 | 9.1 | 39.2 | Linux | Linux | — | ksmbd: use opener credentials for FSCTL mutations |
| CVE-2026-74550 | 7.5 | 39.2 | Linux | Linux | — | net: do not send ICMP/NDISC Redirects when peer allocation fails |
| CVE-2026-73193 | 9.8 | 39.0 | — | DBI | CWE-190 | DBI versions before 1.652 for Perl allow a heap out-of-bounds write on 32-bit… |
| CVE-2026-72492 | 8.8 | 39.0 | Linux | Linux | — | ksmbd: fix use-after-free in same_client_has_lease() |
| CVE-2026-74469 | 8.8 | 38.5 | Linux | Linux | — | sctp: prevent peer transport count overflow |
| CVE-2026-72186 | 9.1 | 38.4 | Linux | Linux | — | ntfs: make system files immutable to prevent corruption |
| CVE-2026-72202 | 7.5 | 38.4 | Linux | Linux | — | ntfs: avoid heap allocation for free-cluster readahead state |
| CVE-2026-72188 | 9.1 | 38.4 | Linux | Linux | — | ntfs: sanitize MFT references returned from ntfs_lookup_inode_by_name() |
| CVE-2026-74474 | 9.8 | 37.7 | Linux | Linux | — | vxlan: use pskb_network_may_pull() for transmit path header pulls |
| CVE-2026-74545 | 9.8 | 37.7 | Linux | Linux | — | rtase: fix double free of multi-frag skb on DMA map failure |
| CVE-2026-74490 | 8.8 | 37.6 | Linux | Linux | — | tipc: avoid use-after-free in poll trace queue dumps |
| CVE-2026-74475 | 10.0 | 37.5 | Linux | Linux | — | vxlan: use neigh_ha_snapshot() in route_shortcircuit() |
| CVE-2026-19901 | 8.2 | 37.5 | LB-LINK | X-PRO | CWE-259 | LB-LINK X-PRO easycwmp hard-coded credentials |
| CVE-2026-73635 | 7.5 | 37.3 | Apache Software Foundation | Apache Struts | CWE-770 | Apache Struts: Unbounded growth of localized-text caches driven by the reques… |
| CVE-2026-72420 | 8.8 | 36.9 | Linux | Linux | — | md/raid5: avoid R5_Overlap races while breaking stripe batches |
| CVE-2026-74345 | 9.8 | 36.8 | Linux | Linux | — | RDMA/siw: Fix endpoint/socket association handling |
| CVE-2026-74401 | 9.8 | 36.8 | Linux | Linux | — | dlm: fix add msg handle in send_queue ordered |
| CVE-2026-15303 | 9.8 | 36.7 | sixstorage | 6Storage Rentals | CWE-287 | 6Storage Rentals <= 2.27.0 - Unauthenticated Account Takeover via 'email' Par… |
| CVE-2026-74309 | 10.0 | 36.6 | Linux | Linux | — | vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler |
| CVE-2026-74361 | 9.8 | 36.6 | Linux | Linux | — | nvme: fix FDP fdpcidx bounds check |
| CVE-2026-74316 | 7.5 | 36.5 | Linux | Linux | — | NFSD: Handle layout stid in nfsd4_drop_revoked_stid() |
| CVE-2026-74522 | 8.8 | 36.0 | Linux | Linux | — | ksmbd: fix use-after-free in __close_file_table_ids() |
| CVE-2026-74385 | 7.5 | 35.3 | Linux | Linux | — | nvmet-tcp: check return value of nvmet_tcp_set_queue_sock |
| CVE-2026-73046 | 9.3 | 35.2 | siyuan-note | siyuan | CWE-307 | SiYuan before v3.7.4 Authentication Bypass via HTTP Basic Auth |
| CVE-2026-73634 | 7.5 | 35.2 | Apache Software Foundation | Apache Struts | CWE-400 | Apache Struts: Unbounded read of a Content Security Policy violation report |
| CVE-2026-72494 | 9.8 | 33.6 | Linux | Linux | — | RDMA/irdma: Replace waitqueue and flag with completion |
| CVE-2026-74764 | 10.0 | 33.3 | pandora-analysis | pandora | CWE-22 | Path Traversal in TAR Archive Extraction Allows Arbitrary File Write in Pandora |
| CVE-2026-74427 | 9.8 | 33.3 | Linux | Linux | — | afs: Fix netns teardown to cancel the preallocation charger |
| CVE-2026-19895 | 2.9 | 33.1 | opensourcepos | Open Source Point of Sale | CWE-307 | opensourcepos Open Source Point of Sale Login Endpoint Filters.php index exce… |
| CVE-2026-74436 | 9.8 | 32.7 | Linux | Linux | — | rxrpc: serialize kernel accept preallocation with socket teardown |
| CVE-2026-74556 | 9.8 | 32.7 | Linux | Linux | — | scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer |
| CVE-2026-12248 | 6.5 | 32.7 | WPML | WPML Multilingual CMS | CWE-89 | WPML Multilingual CMS <= 4.9.5 - Authenticated (Translator+) SQL Injection vi… |
| CVE-2026-72029 | 8.8 | 32.6 | Linux | Linux | — | net: wwan: iosm: bound device offsets in the MUX downlink decoder |
| CVE-2026-74569 | 9.8 | 31.6 | Linux | Linux | — | netfilter: nf_conntrack_sip: widen NAT rewrite delta to s32 in sip_help_tcp() |
| CVE-2026-72408 | 10.0 | 30.7 | Linux | Linux | — | geneve: gate GRO hint in geneve_gro_complete() on gs->gro_hint |
| CVE-2026-72463 | 9.8 | 30.7 | Linux | Linux | — | xfrm: Fix dev use-after-free in xfrm async resumption |
| CVE-2026-74269 | 9.8 | 30.7 | Linux | Linux | — | bnxt: fix head underflow on XDP head-grow |
| CVE-2026-74315 | 9.8 | 30.7 | Linux | Linux | — | lockd: Avoid hashing uninitialized bytes in nlm4svc_lookup_file() |
| CVE-2026-74350 | 9.8 | 30.7 | Linux | Linux | — | ocfs2: validate fast symlink target during inode read |
| CVE-2026-18387 | 6.5 | 30.8 | trainingbusinesspros | Groundhogg — CRM, Newsletters, and Marketing Automation | CWE-89 | Groundhogg <= 4.5.14 - Authenticated (Vendor+) SQL Injection via 'tag_query' … |
| CVE-2026-15001 | 8.8 | 30.6 | connectordev | bLoyal: Loyalty & Promotions by bLoyal | CWE-269 | bLoyal: Loyalty & Promotions by bLoyal <= 3.1.611.78 - Authenticated (Subscri… |
| CVE-2026-16142 | 9.8 | 30.4 | themetechmount | TrueBooker – Appointment Booking and Scheduler System | CWE-639 | TrueBooker <= 1.2.6 - Unauthenticated Account Takeover via Insecure Direct Ob… |
| CVE-2026-74576 | 7.5 | 30.3 | Linux | Linux | — | mm/slab: prevent unbounded recursion in free path with new kmalloc type |
| CVE-2026-73043 | 9.4 | 29.9 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 Remote Code Execution via Template Calculation |
| CVE-2026-19897 | 2.9 | 29.7 | mangroup | dtale | CWE-307 | mangroup dtale Login Endpoint auth.py login excessive authentication |
| CVE-2026-72440 | 7.1 | 29.1 | Linux | Linux | — | md/raid1: fix writes_pending and barrier reference leaks on write failures |
| CVE-2026-72438 | 7.5 | 28.6 | Linux | Linux | — | md/raid10: fix writes_pending and barrier reference leaks on discard failures |
| CVE-2026-74425 | 7.5 | 27.6 | Linux | Linux | — | afs: handle CB.InitCallBackState3 requests without a server record |
| CVE-2026-72493 | 9.9 | 27.4 | Linux | Linux | — | net: serialize netif_running() check in enqueue_to_backlog() |
| CVE-2026-12128 | 5.3 | 27.4 | dotonpaper | Pinpoint Booking System – Version 2 | CWE-20 | Pinpoint Booking System <= 2.9.9.6.8 - Unauthenticated Improper Input Validat… |
| CVE-2026-74428 | 9.8 | 27.3 | Linux | Linux | — | rxrpc: Fix double unlock in rxrpc_recvmsg() |
| CVE-2026-74433 | 9.8 | 27.3 | Linux | Linux | — | rxrpc: Fix UAF in rxgk_issue_challenge() |
| CVE-2026-74435 | 7.5 | 27.1 | Linux | Linux | — | rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc |
| CVE-2026-74572 | 7.5 | 27.1 | Linux | Linux | — | btrfs: zoned: fix deadlock between metadata writeback and transaction commit |
| CVE-2026-16094 | 4.9 | 27.2 | matthiasnordwig | Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms | CWE-89 | Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection … |
| CVE-2026-72121 | 8.8 | 27.0 | Linux | Linux | — | can: bcm: add locking when updating filter and timer values |
| CVE-2026-72124 | 8.8 | 27.0 | Linux | Linux | — | can: isotp: serialize TX state transitions under so->rx_lock |
| CVE-2026-72157 | 8.8 | 27.0 | Linux | Linux | — | net: thunderbolt: Fix frags[] overflow by bounding frame_count |
| CVE-2026-74374 | 7.5 | 26.9 | Linux | Linux | — | md/raid1,raid10: fix error-path detection with md_cloned_bio() |
| CVE-2026-15162 | 7.5 | 26.8 | minnpost | Object Sync for Salesforce | CWE-89 | Object Sync for Salesforce <= 2.2.13 - Unauthenticated SQL Injection |
| CVE-2026-72334 | 8.8 | 26.6 | Linux | Linux | — | Bluetooth: ISO: fix malformed ISO_END/CONT handling |
| CVE-2026-18549 | 7.5 | 26.5 | @fastify/multipart | @fastify/multipart | CWE-400 | @fastify/multipart vulnerable to Denial of Service via aborted upload after f… |
| CVE-2026-72003 | 8.8 | 26.4 | Linux | Linux | — | wifi: brcmfmac: cyw: fix heap overflow on a short auth frame |
| CVE-2026-74430 | 7.5 | 26.3 | Linux | Linux | — | rxrpc: Fix ACKALL packet handling |
| CVE-2026-74341 | 8.8 | 26.2 | Linux | Linux | — | wifi: wcn36xx: fix heap overflow from oversized firmware HAL response |
| CVE-2026-74434 | 9.8 | 26.2 | Linux | Linux | — | rxrpc: Don't move a peeked OOB message onto the pending queue |
| CVE-2026-72233 | 8.8 | 25.9 | Linux | Linux | — | batman-adv: bla: reacquire gw address after skb realloc |
| CVE-2026-72235 | 8.8 | 25.9 | Linux | Linux | — | batman-adv: retrieve ethhdr after potential skb realloc on RX |
| CVE-2026-74429 | 7.5 | 25.9 | Linux | Linux | — | rxrpc: Fix the reception of a reply packet before data transmission |
| CVE-2026-74431 | 7.5 | 25.9 | Linux | Linux | — | rxrpc: Fix potential infinite loop in rxrpc_recvmsg() |
| CVE-2026-15341 | 9.8 | 25.7 | rafasashi | User Session Synchronizer | CWE-287 | User Session Synchronizer <= 1.4.0 - Unauthenticated Authentication Bypass to… |
| CVE-2026-72227 | 8.1 | 25.5 | Linux | Linux | — | batman-adv: mcast: avoid OOB read of num_dests header |
| CVE-2026-72148 | 8.8 | 25.3 | Linux | Linux | — | dmaengine: dw-edma: Add spinlock to protect DONE_INT_MASK and ABORT_INT_MASK |
| CVE-2026-74557 | 7.5 | 25.2 | Linux | Linux | — | scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer |
| CVE-2026-19906 | 6.3 | 25.2 | pkp | pkp-lib | CWE-330 | pkp pkp-lib API Key Generation APIProfileForm.php setData entropy |
| CVE-2026-16586 | 6.5 | 24.1 | contest-gallery | Contest Gallery – Upload & Vote Photos, Media, Sell with PayPal & Stripe | CWE-89 | Contest Gallery <= 30.0.6 - Authenticated (Author+) Second-Order SQL Injectio… |
| CVE-2026-72469 | 8.8 | 23.9 | Linux | Linux | — | xprtrdma: Fix ep kref imbalance on ADDR_CHANGE |
| CVE-2026-74521 | 9.1 | 23.6 | Linux | Linux | — | ksmbd: use memcmp() to compare ClientGUIDs |
| CVE-2026-72471 | 7.1 | 23.7 | Linux | Linux | — | fs/ntfs3: prevent potential lcn remains uninitialized |
| CVE-2026-8840 | 5.3 | 23.6 | wpdevart | Booking calendar, Appointment Booking System | CWE-862 | Booking calendar, Appointment Booking System <= 3.2.36 - Missing Authorizatio… |
| CVE-2026-68471 | 8.8 | 23.6 | Linux | Linux | — | wifi: ieee80211: validate MLE common info length |
| CVE-2026-73054 | 8.7 | 23.5 | siyuan-note | siyuan | CWE-287 | SiYuan before v3.7.4 Authentication Bypass via WebSocket |
| CVE-2026-19903 | 5.5 | 23.3 | SourceCodester | Online Clothing Store | CWE-425 | SourceCodester Online Clothing Store SQL Database Backup shopping.sql file ac… |
| CVE-2026-74570 | 9.8 | 22.9 | Linux | Linux | — | ntfs: harden runlist realloc size calculations |
| CVE-2026-19896 | 2.9 | 22.9 | mangroup | dtale | CWE-310 | mangroup dtale Flask Session Cookie app.py build_secret_key random values |
| CVE-2026-73045 | 8.7 | 22.3 | siyuan-note | siyuan | CWE-307 | SiYuan before 3.7.4 Brute-Force via authFilePublishAccess |
| CVE-2026-15993 | 5.3 | 22.2 | 10web | Form Maker by 10Web – Mobile-Friendly Drag & Drop Contact Form Builder | CWE-89 | Form Maker by 10Web <= 1.15.44 - Authenticated (Subscriber+) SQL Injection vi… |
| CVE-2026-73042 | 9.4 | 22.0 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 Remote Code Execution via Menu Metadata |
| CVE-2026-73052 | 9.4 | 22.0 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 Stored XSS via Attribute-View Field Names |
| CVE-2026-68472 | 8.1 | 21.8 | Linux | Linux | — | wifi: cfg80211: validate EHT MLE before MLD ID read |
| CVE-2026-72115 | 8.1 | 21.4 | Linux | Linux | — | can: bcm: track a single source interface for ANYDEV timeout/throttle ops |
| CVE-2026-16146 | 4.9 | 21.4 | matthiasnordwig | Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms | CWE-89 | Invisible Anti-Spam & CAPTCHA <= 5.1 - Authenticated (Editor+) SQL Injection … |
| CVE-2026-68470 | 8.8 | 20.8 | Linux | Linux | — | wifi: mac80211: validate extension-frame layout before RX |
| CVE-2026-72380 | 8.8 | 20.8 | Linux | Linux | — | xen/pvcalls: bound backend response req_id before indexing rsp[] |
| CVE-2026-18216 | 6.5 | 20.6 | Unknown | Backup Migration | CWE-287 | Backup Migration < 2.1.7 - Admin+ Privilege Escalation via Post-Restore Auto-… |
| CVE-2026-19893 | 2.3 | 20.6 | D-Link | DIR-842 | CWE-266 | D-Link DIR-842 vsftpd vsftpd.conf default permission |
| CVE-2026-73053 | 9.4 | 20.3 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 Cross-Site Scripting via unicode2Emoji |
| CVE-2026-74410 | 8.1 | 19.7 | Linux | Linux | — | wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer |
| CVE-2026-19474 | 7.5 | 19.7 | @fastify/multipart | @fastify/multipart | CWE-459 | @fastify/multipart vulnerable to Denial of Service via temporary file leak on… |
| CVE-2026-14279 | 8.8 | 19.4 | cedcommerce | Wholesale Market | CWE-269 | Wholesale Market <= 2.2.2 - Authenticated (Subscriber+) Privilege Escalation … |
| CVE-2026-15312 | 8.8 | 19.4 | fassionstorage | Propovoice: All-in-One Client Management System | CWE-269 | Propovoice: All-in-One Client Management System <= 1.7.8 - Authenticated (ndp… |
| CVE-2026-74340 | 8.1 | 19.2 | Linux | Linux | — | wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication |
| CVE-2026-16145 | 7.2 | 18.1 | matthiasnordwig | Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms | CWE-79 | Invisible Anti-Spam & CAPTCHA <= 5.1 - Unauthenticated Stored Cross-Site Scri… |
| CVE-2026-19899 | 5.5 | 17.7 | SourceCodester | Class and Exam Timetabling System | CWE-74 | SourceCodester Class and Exam Timetabling System edit_teacher.php sql injection |
| CVE-2026-19919 | 5.5 | 17.7 | code-projects | Online Shopping System | CWE-74 | code-projects Online Shopping System Login login.php sql injection |
| CVE-2026-74408 | 8.8 | 17.6 | Linux | Linux | — | wifi: ath9k: fix OOB access from firmware tx status queue ID |
| CVE-2026-74508 | 8.8 | 17.6 | Linux | Linux | — | Bluetooth: HIDP: reject frames without a transaction header |
| CVE-2026-73631 | 4.3 | 17.5 | Apache Software Foundation | Apache Struts | CWE-567 | Apache Struts: Shared parsing state in the JSON plugin |
| CVE-2026-73632 | 4.3 | 17.5 | Apache Software Foundation | Apache Struts | CWE-567 | Apache Struts: Shared serialization state in the JSON plugin |
| CVE-2026-74300 | 8.8 | 16.9 | Linux | Linux | — | Bluetooth: hci: validate codec capability element length |
| CVE-2026-16611 | 7.5 | 16.9 | Unknown | Product Feed PRO for WooCommerce by AdTribes | CWE-200 | Product Feed PRO for WooCommerce < 13.5.7 - Unauthenticated Feed Configuratio… |
| CVE-2026-74488 | 8.8 | 16.7 | Linux | Linux | — | wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames |
| CVE-2026-74540 | 8.8 | 16.7 | Linux | Linux | — | Bluetooth: L2CAP: fix UAF in l2cap_le_connect_rsp |
| CVE-2026-74411 | 8.8 | 16.6 | Linux | Linux | — | wifi: rtw89: Correct data type for scan index to avoid infinite loop |
| CVE-2026-74531 | 8.8 | 16.6 | Linux | Linux | — | Bluetooth: hci_conn: hold conn reference in abort_conn_sync() |
| CVE-2026-19905 | 5.5 | 16.6 | Jinher | OA | CWE-74 | Jinher OA attendance_out_approve.aspx sql injection |
| CVE-2026-74767 | 8.7 | 16.4 | pandora-analysis | pandora | CWE-434 | Unbounded DAA Decompression in Pandora Allows Denial of Service via Decompres… |
| CVE-2026-19894 | 2.1 | 16.1 | itsourcecode | Hospital Management System | CWE-74 | itsourcecode Hospital Management System viewmedicine.php sql injection |
| CVE-2026-74539 | 8.0 | 15.9 | Linux | Linux | — | Bluetooth: ISO: lock sk in iso_sock_getname |
| CVE-2026-73044 | 9.4 | 15.7 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 Stored Cross-Site Scripting via Column Width |
| CVE-2026-73050 | 9.4 | 15.7 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 Stored XSS via select option color |
| CVE-2026-74509 | 8.8 | 15.7 | Linux | Linux | — | Bluetooth: hci_sync: Fix advertising data UAFs |
| CVE-2026-74541 | 8.8 | 15.7 | Linux | Linux | — | Bluetooth: ISO: clear iso_data always when detaching conn from hcon |
| CVE-2026-13360 | 7.2 | 15.7 | wplegalpages | WPLP Cookie Consent – Cookie Banner & Consent Management for GDPR, CCPA & Google Consent Mode | CWE-79 | Cookie Banner for GDPR / CCPA <= 4.3.5 - Authenticated (Subscriber+) Stored C… |
| CVE-2026-74507 | 7.1 | 15.1 | Linux | Linux | — | Bluetooth: HIDP: validate numbered report payloads |
| CVE-2026-15453 | 6.5 | 15.0 | iqonicdesign | KiviCare – Clinic & Patient Management System (EHR) | CWE-89 | KiviCare <= 4.5.1 - Authenticated (Doctor+) SQL Injection via 'searchTerm' Pa… |
| CVE-2026-16080 | 6.5 | 15.0 | fishpie | Image Uploader for Welcart | CWE-89 | Image Uploader for Welcart <= 1.4.6 - Authenticated (Author+) SQL Injection v… |
| CVE-2026-74535 | 8.8 | 15.0 | Linux | Linux | — | Bluetooth: ISO: avoid deadlocks in iso_sock_timeout |
| CVE-2026-74409 | 8.8 | 14.8 | Linux | Linux | — | wifi: rtw89: add bounds check on firmware mac_id in link lookup |
| CVE-2026-74412 | 8.8 | 14.8 | Linux | Linux | — | wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers |
| CVE-2026-74413 | 8.8 | 14.8 | Linux | Linux | — | wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers |
| CVE-2026-74323 | 8.8 | 14.7 | Linux | Linux | — | wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb() |
| CVE-2026-74534 | 8.8 | 14.7 | Linux | Linux | — | Bluetooth: ISO: fix refcounting of iso_conn |
| CVE-2026-74537 | 8.8 | 14.7 | Linux | Linux | — | Bluetooth: ISO: hold sk properly in iso_conn_ready |
| CVE-2026-74538 | 8.8 | 14.7 | Linux | Linux | — | Bluetooth: ISO: lock sk in iso_connect_ind |
| CVE-2026-74575 | 8.8 | 14.5 | Linux | Linux | — | thunderbolt: Prevent XDomain delayed work use-after-free on disconnect |
| CVE-2026-14433 | 7.2 | 14.4 | vcita | Online Booking & Scheduling Calendar for WordPress by vcita | CWE-79 | Online Booking & Scheduling Calendar for WordPress by vcita <= 4.6.0 - Unauth… |
| CVE-2026-73041 | 9.4 | 14.0 | siyuan-note | siyuan | CWE-79 | SiYuan before v3.7.4 Remote Code Execution via PDF Annotations |
| CVE-2026-74356 | 7.4 | 13.9 | Linux | Linux | — | vhost: fix vhost_get_avail_idx for a non empty ring |
| CVE-2026-74528 | 8.0 | 13.6 | Linux | Linux | — | Bluetooth: hci_sync: hold conn in hci_past_sync() callback |
| CVE-2026-17090 | 6.4 | 13.3 | beaverbuilder | Beaver Builder Page Builder – Drag and Drop Website Builder | CWE-79 | Beaver Builder Page Builder <= 2.10.2.2 - Authenticated (Author+) Stored Cros… |
| CVE-2026-19918 | 2.1 | 13.4 | SpaceX | Starlink Router Gen 3 | CWE-266 | SpaceX Starlink Router Gen 3 gRPC Management get_status access control |
| CVE-2026-72441 | await | 13.2 | Linux | Linux | — | ieee802154: fix kernel-infoleak in dgram_recvmsg() |
| CVE-2026-72236 | await | 12.5 | Linux | Linux | — | s390/perf_cpum_cf: Add missing array_index_nospec() to __hw_perf_event_init() |
| CVE-2026-72245 | await | 12.4 | Linux | Linux | — | gpu: host1x: Fix device reference leak in host1x_device_parse_dt() error path |
| CVE-2026-72056 | await | 12.3 | Linux | Linux | — | net: ena: clean up XDP TX queues when regular TX setup fails |
| CVE-2026-72063 | await | 12.3 | Linux | Linux | — | gpio: tegra: do not call pinctrl for GPIO direction |
| CVE-2026-72068 | await | 12.3 | Linux | Linux | — | posix-cpu-timers: Use u64 multiplication in update_rlimit_cpu() |
| CVE-2026-72070 | await | 12.3 | Linux | Linux | — | wifi: libertas_tf: fix use-after-free in lbtf_free_adapter() |
| CVE-2026-72074 | await | 12.3 | Linux | Linux | — | Input: ims-pcu - fix type confusion in CDC union descriptor parsing |
| CVE-2026-72076 | await | 12.3 | Linux | Linux | — | Input: ims-pcu - fix out-of-bounds read in ims_pcu_irq() debug logging |
| CVE-2026-72077 | await | 12.3 | Linux | Linux | — | Input: ims-pcu - fix firmware leak in async update |
| CVE-2026-72078 | await | 12.3 | Linux | Linux | — | Input: ims-pcu - validate control endpoint type |
| CVE-2026-72079 | await | 12.3 | Linux | Linux | — | Input: ims-pcu - fix use-after-free and double-free in disconnect |
| CVE-2026-72087 | await | 12.3 | Linux | Linux | — | scsi: lpfc: Fix memory leak in lpfc_sli4_driver_resource_setup() |
| CVE-2026-72223 | await | 12.3 | Linux | Linux | — | nvdimm/btt: Free arena sub-allocations on discover_arenas() error path |
| CVE-2026-72224 | await | 12.3 | Linux | Linux | — | nvdimm/btt: Free arenas on btt_init() error paths |
| CVE-2026-72307 | await | 12.3 | Linux | Linux | — | mlxsw: fix refcount leak in mlxsw_sp_vrs_lpm_tree_replace() |
| CVE-2026-72308 | await | 12.3 | Linux | Linux | — | mlxsw: fix refcount leak in mlxsw_sp_port_lag_join() |
| CVE-2026-72316 | await | 12.3 | Linux | Linux | — | dm era: fix NULL pointer dereference in metadata_open() |
| CVE-2026-72326 | await | 12.3 | Linux | Linux | — | net/sched: cake: reject overhead values that underflow length |
| CVE-2026-72349 | await | 12.3 | Linux | Linux | — | netfilter: xt_rateest: fix u64 truncation in xt_rateest_mt() |
| CVE-2026-72396 | await | 12.3 | Linux | Linux | — | hwmon: adm1275: Prevent reading uninitialized stack |
| CVE-2026-72414 | await | 12.3 | Linux | Linux | — | net: dsa: sja1105: round up PTP perout pin duration |
| CVE-2026-72447 | await | 12.3 | Linux | Linux | — | sctp: hold socket lock when dumping endpoints in sctp_diag |
| CVE-2026-16541 | 6.5 | 12.2 | Unknown | Simply Schedule Appointments | CWE-200 | Simply Schedule Appointments < 1.6.12.17 - Team Member+ User Email Disclosure… |
| CVE-2026-72073 | await | 12.2 | Linux | Linux | — | mmc: vub300: fix use-after-free on probe failure |
| CVE-2026-74407 | 8.8 | 12.1 | Linux | Linux | — | wifi: ath11k: cancel SSR work items during PCI shutdown |
| CVE-2026-74489 | 8.8 | 12.1 | Linux | Linux | — | wifi: mac80211: fix tid_tx use-after-free on BA session stop |
| CVE-2026-74530 | 8.8 | 12.1 | Linux | Linux | — | Bluetooth: hci_sync: hold conn in hci_connect_big_sync() callback |
| CVE-2026-74533 | 8.8 | 12.1 | Linux | Linux | — | Bluetooth: ISO: fix race of kfree vs kref_get_unless_zero |
| CVE-2026-72106 | await | 11.9 | Linux | Linux | — | dm-ioctl: fix a possible overflow in list_version_get_info |
| CVE-2026-72260 | await | 11.8 | Linux | Linux | — | ASoC: mediatek: mt8192: Check runtime resume during probe |
| CVE-2026-72058 | await | 11.7 | Linux | Linux | — | net: ixp4xx_hss: fix duplicate HDLC netdev allocation |
| CVE-2026-72059 | await | 11.7 | Linux | Linux | — | net: wwan: t7xx: destroy DMA pool on CLDMA late init failure |
| CVE-2026-72062 | await | 11.7 | Linux | Linux | — | gpio: mt7621: avoid corruption of shared interrupt trigger state |
| CVE-2026-72075 | await | 11.7 | Linux | Linux | — | Input: ims-pcu - fix race condition in reset_device sysfs callback |
| CVE-2026-72081 | await | 11.7 | Linux | Linux | — | scsi: elx: efct: Fix I/O leak on unsupported additional CDB |
| CVE-2026-72082 | await | 11.7 | Linux | Linux | — | scsi: elx: efct: Fix refcount leak in efct_hw_io_abort() |
| CVE-2026-72276 | await | 11.7 | Linux | Linux | — | fbdev: metronomefb: fix potential memory leak in metronomefb_probe() |
| CVE-2026-72306 | await | 11.7 | Linux | Linux | — | vduse: Fix race in vduse_dev_msg_sync and vduse_dev_read_iter |
| CVE-2026-72437 | await | 11.7 | Linux | Linux | — | md/raid1: free r1_bio when REQ_NOWAIT is set and read would block on retry |
| CVE-2026-72011 | await | 11.4 | Linux | Linux | — | s390/diag: Add missing array_index_nospec() call to memtop_get_page_count() |
| CVE-2026-68469 | await | 11.3 | Linux | Linux | — | wifi: mwifiex: fix permanently busy scans after multiple roam iterations |
| CVE-2026-14229 | 5.3 | 11.2 | Unknown | ECS | CWE-284 | ECS < 4.3.8 - Unauthenticated Private Content Disclosure via ecsload |
| CVE-2026-68475 | await | 11.1 | Linux | Linux | — | reset: sunxi: fix memory region leak on ioremap failure |
| CVE-2026-72004 | await | 11.1 | Linux | Linux | — | wifi: mac80211: fix memory leak in ieee80211_register_hw() |
| CVE-2026-72010 | await | 11.1 | Linux | Linux | — | cgroup/cpuset: rebind mm mempolicy to effective_mems, not mems_allowed |
| CVE-2026-72015 | await | 11.1 | Linux | Linux | — | fs/resctrl: Fix double-add of pseudo-locked region's RMID to free list |
| CVE-2026-72022 | await | 11.1 | Linux | Linux | — | llc: fix SAP refcount leak in llc_ui_autobind() |
| CVE-2026-72023 | await | 11.1 | Linux | Linux | — | octeontx2-pf: fix SQB pointer leak on init failure |
| CVE-2026-72025 | await | 11.1 | Linux | Linux | — | s390/monwriter: Reject buffer reuse with different data length |
| CVE-2026-72038 | await | 11.1 | Linux | Linux | — | net: liquidio: fix BAR resource leak on PF number failure |
| CVE-2026-72039 | await | 11.1 | Linux | Linux | — | bnx2x: fix potential memory leak in bnx2x_alloc_mem_bp() |
| CVE-2026-72048 | await | 11.1 | Linux | Linux | — | ieee802154: ca8210: fix cas_ctl leak on spi_async failure |
| CVE-2026-72096 | await | 11.1 | Linux | Linux | — | dm-verity: make error counter atomic |
| CVE-2026-72117 | await | 11.1 | Linux | Linux | — | can: bcm: fix data race on rx_stamp/rx_ifindex in bcm_rx_handler() |
| CVE-2026-72118 | await | 11.1 | Linux | Linux | — | can: bcm: fix CAN frame rx/tx statistics |
| CVE-2026-72142 | await | 11.1 | Linux | Linux | — | i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) |
| CVE-2026-72152 | await | 11.1 | Linux | Linux | — | tpm: tpm_tis_spi: Use wait_woken() in wait_for_tmp_stat() |
| CVE-2026-72153 | await | 11.1 | Linux | Linux | — | irqchip/crossbar: Use correct index in crossbar_domain_free() |
| CVE-2026-72155 | await | 11.1 | Linux | Linux | — | mtd: spi-nor: swp: Improve locking user experience |
| CVE-2026-72159 | await | 11.1 | Linux | Linux | — | ocfs2: reject non-inline dinodes with i_size and zero i_clusters |
| CVE-2026-72163 | await | 11.1 | Linux | Linux | — | ocfs2: fix NULL h_transaction deref in ocfs2_assure_trans_credits |
| CVE-2026-72166 | await | 11.1 | Linux | Linux | — | net/9p: fix infinite loop in p9_client_rpc on fatal signal |
| CVE-2026-72182 | await | 11.1 | Linux | Linux | — | power: supply: charger-manager: fix refcount leak in is_full_charged() |
| CVE-2026-72215 | await | 11.1 | Linux | Linux | — | MIPS: DEC: Ensure 32-bit stack location for o32 prom_printf() |
| CVE-2026-72218 | await | 11.1 | Linux | Linux | — | lockd: Plug nlm_file refcount leak on cached nlm_do_fopen() failure |
| CVE-2026-72219 | await | 11.1 | Linux | Linux | — | lockd: Plug nlm_file leak when nlm_do_fopen() fails |
| CVE-2026-72228 | await | 11.1 | Linux | Linux | — | batman-adv: frag: fix primary_if leak on failed linearization |
| CVE-2026-72229 | await | 11.1 | Linux | Linux | — | batman-adv: clean untagged VLAN on netdev registration failure |
| CVE-2026-72230 | await | 11.1 | Linux | Linux | — | batman-adv: frag: free unfragmentable packet |
| CVE-2026-72238 | await | 11.1 | Linux | Linux | — | x86/boot: Validate console=uart8250 baud rate to fix early boot hang |
| CVE-2026-72240 | await | 11.1 | Linux | Linux | — | mfd: sm501: Fix reference leak on failed device registration |
| CVE-2026-72241 | await | 11.1 | Linux | Linux | — | leds: uleds: Fix potential buffer overread |
| CVE-2026-72256 | await | 11.1 | Linux | Linux | — | netfilter: xt_cluster: reject template conntracks in hash match |
| CVE-2026-72264 | await | 11.1 | Linux | Linux | — | fbdev: tridentfb: fix potential memory leak in trident_pci_probe() |
| CVE-2026-72268 | await | 11.1 | Linux | Linux | — | fbdev: tdfxfb: fix potential memory leak in tdfxfb_probe() |
| CVE-2026-72269 | await | 11.1 | Linux | Linux | — | fbdev: uvesafb: fix potential memory leak in uvesafb_probe() |
| CVE-2026-72270 | await | 11.1 | Linux | Linux | — | fbdev: s3fb: fix potential memory leak in s3_pci_probe() |
| CVE-2026-72271 | await | 11.1 | Linux | Linux | — | fbdev: i740fb: fix potential memory leak in i740fb_probe() |
| CVE-2026-72272 | await | 11.1 | Linux | Linux | — | fbdev: radeon: fix potential memory leak in radeonfb_pci_register() |
| CVE-2026-72392 | await | 11.1 | Linux | Linux | — | ipv6: fib6: fix NULL deref in fib6_walk_continue() on multi-batch dump |
| CVE-2026-72428 | await | 11.1 | Linux | Linux | — | bpf: Fix stack slot index in nospec checks |
| CVE-2026-72479 | await | 11.1 | Linux | Linux | — | iio: accel: mma8452: handle I2C read error(s) in mma8452_read() |
| CVE-2026-72481 | await | 11.1 | Linux | Linux | — | iio: magnetometer: ak8975: fix potential kernel stack memory leak |
| CVE-2026-72484 | await | 11.1 | Linux | Linux | — | staging: most: video: avoid double free on video register failure |
| CVE-2026-74284 | await | 11.1 | Linux | Linux | — | net/sched: sch_hfsc: Don't make class passive twice |
| CVE-2026-15948 | 6.4 | 11.1 | themefic | Hydra Booking — Appointment Scheduling & Booking Calendar | CWE-79 | Hydra Booking <= 1.2.2 - Authenticated (Host+) Stored Cross-Site Scripting vi… |
| CVE-2026-19904 | 1.9 | 11.1 | SourceCodester | Online Book Store System | CWE-79 | SourceCodester Online Book Store System System Settings index.php site_settin… |
| CVE-2026-68478 | await | 11.1 | Linux | Linux | — | memstick: ms_block: reject a card that reports too many blocks |
| CVE-2026-72047 | await | 11.1 | Linux | Linux | — | ieee802154: ca8210: fix pointer truncation in kfifo on 64-bit |
| CVE-2026-72088 | await | 11.1 | Linux | Linux | — | scsi: hpsa: Fix DMA mapping leak on IOACCEL2 reset path |
| CVE-2026-72138 | await | 11.1 | Linux | Linux | — | xen/gntdev: fix error handling in ioctl |
| CVE-2026-72140 | await | 11.1 | Linux | Linux | — | i2c: mlxbf: Fix use-after-free in mlxbf_i2c_init_resource() |
| CVE-2026-72265 | await | 11.1 | Linux | Linux | — | fbdev: nvidia: fix potential memory leak in nvidiafb_probe() |
| CVE-2026-72267 | await | 11.1 | Linux | Linux | — | fbdev: carminefb: fix potential memory leak in alloc_carmine_fb() |
| CVE-2026-72401 | await | 11.1 | Linux | Linux | — | bpf: Fix insn_aux_data leak on verifier err_free_env path |
| CVE-2026-72433 | await | 11.1 | Linux | Linux | — | netfilter: nft_meta_bridge: fix NFT_META_BRI_IIFPVID stack leak |
| CVE-2026-72324 | await | 10.9 | Linux | Linux | — | gpio: mvebu: free generic chips on unbind |
| CVE-2026-72325 | await | 10.9 | Linux | Linux | — | perf/x86/amd/core: Avoid enabling BRS from the SVM reload path |
| CVE-2026-72327 | await | 10.9 | Linux | Linux | — | drm/v3d: Reject invalid indirect BO handle in indirect CSD setup |
| CVE-2026-72333 | await | 10.9 | Linux | Linux | — | Bluetooth: L2CAP: fix tx ident leak for commands without a response |
| CVE-2026-72361 | await | 10.9 | Linux | Linux | — | drm/xe/hw_engine: Fix double-free of managed BO in error path |
| CVE-2026-72376 | await | 10.9 | Linux | Linux | — | afs: Fix misplaced inc of net->cells_outstanding |
| CVE-2026-72379 | await | 10.9 | Linux | Linux | — | fs: refuse O_TMPFILE creation with an unmapped fsuid or fsgid |
| CVE-2026-72474 | await | 10.9 | Linux | Linux | — | dmaengine: dma-axi-dmac: use DMA pool to manange DMA descriptor |
| CVE-2026-15142 | 7.5 | 10.8 | WebCodingPlace | Real Estate Manager Pro | CWE-269 | Real Estate Manager Pro <= 12.8.6 - Authenticated (Subscriber+) Privilege Esc… |
| CVE-2026-73055 | 9.3 | 10.7 | ericcornelissen | shescape | CWE-116 | Shescape before 2.1.15 Home Directory Disclosure via BusyBox |
| CVE-2026-72092 | await | 10.6 | Linux | Linux | — | accel/amdxdna: reject command submission on devices without a submit op |
| CVE-2026-72321 | await | 10.6 | Linux | Linux | — | ipv4: igmp: Fix potential memory leaks in igmp_mod_timer() and igmp_stop_timer() |
| CVE-2026-72341 | await | 10.6 | Linux | Linux | — | net/mlx5e: Fix publication race for priv->channel_stats[] |
| CVE-2026-72363 | await | 10.6 | Linux | Linux | — | netfs: Fix folio state after ENOMEM whilst under writeback iteration |
| CVE-2026-72365 | await | 10.6 | Linux | Linux | — | netfs: Fix writethrough to use collection offload |
| CVE-2026-72445 | await | 10.6 | Linux | Linux | — | ALSA: usb-audio: qcom: clear opened when stream enable fails |
| CVE-2026-72457 | await | 10.6 | Linux | Linux | — | apparmor: fail policy unpack on accept2 allocation failure |
| CVE-2026-72013 | await | 10.5 | Linux | Linux | — | riscv: Prevent NULL pointer dereference in machine_kexec_prepare() |
| CVE-2026-72017 | await | 10.5 | Linux | Linux | — | net: macb: drop in-flight Tx SKBs on close |
| CVE-2026-72030 | await | 10.5 | Linux | Linux | — | ata: libata-core: Reject an invalid concurrent positioning ranges count |
| CVE-2026-72037 | await | 10.5 | Linux | Linux | — | net: lan743x: Initialize eth_syslock spinlock before use |
| CVE-2026-72040 | await | 10.5 | Linux | Linux | — | ipmi: fix refcount leak in i_ipmi_request() |
| CVE-2026-72060 | await | 10.6 | Linux | Linux | — | net: ethernet: ti: icssg: guard PA stat lookups |
| CVE-2026-72086 | await | 10.5 | Linux | Linux | — | scsi: xen: scsiback: Free the command tag on the TMR submit-failure path |
| CVE-2026-72156 | await | 10.5 | Linux | Linux | — | fpga: microchip-spi: fix zero header_size OOB read in mpf_ops_parse_header() |
| CVE-2026-72161 | await | 10.5 | Linux | Linux | — | ocfs2: add journal NULL check in ocfs2_checkpoint_inode() |
| CVE-2026-72167 | await | 10.5 | Linux | Linux | — | mtd: rawnand: pl353: fix probe resource allocation |
| CVE-2026-72168 | await | 10.5 | Linux | Linux | — | mtd: maps: vmu-flash: fix fault in unaligned fixup |
| CVE-2026-72177 | await | 10.5 | Linux | Linux | — | mm/damon/sysfs-schemes: fix dir put orders in access_pattern_add_dirs() |
| CVE-2026-72179 | await | 10.5 | Linux | Linux | — | riscv: cacheinfo: Fix node reference leak in populate_cache_leaves |