Security Box Score — September 4, 2026 — page 2
Edition of September 4, 2026, continued — page 2 of 2. Back to page 1
| CVE | CVSS | EPSS %ile | Vendor | Product | CWE | Title |
|---|---|---|---|---|---|---|
| CVE-2026-79390 | await | — | n/a | n/a | — | Trueview TI8161 6.0.23.4 is vulnerable to information disclosure due to the t… |
| CVE-2026-79391 | await | — | n/a | n/a | — | No authentication exists in the MQTT service of Trueview 6.0.23.4. The MQTT b… |
| CVE-2026-79418 | await | — | n/a | n/a | — | EMX Tecnologia Gestao X version <= 8.4 contains a Stored Cross-Site Scripting… |
| CVE-2026-79419 | await | — | n/a | n/a | — | A reflected cross-site scripting (XSS) vulnerability exists in EMX Tecnologia… |
| CVE-2026-79423 | await | — | n/a | n/a | — | An authenticated remote code execution (RCE) vulnerability in the admin_confi… |
| CVE-2026-79426 | await | — | n/a | n/a | — | An arbitrary file deletion vulnerability in the /adminapi/file/video_data_sav… |
| CVE-2026-80758 | await | — | Linux | Linux | — | futex: Avoid private hash use-after-free on final put |
| CVE-2026-80759 | await | — | Linux | Linux | — | Bluetooth: hci_aml: validate firmware segment lengths |
| CVE-2026-80760 | await | — | Linux | Linux | — | Bluetooth: MGMT: reject HCI_CMD_SYNC params_len above 255 |
| CVE-2026-80761 | await | — | Linux | Linux | — | Bluetooth: ISO: zero the sockaddr before returning it in getname |
| CVE-2026-80762 | await | — | Linux | Linux | — | Bluetooth: hci_sync: Fix accept list UAF during suspend |
| CVE-2026-80763 | await | — | Linux | Linux | — | Bluetooth: hci_event: validate LE Set CIG Parameters response |
| CVE-2026-80764 | await | — | Linux | Linux | — | Bluetooth: hci_event: fix LE list UAF on reset |
| CVE-2026-80765 | await | — | Linux | Linux | — | HID: hyperv: validate initial device info bounds |
| CVE-2026-80766 | await | — | Linux | Linux | — | HID: uclogic: fix use-after-free of inrange_timer on remove |
| CVE-2026-80767 | await | — | Linux | Linux | — | HID: sensor: custom: Fix use-after-free in enable_sensor |
| CVE-2026-80768 | await | — | Linux | Linux | — | HID: ft260: fix stack-use-after-return write in I2C read race |
| CVE-2026-80769 | await | — | Linux | Linux | — | HID: rapoo: fix missing hid_is_usb() check |
| CVE-2026-80770 | await | — | Linux | Linux | — | HID: nintendo: stop device IO before hid_hw_stop on probe failure |
| CVE-2026-80771 | await | — | Linux | Linux | — | HID: nintendo: register input device after capabilities are set |
| CVE-2026-80772 | await | — | Linux | Linux | — | HID: nintendo: fix out-of-bounds read in joycon_ctlr_read_handler() |
| CVE-2026-80773 | await | — | Linux | Linux | — | HID: huawei: fix missing hid_is_usb() check |
| CVE-2026-80774 | await | — | Linux | Linux | — | HID: asus: fix missing hid_is_usb() check |
| CVE-2026-80775 | await | — | Linux | Linux | — | futex: Fix race on the initial mm->futex.phash.ref allocation |
| CVE-2026-80776 | await | — | Linux | Linux | — | futex: Fix race in futex_pivot_pending() during private hash resize |
| CVE-2026-80777 | await | — | Linux | Linux | — | futex/pi: Plug private futex exec() race |
| CVE-2026-80778 | await | — | Linux | Linux | — | futex/pi: Reject cross-mm private futex owners |
| CVE-2026-80779 | await | — | Linux | Linux | — | net/ionic: avoid OOB TX partner lookup for hwstamp RXQ |
| CVE-2026-80780 | await | — | Linux | Linux | — | HID: pidff: fix OOB write when hid->inputs is empty |
| CVE-2026-80781 | await | — | Linux | Linux | — | HID: core: fix OOB read of field->usage in hid_set_field() |
| CVE-2026-80782 | await | — | Linux | Linux | — | HID: magicmouse: do not keep a stale msc->input if no input is claimed |
| CVE-2026-80783 | await | — | Linux | Linux | — | HID: magicmouse: prevent unbounded recursion in magicmouse_raw_event() |
| CVE-2026-80784 | await | — | Linux | Linux | — | mptcp: pm: fix memory leak from alloc-during-teardown race |
| CVE-2026-80785 | await | — | Linux | Linux | — | fbdev: serialize mode sysfs access with lock_fb_info() |
| CVE-2026-80786 | await | — | Linux | Linux | — | fbdev: Wrap user-invoked calls to fb_set_var() in helper |
| CVE-2026-80787 | await | — | Linux | Linux | — | nvmet: pci-epf: fix use-after-free in nvmet_pci_epf_exec_iod_work() |
| CVE-2026-80788 | await | — | Linux | Linux | — | nvmet-tcp: Do not WARN on remotely-controlled oversized SGL allocations |
| CVE-2026-80789 | await | — | Linux | Linux | — | nvmet-tcp: bound SGL data length before allocating command buffers |
| CVE-2026-80790 | await | — | Linux | Linux | — | nvmet-fc: fix invalid free in LS IOD error path |
| CVE-2026-80791 | await | — | Linux | Linux | — | nvmet-auth: zero the AUTH_RECEIVE response buffer |
| CVE-2026-80792 | await | — | Linux | Linux | — | ipv6: fix use-after-free in ip6_finish_output2() |
| CVE-2026-80793 | await | — | Linux | Linux | — | ipv4: reject undersized MTUs in ip_do_fragment() |
| CVE-2026-80794 | await | — | Linux | Linux | — | nfc: nci: fix uninit-value in the RF discover/activated NTF handlers |
| CVE-2026-80795 | await | — | Linux | Linux | — | nfc: nci: fix out-of-bounds write in nci_target_auto_activated() |
| CVE-2026-80796 | await | — | Linux | Linux | — | nfc: nci: add data_len bound checks to activation parameter extractors |
| CVE-2026-80797 | await | — | Linux | Linux | — | nfc: pn533: purge fragmented skbs during cleanup |
| CVE-2026-80798 | await | — | Linux | Linux | — | nfc: llcp: reject PDUs shorter than the LLCP header |
| CVE-2026-80799 | await | — | Linux | Linux | — | nfc: llcp: fix OOB read and u8 offset wrap in TLV parsers |
| CVE-2026-80800 | await | — | Linux | Linux | — | nfc: llcp: bound the connect_sn TLV walk to the skb |
| CVE-2026-80801 | await | — | Linux | Linux | — | nfc: microread: validate target discovery payload lengths |
| CVE-2026-80802 | await | — | Linux | Linux | — | nfc: fdp: bound the device-reported read length and fix an skb leak |
| CVE-2026-80803 | await | — | Linux | Linux | — | nfc: digital: clamp SENSF_RES length to the destination buffer |
| CVE-2026-80804 | await | — | Linux | Linux | — | xfs: restore nofs context unconditionally in xfs_trans_roll |
| CVE-2026-80805 | await | — | Linux | Linux | — | xfs: validate attr entry pointer before field access |
| CVE-2026-80806 | await | — | Linux | Linux | — | ext4: don't enable DAX on new encrypted files |
| CVE-2026-80807 | await | — | Linux | Linux | — | nilfs2: reject invalid block index in GC ioctl |
| CVE-2026-80808 | await | — | Linux | Linux | — | ext4: stop retrying saturated xattr cache entries |
| CVE-2026-80809 | await | — | Linux | Linux | — | ocfs2: fix missing metadata reservation for large xattrs |
| CVE-2026-80810 | await | — | Linux | Linux | — | io_uring/rsrc: fix folio size overflow in io_vec_fill_bvec() |
| CVE-2026-80811 | await | — | Linux | Linux | — | io_uring/cmd: fix iovec leak when the async cmd is not recycled |
| CVE-2026-80812 | await | — | Linux | Linux | — | ALSA: dummy: Check card index validity at probe |
| CVE-2026-80813 | await | — | Linux | Linux | — | nvmet: fix NULL pointer dereference in nvmet_execute_identify_nslist() |
| CVE-2026-80814 | await | — | Linux | Linux | — | rndis_host: add overflow check in rndis_rx_fixup() |
| CVE-2026-80815 | await | — | Linux | Linux | — | ALSA: scarlett2: Use a private URB for the notification endpoint |
| CVE-2026-80816 | await | — | Linux | Linux | — | ALSA: FCP: Use a private URB for the notification endpoint |
| CVE-2026-80817 | await | — | Linux | Linux | — | iommu/iommufd: Fix NULL pointer deref in iommufd_ioas_change_process when rac… |
| CVE-2026-80818 | await | — | Linux | Linux | — | iommu/tegra241-cmdqv: Fix CMD_SYNC use-after-free on teardown |
| CVE-2026-80819 | await | — | Linux | Linux | — | Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept |
| CVE-2026-80820 | await | — | Linux | Linux | — | xfs: don't livelock in scrub on a circular unlinked list |
| CVE-2026-80821 | await | — | Linux | Linux | — | nvmet: pci-epf: put CQ ref on create_cq mapping failure |
| CVE-2026-80822 | await | — | Linux | Linux | — | mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf() |
| CVE-2026-80823 | await | — | Linux | Linux | — | nfc: st21nfca: validate ATR_REQ length against the received frame |
| CVE-2026-80824 | await | — | Linux | Linux | — | usb: usbfs: fix use-after-free of usb_device in usbdev_release() |
| CVE-2026-80825 | await | — | Linux | Linux | — | wifi: mt76: mt7925: ensure tx headroom in usb_sdio_tx_prepare_skb |
| CVE-2026-80826 | await | — | Linux | Linux | — | USB: c67x00: fix use-after-free in c67x00_add_iso_urb() |
| CVE-2026-80827 | await | — | Linux | Linux | — | USB: serial: option: fix slab OOB read in interrupt URB callback |
| CVE-2026-80828 | await | — | Linux | Linux | — | ALSA: usb-audio: Complete cleanup after system-resume errors |
| CVE-2026-80829 | await | — | Linux | Linux | — | ALSA: usb-audio: fix OOB write in snd_usbmidi_novation_output() |
| CVE-2026-80830 | await | — | Linux | Linux | — | usb: core: Add lock to usb_wakeup_notification() |
| CVE-2026-80831 | await | — | Linux | Linux | — | crypto: mxs-dcp - fix source scatterlist length access |
| CVE-2026-80832 | await | — | Linux | Linux | — | crypto: qce - fix CCM AAD buffer underallocation |
| CVE-2026-80833 | await | — | Linux | Linux | — | crypto: sun8i-ss - Remove crypto_rng interface |
| CVE-2026-80834 | await | — | Linux | Linux | — | crypto: sun8i-ce - Remove crypto_rng interface |
| CVE-2026-80835 | await | — | Linux | Linux | — | crypto: qcom-rng - Remove crypto_rng interface |
| CVE-2026-80836 | await | — | Linux | Linux | — | crypto: virtio - bound the akcipher result length |
| CVE-2026-80837 | await | — | Linux | Linux | — | netfilter: nf_tables: don't queue packet path object notifications |
| CVE-2026-80838 | await | — | Linux | Linux | — | vxlan: keep the last remote linked during FDB flush |
| CVE-2026-80839 | await | — | Linux | Linux | — | batman-adv: reject unrepresentable multicast TVLV offsets |
| CVE-2026-80840 | await | — | Linux | Linux | — | ipv6: seg6: clear IPv4 control block on IPIP decapsulation |
| CVE-2026-80841 | await | — | Linux | Linux | — | net/packet: defer vmalloc TX_RING free until skbs finish |
| CVE-2026-80842 | await | — | Linux | Linux | — | net: bridge: mcast: fix use-after-free of a master VLAN's multicast context |
| CVE-2026-80843 | await | — | Linux | Linux | — | xfrm: fix xfrm_state_construct() auth-trunc leak |
| CVE-2026-80844 | await | — | Linux | Linux | — | xfrm: ah6: validate routing header segments_left |
| CVE-2026-80845 | await | — | Linux | Linux | — | xfrm: avoid lock inversion in nat keepalive work |
| CVE-2026-80846 | await | — | Linux | Linux | — | xfrm: drop ESP-in-TCP packets with no ingress device |
| CVE-2026-80847 | await | — | Linux | Linux | — | tcp: clamp route advmss to TCP_MIN_MSS |
| CVE-2026-80848 | await | — | Linux | Linux | — | xfrm: espintcp: fix UAF during close |
| CVE-2026-80849 | await | — | Linux | Linux | — | net/tcp-ao: fix use-after-free of current_key on reconnect to another peer |
| CVE-2026-80850 | await | — | Linux | Linux | — | tcp: fix AO info use-after-free in tcp_ao_connect_init() |
| CVE-2026-80851 | await | — | Linux | Linux | — | gtp: serialize PDP context updates |
| CVE-2026-80852 | await | — | Linux | Linux | — | tls: device: fix out-of-bounds write in tls_append_frag() |
| CVE-2026-80853 | await | — | Linux | Linux | — | KVM: SEV: Allocate full pages for {DE,EN}CRYPT ops on SNP-enabled hosts |
| CVE-2026-80854 | await | — | Linux | Linux | — | usb: gadget: f_tcm: keep port count until LUN teardown completes |
| CVE-2026-80855 | await | — | Linux | Linux | — | fuse: fix invalidate lock leak on open O_TRUNC DAX failure |
| CVE-2026-80856 | await | — | Linux | Linux | — | fuse: fix invalidate lock leak on setattr writeback failure |
| CVE-2026-80857 | await | — | Linux | Linux | — | fuse: wait for FR_FINISHED on abort_on_kill to prevent use-after-free |
| CVE-2026-80858 | await | — | Linux | Linux | — | fuse: publish io-uring queues with release semantics |
| CVE-2026-80859 | await | — | Linux | Linux | — | fuse: fix missing barrier when checking io-uring readiness |
| CVE-2026-80860 | await | — | Linux | Linux | — | fuse: fix race between interrupt and resend |
| CVE-2026-80861 | await | — | Linux | Linux | — | usb: xhci: bail out of setup if the controller is inaccessible |
| CVE-2026-80862 | await | — | Linux | Linux | — | nvme-tcp: fix usage of page_frag_cache |
| CVE-2026-80863 | await | — | Linux | Linux | — | RDMA/rxe: Fix OOB in free_rd_atomic_resources() |
| CVE-2026-80864 | await | — | Linux | Linux | — | RDMA/rxe: Fix responder UAF on IB_QP_MAX_DEST_RD_ATOMIC modify_qp |
| CVE-2026-80865 | await | — | Linux | Linux | — | bpf: Add missing access_ok call to copy_user_syms |
| CVE-2026-80866 | await | — | Linux | Linux | — | tipc: avoid busy looping in tipc_exit_net() |
| CVE-2026-80867 | await | — | Linux | Linux | — | alpha/PCI: Add security_locked_down() check to pci_mmap_resource() |
| CVE-2026-80868 | await | — | Linux | Linux | — | ntfs3: Allocate iomap inline_data using alloc_page |
| CVE-2026-80869 | await | — | Linux | Linux | — | ntfs: bound the attribute-list entry in ntfs_read_inode_mount() |
| CVE-2026-80870 | await | — | Linux | Linux | — | drm/amdkfd: Validate CRIU-restored IDs before idr_alloc |
| CVE-2026-80871 | await | — | Linux | Linux | — | crypto: xilinx-trng - Remove crypto_rng interface |
| CVE-2026-80872 | await | — | Linux | Linux | — | ALSA: hda/tas2781: Cancel async firmware request at unbind |
| CVE-2026-80873 | await | — | Linux | Linux | — | KVM: arm64: nv: Write ESR_EL2 for injected nested SError exceptions |
| CVE-2026-80874 | await | — | Linux | Linux | — | arm64: dts: renesas: ironhide: Describe inline ECC carveouts |
| CVE-2026-80875 | await | — | Linux | Linux | — | ipvs: use parsed transport offset in TCP state lookup |
| CVE-2026-80876 | await | — | Linux | Linux | — | ring-buffer: Fix event length with forced 8-byte alignment |
| CVE-2026-80877 | await | — | Linux | Linux | — | afs: Fix vllist leak |
| CVE-2026-80878 | await | — | Linux | Linux | — | afs: Fix leak of ungot volume |
| CVE-2026-80879 | await | — | Linux | Linux | — | ocfs2: fix circular locking dependency in ocfs2_dio_end_io_write |
| CVE-2026-80880 | await | — | Linux | Linux | — | IB/mlx5: Properly support implicit ODP rereg_mr |
| CVE-2026-80881 | await | — | Linux | Linux | — | ocfs2: fix buffer head management in ocfs2_read_blocks() |
| CVE-2026-80882 | await | — | Linux | Linux | — | crypto: tegra - Return ENOMEM when input buffer allocation fails for ccm |
| CVE-2026-80883 | await | — | Linux | Linux | — | drm/tegra: gr2d/gr3d: Initialize address register map before HOST1X client is… |
| CVE-2026-80884 | await | — | Linux | Linux | — | ntb: Store original DMA address for future release |
| CVE-2026-80885 | await | — | Linux | Linux | — | afs: Fix uncancelled rxrpc OOB message handler |
| CVE-2026-80886 | await | — | Linux | Linux | — | serial: msm: Disable DMA for kernel console UART |
| CVE-2026-80887 | await | — | Linux | Linux | — | drm/vmwgfx: use check_add_overflow for shader size+offset bound |
| CVE-2026-80888 | await | — | Linux | Linux | — | drm/vmwgfx: drop dma_buf reference on foreign-fd prime import |
| CVE-2026-80889 | await | — | Linux | Linux | — | can: isotp: fix timer drain order, wakeup handling and tx_gen ordering |
| CVE-2026-80890 | await | — | Linux | Linux | — | sctp: reject stale cookies with mismatched verification tags |
| CVE-2026-80891 | await | — | Linux | Linux | — | KVM: s390: pci: Validate AIBV and AISB before pinning guest pages |
| CVE-2026-80892 | await | — | Linux | Linux | — | erofs: cap LZMA stream pool size |
| CVE-2026-80893 | await | — | Linux | Linux | — | mm/hugetlb: fix swap entry corruption when clearing uffd-wp at fork() |
| CVE-2026-80894 | await | — | Linux | Linux | — | iommufd: Fix wrong hwpt passed to iommufd_auto_response_faults on replace |
| CVE-2026-80895 | await | — | Linux | Linux | — | mshv: Order pt_vp_array publish against irqfd assertion path |
| CVE-2026-80896 | await | — | Linux | Linux | — | mshv: Fix race in mshv_irqfd_deassign |
| CVE-2026-80897 | await | — | Linux | Linux | — | netfs: release readahead folios on iterator preparation failure |
| CVE-2026-80898 | await | — | Linux | Linux | — | netfs: clear PG_private_2 on copy-to-cache append failure |
| CVE-2026-80899 | await | — | Linux | Linux | — | erofs: remove fscache backend entirely |
| CVE-2026-80900 | await | — | Linux | Linux | — | ASoC: SDCA: Make UMP message size check more robust |
| CVE-2026-80901 | await | — | Linux | Linux | — | ipvs: fix the checksum validations |
| CVE-2026-80902 | await | — | Linux | Linux | — | dmaengine: sun6i-dma: Fix reclaim descriptors while terminating DMA |
| CVE-2026-80903 | await | — | Linux | Linux | — | drm/xe/oa: Fix sync entry leak on OA config emit failure |
| CVE-2026-80904 | await | — | Linux | Linux | — | net/tls: Fail tls_sw_splice_read() after a failed async decrypt |
| CVE-2026-80905 | await | — | Linux | Linux | — | net: tap: fix wrong transport_header when sending VLAN-tagged frame |
| CVE-2026-80906 | await | — | Linux | Linux | — | net: packet: fix wrong transport_header when sending VLAN-tagged frame |
| CVE-2026-80907 | await | — | Linux | Linux | — | drm/amdgpu: Fix UVD dpb min size calculation for H264 |
| CVE-2026-80908 | await | — | Linux | Linux | — | drm/amdgpu: Reject UVD message with dimensions above 4096 |
| CVE-2026-80909 | await | — | Linux | Linux | — | drm/amdgpu: Reject UVD message with invalid number of h265 refs |
| CVE-2026-80910 | await | — | Linux | Linux | — | ASoC: codecs: lpass-wsa-macro: Fix enum kcontrol accesses |
| CVE-2026-80911 | await | — | Linux | Linux | — | ASoC: SOF: sof-audio: Fix error path in sof_widget_setup_unlocked() |
| CVE-2026-80912 | await | — | Linux | Linux | — | selinux: reject an unclaimed class value in security_get_classes() |
| CVE-2026-80913 | await | — | Linux | Linux | — | selinux: require every boolean value to be defined |
| CVE-2026-82309 | await | — | — | Robots-Validate | CWE-405 | Robots::Validate versions from 0.3.2 before 0.3.11 for Perl allow unbounded o… |