boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Wednesday, September 16, 2026 · all times UTC← 2026-09-15 · archive

Security Box Score — September 16, 2026 — page 2

Edition of September 16, 2026, continued — page 2 of 2. Back to page 1

Results (continued, ranked) — ranks 401–871 of 871
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-898037.8—LinuxLinux—drm/nouveau: unsubscribe the channel-kill event before the fence context
CVE-2026-898057.8—LinuxLinux—drm/pagemap: Fix folio allocation fallback and use-after-put
CVE-2026-898087.8—LinuxLinux—drm/amdkfd: Fix the case that vm range is hole at svm_migrate_copy_to_vram
CVE-2026-898107.8—LinuxLinux—drm/amdkfd: Fix error path at svm_migrate_copy_to_ram
CVE-2026-898147.8—LinuxLinux—drm/amdgpu: clamp the isolation index for rings outside a partition
CVE-2026-898157.8—LinuxLinux—drm/ttm: Drop tt->restore after successful restore
CVE-2026-898197.8—LinuxLinux—drm/amd/display: validate plane degamma LUT size for private color prop
CVE-2026-898237.8—LinuxLinux—drm: fix race between partial drm_dev_register() failure and ioctl
CVE-2026-898257.8—LinuxLinux—drm/panthor: fix firmware control interface bounds checks
CVE-2026-898297.8—LinuxLinux—f2fs: fix to pass folio->index to f2fs_sanity_check_node_footer()
CVE-2026-898327.8—LinuxLinux—f2fs: fix to clear dirty flag on folio in error path
CVE-2026-898367.8—LinuxLinux—f2fs: fix folio_nr_pages() race after put in large folio invalidate
CVE-2026-898417.8—LinuxLinux—f2fs: only redirty pinned folios in redirty_blocks
CVE-2026-898547.8—LinuxLinux—scsi: qla2xxx: Fix cs84xx use-after-free on host teardown
CVE-2026-898707.8—LinuxLinux—media: zoran: Avoid freeing a registered video_device twice
CVE-2026-898737.8—LinuxLinux—media: v4l2-ctrls: validate HEVC EXT SPS RPS counts
CVE-2026-898757.8—LinuxLinux—media: ti: vpe: quiesce overflow recovery before freeing streams
CVE-2026-898807.8—LinuxLinux—media: rtl2832_sdr: release URBs and stream buffers on start_streaming() failure
CVE-2026-898827.8—LinuxLinux—media: rkvdec: hevc: guard INTER_REF_PIC_SET_PRED index underflow
CVE-2026-898837.8—LinuxLinux—media: rc: sunxi-cir: Unregister rc device on probe failure
CVE-2026-898877.8—LinuxLinux—media: i2c: ov7740: fix use-after-destroy in remove
CVE-2026-898887.8—LinuxLinux—media: i2c: ov02a10: fix endpoint parsing use-after-free
CVE-2026-898907.8—LinuxLinux—media: go7007: defer the ALSA v4l2 put until card release
CVE-2026-898937.8—LinuxLinux—media: cx23885: cancel NetUP CI work before teardown
CVE-2026-898947.8—LinuxLinux—media: cx231xx: reject geometry changes while the VBI queue is busy
CVE-2026-898997.8—LinuxLinux—media: cec: disable delayed work before freeing an interrupted transmit
CVE-2026-899027.8—LinuxLinux—LoongArch: Avoid preempt count underflow without probe
CVE-2026-899037.8—LinuxLinux—LoongArch: Do not save/restore percpu base register in rethook trampoline
CVE-2026-899067.8—LinuxLinux—LoongArch: BPF: Refactor jump offset calculation in tail call
CVE-2026-899197.8—LinuxLinux—KVM: s390: keyop: use mmu_lock to read gmap->asce
CVE-2026-899207.8—LinuxLinux—KVM: s390: Fix memory corruption by not reinjecting CK machine checks
CVE-2026-899227.8—LinuxLinux—KVM: s390: Take srcu when importing watchpoint data
CVE-2026-899387.8—LinuxLinux—iio: chemical: atlas-sensor: use iio_trigger_poll_nested() to fix remove UAF
CVE-2026-899407.8—LinuxLinux—iio: buffer: Tie IIO dma fence lock lifetime to the fence
CVE-2026-899417.8—LinuxLinux—iio: buffer: Make IIO DMA fence release RCU-safe
CVE-2026-899427.8—LinuxLinux—iio: buffer: Fix potential use-after-free in anonymous buffer release
CVE-2026-899617.8—LinuxLinux—powerpc/mm: fix wrong addr_pfn tracking in compound vmemmap population
CVE-2026-899657.8—LinuxLinux—nvdimm/btt: reject an arena whose nfree is below the lane count
CVE-2026-899677.8—LinuxLinux—mm/migrate_device: avoid out-of-bounds writes for compound folios
CVE-2026-899797.8—LinuxLinux—ALSA: pcm: Fix race between non-atomic ops and trigger-start
CVE-2026-899857.8—LinuxLinux—memcg: keep folio's objcg same as its node
CVE-2026-899867.8—LinuxLinux—mm/mempolicy: fix sleeping allocation in alloc_pages_bulk_weighted_interleave()
CVE-2026-899887.8—LinuxLinux—kprobes: Protect kprobe_blacklist with RCU
CVE-2026-899947.8—LinuxLinux—dmaengine: fsl-edma: tracing: no ptr dereference during log output
CVE-2026-899977.8—LinuxLinux—dm: fix resume-vs-remove race
CVE-2026-899987.8—LinuxLinux—dm: fix race when loading and unloading a table
CVE-2026-900017.8—LinuxLinux—HID: bpf: serialize device reference release in struct_ops destroy path
CVE-2026-900027.8—LinuxLinux—ftrace: Take trace_array reference before accessing its ftrace_ops
CVE-2026-900037.8—LinuxLinux—futex: Prevent rcuwait use-after-free during requeue PI
CVE-2026-900077.8—LinuxLinux—scsi: pm8001: Use rollback index when freeing MSI-X vectors
CVE-2026-900087.8—LinuxLinux—scsi: megaraid_sas: Limit NVMe request size to the PRP chain frame
CVE-2026-900097.8—LinuxLinux—scsi: bsg: Fix TOCTOU in io_uring passthrough command setup
CVE-2026-900107.8—LinuxLinux—scsi: bsg: Cap io_uring sense copy to max_response_len
CVE-2026-900137.8—LinuxLinux—tracing: Take trace_array reference when opening options file
CVE-2026-900147.8—LinuxLinux—tracing: Have show_event_filters/triggers files take trace array ref
CVE-2026-900227.8—LinuxLinux—usb: gadget: f_midi2: fix use-after-free in string attribute show path
CVE-2026-900267.8—LinuxLinux—usb: typec: qcom-pmic: cancel reset_work on stop
CVE-2026-900277.8—LinuxLinux—usb: typec: qcom-pmic-typec: disable cc_debounce_dwork on stop
CVE-2026-900307.8—LinuxLinux—usb: dwc3: clear forceRM when issuing EndTransfer
CVE-2026-900327.8—LinuxLinux—media: usbtv: keep device alive while ALSA card exists
CVE-2026-900437.8—LinuxLinux—zram: fix slot lock bit position on big-endian 64-bit
CVE-2026-900447.8—LinuxLinux—usb: gadget: f_fs: Fix Use-After-Free in AIO error path
CVE-2026-900457.8—LinuxLinux—USB: gadget: ffs: fix mm lifetime handling
CVE-2026-900467.8—LinuxLinux—mm/page_alloc: don't spin_trylock() in NMI on UP
CVE-2026-900477.8—LinuxLinux—drm/xe: Don't hand out the flat CCS storage as usable VRAM
CVE-2026-149167.7—KongKong Enteprise GatewayCWE-241Kong API Gateway Enterprise: JWT Algorithm-Confusion
CVE-2026-149177.7—KongKong Enterprise GatewayCWE-288Kong API Gateway Enterprise: SAML Authentication bypass
CVE-2026-203427.7—CiscoCisco Secure Firewall Management Center (FMC)CWE-639Cisco Secure Firewall Management Center Software Low Privileged Arbitrary Fil…
CVE-2026-615957.7—djust-orgdjustCWE-636djust: Multi-tenant isolation fails open on the WebSocket/SSE path, disclosin…
CVE-2026-629977.7—kedro-orgkedro-pluginsCWE-502Kedro-Datasets: Remote code execution in experimental `PyTorchDataset` via un…
CVE-2026-853857.7—Concrete CMSConcrete CMSCWE-79Concrete CMS below 9.5.4 is vulnerable to Stored XSS via User Timezone Field
CVE-2026-864747.7—Fermax Electronica S.A.U.DUOX PLUS monitor firmware (VEO Wi-Fi range)CWE-295Improper Certificate Validation in the Firmware Download vulnerability
CVE-2026-865857.7—Fermax Electronica S.A.U.DUOX PLUS monitor firmware (VEO Wi-Fi range)CWE-347Improper Verification of the Firmware Signature vulnerability
CVE-2026-900257.7—LinuxLinux—usb: typec: ucsi: displayport: Fix OOB altmode array index
CVE-2026-927847.7—refinedev@refinedev/inferencerCWE-94@refinedev/inferencer through 7.0.0 Code Injection via API Field Names
CVE-2026-764257.6—CiscoCisco Identity Services Engine SoftwareCWE-89Cisco ISE SQL Injection Vulnerability
CVE-2026-924657.6—ThemeumWP Mega MenuCWE-89WordPress WP Mega Menu plugin <= 1.4.2 - SQL Injection vulnerability
CVE-2026-926167.6—error311FileRiseCWE-613FileRise < 3.28.0 Privilege Escalation via WebDAV Session Inheritance
CVE-2026-928007.6—suitenumeriqueDocsCWE-613Docs before 5.4.1 Stale Collaboration Session After Access Revocation
CVE-2026-928127.6—decaporgdecap-serverCWE-22decap-server Path Traversal via Sibling Directory Prefix Matching
CVE-2026-182127.5—Red HatRed Hat build of Keycloak 26.4CWE-401Keycloak-services: keycloak-services: saml redirect deflate helpers leak nati…
CVE-2026-196667.5—ISCBIND 9CWE-416Use-after-free in query_addnoqnameproof() via the DNS64 filter64 path
CVE-2026-196677.5—ISCBIND 9CWE-197Remote assertion failure via 16-bit length truncation in `dns_ncache_add()`
CVE-2026-202477.5—CiscoCisco Identity Services Engine SoftwareCWE-89Cisco Identity Services Engine Unauthenticated SQL Injection Vulnerability
CVE-2026-203437.5—CiscoCisco Secure Firewall Management Center (FMC)CWE-306Cisco Secure Firewall Management Center Software Information Disclosure and D…
CVE-2026-463527.5—OISFsuricataCWE-833Suricata defrag: fragmented encapsulated traffic with fragments can lead to d…
CVE-2026-631267.5—squarewireCWE-190Wire: Unauthenticated decoder crash via 32-bit length integer overflow in Byt…
CVE-2026-631287.5—modelcontextprotocolrust-sdkCWE-400RMCP: Unauthenticated permanent session-table leak in rmcp Streamable HTTP se…
CVE-2026-761637.5—ISCBIND 9CWE-617named aborts on a TKEY query when the user configuration has no global option…
CVE-2026-776927.5—ISCBIND 9CWE-476Unauthenticated remote crash of named via a single DoH SIG(0) request
CVE-2026-796517.5—Red HatRed Hat build of Keycloak 26.4CWE-400Keycloak-services: keycloak-services: unauthenticated dos via unbounded local…
CVE-2026-802747.5—ISCBIND 9CWE-617Validating resolver can abort while caching a mismatched NOQNAME proof
CVE-2026-815637.5—ISCBIND 9CWE-401SVCB AliasMode additional-data error leaks qpcache references
CVE-2026-817367.5—ISCBIND 9CWE-1050Remote CPU denial of service through cached SVCB/HTTPS AliasMode trees
CVE-2026-818757.5—hapifhirorg.hl7.fhir.coreCWE-20HAPI FHIR: SHCParser unbounded DEFLATE decompression causes denial of service
CVE-2026-818767.5—hapifhirorg.hl7.fhir.coreCWE-20HAPI FHIR: SHCParser DEFLATE infinite loop causes denial of service
CVE-2026-823997.5—corednscorednsCWE-770CoreDNS: Unauthenticated memory exhaustion in custom transports
CVE-2026-849977.5—reactphphttpCWE-835react/http: A malformed HTTP chunked body can lead to a denial-of-service and…
CVE-2026-857567.5—sshnetSSH.NETCWE-78SSH.NET: ScpClient allows server-side RCE via default SCP path handling
CVE-2026-860037.5—corednscorednsCWE-441CoreDNS DoH/DoQ/gRPC bypass UPDATE rejection enforced on UDP/TCP
CVE-2026-860437.5—zalandoskipperCWE-863Skipper: OPA body-authz bypass: truncated_body mitigation fails open on chunk…
CVE-2026-898637.5—LinuxLinux—scsi: qla2xxx: edif: Fix NULL pointer deref in RX SA delete check
CVE-2026-898977.5—LinuxLinux—media: cec: Serialize exclusive follower delivery
CVE-2026-899687.5—LinuxLinux—nvmet-tcp: reject unsolicited H2CData PDUs
CVE-2026-899717.5—LinuxLinux—nvme: skip the zoned limits update if the zone info query failed
CVE-2026-899747.5—LinuxLinux—nvme-fc: fix double free of fabrics options when nvme_add_ctrl() fails
CVE-2026-921287.5—Jenkins ProjectJenkins Script Security PluginCWE-494Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier downloads a …
CVE-2026-921297.5—Jenkins ProjectJenkins Script Security PluginCWE-693Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not che…
CVE-2026-926257.5—Control iDiDSecureCWE-306Control iD iDSecure Unauthenticated Denial of Service
CVE-2026-926267.5—Control iDiDSecureCWE-476Control iD iDSecure Unauthenticated Denial of Service
CVE-2026-202227.4—CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-401Cisco Secure Adaptive Security Appliance Software and Secure Firewall Threat …
CVE-2026-427847.4—Red HatConfidential Compute AttestationCWE-347Sequoia-openpgp: sequoia-openpgp: cryptographic integrity compromise via key …
CVE-2026-615907.4—djust-orgdjustCWE-306djust's observability endpoints are network-exposed: the localhost gate is an…
CVE-2026-615927.4—djust-orgdjustCWE-384djust: SSE sessions are not bound to the authenticated user; the client-chose…
CVE-2026-711797.3—DellUpdate Package FrameworkCWE-78Dell Update Package Framework, versions prior to 26.07.03, contains an Improp…
CVE-2026-853867.3—Concrete CMSConcrete CMSCWE-79Concrete CMS before 9.5.4 stored is vulneratble to cross-site scripting via u…
CVE-2026-899107.3—LinuxLinux—LoongArch: KVM: Fix uninitialized stack variable issue with dmsintc
CVE-2026-175267.2—Red HatRed Hat build of Keycloak 26.4CWE-862Keycloak-services: keycloak-services: privilege escalation via impersonation …
CVE-2026-764247.2—CiscoCisco Identity Services Engine SoftwareCWE-23Cisco ISE Arbitrary File Access Vulnerability
CVE-2026-870247.2—TaniumAssetCWE-89Tanium addressed a SQL injection vulnerability in Asset.
CVE-2026-879767.2—Apache Software FoundationApache NiFi RegistryCWE-22Apache NiFi Registry: Improper Limitation of Pathname in Persisted Extension …
CVE-2026-924697.2—zlt2000microservices-platformCWE-639microservices-platform through 6.0.0 Arbitrary File Deletion via Missing Owne…
CVE-2026-926047.2—StamusNetworkssciriusCWE-22Scirius through 3.8.0 Arbitrary File Write via PCAP Upload
CVE-2026-927517.2—yahooCMAKCWE-352CMAK through 3.0.0.6 Cross-Site Request Forgery via Missing CSRF Filter
CVE-2026-927797.2—BuilderIO@builder.io/sdk-reactCWE-1321Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via Bindings
CVE-2026-927837.2—yeti-platformyetiCWE-862Yeti through 2.11.0 Missing Authorization on RBAC Relationship Deletion
CVE-2026-928067.2—phpListphpListCWE-352phpList before 3.6.17 Cross-Site Request Forgery via massremove.php
CVE-2026-203007.1—CiscoCisco Identity Services Engine SoftwareCWE-89Cisco Identity Services Engine SQL Injection Vulnerability
CVE-2026-408567.1—WNCT-Mobile 5G Box IDUCWE-306Config disclosure in T-Mobile 5G Box IDU routers
CVE-2026-615967.1—djust-orgdjustCWE-639djust has broken object-level access control (IDOR)
CVE-2026-615987.1—djust-orgdjustCWE-915Client mass-assignment of arbitrary view attributes via the default dj-model …
CVE-2026-731757.1—AdvantechEKI-1242IEIMSCWE-400Nozomi Networks Labs identified a CWE-400: Uncontrolled Resource Consumption …
CVE-2026-734627.1—Arista NetworksEOSCWE-125On affected platforms running Arista EOS with IGMP (Internet Group Management…
CVE-2026-890347.1—TCHQRingCWE-306TCH QRing R20_B006 Unauthenticated BLE Access
CVE-2026-898187.1—LinuxLinux—drm/amdgpu/vcn: fix integer overflow in dec_msg buffer count check
CVE-2026-898267.1—LinuxLinux—drm/panthor: harden firmware build-info bounds checks
CVE-2026-898387.1—LinuxLinux—f2fs: limit recovery filename logging to stored length
CVE-2026-898407.1—LinuxLinux—f2fs: validate MOVE_RANGE destination size
CVE-2026-899127.1—LinuxLinux—KVM: arm64: vgic-its: Don't dereference a NULL collection on ITT save
CVE-2026-899277.1—LinuxLinux—KVM: x86: hyper-v: Clamp stimer deadline to avoid livelock
CVE-2026-900167.1—LinuxLinux—staging: rtl8723bs: fix OOB read in rtw_restruct_wmm_ie()
CVE-2026-900177.1—LinuxLinux—staging: rtl8723bs: fix OOB read in rtw_action_frame_parse()
CVE-2026-924177.1—n/aOpen5GSCWE-404Open5GS PFCP types.c ogs_pfcp_parse_volume_measurement null pointer dereference
CVE-2026-924567.1—guchengwuyueyshop-crmCWE-862yshop-crm through 2.1.3 Missing Authorization via CRM Customer Rule-Configura…
CVE-2026-924577.1—guchengwuyueyshop-crmCWE-862yshop-crm through 2.1.3 Missing Authorization via CrmInvoiceController issueI…
CVE-2026-924597.1—guchengwuyueyshop-crmCWE-862yshop-crm through 2.1.3 Missing Authorization via CRM Lead-Claim Endpoint
CVE-2026-924607.1—guchengwuyueyshop-crmCWE-862yshop-crm through 2.1.3 Missing Authorization via CRM Operation-Log Listing
CVE-2026-924627.1—guchengwuyueyshop-crmCWE-862yshop-crm through 2.1.3 Missing Authorization via CrmFlowController deleteFlo…
CVE-2026-924637.1—guchengwuyueyshop-crmCWE-862yshop-crm through 2.1.3 Missing Authorization via Disabled Annotation on Syst…
CVE-2026-924687.1—zlt2000microservices-platformCWE-639microservices-platform through 6.0.0 Arbitrary Elasticsearch Index Read via s…
CVE-2026-925677.1—TDuckCloudtduck-survey-formCWE-639TDuck survey form through 5.0 Unauthorized Data Modification
CVE-2026-925707.1—yogeshojharengineCWE-862reNgine through 2.2.0 Unauthorized Configuration File Read
CVE-2026-925827.1—WWBNAVideoCWE-352AVideo through 29.0 Broken Access Control via videoAddNew.json.php CSRF Bypass
CVE-2026-926007.1—stylefengGunsCWE-862Guns through 8.3.5 Information Disclosure via Missing Permission Check
CVE-2026-926017.1—stylefengGunsCWE-862Guns through 8.3.5 Improper Access Control via SysNoticeController
CVE-2026-926027.1—TDuckCloudtduck-survey-formCWE-918TDuck survey form through 5.3 Server-Side Request Forgery via Unvalidated Web…
CVE-2026-926037.1—continew-orgcontinew-adminCWE-639ContiNew Admin through 4.1.0 Unauthorized Message Deletion via UserMessageCon…
CVE-2026-926057.1—dfir-irisiris-webCWE-639IRIS through 2.4.29 Unauthorized Comment Access via Object ID
CVE-2026-927507.1—harnessharnessCWE-862Harness through 3.3.0 Missing Access Control via infraproviders endpoint
CVE-2026-927537.1—PatrowlPatrowlManagerCWE-862PatrowlManager through 1.8.4 Authorization Bypass via Events API
CVE-2026-927597.1—SecObserveSecObserveCWE-522SecObserve before 1.59.1 Information Disclosure via API Configuration
CVE-2026-927607.1—shlinkioshlinkCWE-863Shlink through 5.1.6 Mercure Token Authorization Bypass
CVE-2026-927657.1—archerysecarcherysecCWE-639ArcherySec through 2.0.6 Information Disclosure via WebScanVulnList
CVE-2026-927707.1—goharborharborCWE-200Harbor through 2.15.2 Scanner Credential Disclosure via Query Parameter
CVE-2026-927717.1—twentyhqtwentyCWE-863Twenty before 2.35.0 Permission Bypass via groupBy-with-records Query
CVE-2026-927727.1—LeantimeleantimeCWE-862Leantime before 3.9.6 Unauthorized Plugin Installation via HTMX
CVE-2026-927737.1—triggerdotdevtrigger.devCWE-639Trigger.dev before 4.6.0 GitHub App Installation Takeover
CVE-2026-927757.1—requarksWiki.jsCWE-918Wiki.js through 2.5.314 Server-Side Request Forgery via Image Prefetch
CVE-2026-927897.1—Graylog2graylog2-serverCWE-918Graylog through 7.1.4 Server-Side Request Forgery via HTTP Redirect
CVE-2026-927957.1—coze-devcoze-studioCWE-918Coze Studio through 0.5.1 Server-Side Request Forgery via Plugin
CVE-2026-928047.1—NangoHQNangoCWE-918Nango through 0.70.4 Server-Side Request Forgery via Configuration
CVE-2026-928117.1—browserlessbrowserlessCWE-200browserless 1.44.0 through 2.56.7 File Protocol Restriction Bypass
CVE-2026-689047.0—node-opcuanode-opcuaCWE-400node-opcua: TCP Socket Leak (FIN-WAIT-2) via keepalive reconnection cycle - R…
CVE-2026-774077.0—rabbitmqamqp091-goCWE-316RabbitMQ amqp091-go: Plaintext Credential Exposure via Exported PLAIN Authent…
CVE-2026-910977.0—HP Inc.HP Linux Imaging and Printing Software (HPLIP)CWE-787HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
CVE-2026-927187.0—projectdiscoverynucleiCWE-347Nuclei from 3.7.0 before 3.11.1 Template Signature Bypass via Modification-Ti…
CVE-2026-923626.9—ag-ui-protocolag-uiCWE-400ag-ui-protocol ag-ui SSE Frame sse.rs resource consumption
CVE-2026-924016.9—ChangeWeDercrmCWE-287ChangeWeDer crm improper authentication
CVE-2026-925656.9—lukevellaralllyCWE-359Rallly before 4.15.0 Information Disclosure via polls.get
CVE-2026-925836.9—WWBNAVideoCWE-307AVideo through 29.0 Rate Limit Bypass via Non-Atomic Counter Increment
CVE-2026-927906.9—higress-grouphigressCWE-703Higress before 2.2.4 Rate Limit Bypass via Malformed Cookie Header
CVE-2026-928036.9—LibreTranslateLibreTranslateCWE-862LibreTranslate through 1.9.6 Missing Access Check on the download_file Route
CVE-2026-928136.9—metabaseMetabaseCWE-918Metabase through 0.63.18 SSRF via GeoJSON URL validation bypass
CVE-2026-202486.8—CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-195Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat …
CVE-2026-646846.8—modelcontextprotocolrust-sdkCWE-200RMCP: Custom HTTP headers leak to cross-origin redirect targets
CVE-2026-774016.8—zopefoundationAccessControlCWE-693Zope AccessControl: Information disclosure through Python string `format` and…
CVE-2026-911006.8—HP Inc.HP Linux Imaging and Printing Software (HPLIP)CWE-78HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
CVE-2026-921406.8—Jenkins ProjectJenkins Gitee PluginCWE-79Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sende…
CVE-2026-269476.7—DellECSCWE-269Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prio…
CVE-2026-926156.6—Red HatRed Hat Advanced Cluster Management for Kubernetes 2CWE-413Flightctl: flightctl: package-global go-git https transport mutated per-repo …
CVE-2026-190336.5—ISCBIND 9CWE-349Unauthenticated IXFR deltas are applied to the live zone before TSIG verifica…
CVE-2026-202836.5—CiscoCisco Identity Services Engine SoftwareCWE-78Cisco Identity Services Engine IPSec Open API Command Injection Vulnerability
CVE-2026-202876.5—CiscoCisco Identity Services Engine SoftwareCWE-269Cisco Identity Services Engine Hardening Release - Improper Privlege Manageme…
CVE-2026-571736.5—vllm-projectvllmCWE-770vLLM: Unauthenticated audio decompression-bomb DoS in /v1/chat/completions
CVE-2026-615886.5—djust-orgdjustCWE-200djust's Django model serialization has no sensitive-field denylist: password …
CVE-2026-629496.5—ronfasyncsshCWE-835AsyncSSH: asyncio event-loop freeze via SSH maximum packet size = 0 in SSH_MS…
CVE-2026-691476.5—vllm-projectvllmCWE-400vLLM: Request-selected PyNvVideoCodec GPU decode bypasses static VRAM reserva…
CVE-2026-764386.5—CiscoCisco BroadWorksCWE-863Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerab…
CVE-2026-848596.5—Scada-LTSScada-LTS—Scada-LTS Authenticated Blind SQL Injection
CVE-2026-849936.5—mikro-ormmikro-ormCWE-89MikroORM: SQL injection via unvalidated order direction in orderBy
CVE-2026-863586.5—DellUpdate Package FrameworkCWE-121Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-b…
CVE-2026-870766.5—TaniumDiscoverCWE-200Tanium addressed an information disclosure vulnerability in Discover.
CVE-2026-871166.5—TaniumThreat ResponseCWE-918Tanium addressed a server-side request forgery vulnerability in Threat Response.
CVE-2026-921396.5—Jenkins ProjectJenkins Bitbucket Push and Pull Request PluginCWE-918Jenkins Bitbucket Push and Pull Request Plugin 4.0.1 and earlier trusts value…
CVE-2026-181206.3—Concrete CMSConcrete CMSCWE-862Missing Authorization in legacy Express entries search endpoint allows disclo…
CVE-2026-567196.3—MikroTikRouterOSCWE-125MikroTik RouterOS < 7.24 Out-of-Bounds Read via SMB1 SessionSetupAndX
CVE-2026-615896.3—djust-orgdjustCWE-348djust: WebSocket/runtime reconstructed request omits the client Host, causing…
CVE-2026-731696.3—AdvantechEKI-1242IEIMSCWE-79Nozomi Networks Labs identified a CWE-79: Improper Neutralization of Input Du…
CVE-2026-773606.3—middleapiorpcCWE-113oRPC: Vary Header Injection in CORS Plugin leading to potential Cache/CORS By…
CVE-2026-818716.3—open-telemetryopentelemetry-goCWE-295OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pin…
CVE-2026-818726.3—open-telemetryopentelemetry-goCWE-400OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is full
CVE-2026-871136.3—TaniumThreat ResponseCWE-639Tanium addressed an improper access controls vulnerability in Threat Response.
CVE-2026-203096.1—CiscoCisco Identity Services Engine SoftwareCWE-79Cisco Identity Services Engine Cross-Site Scripting Vulnerability
CVE-2026-599446.1—composercomposerCWE-22Composer: CVE-2026-59946 fix bypass via symlinked package bin path
CVE-2026-889766.1—udecodeplateCWE-79@platejs/core HTML deserialization can trigger browser behavior during parsing
CVE-2026-734576.0—Arista NetworksEOSCWE-532Under certain circumstances, the gNPSI client credentials might be logged in …
CVE-2026-771906.0—Arista NetworksEOSCWE-20Security Advisory 0177
CVE-2026-925956.0—nodemailernodemailerCWE-73Nodemailer before 9.1.1 Security Sandbox Bypass via resolveContent
CVE-2026-196625.9—ISCBIND 9CWE-416qpcache NOQNAME proof use-after-free crashes recursive resolver
CVE-2026-199415.9—ISCBIND 9CWE-345checkwildcard() accepts an out-of-zone NSEC as a wildcard-nonexistence proof
CVE-2026-771195.9—ISCBIND 9CWE-346NSEC3 insecure-referral proof can use unrelated cached NSEC3 RRsets
CVE-2026-825615.9—Apache Software FoundationApache NiFiCWE-862Apache NiFi: Missing Authorization for Components Referenced in Flow Update M…
CVE-2026-925885.9—n8n-ion8nCWE-639n8n before 1.123.76 Improper Authorization via Source Control Push
CVE-2026-201205.8—CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-284Cisco FTD ACL bypass vulnerability
CVE-2026-202905.8—CiscoCisco Secure Firewall Threat Defense (FTD) SoftwareCWE-805Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Servi…
CVE-2026-783015.8—ISCBIND 9CWE-349Out-of-zone database nodes can become authoritative zone cuts
CVE-2026-761045.5—DellObjectScaleCWE-732Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Permission…
CVE-2026-923665.5—code-projectsMatrimonial SystemCWE-74code-projects Matrimonial System Regular Search search.php sql injection
CVE-2026-923805.5—n/aWuzhiCMSCWE-918WuzhiCMS Remote Image Fetch index.php saveRemote server-side request forgery
CVE-2026-923995.5—n/aGPACCWE-119GPAC WebSocket rmt_ws.c rmt_client_handle_ws_frame heap-based overflow
CVE-2026-924055.5—SourceCodesterInventory and Monitoring SystemCWE-74SourceCodester Inventory and Monitoring System index.php sql injection
CVE-2026-924065.5—SourceCodesterInventory and Monitoring SystemCWE-74SourceCodester Inventory and Monitoring System btn_functions.php add sql inje…
CVE-2026-843975.4—AdobeAdobe Experience Manager as a Cloud ServiceCWE-79Adobe Experience Manager | Cross-site Scripting (Stored XSS) (CWE-79)
CVE-2026-921325.4—Jenkins ProjectJenkins Gradle PluginCWE-74Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build sc…
CVE-2026-921335.4—Jenkins ProjectJenkins GitLab PluginCWE-522Jenkins GitLab Plugin 1.2149.vcfc32c82b_f7f and earlier caches the GitLab API…
CVE-2026-196075.3—Red HatRed Hat build of Keycloak 26.4CWE-287Keycloak-services: keycloak-services: broker-originated username collision ca…
CVE-2026-196685.3—ISCBIND 9CWE-407Resource Exhaustion via Excessive DNSSEC Cryptographic Material Matching
CVE-2026-201215.3—CiscoCisco Secure Firewall Adaptive Security Appliance (ASA) SoftwareCWE-284CIsco FTD Bypass Access List
CVE-2026-598235.3—BerriAIlitellmCWE-918LiteLLM: Server-side request forgery via the `user_config` request parameter …
CVE-2026-617095.3—openfgaopenfgaCWE-281OpenFGA: ListUsers returns a deliberately-excluded user (authorization-decisi…
CVE-2026-734435.3—Arista NetworksEOSCWE-294On affected platforms running Arista EOS with VRRPv2 IP-AH authentication con…
CVE-2026-750295.3—ISCBIND 9CWE-405Message parser retains every identical singleton RDATA, enabling wire-to-work…
CVE-2026-764335.3—CiscoCisco Identity Services Engine SoftwareCWE-22Cisco Identity Services Engine Information Disclosure Vulnerability
CVE-2026-764395.3—CiscoCisco Identity Services Engine SoftwareCWE-306Cisco Identity Services Engine Event Injection Vulnerability
CVE-2026-764445.3—CiscoCisco Identity Services Engine SoftwareCWE-306Cisco Identity Services Engine Information Disclosure Vulnerability
CVE-2026-764475.3—CiscoCisco Identity Services Engine SoftwareCWE-306Cisco Identity Services Engine Certificate Reload Vulnerability
CVE-2026-811765.3—sveltejsdevalueCWE-770Svelte devalue: DoS via malformed input
CVE-2026-851045.3—SoomaSooma tDCS Home TherapyCWE-924Brain stimulation parameters can be modified via Bluetooth in Sooma
CVE-2026-870285.3—Concrete CMSConcrete CMSCWE-862Cross-Board IDOR in the Board Custom Slot Preview in Concrete CMS 9.0.0 throu…
CVE-2026-890295.3—AdenionBlog2SocialCWE-639Blog2Social WordPress Plugin < 9.1.0 User Enumeration via AJAX Handler
CVE-2026-890305.3—AdenionBlog2SocialCWE-862Blog2Social WordPress Plugin < 9.1.0 User Email Disclosure via b2s_search_user
CVE-2026-890315.3—AdenionBlog2SocialCWE-639Blog2Social WordPress Plugin < 9.1.0 Broken Access Control via b2s_calendar_m…
CVE-2026-923565.3—a2ui-projecta2uiCWE-400a2ui-project a2ui Update Components basic_functions.ts updateComponents resou…
CVE-2026-923575.3—a2ui-projecta2uiCWE-200a2ui-project a2ui Model Processor model-processor.ts information disclosure
CVE-2026-923605.3—ag-ui-protocolag-uiCWE-345ag-ui-protocol ag-ui Event Application Layer agent.ts prepareRunAgentInput or…
CVE-2026-923615.3—ag-ui-protocolag-uiCWE-400ag-ui-protocol ag-ui SSE Client client.go resource consumption
CVE-2026-923635.3—ag-ui-protocolag-uiCWE-400ag-ui-protocol ag-ui JSON sse_parser.cpp resource consumption
CVE-2026-923655.3—vllm-projectvllmCWE-404vllm-project vllm thinking_budget_state.py algorithmic complexity
CVE-2026-924025.3—ChangeWeDercrmCWE-862ChangeWeDer crm top.upstudy.crm.controller.UserController UserController.java…
CVE-2026-924165.3—n/aOpen5GSCWE-617Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report…
CVE-2026-924555.3—guchengwuyueyshop-crmCWE-862yshop-crm through 2.1.3 Missing Authorization via CRM Customer Messaging Endp…
CVE-2026-924585.3—guchengwuyueyshop-crmCWE-862yshop-crm through 2.1.3 Missing Authorization via StoreProductController onSale
CVE-2026-924615.3—guchengwuyueyshop-crmCWE-862yshop-crm through 2.1.3 Missing Authorization via CRM Approval-Chain Endpoint
CVE-2026-925685.3—mlrunmlrunCWE-918MLRun through 1.11.0 Server-Side Request Forgery via Webhook
CVE-2026-925695.3—opengoofyhippo4jCWE-918Hippo4j through 1.5.0 SSRF via clientAddress Parameter
CVE-2026-925795.3—WWBNAVideoCWE-289AVideo through 29.0 Broken Access Control via CSRF Exemption Basename Collision
CVE-2026-925815.3—WWBNAVideoCWE-20AVideo through 29.0 Like Counter Desynchronization via Array Parameter
CVE-2026-925845.3—WWBNAVideoCWE-79AVideo through 29.0 Stored Cross-Site Scripting via User-Agent Header
CVE-2026-925855.3—WWBNAVideoCWE-862AVideo through 29.0 Missing Authorization Check via API Like Endpoint
CVE-2026-925865.3—WWBNAVideoCWE-862AVideo through 29.0 Missing Authorization via comment API endpoint
CVE-2026-925875.3—n8n-ion8nCWE-426n8n before 1.123.76 Sandbox Escape via Git Relative URL
CVE-2026-925895.3—craftcmscmsCWE-862Craft CMS 5.0.0 before 5.10.13 Broken Access Control via nested-elements/reorder
CVE-2026-927545.3—PatrowlPatrowlManagerCWE-862PatrowlManager through 1.8.4 Improper Access Control via users API
CVE-2026-927645.3—opencveopencveCWE-863OpenCVE before 3.1.0 Organization API Ignores Token Scope
CVE-2026-927745.3—requarksWiki.jsCWE-863Wiki.js through 2.5.314 Authorization Bypass via GraphQL Tag Omission
CVE-2026-927785.3—yahooCMAKCWE-693CMAK through 3.0.0.6 Feature Gate Bypass via HTML Form Routes
CVE-2026-927815.3—BuilderIO@builder.io/sdk-reactCWE-1321Builder.io Gen2 SDKs through 5.2.11 Prototype Pollution via builder.userAttri…
CVE-2026-928025.3—kanbnkanCWE-862kan through 0.6.0 Authorization Bypass via GitHub Project Import
CVE-2026-928095.3—PrestaShoppsgdprCWE-639PrestaShop psgdpr through 1.4.3 GDPR Log Forgery
CVE-2026-928105.3—PrestaShopblockwishlistCWE-639PrestaShop blockwishlist through 3.0.2 Information Disclosure
CVE-2026-615975.1—djust-orgdjustCWE-79djust is vulnerable to stored/reflected XSS via javascript: URLs in built-in …
CVE-2026-818695.1—open-telemetryopentelemetry-goCWE-176OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncation
CVE-2026-910995.1—HP Inc.HP Linux Imaging and Printing Software (HPLIP)CWE-61HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
CVE-2026-911015.1—HP Inc.HP Linux Imaging and Printing Software (HPLIP)CWE-129HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
CVE-2026-911035.1—HP Inc.HP Linux Imaging and Printing Software (HPLIP)CWE-191HP Linux Imaging and Printing (HPLIP) Software– Multiple Vulnerabilities
CVE-2026-925905.1—craftcmscmsCWE-79Craft CMS 5.7.0 before 5.10.13 Stored XSS via Generated Fields
CVE-2026-200724.9—CiscoCisco Identity Services Engine SoftwareCWE-863ISE information disclosure
CVE-2026-202354.9—CiscoCisco Identity Services Engine SoftwareCWE-89Cisco Identity Services Engine Information Disclosure Vulnerability
CVE-2026-202824.9—CiscoCisco Identity Services Engine SoftwareCWE-641Cisco Identity Services Engine Authenticated Write Vulnerability
CVE-2026-764264.9—CiscoCisco Identity Services Engine SoftwareCWE-89Cisco ISE REST API SQL Injection Vulnerability
CVE-2026-764274.9—CiscoCisco Identity Services Engine SoftwareCWE-611Cisco ISE XML External Entity Injection Vulnerability
CVE-2026-764284.9—CiscoCisco Identity Services Engine SoftwareCWE-89Cisco ISE Profiler SQL Injection Vulnerability
CVE-2026-764314.9—CiscoCisco Identity Services Engine SoftwareCWE-22Cisco Identity Services Engine Arbitrary File Deletion Vulnerability
CVE-2026-764324.9—CiscoCisco Identity Services Engine SoftwareCWE-22Cisco Identity Services Engine Arbitrary File Write Vulnerability
CVE-2026-764344.9—CiscoCisco Identity Services Engine SoftwareCWE-22Cisco Identity Services Engine Arbitrary File Read Vulnerability
CVE-2026-764464.9—CiscoCisco Identity Services Engine SoftwareCWE-611Cisco Identity Services Engine External Entity Injection Vulnerability
CVE-2026-764484.9—CiscoCisco Identity Services Engine SoftwareCWE-89Cisco Identity Services Engine SQL Injection Vulnerability
CVE-2026-764494.9—CiscoCisco Identity Services Engine SoftwareCWE-89Cisco Identity Services Engine SQL Injection Vulnerability
CVE-2026-764504.9—CiscoCisco Identity Services Engine SoftwareCWE-564Cisco Identity Services Engine SQL Injection Vulnerability
CVE-2026-764514.9—CiscoCisco Identity Services Engine SoftwareCWE-564Cisco Identity Services Engine Certificate Management SQL Injection Vulnerabi…
CVE-2026-203504.7—CiscoCisco ThousandEyes Enterprise AgentCWE-78Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Inje…
CVE-2026-750254.7—MattermostMattermostCWE-346Mattermost Desktop local network access from server-rendered content
CVE-2026-857324.7—oras-projectoras-goCWE-918oras-go: Blind SSRF via unvalidated Link header URL in pagination allows inte…
CVE-2026-761514.6—qtqtCWE-125Out-of-bounds read (buffer over-read) vulnerability in HTTP Cache-Control res…
CVE-2026-926274.6—The HDF GroupHDF5CWE-416Heap Use-After-Free in H5T__conv_f_f
CVE-2025-365914.4—DellElastic Cloud Storage (ECS)CWE-327Dell ECS versions 3.8.1.0 through 3.8.1.7, and Dell ObjectScale versions prio…
CVE-2026-632254.4—Redoclyredocly-cliCWE-22Redocly CLI: Path traversal when using `split` command
CVE-2026-202854.3—CiscoCisco Identity Services Engine SoftwareCWE-285Cisco Identity Services Engine Authorization Bypass Vulnerability
CVE-2026-202864.3—CiscoCisco Identity Services Engine SoftwareCWE-285Cisco Identity Services Engine Authorization Bypass Vulnerability
CVE-2026-921414.3—Jenkins ProjectJenkins Keycloak Authentication PluginCWE-601Jenkins Keycloak Authentication Plugin 2.4.1 and earlier does not restrict th…
CVE-2026-921314.2—Jenkins ProjectJenkins Pipeline: Groovy Libraries PluginCWE-22Jenkins Pipeline: Groovy Libraries Plugin 805.va_fc79344957d and earlier does…
CVE-2026-921384.2—Jenkins ProjectJenkins Bitbucket Server Integration PluginCWE-345The OAuth authorization endpoint in Jenkins Bitbucket Server Integration Plug…
CVE-2026-200713.8—CiscoCisco Identity Services Engine SoftwareCWE-290ISE 802.1x Session Hijack Vulnerability
CVE-2026-870263.8—TaniumThreat ResponseCWE-862Tanium addressed an improper access controls vulnerability in Threat Response.
CVE-2026-692003.7—node-opcuanode-opcuaCWE-1321node-opcua: Prototype Pollution via internal `fieldsToJson()` implementation …
CVE-2026-860713.7—junrarjunrarCWE-22Junrar: LocalFolderExtractor mkdir escape allows directory creation outside e…
CVE-2026-921303.1—Jenkins ProjectJenkins Pipeline: Multibranch PluginCWE-863Jenkins Pipeline: Multibranch Plugin 841.vec5b_9e1806ec and earlier does not …
CVE-2026-711813.0—DellUpdate Package FrameworkCWE-59Dell Update Package Framework, versions prior to 26.07.03, contains an Improp…
CVE-2026-711823.0—DellUpdate Package FrameworkCWE-59Dell Update Package Framework, versions prior to 26.07.03, contains an Improp…
CVE-2026-860892.3—Apache Software FoundationApache NiFiCWE-862Apache NiFi: Missing Process Group Authorization for Connector Migration
CVE-2026-923592.3—ag-ui-protocolag-uiCWE-346ag-ui-protocol ag-ui CORSMiddleware utils.py create_strands_app cross-domain …
CVE-2026-928142.3—dgtlmoonchangedetection.ioCWE-79changedetection.io through 0.60.6 Cross-Site Scripting via watch_title
CVE-2026-734422.1—Arista NetworksEOSCWE-532On affected platforms running Arista EOS with VRRP enabled, the peer device V…
CVE-2026-870312.1—Concrete CMSConcrete CMSCWE-862Missing authorization in the REST API user creation endpoint in Concrete CMS …
CVE-2026-923642.1—itsourcecodeLeave Management SystemCWE-74itsourcecode Leave Management System index.php sql injection
CVE-2026-923832.1—n/aPbootCMSCWE-352PbootCMS User Management UserController.php mod cross-site request forgery
CVE-2026-924132.1—ArtifexMuPDFCWE-404Artifex MuPDF PDF Xref Loading pdf-stream.c pdf_open_filter null pointer dere…
CVE-2026-925262.1—itsourcecodeLeave Management SystemCWE-74itsourcecode Leave Management System index.php sql injection
CVE-2026-925272.1—n/achatwootCWE-918chatwoot Shopify OAuth callbacks_controller.rb server-side request forgery
CVE-2026-818702.0—open-telemetryopentelemetry-goCWE-200OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logs
CVE-2026-853872.0—Concrete CMSConcrete CMSCWE-613Concrete CMS before 9.5.4 allows a deactivated user to retain OAuth-authentic…
CVE-2026-923812.0—n/aPbootCMSCWE-79PbootCMS Template Rendering ContentController.php decode_string cross site sc…
CVE-2026-924182.0—ChangeWeDercrmCWE-79ChangeWeDer crm Save Endpoint customer.serve.js cross site scripting
CVE-2026-923851.9—SourceCodesterOnline Food Ordering SystemCWE-79SourceCodester Online Food Ordering System Category Update update_category.ph…
CVE-2026-924721.9—n/aGPACCWE-119GPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after free
CVE-2026-924731.9—n/aGPACCWE-119GPAC BIFS commands.c gf_sg_command_del use after free
CVE-2026-924741.9—n/aGPACCWE-119GPAC Proto Link mpeg4_inline.c gf_inline_get_proto_lib use after free
CVE-2026-924751.9—n/aGPACCWE-119GPAC downloader.c wait_for_header_and_parse out-of-bounds
CVE-2026-818660.5—Apache Software FoundationApache NiFiCWE-862Apache NiFi: Missing Authorization for Assets and Secrets Referenced by Conne…
CVE-2025-56563await—n/an/a—A Server-Side Request Forgery vulnerability exists in sat_proxy.php in Zenith…
CVE-2025-56565await—n/an/a—DD-WRT firmware, as deployed on TP-Link TL-WR740N v1 through v4 hardware, sto…
CVE-2025-56566await—n/an/a—MikroTik firmware 7.19.4 stores sensitive authentication credentials and netw…
CVE-2026-38999await—n/an/a—A Null Pointer Dereference in the mk_sched_event_close function (mk_server/mk…
CVE-2026-51990await—n/an/a—An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) all…
CVE-2026-65388await—Applecontainerization—A remote attacker who controls a container registry may be able to direct a c…
CVE-2026-68536await—Apache Software FoundationApache MyFacesCWE-918Apache MyFaces: Server-Side Request Forgery / Local File Inclusion Vulnerability
CVE-2026-70469await—Apache Software FoundationApache NiFiCWE-409Apache NiFi: Improper Handling of Case Sensitivity for Content-Encoding in HT…
CVE-2026-76646await—Apache Software FoundationApache MyFacesCWE-400Apache MyFaces: Denial of Service via Unbounded Request Parsing
CVE-2026-79298await—n/an/a—An issue in Howyar Technologies Inc SysReturn Versions prior to 11.3.034 and …
CVE-2026-88592await—n/an/a—kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The …
CVE-2026-88593await—n/an/a—kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview en…
CVE-2026-89794await—LinuxLinux—ksmbd: zero pipe read compound padding
CVE-2026-89796await—LinuxLinux—mm/damon/core: avoid infinite kdamond_merge_regions() internal loop
CVE-2026-89797await—LinuxLinux—power: supply: ab8500_fg: fix use-after-free on remove
CVE-2026-89798await—LinuxLinux—rpcrdma: arm rn_done before publishing the notification
CVE-2026-89800await—LinuxLinux—drm/nouveau/uvmm: clear the dirty flag when unwinding an OP_UNMAP_SPARSE
CVE-2026-89802await—LinuxLinux—drm/nouveau/uvmm: fix NULL deref unwinding an OP_MAP_SPARSE op
CVE-2026-89807await—LinuxLinux—drm/amdkfd: guard against NULL restore_mqd in CRIU queue restore
CVE-2026-89809await—LinuxLinux—drm/amdkfd: fix scope of mqd_mgr dereference in pqm_debugfs_mqds
CVE-2026-89812await—LinuxLinux—drm/amdgpu: force complete the MES ring fences on reset
CVE-2026-89813await—LinuxLinux—drm/amdgpu: force complete the KIQ ring fences on reset
CVE-2026-89816await—LinuxLinux—drm: Fix drm_crtc_commit leak if signaled when PAGE_FLIP_EVENT is used
CVE-2026-89817await—LinuxLinux—drm/gud: NUL-terminate TV mode names read from the device
CVE-2026-89820await—LinuxLinux—drm/amd/display: fix dc_lock leak on GPU reset error paths
CVE-2026-89821await—LinuxLinux—drm/amd/display: avoid divide-by-zero in __is_lut_linear()
CVE-2026-89822await—LinuxLinux—drm/i915: Guard against NULL driver_data in i915_pci_probe()
CVE-2026-89824await—LinuxLinux—drm/panel-edp: fix i2c adapter leak on probe failure
CVE-2026-89827await—LinuxLinux—drm/amdgpu: avoid force-completing uninitialized UVD rings
CVE-2026-89828await—LinuxLinux—drm/amdgpu: Fix init ordering in amdgpu_vram_mgr_init()
CVE-2026-89830await—LinuxLinux—f2fs: fix valid block count leak on data block allocation failure
CVE-2026-89831await—LinuxLinux—f2fs: protect critical_task_priority updates with s_umount
CVE-2026-89833await—LinuxLinux—f2fs: fix to avoid potential deadloop in f2fs_fsync_node_pages()
CVE-2026-89834await—LinuxLinux—f2fs: fix to migrate all curseg types during free_segment_range
CVE-2026-89835await—LinuxLinux—f2fs: avoid NULL checkpoint thread access in sysfs
CVE-2026-89837await—LinuxLinux—f2fs: fix dentry folio leak in find_in_level
CVE-2026-89839await—LinuxLinux—f2fs: use the mount idmap for the owner check in f2fs_xattr_advise_set()
CVE-2026-89842await—LinuxLinux—scsi: qla2xxx: Skip NVMe LS reject IOCB when FW not started
CVE-2026-89843await—LinuxLinux—scsi: qla2xxx: Zero-init bsg stack buffers to avoid info leak
CVE-2026-89845await—LinuxLinux—scsi: qla2xxx: Avoid req_q_map double-read in qla2x00_error_entry()
CVE-2026-89850await—LinuxLinux—scsi: qla2xxx: Don't query firmware state while chip is down
CVE-2026-89851await—LinuxLinux—scsi: qla2xxx: Fix FCE trace enable parsing in debugfs
CVE-2026-89852await—LinuxLinux—scsi: qla2xxx: Zero mailbox struct in qla2x00_get_firmware_state()
CVE-2026-89853await—LinuxLinux—scsi: qla2xxx: Fix FCE trace use-after-free during firmware dump
CVE-2026-89855await—LinuxLinux—scsi: qla2xxx: Serialize flash version read in reset handler
CVE-2026-89858await—LinuxLinux—scsi: qla2xxx: Bound image count in qla2x00_update_fru_versions()
CVE-2026-89859await—LinuxLinux—scsi: qla2xxx: Zero dport diagnostics buffer to avoid info leak
CVE-2026-89862await—LinuxLinux—scsi: qla2xxx: Fix BSG job leak on validate flash image error path
CVE-2026-89864await—LinuxLinux—scsi: qla2xxx: Bound i2c->length in I2C bsg handlers
CVE-2026-89865await—LinuxLinux—scsi: qla2xxx: Zero SFP DMA buffer in FRU/I2C bsg handlers
CVE-2026-89866await—LinuxLinux—media: chips-media: wave5: Resume device before setting EOS flag
CVE-2026-89867await—LinuxLinux—media: chips-media: wave5: Defer job_finish() only when a DEC_PIC was queued
CVE-2026-89868await—LinuxLinux—media: chips-media: wave5: Add timeout while stop_streaming
CVE-2026-89869await—LinuxLinux—media: qcom: iris: use disable_irq() during power-off
CVE-2026-89871await—LinuxLinux—media: video-i2c: fix kthread error pointer left in kthread_vid_cap on failure
CVE-2026-89872await—LinuxLinux—media: v4l2-fwnode: Fix fwnode leak in v4l2_fwnode_parse_link
CVE-2026-89874await—LinuxLinux—media: v4l2-async: avoid deleting unlinked ASC entry on link error
CVE-2026-89876await—LinuxLinux—media: tda18250: fix possible integer overflow
CVE-2026-89878await—LinuxLinux—media: s2255: check firmware size before reading trailing marker
CVE-2026-89879await—LinuxLinux—media: s2255: bound JPEG frame size before copying into the buffer
CVE-2026-89881await—LinuxLinux—media: rtl2832_sdr: use vb2_video_unregister_device() on remove to fix DMA leak
CVE-2026-89884await—LinuxLinux—media: platform: mtk-mdp3: fix NULL deref on failed SCP lookup
CVE-2026-89886await—LinuxLinux—media: intel/ipu6: fix async notifier cleanup leak on parse error
CVE-2026-89889await—LinuxLinux—media: i2c: imx415: Release runtime PM reference on VBLANK error
CVE-2026-89891await—LinuxLinux—media: em28xx: fix use-after-free of dev_next->devlist on disconnect
CVE-2026-89892await—LinuxLinux—media: em28xx: defer audio-only extension registration
CVE-2026-89895await—LinuxLinux—media: cobalt: Avoid freeing ALSA private data twice
CVE-2026-89896await—LinuxLinux—media: cedrus: fix memory leak in cedrus_init_ctrls()
CVE-2026-89900await—LinuxLinux—media: cec: core: Fix kmemleak due to missed rc_free_device() call
CVE-2026-89901await—LinuxLinux—media: airspy: use vb2_video_unregister_device() on disconnect to fix NULL deref
CVE-2026-89905await—LinuxLinux—LoongArch: BPF: Move arena register slot below TCC context
CVE-2026-89909await—LinuxLinux—LoongArch: KVM: Free init resources if kvm_init() fails
CVE-2026-89917await—LinuxLinux—KVM: arm64: Handle VNCR TLB invalidation race with vcpu_put() VNCR unmapping
CVE-2026-89921await—LinuxLinux—KVM: s390: Zero initialize data structures for inject_pfault_token
CVE-2026-89923await—LinuxLinux—KVM: s390: Free guest debug data on vcpu destroy
CVE-2026-89924await—LinuxLinux—KVM: s390: Fix old_data leak in guest debug error path
CVE-2026-89925await—LinuxLinux—KVM: s390: Fix memory leak in guest debug handling
CVE-2026-89926await—LinuxLinux—KVM: s390: Fix length check __import_wp_info()
CVE-2026-89931await—LinuxLinux—KVM: nVMX: Ensure KVM_REQ_GET_NESTED_STATE_PAGES is cleared on VM-Exit
CVE-2026-89933await—LinuxLinux—iio: pressure: dps310: fix NULL pointer dereference on ACPI probe
CVE-2026-89934await—LinuxLinux—iio: light: ltrf216a: fix runtime PM reference leak in error path
CVE-2026-89935await—LinuxLinux—iio: light: apds9306: fix PM reference leak in apds9306_read_data()
CVE-2026-89936await—LinuxLinux—iio: dac: m62332: Fix regulator reference count imbalance
CVE-2026-89937await—LinuxLinux—iio: chemical: sgp30: Handle IAQ thread creation failure
CVE-2026-89939await—LinuxLinux—iio: chemical: atlas-sensor: fix PM reference leak in buffer postenable
CVE-2026-89944await—LinuxLinux—ASoC: hdac_hda: Fix hlink refcount leak on component registration failure
CVE-2026-89945await—LinuxLinux—ASoC: cs35l34: drain threaded IRQ before runtime suspend
CVE-2026-89946await—LinuxLinux—ASoC: cs35l33: drain threaded IRQ before runtime suspend
CVE-2026-89948await—LinuxLinux—batman-adv: bla: fix freeing of claims on meshif deletion
CVE-2026-89949await—LinuxLinux—batman-adv: dat: avoid unaligned fault in IP extraction
CVE-2026-89950await—LinuxLinux—batman-adv: mcast: linearize skbuff for packet generation
CVE-2026-89952await—LinuxLinux—mtd: rawnand: validate ONFI extended parameter page sections
CVE-2026-89953await—LinuxLinux—mtd: mtdoops: free page bitmap when the backing MTD is removed
CVE-2026-89955await—LinuxLinux—s390/vfio-ap: Fix NULL deref in status_show() during queue probe
CVE-2026-89956await—LinuxLinux—s390/vfio-ap: Fix missing lock required to access list of ap_matrix_mdev objects
CVE-2026-89958await—LinuxLinux—s390/vfio-ap: Fix dereference matrix_mdev->kvm without checking for NULL
CVE-2026-89962await—LinuxLinux—powerpc/kexec_file: Prevent kexec range truncation
CVE-2026-89963await—LinuxLinux—powerpc/kexec_file: Fix null-ptr-def in extra size calculation
CVE-2026-89964await—LinuxLinux—parisc: eisa: Fix infinite loop when parsing invalid IRQ value
CVE-2026-89966await—LinuxLinux—mm/hugetlb_cma: fix null nodemask dereference in hugetlb_cma_alloc_frozen_folio
CVE-2026-89975await—LinuxLinux—nvme-fabrics: fix DHCHAP secret leak on parse failure
CVE-2026-89976await—LinuxLinux—accel/ethosu: fix job completion fence cleanup
CVE-2026-89977await—LinuxLinux—accel/ethosu: check MMIO mapping errors in probe
CVE-2026-89978await—LinuxLinux—accel/amdxdna: return early from a zero-length flush
CVE-2026-89981await—LinuxLinux—arm64: Don't read GMID_EL1 when MTE is disabled
CVE-2026-89982await—LinuxLinux—i2c: mux: Fix channel node leak on adapter add failure
CVE-2026-89983await—LinuxLinux—i2c: core: fix debugfs UAF on adapter removal
CVE-2026-89984await—LinuxLinux—perf/x86/intel: Fix kernel address leakages in LBR stack
CVE-2026-89987await—LinuxLinux—mm/huge_memory: transfer the pmd dirty bit to the folio on zap
CVE-2026-89989await—LinuxLinux—ima: Check for ERR_PTR from dentry_path() in validate_hash_algo()
CVE-2026-89991await—LinuxLinux—bpf: Fix infinite loop in pcpu_freelist push with one possible CPU
CVE-2026-89993await—LinuxLinux—dmaengine: dw-edma: Initialize IRQ data before requesting IRQs
CVE-2026-89996await—LinuxLinux—dma-buf: dma-heap: don't publish fd before copy_to_user() succeeds
CVE-2026-90004await—LinuxLinux—mm/damon/core: handle region split failure in apply_min_nr_regions()
CVE-2026-90005await—LinuxLinux—samples/damon/wsse: handle damon_start() failure
CVE-2026-90006await—LinuxLinux—samples/damon/mtier: handle damon_stop() failure
CVE-2026-90015await—LinuxLinux—xhci: fix lost bounce buffers on TDs spanning several ring segments
CVE-2026-90019await—LinuxLinux—usb: gadget: fix null pointer dereference in usb_put_function_instance()
CVE-2026-90020await—LinuxLinux—USB: gadget: fix NULL pointer dereference in gadget_dev_ioctl()
CVE-2026-90021await—LinuxLinux—usb: gadget: f_midi: initialize work in f_midi_alloc()
CVE-2026-90023await—LinuxLinux—usb: gadget: f_mass_storage: fix null pointer dereference in fsg_common_set_n…
CVE-2026-90024await—LinuxLinux—usb: gadget: midi2: Fix null-pointer dereference in f_midi2_free_ep_reqs
CVE-2026-90028await—LinuxLinux—usb: typec: hd3ss3220: track VBUS enable state per consumer
CVE-2026-90029await—LinuxLinux—usb: storage: realtek_cr: fix use-after-free on disconnect
CVE-2026-90031await—LinuxLinux—usb-storage: ene_ub6250: fix race between scan work and probe
CVE-2026-90033await—LinuxLinux—ALSA: usb-audio: fix OOB write in snd_usbmidi_us122l_output()
CVE-2026-90034await—LinuxLinux—usb: image: mdc800: change kmalloc() to kzalloc()
CVE-2026-90035await—LinuxLinux—drm/amd/display: fix division by zero in get_estimated_bw()
CVE-2026-90039await—LinuxLinux—NFSD: Guard admin state-revocation walks with NFSD_NET_UP
CVE-2026-90040await—LinuxLinux—KVM: SEV: Forcefully invalidate SNP VMSA if its backing gmem page is zapped
CVE-2026-90999await—Functional Software, Inc.Sentry Seer—Sentry Seer vulnerability allows attacker-controlled input to be executed in …
CVE-2026-92126await—Jenkins ProjectJenkins Script Security Plugin—Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not rej…