boxscore/security

A daily page of record for published software vulnerabilities — the previous UTC day, closed and final. New here?

Thursday, September 17, 2026 · all times UTC← 2026-09-16 · archive

Security Box Score — September 17, 2026 — page 3

Edition of September 17, 2026, continued — page 3 of 3. Back to page 1 · page 2

Results (continued, ranked) — ranks 1001–1035 of 1035
CVECVSSEPSS %ileVendorProductCWETitle
CVE-2026-93186await—LinuxLinux—cxl/mbox: Clamp mailbox output allocation to the payload size
CVE-2026-93187await—LinuxLinux—ASoC: SOF: ipc4-topology: Return error for invalid number of formats
CVE-2026-93188await—LinuxLinux—HID: roccat: bound device-supplied profile index
CVE-2026-93189await—LinuxLinux—HID: core: quiesce input in hid_hw_stop() to prevent use-after-free
CVE-2026-93190await—LinuxLinux—platform/chrome: cros_ec_typec: Reject out-of-bounds PD cap count
CVE-2026-93191await—LinuxLinux—smack: fix incorrect task context in smack_msg_queue_msgrcv
CVE-2026-93192await—LinuxLinux—drm/v3d: Clear queue->active_job when v3d_fence_create() fails
CVE-2026-93193await—LinuxLinux—drm/rockchip: analogix_dp: Fix OF node reference leak via auto cleanup
CVE-2026-93194await—LinuxLinux—drm/rockchip: dw_dp: Release core resources
CVE-2026-93195await—LinuxLinux—drm/bridge: synopsys: dw-dp: Support unregistering the AUX channel
CVE-2026-93196await—LinuxLinux—nvdimm: virtio_pmem: refcount requests for token lifetime
CVE-2026-93197await—LinuxLinux—memcg: move LRU size accounting on reparenting instead of copying it
CVE-2026-93198await—LinuxLinux—dm-pcache: validate the persisted dirty_tail chain at load
CVE-2026-93199await—LinuxLinux—i3c: master: Do not treat master device as a duplicate target
CVE-2026-93200await—LinuxLinux—i3c: master: Fix use-after-free of master->this
CVE-2026-93201await—LinuxLinux—dm-pcache: validate seg_id fields from persistent memory
CVE-2026-93202await—LinuxLinux—i3c: master: Fix recursive locking during device registration
CVE-2026-93203await—LinuxLinux—batman-adv: bla: avoid CRC corruption due to parallel claim add
CVE-2026-93204await—LinuxLinux—batman-adv: dat: atomically update mac addresses
CVE-2026-93372await—GoogleChromeCWE-121Buffer overflow in WebGL in Google Chrome on on Android prior to 153.0.8010.5…
CVE-2026-93373await—GoogleChromeCWE-416Use after free in Extensions in Google Chrome prior to 153.0.8010.52 allowed …
CVE-2026-93374await—GoogleChromeCWE-416Use after free in Dawn in Google Chrome on on Android prior to 153.0.8010.52 …
CVE-2026-93375await—GoogleChromeCWE-706Incorrect reference resolution in Tracing in Google Chrome on on Windows prio…
CVE-2026-93376await—GoogleChromeCWE-125Out of bounds read in DataTransfer in Google Chrome prior to 153.0.8010.52 al…
CVE-2026-93377await—GoogleChromeCWE-843Type confusion in V8 in Google Chrome prior to 153.0.8010.52 allowed a remote…
CVE-2026-93378await—GoogleChromeCWE-862Missing authorization in Storage in Google Chrome prior to 153.0.8010.52 allo…
CVE-2026-93379await—GoogleChromeCWE-863Incorrect authorization in ORB in Google Chrome prior to 153.0.8010.52 allowe…
CVE-2026-93380await—GoogleChromeCWE-367Race condition in FileSystem in Google Chrome prior to 153.0.8010.52 allowed …
CVE-2026-93381await—GoogleChromeCWE-122Buffer overflow in PDFium in Google Chrome on on Windows prior to 153.0.8010.…
CVE-2026-93382await—GoogleChromeCWE-416Use after free in PDFium in Google Chrome prior to 153.0.8010.52 allowed a re…
CVE-2026-93383await—GoogleChromeCWE-200Information leak in Permissions in Google Chrome prior to 153.0.8010.52 allow…
CVE-2026-93384await—GoogleChromeCWE-918Server-side request forgery in Omnibox in Google Chrome on on Android prior t…
CVE-2026-93385await—GoogleChromeCWE-200Information leak in Paint in Google Chrome prior to 153.0.8010.52 allowed a r…
CVE-2026-93386await—GoogleChromeCWE-451UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.5…
CVE-2026-93387await—GoogleChromeCWE-754Improper state validation in Skia in Google Chrome prior to 153.0.8010.52 all…