Report Name: Linux Patch Wednesday July 2026Generated: 2026-07-31 15:39:02
| Product Name | Prevalence | U | C | H | M | L | A | Comment |
|---|---|---|---|---|---|---|---|---|
| Angular | 0.95 | 4 | 12 | 16 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |||
| Vim | 0.95 | 1 | 4 | 7 | 12 | Highly configurable command-line text editor used in development and system administration. | ||
| pip | 0.95 | 1 | 1 | pip is the standard package installer for Python, used to install and manage software packages from the Python Package Index (PyPI) and other repositories. | ||||
| Apache Log4j | 0.9 | 1 | 1 | Apache Log4j is a Java-based logging utility | ||||
| Django | 0.9 | 3 | 3 | Django is a high-level Python web framework that encourages rapid development and clean, pragmatic design. It provides built-in tools for database models, authentication, URL routing, templates, and security features, making it one of the most widely used frameworks for building scalable and maintainable web applications. | ||||
| HTTP/2 | 0.9 | 2 | 2 | HTTP/2 is a major revision of the HTTP network protocol used by the World Wide Web | ||||
| Linux Kernel | 0.9 | 2 | 19 | 425 | 93 | 539 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| Rust | 0.9 | 1 | 1 | Rust is a modern, high-performance systems programming language focused on safety, concurrency, and memory management. | ||||
| Sudo | 0.9 | 1 | 1 | Sudo is a widely used Unix/Linux utility that allows permitted users to execute commands with elevated (typically root) privileges while providing extensive logging and fine-grained security controls. It is a foundational component in most Linux and BSD distributions. | ||||
| Windows Kernel | 0.9 | 1 | 1 | Windows Kernel | ||||
| nghttp2 | 0.9 | 1 | 1 | nghttp2 is an implementation of HTTP/2 and its header compression algorithm HPACK in C | ||||
| util-linux | 0.9 | 1 | 1 | Linux utility suite providing core system tools including mount. Vulnerability affects SUID mount binary due to TOCTOU race condition. | ||||
| Grafana | 0.85 | 1 | 2 | 3 | Grafana is an open-source analytics and monitoring platform that provides dashboards and visualization tools for metrics collected from various data sources. | |||
| Chromium | 0.8 | 2 | 247 | 254 | 1 | 504 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| FreeIPA | 0.8 | 1 | 1 | 2 | FreeIPA is a free and open source identity management system | |||
| Keycloak | 0.8 | 4 | 8 | 12 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |||
| Microsoft PowerShell | 0.8 | 1 | 1 | PowerShell or Microsoft PowerShell (formerly Windows PowerShell) is a task automation and configuration management program from Microsoft, consisting of a command-line shell and the associated scripting language | ||||
| Mozilla Firefox | 0.8 | 2 | 1 | 3 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |||
| Netty | 0.8 | 1 | 1 | Netty is a non-blocking I/O client-server framework for the development of Java network applications such as protocol servers and clients | ||||
| OpenSSH | 0.8 | 1 | 3 | 7 | 11 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | ||
| OpenSSL | 0.8 | 1 | 8 | 9 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |||
| PHP | 0.8 | 3 | 1 | 4 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |||
| RPC | 0.8 | 2 | 2 | Remote Procedure Call Runtime | ||||
| Safari | 0.8 | 5 | 17 | 22 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |||
| Samba | 0.8 | 1 | 1 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | ||||
| Windows Resilient File System (ReFS) | 0.8 | 1 | 1 | Windows component | ||||
| Gitea | 0.75 | 2 | 3 | 3 | 1 | 9 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| Apache Tomcat | 0.7 | 2 | 4 | 6 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |||
| Apache Traffic Server | 0.7 | 1 | 1 | The Apache Traffic Server is a modular, high-performance reverse proxy and forward proxy server, generally comparable to Nginx and Squid | ||||
| Asterisk | 0.7 | 1 | 1 | 2 | Asterisk is a free and open source framework for building communications applications and is sponsored by Sangoma | |||
| Babel | 0.7 | 1 | 1 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | ||||
| Calibre | 0.7 | 1 | 1 | Calibre is a cross-platform free and open-source suite of e-book software | ||||
| Envoy | 0.7 | 1 | 11 | 1 | 1 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| FFmpeg | 0.7 | 1 | 1 | 1 | 3 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | ||
| Kubernetes | 0.7 | 2 | 1 | 3 | Kubernetes is an open-source container orchestration system for automating software deployment, scaling, and management | |||
| MediaWiki | 0.7 | 1 | 1 | 6 | 8 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | ||
| MinIO | 0.7 | 1 | 1 | 2 | MinIO is a high-performance, S3-compatible object storage system designed for large-scale data infrastructure. It supports cloud-native workloads and provides APIs for storing, retrieving, and managing unstructured data such as photos, videos, log files, and backups, with a focus on scalability, speed, and simplicity. | |||
| Minio | 0.7 | 1 | 1 | Minio is a Multi-Cloud Object Storage framework | ||||
| Open Asset Import Library Assimp | 0.7 | 3 | 3 | Open Asset Import Library is a library that loads various 3D file formats into a shared, in-memory format | ||||
| Oracle MySQL | 0.7 | 1 | 1 | MySQL is an open-source relational database management system | ||||
| Oracle VM VirtualBox | 0.7 | 11 | 11 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | ||||
| QEMU | 0.7 | 1 | 1 | QEMU is a generic and open source machine & userspace emulator and virtualizer | ||||
| SQLite | 0.7 | 2 | 2 | SQLite is a database engine written in the C programming language | ||||
| cpp-httplib | 0.7 | 1 | 1 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library | ||||
| musl libc | 0.7 | 2 | 2 | musl libc is a lightweight, fast, and standards-conformant implementation of the C standard library, commonly used in embedded systems and Linux distributions such as Alpine Linux. | ||||
| idna | 0.65 | 1 | 1 | idna is a Python library implementing Internationalized Domain Names in Applications (IDNA), providing support for Unicode domain name encoding and decoding according to the IDNA standard. It is widely used by Python networking, HTTP, and DNS-related software. | ||||
| Apache ActiveMQ | 0.6 | 2 | 6 | 8 | Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client | |||
| Canonical LXD | 0.6 | 1 | 1 | Canonical LXD is a system container and VM manager for Linux. LXD-UI is the web UI component of LXD that provides a browser-based interface for creating, managing and starting containers and instances. | ||||
| ClamAV | 0.6 | 7 | 7 | ClamAV (Clam AntiVirus) is a free software, cross-platform antimalware toolkit able to detect many types of malware, including viruses | ||||
| FreeRDP | 0.6 | 4 | 4 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | ||||
| ImageMagick | 0.6 | 24 | 3 | 27 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |||
| Jetty | 0.6 | 2 | 1 | 3 | Jetty is a Java based web server and servlet engine | |||
| PHP Secure Communications Library | 0.6 | 1 | 1 | phpseclib provides pure-PHP implementations of SSH2, SFTP, RSA, DSA, Elliptic Curves, AES, ChaCha20, X. 509, CSR, CRL, SPKAC | ||||
| Perl | 0.6 | 1 | 27 | 2 | 30 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | ||
| Puma | 0.6 | 2 | 2 | Puma is a Ruby/Rack web server built for parallelism | ||||
| Python | 0.6 | 3 | 15 | 4 | 22 | Python is a high-level, general-purpose programming language | ||
| Rclone | 0.6 | 3 | 3 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | ||||
| Roundcube | 0.6 | 1 | 5 | 6 | Roundcube is a web-based IMAP email client | |||
| Undertow | 0.6 | 1 | 1 | Undertow is a lightweight, high-performance Java web server and servlet container designed for both embedded and standalone deployments. It is the default web server in WildFly and is also used by Red Hat products including JBoss EAP and builds of Apache Camel. | ||||
| Wireshark | 0.6 | 8 | 3 | 11 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |||
| libxml2 | 0.6 | 2 | 2 | libxml2 is an XML toolkit implemented in C, originally developed for the GNOME Project | ||||
| pgAdmin | 0.6 | 1 | 2 | 3 | pgAdmin is the most popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world | |||
| shell-quote | 0.55 | 1 | 1 | shell-quote is a JavaScript/Node.js library for safely parsing and quoting POSIX shell commands. It is commonly used by CLI tools, build systems, and developer utilities to construct and parse shell command lines. | ||||
| .NET | 0.5 | 1 | 1 | Product detected by a:microsoft:.net (exists in CPE dict) | ||||
| 389 Directory Server | 0.5 | 2 | 2 | 4 | 389 Directory Server is a highly usable, fully featured, reliable and secure LDAP server implementation | |||
| 7-Zip | 0.5 | 1 | 1 | 2 | 7-Zip is a free and open-source file archiver, a utility used to place groups of files within compressed containers known as "archives" | |||
| Alinto SOGo | 0.5 | 2 | 2 | SOGo is an open source groupware and webmail server developed by Alinto, providing email, calendar, and contact management through a web-based interface and standard protocols. | ||||
| Aptio V UEFI Firmware Integrator Tools | 0.5 | 1 | 1 | Product detected by a:intel:aptio_v_uefi_firmware_integrator_tools (exists in CPE dict) | ||||
| Authlib | 0.5 | 1 | 1 | Authlib is a Python library for building OAuth and OpenID Connect clients and servers, providing tools for secure authentication, token management, and authorization flows. | ||||
| Cacti | 0.5 | 1 | 9 | 4 | 1 | 15 | Cacti is an open source operational monitoring and fault management framework | |
| Caddy | 0.5 | 3 | 3 | Product detected by a:caddyserver:caddy (exists in CPE dict) | ||||
| CarrierWave | 0.5 | 1 | 1 | Product detected by a:carrierwave_project:carrierwave (exists in CPE dict) | ||||
| Curl | 0.5 | 5 | 12 | 17 | Product detected by a:haxx:curl (exists in CPE dict) | |||
| DBI | 0.5 | 1 | 2 | 3 | Product detected by a:perl:dbi (exists in CPE dict) | |||
| DCMTK | 0.5 | 2 | 2 | DCMTK (DICOM Toolkit) is an open-source collection of libraries and applications implementing large parts of the DICOM standard, including image processing, storage, and network services for medical imaging. | ||||
| DNSSEC | 0.5 | 1 | 1 | The Domain Name System Security Extensions (DNSSEC) is a feature of the Domain Name System (DNS) that authenticates responses to domain name lookups | ||||
| DOMPurify | 0.5 | 4 | 4 | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG | ||||
| Electron | 0.5 | 1 | 2 | 3 | Product detected by a:electronjs:electron (exists in CPE dict) | |||
| Excon | 0.5 | 1 | 1 | Product detected by a:excon_project:excon (exists in CPE dict) | ||||
| Faraday | 0.5 | 1 | 1 | Product detected by a:faraday_project:faraday (exists in CPE dict) | ||||
| GIMP | 0.5 | 2 | 2 | 4 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | |||
| Gawk | 0.5 | 4 | 4 | Product detected by a:fossies:gawk (exists in CPE dict) | ||||
| Go | 0.5 | 2 | 2 | Product detected by a:golang:go (exists in CPE dict) | ||||
| Gpsd | 0.5 | 1 | 1 | Product detected by a:gpsd_project:gpsd (exists in CPE dict) | ||||
| Guzzle | 0.5 | 3 | 3 | Product detected by a:guzzlephp:guzzle (exists in CPE dict) | ||||
| Gzip | 0.5 | 1 | 1 | 2 | Product detected by a:gnu:gzip (exists in CPE dict) | |||
| HashiCorp Nomad | 0.5 | 1 | 1 | 2 | HashiCorp Nomad is a workload scheduler and orchestrator designed to deploy and manage applications, including containerized and non-containerized workloads, across various infrastructure platforms | |||
| Hugo | 0.5 | 3 | 3 | Product detected by a:gohugo:hugo (exists in CPE dict) | ||||
| Jackson-databind | 0.5 | 1 | 2 | 4 | 7 | Product detected by a:fasterxml:jackson-databind (exists in CPE dict) | ||
| Kafka | 0.5 | 1 | 1 | Product detected by a:apache:kafka (exists in CPE dict) | ||||
| Kotlin | 0.5 | 2 | 2 | Product detected by a:jetbrains:kotlin (exists in CPE dict) | ||||
| LXD | 0.5 | 2 | 2 | Product detected by a:canonical:lxd (exists in CPE dict) | ||||
| LibXFont | 0.5 | 3 | 3 | Product detected by a:x:libxfont (exists in CPE dict) | ||||
| Libarchive | 0.5 | 2 | 2 | Multi-format archive and compression library | ||||
| Libheif | 0.5 | 1 | 1 | Product detected by a:struktur:libheif (exists in CPE dict) | ||||
| Mistune | 0.5 | 6 | 1 | 7 | Product detected by a:mistune_project:mistune (exists in CPE dict) | |||
| ModSecurity | 0.5 | 1 | 1 | 2 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx | |||
| NGINX | 0.5 | 1 | 2 | 3 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |||
| Node.js | 0.5 | 4 | 8 | 12 | Product detected by a:nodejs:node.js (exists in CPE dict) | |||
| OpenTelemetry | 0.5 | 1 | 1 | OpenTelemetry is a collection of APIs, SDKs, and tools. Use it to instrument, generate, collect, and export telemetry data (metrics, logs and traces) to help you analyze your software's performance and behavior | ||||
| Patch | 0.5 | 2 | 2 | Product detected by a:gnu:patch (exists in CPE dict) | ||||
| Pillow | 0.5 | 11 | 11 | Pillow is a Python imaging library that adds image processing capabilities to Python, supporting formats such as PNG, JPEG, GIF, TIFF, and BMP. | ||||
| ProFTPD | 0.5 | 1 | 3 | 4 | ProFTPD is a highly configurable and modular open-source FTP server designed for Unix-like systems, offering advanced features such as virtual hosting, authentication modules, and flexible configuration similar to Apache. | |||
| Psr-7 | 0.5 | 2 | 2 | Product detected by a:guzzlephp:psr-7 (exists in CPE dict) | ||||
| Pypdf | 0.5 | 9 | 1 | 10 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |||
| Setuptools | 0.5 | 1 | 1 | Setuptools is a fully-featured, actively-maintained, and stable library designed to facilitate packaging Python projects | ||||
| Shiro | 0.5 | 1 | 1 | Product detected by a:apache:shiro (exists in CPE dict) | ||||
| Spice-vdagent | 0.5 | 2 | 2 | Product detected by a:spice-space:spice-vdagent (exists in CPE dict) | ||||
| Starlette | 0.5 | 1 | 2 | 3 | Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit | |||
| Symfony | 0.5 | 1 | 1 | Product detected by a:sensiolabs:symfony (exists in CPE dict) | ||||
| TLS | 0.5 | 1 | 2 | 3 | TLS | |||
| Thunderbird | 0.5 | 2 | 2 | Product detected by a:mozilla:thunderbird (exists in CPE dict) | ||||
| Twig | 0.5 | 1 | 1 | Twig is a template language for PHP | ||||
| UltraJSON | 0.5 | 1 | 1 | Product detected by a:ultrajson_project:ultrajson (exists in CPE dict) | ||||
| VBScript | 0.5 | 1 | 1 | VBScript | ||||
| Wget | 0.5 | 4 | 4 | Product detected by a:gnu:wget (exists in CPE dict) | ||||
| Ws | 0.5 | 1 | 1 | Product detected by a:ws_project:ws (exists in CPE dict) | ||||
| X Server | 0.5 | 2 | 2 | Product detected by a:x.org:x_server (exists in CPE dict) | ||||
| Xrdp | 0.5 | 2 | 8 | 10 | xrdp is an open source remote desktop protocol server | |||
| aardvark-dns | 0.5 | 1 | 1 | Product detected by a:containers:aardvark-dns (does NOT exist in CPE dict) | ||||
| busybox | 0.5 | 4 | 4 | Product detected by a:busybox:busybox (exists in CPE dict) | ||||
| concurrent_ruby | 0.5 | 1 | 2 | 3 | Product detected by a:rubyconcurrency:concurrent_ruby (does NOT exist in CPE dict) | |||
| containerd | 0.5 | 1 | 1 | 1 | 3 | Product detected by a:linuxfoundation:containerd (exists in CPE dict) | ||
| dos | 0.5 | 1 | 1 | 2 | Product detected by a:f5:dos (does NOT exist in CPE dict) | |||
| erlang\\/otp | 0.5 | 1 | 1 | Product detected by a:erlang:erlang\\/otp (does NOT exist in CPE dict) | ||||
| etcd | 0.5 | 1 | 1 | Product detected by a:etcd:etcd (exists in CPE dict) | ||||
| extract-zip | 0.5 | 1 | 1 | Product detected by a:max-mapper:extract-zip (does NOT exist in CPE dict) | ||||
| fast-uri | 0.5 | 1 | 1 | Product detected by a:openjsf:fast-uri (does NOT exist in CPE dict) | ||||
| freeswitch | 0.5 | 8 | 1 | 9 | Product detected by a:freeswitch:freeswitch (exists in CPE dict) | |||
| fzf | 0.5 | 2 | 2 | Product detected by a:junegunn:fzf (does NOT exist in CPE dict) | ||||
| grafana | 0.5 | 3 | 3 | Product detected by a:grafana:grafana (exists in CPE dict) | ||||
| gstreamer | 0.5 | 2 | 2 | Product detected by a:gstreamer:gstreamer (exists in CPE dict) | ||||
| haproxy | 0.5 | 2 | 2 | Product detected by a:haproxy:haproxy (exists in CPE dict) | ||||
| hardened_images | 0.5 | 1 | 1 | Product detected by a:redhat:hardened_images (does NOT exist in CPE dict) | ||||
| httpcomponents_core | 0.5 | 2 | 2 | Product detected by a:apache:httpcomponents_core (does NOT exist in CPE dict) | ||||
| httplib2 | 0.5 | 1 | 1 | Product detected by a:httplib2_project:httplib2 (exists in CPE dict) | ||||
| imager | 0.5 | 1 | 1 | Product detected by a:tonycoz:imager (does NOT exist in CPE dict) | ||||
| immutable | 0.5 | 2 | 2 | Product detected by a:immutable-js:immutable (does NOT exist in CPE dict) | ||||
| incus | 0.5 | 1 | 1 | Product detected by a:linuxcontainers:incus (does NOT exist in CPE dict) | ||||
| js-yaml | 0.5 | 2 | 2 | Product detected by a:nodeca:js-yaml (does NOT exist in CPE dict) | ||||
| jupyter_server | 0.5 | 1 | 1 | Product detected by a:jupyter:jupyter_server (exists in CPE dict) | ||||
| libexpat | 0.5 | 12 | 12 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | ||||
| libjpeg | 0.5 | 1 | 1 | libjpeg | ||||
| libreswan | 0.5 | 1 | 2 | 3 | Product detected by a:libreswan:libreswan (exists in CPE dict) | |||
| libsoup | 0.5 | 1 | 1 | Product detected by a:gnome:libsoup (exists in CPE dict) | ||||
| libssh2 | 0.5 | 1 | 3 | 1 | 5 | Product detected by a:libssh2:libssh2 (exists in CPE dict) | ||
| libzypp | 0.5 | 1 | 1 | 2 | Product detected by a:opensuse:libzypp (exists in CPE dict) | |||
| loki_datasource | 0.5 | 1 | 1 | Product detected by a:grafana:loki_datasource (does NOT exist in CPE dict) | ||||
| markdown-it | 0.5 | 1 | 1 | Product detected by a:markdown-it_project:markdown-it (exists in CPE dict) | ||||
| mediawiki | 0.5 | 2 | 2 | Product detected by a:mediawiki:mediawiki (exists in CPE dict) | ||||
| nats-server | 0.5 | 3 | 4 | 7 | Product detected by a:linuxfoundation:nats-server (exists in CPE dict) | |||
| njs | 0.5 | 1 | 1 | Product detected by a:f5:njs (exists in CPE dict) | ||||
| nltk | 0.5 | 3 | 3 | Product detected by a:nltk:nltk (exists in CPE dict) | ||||
| nmap | 0.5 | 1 | 1 | Product detected by a:nmap:nmap (exists in CPE dict) | ||||
| nokogiri | 0.5 | 7 | 7 | Product detected by a:nokogiri:nokogiri (exists in CPE dict) | ||||
| nsd | 0.5 | 1 | 3 | 4 | Product detected by a:nlnetlabs:nsd (exists in CPE dict) | |||
| onnx | 0.5 | 1 | 1 | Product detected by a:linuxfoundation:onnx (exists in CPE dict) | ||||
| op-tee | 0.5 | 1 | 3 | 3 | 7 | Product detected by o:trustedfirmware:op-tee (does NOT exist in CPE dict) | ||
| openbao | 0.5 | 1 | 1 | Product detected by a:openbao:openbao (does NOT exist in CPE dict) | ||||
| openvpn | 0.5 | 2 | 2 | Product detected by a:openvpn:openvpn (exists in CPE dict) | ||||
| perl | 0.5 | 2 | 2 | Product detected by a:perl:perl (exists in CPE dict) | ||||
| pgx | 0.5 | 1 | 1 | Product detected by a:jackc:pgx (does NOT exist in CPE dict) | ||||
| postgresql_jdbc_driver | 0.5 | 1 | 1 | Product detected by a:postgresql:postgresql_jdbc_driver (exists in CPE dict) | ||||
| prometheus | 0.5 | 1 | 1 | Product detected by a:prometheus:prometheus (exists in CPE dict) | ||||
| pyasn1 | 0.5 | 3 | 3 | Product detected by a:pyasn1:pyasn1 (does NOT exist in CPE dict) | ||||
| pymdown_extensions | 0.5 | 2 | 2 | Product detected by a:facelessuser:pymdown_extensions (does NOT exist in CPE dict) | ||||
| python-multipart | 0.5 | 1 | 1 | Product detected by a:fastapiexpert:python-multipart (does NOT exist in CPE dict) | ||||
| rabbitmq_server | 0.5 | 1 | 7 | 1 | 9 | Product detected by a:broadcom:rabbitmq_server (does NOT exist in CPE dict) | ||
| rtklib | 0.5 | 1 | 3 | 4 | Product detected by a:rtklib:rtklib (does NOT exist in CPE dict) | |||
| sigstore-go | 0.5 | 1 | 1 | Product detected by a:sigstore:sigstore-go (does NOT exist in CPE dict) | ||||
| sigstore_timestamp_authority | 0.5 | 1 | 1 | Product detected by a:linuxfoundation:sigstore_timestamp_authority (does NOT exist in CPE dict) | ||||
| simplesamlphp | 0.5 | 1 | 1 | Product detected by a:simplesamlphp:simplesamlphp (exists in CPE dict) | ||||
| socat | 0.5 | 1 | 1 | Product detected by a:dest-unreach:socat (exists in CPE dict) | ||||
| soup_sieve | 0.5 | 2 | 2 | Product detected by a:facelessuser:soup_sieve (does NOT exist in CPE dict) | ||||
| sssd | 0.5 | 1 | 1 | Product detected by a:fedoraproject:sssd (exists in CPE dict) | ||||
| storable | 0.5 | 1 | 1 | Product detected by a:nwclark:storable (does NOT exist in CPE dict) | ||||
| swift | 0.5 | 1 | 1 | Product detected by a:openstack:swift (exists in CPE dict) | ||||
| tar | 0.5 | 4 | 4 | Product detected by a:isaacs:tar (does NOT exist in CPE dict) | ||||
| tempo | 0.5 | 1 | 1 | Product detected by a:grafana:tempo (does NOT exist in CPE dict) | ||||
| tiff | 0.5 | 1 | 1 | Product detected by a:golang:tiff (exists in CPE dict) | ||||
| undici | 0.5 | 4 | 3 | 7 | Product detected by a:nodejs:undici (exists in CPE dict) | |||
| webob | 0.5 | 1 | 1 | Product detected by a:pylonsproject:webob (does NOT exist in CPE dict) | ||||
| wireshark | 0.5 | 1 | 1 | Product detected by a:wireshark:wireshark (exists in CPE dict) | ||||
| wolfSSL | 0.5 | 2 | 1 | 3 | wolfSSL is a small, portable, embedded SSL/TLS library targeted for use by embedded systems developers | |||
| wolfssl | 0.5 | 14 | 1 | 15 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |||
| youtube-dl | 0.5 | 1 | 1 | 2 | 4 | youtube-dl is a free and open source software tool for downloading video and audio from YouTube and over 1,000 other video hosting websites | ||
| zeep | 0.5 | 1 | 1 | Product detected by a:python-zeep:zeep (does NOT exist in CPE dict) | ||||
| Gogs | 0.45 | 1 | 2 | 9 | 3 | 2 | 17 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. |
| dhcpcd | 0.45 | 1 | 5 | 6 | dhcpcd is an open-source DHCP and network configuration client used on Linux, BSD, and other Unix-like operating systems to automatically configure network interfaces, IP addresses, routes, and DNS settings. | |||
| Erlang/OTP | 0.4 | 5 | 5 | Erlang/OTP is a set of libraries for the Erlang programming language | ||||
| Flatpak | 0.4 | 1 | 1 | Flatpak is a utility for software deployment and package management for Linux | ||||
| GPAC | 0.4 | 2 | 3 | 5 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |||
| Horde IMP | 0.4 | 1 | 1 | IMP is the Internet Messaging Program. It is written in PHP and provides webmail access to IMAP and POP3 accounts. It uses the best-of-class Horde/Imap_Client library to provide fast, robust connections to the remote IMAP/POP3 server. | ||||
| Keras | 0.4 | 1 | 2 | 3 | High-level neural networks API, running on top of TensorFlow, allowing model building and training | |||
| Spring Framework | 0.4 | 1 | 1 | The Spring Framework is an application framework and inversion of control container for the Java platform | ||||
| Oj | 0.35 | 2 | 7 | 3 | 12 | Oj (Optimized JSON) is a high-performance JSON parser and object serialization library packaged as a Ruby gem, designed to provide fast JSON encoding and decoding for Ruby applications. | ||
| JOSE | 0.3 | 3 | 3 | JavaScript module for JSON Object Signing and Encryption (JOSE) | ||||
| gitoxide | 0.3 | 1 | 1 | gitoxide is an idiomatic, lean, fast & safe pure Rust implementation of Git, designed for correctness and performance, available both as a Rust library (gix crate) and command-line interface tools. | ||||
| jqlang jq | 0.3 | 1 | 1 | jq is a lightweight and flexible command-line JSON processor, allowing powerful querying and manipulation of JSON data streams. | ||||
| Wasmtime | 0.25 | 2 | 2 | Standalone WebAssembly runtime written in Rust | ||||
| GitHub | 0.2 | 1 | 1 | GitHub, Inc. is an Internet hosting service for software development and version control using Git | ||||
| libtiff | 0.2 | 1 | 1 | libtiff is a widely used library for reading and writing TIFF (Tagged Image File Format) files, offering tools like tiff2ps. | ||||
| Unknown Product | 0 | 89 | 141 | 230 | Unknown Product |
| Vulnerability Type | Criticality | U | C | H | M | L | A |
|---|---|---|---|---|---|---|---|
| Remote Code Execution | 1.0 | 1 | 11 | 98 | 22 | 132 | |
| Authentication Bypass | 0.98 | 6 | 37 | 39 | 82 | ||
| Code Injection | 0.97 | 2 | 9 | 16 | 27 | ||
| Command Injection | 0.97 | 1 | 2 | 4 | 7 | ||
| XXE Injection | 0.97 | 1 | 1 | ||||
| Arbitrary File Writing | 0.95 | 3 | 1 | 4 | |||
| Security Feature Bypass | 0.9 | 4 | 179 | 142 | 325 | ||
| Server-Side Request Forgery | 0.87 | 4 | 11 | 1 | 16 | ||
| Elevation of Privilege | 0.85 | 1 | 3 | 15 | 19 | ||
| Arbitrary File Reading | 0.83 | 2 | 3 | 5 | |||
| Information Disclosure | 0.83 | 10 | 32 | 1 | 43 | ||
| Cross Site Scripting | 0.8 | 13 | 37 | 50 | |||
| Open Redirect | 0.75 | 2 | 4 | 6 | |||
| Denial of Service | 0.7 | 53 | 155 | 7 | 215 | ||
| Path Traversal | 0.7 | 2 | 13 | 20 | 35 | ||
| Incorrect Calculation | 0.5 | 8 | 37 | 2 | 47 | ||
| Memory Corruption | 0.5 | 1 | 36 | 305 | 17 | 359 | |
| Spoofing | 0.4 | 3 | 59 | 62 | |||
| Tampering | 0.3 | 1 | 1 | ||||
| Unknown Vulnerability Type | 0 | 316 | 265 | 581 |
| Source | U | C | H | M | L | A |
|---|---|---|---|---|---|---|
| almalinux | 2 | 19 | 45 | 6 | 72 | |
| altlinux | 1 | 15 | 354 | 569 | 35 | 974 |
| debian | 25 | 422 | 1111 | 271 | 1829 | |
| oraclelinux | 3 | 23 | 51 | 11 | 88 | |
| redhat | 4 | 30 | 55 | 5 | 94 | |
| redos | 3 | 11 | 25 | 10 | 49 | |
| ubuntu | 6 | 39 | 238 | 108 | 391 |
1.
Remote Code Execution - Gogs (CVE-2025-8110) - Urgent [896]
Description: Improper Symbolic link handling in the PutContents API in
altlinux: CVE-2025-8110 was patched at 2026-06-25
2.
Remote Code Execution - pip (CVE-2025-27607) - Critical [729]
Description: Python JSON Logger is a JSON Formatter for Python Logging. Between 30 December 2024 and 4 March 2025 Python JSON Logger was vulnerable to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.95 | 14 | pip is the standard package installer for Python, used to install and manage software packages from the Python Package Index (PyPI) and other repositories. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.7 | 10 | EPSS Probability is 0.01543, EPSS Percentile is 0.7245 |
redos: CVE-2025-27607 was patched at 2026-07-13
3.
Remote Code Execution - FFmpeg (CVE-2026-8461) - Critical [688]
Description: An out-of-bounds write vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:Y5NEKO:CVE-2026-8461-EXP, Vulners:PublicExploit:GitHub:HORKIMHAB:CVE-2026-8461, Vulners:PublicExploit:GitHub:ANYANYTHING:CVE-2026-8461-POC, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.7 | 10 | EPSS Probability is 0.01315, EPSS Percentile is 0.67877 |
debian: CVE-2026-8461 was patched at 2026-06-22, 2026-06-24
4.
Command Injection - Gpsd (CVE-2026-58459) - Critical [673]
Description: gpsd through release-3.27.5, fixed at commit 4c06658, contains a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.com website | |
| 0.97 | 15 | Command Injection | |
| 0.5 | 14 | Product detected by a:gpsd_project:gpsd (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.8 | 10 | EPSS Probability is 0.01796, EPSS Percentile is 0.76239 |
debian: CVE-2026-58459 was patched at 2026-07-14
5.
Remote Code Execution - NGINX (CVE-2026-42533) - Critical [666]
Description: A vulnerability exists in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:0XCYBERSTAN:CVE-2026-42533-CONFIG-SCANNER, Vulners:PublicExploit:GitHub:CHPRATIK:NGINX_2026_CVE_BUNDLE_CTI_REPORT, Vulners:PublicExploit:GitHub:SEGURIDADENTRERIOS:CVE-2026-42533, Vulners:PublicExploit:GitHub:IMBAS007:CVE-2026-42533, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.9 | 10 | EPSS Probability is 0.03596, EPSS Percentile is 0.88277 |
altlinux: CVE-2026-42533 was patched at 2026-07-17, 2026-07-21, 2026-07-22
debian: CVE-2026-42533 was patched at 2026-07-14
6.
Remote Code Execution - Gogs (CVE-2025-64111) - Critical [658]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, Vulners:PublicExploit:GitHub:ACCZDY:CVE-VAULT, Vulners:PublicExploit:GitHub:AYUSHCH80:CVE-POC websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.7 | 10 | EPSS Probability is 0.01229, EPSS Percentile is 0.65894 |
altlinux: CVE-2025-64111 was patched at 2026-06-25
7.
Remote Code Execution - libssh2 (CVE-2026-55200) - Critical [654]
Description: libssh2 through 1.11.1, fixed in commit 7acf3df contains an out-of-bounds write vulnerability in ssh2_transport_read() that fails to enforce upper bounds on packet_length field. Remote attackers can send crafted SSH packets with excessively large packet_length values to corrupt heap memory and achieve remote
altlinux: CVE-2026-55200 was patched at 2026-07-09, 2026-07-13, 2026-07-14, 2026-07-15, 2026-07-17
debian: CVE-2026-55200 was patched at 2026-06-24, 2026-06-25
ubuntu: CVE-2026-55200 was patched at 2026-07-30
8.
Elevation of Privilege - Linux Kernel (CVE-2026-64600) - Critical [647]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:LITOSMARTIN:CVE-64600-REFLUXFS-POC, Vulners:PublicExploit:GitHub:BHA-VIN:CVE-2026-64600-EXPLOIT, Vulners:PublicExploit:GitHub:DEBAJYOTI0-0:CVE-2026-64600, Vulners:PublicExploit:GitHub:VULNQUEST58:VQ-REFLUXCORE, Vulners:PublicExploit:GitHub:LETSR00T:REFLUXFS_CVE-2026-64600, Vulners:PublicExploit:GitHub:HORKIMHAB:CVE-2026-64600, BDU:PublicExploit websites | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00488, EPSS Percentile is 0.39356 |
debian: CVE-2026-64600 was patched at 2026-07-30
oraclelinux: CVE-2026-64600 was patched at 2026-07-16
redhat: CVE-2026-64600 was patched at 2026-07-14, 2026-07-15, 2026-07-16, 2026-07-17, 2026-07-29
9.
Authentication Bypass - Gitea (CVE-2026-28699) - Critical [645]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:ALARDIIANS:GITEA-CVE-2026-28699 website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00567, EPSS Percentile is 0.43785 |
redos: CVE-2026-28699 was patched at 2026-07-14
10.
Remote Code Execution - Chromium (CVE-2026-13036) - Critical [645]
Description: Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:HUSEYINSTIF:CVE-2026-13036-POC website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00293, EPSS Percentile is 0.21621 |
debian: CVE-2026-13036 was patched at 2026-06-25, 2026-07-14
11.
Remote Code Execution - Chromium (CVE-2026-14431) - Critical [645]
Description: Type Confusion in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:JAF0RK:CVE-2026-14431 website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00264, EPSS Percentile is 0.18232 |
altlinux: CVE-2026-14431 was patched at 2026-07-03
debian: CVE-2026-14431 was patched at 2026-07-05, 2026-07-14
12.
Code Injection - Vim (CVE-2026-59856) - Critical [641]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.97 | 15 | Code Injection | |
| 0.95 | 14 | Highly configurable command-line text editor used in development and system administration. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00216, EPSS Percentile is 0.12147 |
altlinux: CVE-2026-59856 was patched at 2026-06-30, 2026-07-06
debian: CVE-2026-59856 was patched at 2026-07-14
redhat: CVE-2026-59856 was patched at 2026-07-29
ubuntu: CVE-2026-59856 was patched at 2026-07-30
13.
Authentication Bypass - Curl (CVE-2026-11856) - Critical [639]
Description: Successfully using libcurl to do a transfer to a specific HTTP origin (`hostA`) with **Digest** authentication and then changing the origin to a different one (`hostB`) for a second transfer, reusing the same handle, makes libcurl wrongly pass on the `Authorization:` header field meant for `hostA`, to `hostB`.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00604, EPSS Percentile is 0.45496 |
altlinux: CVE-2026-11856 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-11856 was patched at 2026-06-24
14.
Code Injection - MediaWiki (CVE-2026-58025) - Critical [635]
Description: Deserialization of untrusted data vulnerability in Wikimedia Foundation
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:SHINTHINK:CVE-2026-58025 website | |
| 0.97 | 15 | Code Injection | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.24982 |
debian: CVE-2026-58025 was patched at 2026-07-05, 2026-07-14
15.
Arbitrary File Writing - youtube-dl (CVE-2026-50023) - Critical [633]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0.5 | 14 | youtube-dl is a free and open source software tool for downloading video and audio from YouTube and over 1,000 other video hosting websites | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0062, EPSS Percentile is 0.46208 |
altlinux: CVE-2026-50023 was patched at 2026-07-27
debian: CVE-2026-50023 was patched at 2026-07-14
16.
Remote Code Execution - rtklib (CVE-2026-56786) - Critical [630]
Description: RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp length counters to destination buffer size, allowing up to 191-byte overflow into fixed 64-byte descriptor fields. An attacker controlling an NTRIP or serial RTCM3 correction stream can craft a valid CRC-bearing type-1033 message to corrupt adjacent rtcm_t object members, potentially achieving arbitrary
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:rtklib:rtklib (does NOT exist in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00438, EPSS Percentile is 0.3601 |
debian: CVE-2026-56786 was patched at 2026-07-14
17.
Authentication Bypass - Curl (CVE-2026-9079) - Critical [627]
Description: libcurl had a flaw that when instructed to clear proxy authentication credentials which made it not do so, leaving the old credentials around to get used for subsequent transfers that should not know nor use them.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00584, EPSS Percentile is 0.44559 |
altlinux: CVE-2026-9079 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-9079 was patched at 2026-07-14
ubuntu: CVE-2026-9079 was patched at 2026-07-30
18.
Authentication Bypass - rabbitmq_server (CVE-2026-57216) - Critical [627]
Description: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, AMQP 0-9-1, AMQP 1.0, and Stream Protocol authentication can allow a loopback-restricted user such as guest to connect remotely when traffic is accepted through a trusted PROXY-protocol path and the backend listener is loopback-bound because the loopback check uses the listener-side socket address instead of the real client source. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:broadcom:rabbitmq_server (does NOT exist in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00504, EPSS Percentile is 0.40278 |
debian: CVE-2026-57216 was patched at 2026-07-14
19.
Arbitrary File Writing - Gogs (CVE-2026-25242) - Critical [625]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00618, EPSS Percentile is 0.46131 |
altlinux: CVE-2026-25242 was patched at 2026-06-25
20.
Memory Corruption - Linux Kernel (CVE-2026-53359) - Critical [620]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:HORKIMHAB:CVE-2026-53359, Vulners:PublicExploit:GitHub:AORIPUS-LTD:JANUSCAPE-HOTFIX, Vulners:PublicExploit:GitHub:X024N:ALMALINUX-JANUSCAPE-MITIGATION, Vulners:PublicExploit:GitHub:NDOUGLAS-CLOUDSMITH:CVE-2026-53359, Vulners:PublicExploit:GitHub:V4BEL:JANUSCAPE, BDU:PublicExploit websites | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00908, EPSS Percentile is 0.56396 |
almalinux: CVE-2026-53359 was patched at 2026-07-09, 2026-07-14
altlinux: CVE-2026-53359 was patched at 2026-07-04, 2026-07-06, 2026-07-07, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53359 was patched at 2026-07-05, 2026-07-14, 2026-07-30
oraclelinux: CVE-2026-53359 was patched at 2026-07-02, 2026-07-03, 2026-07-04, 2026-07-10, 2026-07-14
redhat: CVE-2026-53359 was patched at 2026-07-09, 2026-07-10, 2026-07-13, 2026-07-14, 2026-07-15, 2026-07-17, 2026-07-22, 2026-07-23
21.
Remote Code Execution - 7-Zip (CVE-2026-14266) - Critical [619]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:4MINX:CVE-2026-14266, Vulners:PublicExploit:GitHub:LIYUXUAN504-BYTE:CVE-2026-14266, BDU:PublicExploit websites | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | 7-Zip is a free and open-source file archiver, a utility used to place groups of files within compressed containers known as "archives" | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00919, EPSS Percentile is 0.56734 |
debian: CVE-2026-14266 was patched at 2026-07-14
22.
Security Feature Bypass - Gitea (CVE-2026-28744) - Critical [619]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00343, EPSS Percentile is 0.269 |
redos: CVE-2026-28744 was patched at 2026-06-26
23.
Remote Code Execution - Envoy (CVE-2026-48090) - Critical [616]
Description: Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, the HTTP OAuth2 filter (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00426, EPSS Percentile is 0.3507 |
altlinux: CVE-2026-48090 was patched at 2026-06-25, 2026-07-02
24.
Authentication Bypass - Curl (CVE-2026-8927) - Critical [615]
Description: When reusing a libcurl handle for sequential transfers driven by environment-variable proxy configuration, libcurl fails to clear the proxy authentication state between requests. Specifically, if the initial transfer authenticates against `proxyA` using Digest auth, a subsequent transfer routed through `proxyB` erroneously leaks the `Proxy-Authorization:` header intended solely for `proxyA`.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0044, EPSS Percentile is 0.36135 |
altlinux: CVE-2026-8927 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-8927 was patched at 2026-07-14
ubuntu: CVE-2026-8927 was patched at 2026-07-30
25.
Remote Code Execution - Keras (CVE-2026-12481) - Critical [614]
Description: A vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:huntr.com website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | High-level neural networks API, running on top of TensorFlow, allowing model building and training | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00467, EPSS Percentile is 0.38032 |
debian: CVE-2026-12481 was patched at 2026-07-14
26.
Path Traversal - Cacti (CVE-2026-39938) - Critical [613]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:POLOSSS:BY-POLOSS..-..CVE-2026-39938 website | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.7 | 10 | EPSS Probability is 0.01305, EPSS Percentile is 0.67668 |
altlinux: CVE-2026-39938 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-39938 was patched at 2026-07-14
27.
Arbitrary File Writing - libzypp (CVE-2026-44941) - Critical [610]
Description: A relative path traversal in the "keyhint" option in repomd.xml parsing of libzypp before 17.38.12 can be used by attackers able to supply a malicious repository to inject or
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:bugzilla.suse.com, BDU:PublicExploit websites | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0.5 | 14 | Product detected by a:opensuse:libzypp (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0052, EPSS Percentile is 0.41245 |
debian: CVE-2026-44941 was patched at 2026-07-14
28.
Authentication Bypass - Curl (CVE-2026-8926) - Critical [603]
Description: When asking curl to use a `.netrc` file to find credentials and at the same time specifying a URL with a username(without a password), like `https://user@example.com/`, curl could wrongly get and use the password for *another* user set in the `.netrc` file for that host if such a one exists and there is no match for the specified user.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00376, EPSS Percentile is 0.30345 |
altlinux: CVE-2026-8926 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-8926 was patched at 2026-07-14
ubuntu: CVE-2026-8926 was patched at 2026-07-30
29.
Path Traversal - OpenSSH (CVE-2026-45309) - Critical [603]
Description: AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior to 2.23.0, AsyncSSH expands the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Path Traversal | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00434, EPSS Percentile is 0.35697 |
debian: CVE-2026-45309 was patched at 2026-07-14
30.
Security Feature Bypass - Curl (CVE-2026-8924) - Critical [601]
Description: A flaw in curl’s cookie parsing logic allows a malicious HTTP server to set 'super cookies' that bypass the Public Suffix List check. This enables an attacker-controlled origin to inject cookies that curl subsequently scopes and transmits to unrelated third-party domains.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0056, EPSS Percentile is 0.43408 |
altlinux: CVE-2026-8924 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-8924 was patched at 2026-07-14
ubuntu: CVE-2026-8924 was patched at 2026-07-30
31.
Security Feature Bypass - Jackson-databind (CVE-2026-54512) - Critical [601]
Description: jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeValidator (PTV) is the primary safety mechanism guarding polymorphic deserialization. When polymorphic typing is enabled and a type identifier contains generic parameters (i.e. the type ID string contains <), DatabindContext._resolveAndValidateGeneric() validates only the raw container class name (the substring before <) against the configured PTV. If the container type is approved, the method parses the full canonical type string via TypeFactory.constructFromCanonical() and returns the fully parameterized type without ever validating the nested type arguments against the PTV. The nested type arguments are then resolved, instantiated, and populated as beans during deserialization. An attacker who controls the type ID can therefore place a denied class as a generic type parameter of an allowed container — for example java.util.ArrayList<com.evil.Gadget> when only java.util.ArrayList is allow-listed. The container passes the PTV check; com.evil.Gadget is loaded via Class.forName(name, true, loader), instantiated, and its properties are set from attacker-controlled JSON. This completely bypasses an explicitly configured PTV allow-list. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:fasterxml:jackson-databind (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00779, EPSS Percentile is 0.52274 |
almalinux: CVE-2026-54512 was patched at 2026-07-16, 2026-07-22
debian: CVE-2026-54512 was patched at 2026-07-14
oraclelinux: CVE-2026-54512 was patched at 2026-07-20, 2026-07-23
redhat: CVE-2026-54512 was patched at 2026-07-16, 2026-07-23
32.
Security Feature Bypass - ModSecurity (CVE-2026-52747) - Critical [601]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx | |
| 0.9 | 10 | CVSS Base Score is 8.6. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00519, EPSS Percentile is 0.41227 |
debian: CVE-2026-52747 was patched at 2026-07-14
33.
Path Traversal - Python (CVE-2026-44307) - High [594]
Description: Mako is a template library written in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:THBURGHOUT:DEPENDABOT-PIP-MAKO-CASE-POC website | |
| 0.7 | 15 | Path Traversal | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.5 | 10 | EPSS Probability is 0.00609, EPSS Percentile is 0.45704 |
redos: CVE-2026-44307 was patched at 2026-07-13
34.
Denial of Service - Netty (CVE-2026-44891) - High [591]
Description: Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Netty is a non-blocking I/O client-server framework for the development of Java network applications such as protocol servers and clients | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00423, EPSS Percentile is 0.34847 |
debian: CVE-2026-44891 was patched at 2026-07-14
35.
Authentication Bypass - Kubernetes (CVE-2026-55761) - High [589]
Description: Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Kubernetes is an open-source container orchestration system for automating software deployment, scaling, and management | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.21339 |
altlinux: CVE-2026-55761 was patched at 2026-06-25, 2026-07-02
36.
Path Traversal - pymdown_extensions (CVE-2023-32309) - High [589]
Description: PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. In affected versions an arbitrary file read is possible when using include file syntax. By using the syntax `--8<--"/etc/passwd"` or `--8<--"/proc/self/environ"` the content of these files will be rendered in the generated documentation. Additionally, a path relative to a specified, allowed base path can also be used to render the content of a file outside the specified base paths: `--8<-- "../../../../etc/passwd"`. Within the Snippets extension, there exists a `base_path` option but the implementation is vulnerable to Directory Traversal. The vulnerable section exists in `get_snippet_path(self, path)` lines 155 to 174 in snippets.py. Any readable file on the host where the plugin is executing may have its content exposed. This can impact any use of Snippets that exposes the use of Snippets to external users. It is never recommended to use Snippets to process user-facing, dynamic content. It is designed to process known content on the backend under the control of the host, but if someone were to accidentally enable it for user-facing content, undesired information could be exposed. This issue has been addressed in version 10.0. Users are advised to upgrade. Users unable to upgrade may restrict relative paths by filtering input.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:facelessuser:pymdown_extensions (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.7 | 10 | EPSS Probability is 0.01658, EPSS Percentile is 0.7428 |
debian: CVE-2023-32309 was patched at 2026-07-14
37.
Security Feature Bypass - Curl (CVE-2026-11564) - High [589]
Description: libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. An easy handle that first uses default native CA trust can continue trusting the native platform store after the application switches that same handle to custom CA material for a later transfer.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com, BDU:PublicExploit websites | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00363, EPSS Percentile is 0.29056 |
altlinux: CVE-2026-11564 was patched at 2026-06-24, 2026-06-30
ubuntu: CVE-2026-11564 was patched at 2026-07-30
38.
Security Feature Bypass - rabbitmq_server (CVE-2026-57215) - High [589]
Description: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ allows foreign bindings to amq.rabbitmq.reply-to destinations because volatile direct-reply-to queues can be accepted at bind and route time but are missing from Khepri-backed deletion checks, leaving persistent route entries after unbind. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:broadcom:rabbitmq_server (does NOT exist in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00382, EPSS Percentile is 0.30979 |
debian: CVE-2026-57215 was patched at 2026-07-14
39.
Security Feature Bypass - Envoy (CVE-2026-48743) - High [586]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00217, EPSS Percentile is 0.12316 |
altlinux: CVE-2026-48743 was patched at 2026-06-25, 2026-07-02
40.
Security Feature Bypass - nghttp2 (CVE-2026-58055) - High [584]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | nghttp2 is an implementation of HTTP/2 and its header compression algorithm HPACK in C | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00202, EPSS Percentile is 0.10395 |
debian: CVE-2026-58055 was patched at 2026-07-14
ubuntu: CVE-2026-58055 was patched at 2026-07-30
41.
Elevation of Privilege - Gogs (CVE-2026-25232) - High [583]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00436, EPSS Percentile is 0.35887 |
altlinux: CVE-2026-25232 was patched at 2026-06-25
42.
Remote Code Execution - GIMP (CVE-2026-58380) - High [583]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.gnome.org website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00257, EPSS Percentile is 0.17381 |
almalinux: CVE-2026-58380 was patched at 2026-07-16
debian: CVE-2026-58380 was patched at 2026-07-14
oraclelinux: CVE-2026-58380 was patched at 2026-07-16
redhat: CVE-2026-58380 was patched at 2026-07-16
43.
Remote Code Execution - GIMP (CVE-2026-58384) - High [583]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.gnome.org website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00257, EPSS Percentile is 0.17381 |
almalinux: CVE-2026-58384 was patched at 2026-07-16
debian: CVE-2026-58384 was patched at 2026-07-14
oraclelinux: CVE-2026-58384 was patched at 2026-07-16
redhat: CVE-2026-58384 was patched at 2026-07-16
44.
Command Injection - Gogs (CVE-2026-26194) - High [581]
Description: Gogs is an open source self-hosted Git service. Prior to version 0.14.2, there's a security issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.97 | 15 | Command Injection | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00511, EPSS Percentile is 0.40692 |
altlinux: CVE-2026-26194 was patched at 2026-06-25
45.
Security Feature Bypass - Gogs (CVE-2026-25921) - High [580]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00327, EPSS Percentile is 0.25229 |
altlinux: CVE-2026-25921 was patched at 2026-06-25
46.
Authentication Bypass - Caddy (CVE-2026-52845) - High [579]
Description: Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied identity header before copying the trusted value from the auth gateway. But when the request later goes through php_fastcgi, Caddy normalizes HTTP headers into CGI variables by replacing - with _. This lets a client send an underscore alias that survives the forward_auth delete step but becomes the same PHP/FastCGI variable. Result: a remote client can inject or sometimes override identity/group headers trusted by PHP/FastCGI applications behind Caddy. This vulnerability is fixed in 2.11.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:caddyserver:caddy (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00297, EPSS Percentile is 0.22048 |
altlinux: CVE-2026-52845 was patched at 2026-07-02, 2026-07-03
debian: CVE-2026-52845 was patched at 2026-07-14
47.
Code Injection - Cacti (CVE-2026-40083) - High [577]
Description: Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have SQL Injection through unsanitized unserialize+implode in managers.php. At line 756 of managers.php, the application assigns $selected_items by calling
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.97 | 15 | Code Injection | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00334, EPSS Percentile is 0.25937 |
altlinux: CVE-2026-40083 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-40083 was patched at 2026-07-14
48.
Denial of Service - libssh2 (CVE-2026-55199) - High [577]
Description: libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO handler in src/packet.c that allows a malicious SSH server to cause a client CPU exhaustion loop by sending a crafted extension count value. A malicious server can set nr_extensions to 0xFFFFFFFF during key exchange, causing the client to spin in a tight CPU loop for over 60 seconds because return values from _libssh2_get_string() are unchecked and the session timeout does not apply to CPU-bound loops.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:ETHAN-ANDREWS:EXPLOITARIUM-DETECTIONS website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:libssh2:libssh2 (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00918, EPSS Percentile is 0.56714 |
altlinux: CVE-2026-55199 was patched at 2026-07-09, 2026-07-13, 2026-07-14, 2026-07-15, 2026-07-17
debian: CVE-2026-55199 was patched at 2026-06-24, 2026-06-25
ubuntu: CVE-2026-55199 was patched at 2026-07-30
49.
Incorrect Calculation - dos (CVE-2026-42055) - High [577]
Description: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the large_client_header_buffers directive size is larger than 2 megabytes. A remote, unauthenticated attacker, along with conditions beyond their control, could send large headers while creating an upstream request. This may cause a heap-based buffer overflow in the NGINX worker process leading to a restart. Additionally, attackers can execute code on systems with Address Space Layout Randomization (ASLR) disabled or when the attacker can bypass ASLR. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:CHPRATIK:NGINX_2026_CVE_BUNDLE_CTI_REPORT, Vulners:PublicExploit:GitHub:HORKIMHAB:CVE-2026-42055 websites | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:f5:dos (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.9 | 10 | EPSS Probability is 0.04044, EPSS Percentile is 0.89597 |
almalinux: CVE-2026-42055 was patched at 2026-07-07, 2026-07-08, 2026-07-13
altlinux: CVE-2026-42055 was patched at 2026-06-23, 2026-06-25, 2026-06-26
debian: CVE-2026-42055 was patched at 2026-06-24, 2026-06-30
oraclelinux: CVE-2026-42055 was patched at 2026-07-09, 2026-07-13, 2026-07-14, 2026-07-16
redhat: CVE-2026-42055 was patched at 2026-07-07, 2026-07-08, 2026-07-13
redos: CVE-2026-42055 was patched at 2026-07-14
ubuntu: CVE-2026-42055 was patched at 2026-07-30
50.
Security Feature Bypass - Curl (CVE-2026-12064) - High [577]
Description: When a user invokes curl using a schemeless URL combined with `--proto-default` sftp (or scp), a disconnect occurs between the tool layer and libcurl. The tool layer incorrectly infers the URL scheme, which erroneously bypasses the initialization of critical SSH security options like CURLOPT_SSH_HOST_PUBLIC_KEY_SHA256 and CURLOPT_SSH_KNOWNHOSTS. Conversely, the libcurl runtime successfully honors CURLOPT_DEFAULT_PROTOCOL and establishes the connection via SFTP/SCP as specified. Because the tool layer skipped the security configuration, these SSH host verification options are silently omitted, causing curl to connect to an unverified SSH remote host without throwing an error.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00339, EPSS Percentile is 0.26477 |
altlinux: CVE-2026-12064 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-12064 was patched at 2026-06-24
ubuntu: CVE-2026-12064 was patched at 2026-07-30
51.
Security Feature Bypass - Curl (CVE-2026-8932) - High [577]
Description: libcurl would reuse a previously created connection even when some mTLS config related option had been changed that should have prohibited reuse. libcurl keeps previously used connections in a connection pool for subsequent transfers to reuse if one of them matches the setup. However, some TLS settings related to client certificates were left out from the configuration match checks, making them match too easily. In particular options related to the private key.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00396, EPSS Percentile is 0.32417 |
altlinux: CVE-2026-8932 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-8932 was patched at 2026-07-14
52.
Arbitrary File Reading - nltk (CVE-2026-12243) - High [576]
Description: NLTK version 3.9.4 is vulnerable to a path traversal attack due to an incomplete fix for GitHub Issue #3504. The `_UNSAFE_NO_PROTOCOL_RE` regex in `nltk/data.py` checks for literal `../` sequences but fails to account for percent-encoded traversal sequences such as `..%2f`. The `url2pathname()` function decodes these sequences after the validation step, allowing an attacker to bypass the protection. This vulnerability enables an attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:huntr.com website | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00583, EPSS Percentile is 0.44528 |
debian: CVE-2026-12243 was patched at 2026-07-14
53.
Arbitrary File Reading - nltk (CVE-2026-54293) - High [576]
Description: NLTK (Natural Language Toolkit) is a suite of open source Python modules, data sets, and tutorials supporting research and development in Natural Language Processing. Prior to 3.10.0-rc1, nltk.data.load() in NLTK is vulnerable to path traversal via URL-encoded path separators and traversal segments when using the nltk: URL scheme. The unsafe-path regex check is performed before url2pathname() decodes the %xx sequences (a classic decode-after-check / TOCTOU-style flaw), allowing an attacker to bypass the protection documented in NLTK's SECURITY.md and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00555, EPSS Percentile is 0.43141 |
debian: CVE-2026-54293 was patched at 2026-06-24
54.
Denial of Service - Asterisk (CVE-2026-59925) - High [575]
Description: Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Asterisk is a free and open source framework for building communications applications and is sponsored by Sangoma | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0041, EPSS Percentile is 0.33653 |
debian: CVE-2026-59925 was patched at 2026-07-14
55.
Denial of Service - Envoy (CVE-2026-47220) - High [575]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00424, EPSS Percentile is 0.34906 |
altlinux: CVE-2026-47220 was patched at 2026-06-25, 2026-07-02
56.
Denial of Service - Envoy (CVE-2026-47221) - High [575]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00327, EPSS Percentile is 0.25239 |
altlinux: CVE-2026-47221 was patched at 2026-06-25, 2026-07-02
57.
Denial of Service - Envoy (CVE-2026-48042) - High [575]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00365, EPSS Percentile is 0.29241 |
altlinux: CVE-2026-48042 was patched at 2026-06-25, 2026-07-02
58.
Remote Code Execution - nltk (CVE-2026-12252) - High [571]
Description: In nltk/nltk versions 3.9.3 and earlier, five Stanford interface classes (StanfordPOSTagger, StanfordNERTagger, StanfordParser, StanfordDependencyParser, and StanfordNeuralDependencyParser) are vulnerable to untrusted JAR
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:huntr.com website | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:nltk:nltk (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09452 |
debian: CVE-2026-12252 was patched at 2026-07-14
59.
Path Traversal - Rclone (CVE-2026-59733) - High [570]
Description: Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Path Traversal | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00422, EPSS Percentile is 0.34746 |
altlinux: CVE-2026-59733 was patched at 2026-07-13, 2026-07-16
debian: CVE-2026-59733 was patched at 2026-07-14
60.
Denial of Service - Ws (CVE-2026-48779) - High [565]
Description: ws is an open source WebSocket client and server for Node.js. All versions from 1.1.0 up to (but not including) 5.2.5, from 6.0.0 up to 6.2.4, from 7.0.0 up to 7.5.11, and from 8.0.0 up to 8.21.0 are affected by a memory exhaustion DoS vulnerability. A peer can send a high volume of exceptionally small fragments and data chunks, with modest network traffic, to force the remote peer into allocating and holding structural wrappers that consume far more memory than the default documented message-size limit, leading to process termination due to OOM. This issue has been fixed in versions 5.2.5, 6.2.4, 7.5.11, and 8.21.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:ws_project:ws (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00782, EPSS Percentile is 0.52388 |
debian: CVE-2026-48779 was patched at 2026-06-24
61.
Security Feature Bypass - Curl (CVE-2026-8286) - High [565]
Description: A vulnerability exists where a new transfer that uses STARTTLS to upgrade the connection might reuse an existing live connection even though the TLS configuration mismatches so it should not.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00309, EPSS Percentile is 0.2333 |
altlinux: CVE-2026-8286 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-8286 was patched at 2026-07-14
ubuntu: CVE-2026-8286 was patched at 2026-07-30
62.
Security Feature Bypass - rabbitmq_server (CVE-2026-57217) - High [565]
Description: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.21, 4.1.11, and 4.2.6, RabbitMQ topic authorization can allow restricted topic writes and binds during metadata-store failures because topic-permission lookup errors from Khepri can collapse to undefined, which the internal backend treats as allow. This issue is fixed in versions 3.13.15, 4.0.21, 4.1.11, and 4.2.6.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:broadcom:rabbitmq_server (does NOT exist in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00352, EPSS Percentile is 0.27869 |
debian: CVE-2026-57217 was patched at 2026-07-14
63.
Security Feature Bypass - rabbitmq_server (CVE-2026-57218) - High [565]
Description: RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ AMQP 0-9-1 allows an existing consumer to keep receiving messages after OAuth token expiry or connection.update_secret refresh to reduced scopes because existing consumers are not canceled or reauthorized at delivery time after the channel user state changes. This issue is fixed in version 4.2.6.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:broadcom:rabbitmq_server (does NOT exist in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00352, EPSS Percentile is 0.27868 |
debian: CVE-2026-57218 was patched at 2026-07-14
64.
Information Disclosure - Curl (CVE-2026-9546) - High [564]
Description: A vulnerability in libcurl caused the HTTP `Referer:` header to persist even when explicitly cleared. While the documentation states that passing NULL to `CURLOPT_REFERER` suppresses the header, the option failed to clear the internal state. As a result the previous referrer string was erroneously reused and sent in subsequent requests, potentially leaking sensitive information to unintended servers.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00399, EPSS Percentile is 0.32658 |
altlinux: CVE-2026-9546 was patched at 2026-06-24, 2026-06-30
65.
Denial of Service - Envoy (CVE-2026-48044) - High [563]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0032, EPSS Percentile is 0.24502 |
altlinux: CVE-2026-48044 was patched at 2026-06-25, 2026-07-02
66.
Information Disclosure - Envoy (CVE-2026-47775) - High [562]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.83 | 15 | Information Disclosure | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.05929 |
altlinux: CVE-2026-47775 was patched at 2026-06-25, 2026-07-02
67.
Memory Corruption - Linux Kernel (CVE-2026-53362) - High [560]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00265, EPSS Percentile is 0.18309 |
almalinux: CVE-2026-53362 was patched at 2026-07-02
altlinux: CVE-2026-53362 was patched at 2026-07-04, 2026-07-06, 2026-07-07, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53362 was patched at 2026-07-05, 2026-07-14, 2026-07-30
oraclelinux: CVE-2026-53362 was patched at 2026-07-15
68.
Authentication Bypass - Gogs (CVE-2026-25229) - High [559]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.98 | 15 | Authentication Bypass | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.17029 |
altlinux: CVE-2026-25229 was patched at 2026-06-25
69.
Path Traversal - Rclone (CVE-2026-54572) - High [558]
Description: Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4, with -l/--links,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Path Traversal | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00309, EPSS Percentile is 0.23299 |
altlinux: CVE-2026-54572 was patched at 2026-07-13, 2026-07-16
debian: CVE-2026-54572 was patched at 2026-07-14
70.
Path Traversal - Gogs (CVE-2026-24135) - High [557]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:RESCHJONAS:CVE-2026-24135 website | |
| 0.7 | 15 | Path Traversal | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00654, EPSS Percentile is 0.47745 |
altlinux: CVE-2026-24135 was patched at 2026-06-25
71.
Elevation of Privilege - LXD (CVE-2026-9640) - High [556]
Description: A
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Product detected by a:canonical:lxd (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00366, EPSS Percentile is 0.29278 |
debian: CVE-2026-9640 was patched at 2026-06-28, 2026-07-14
72.
Denial of Service - OpenSSH (CVE-2026-55654) - High [555]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:bugzilla.redhat.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00432, EPSS Percentile is 0.35502 |
almalinux: CVE-2026-55654 was patched at 2026-07-29
debian: CVE-2026-55654 was patched at 2026-06-24
oraclelinux: CVE-2026-55654 was patched at 2026-07-30
redhat: CVE-2026-55654 was patched at 2026-07-29
73.
Denial of Service - Curl (CVE-2026-11352) - High [553]
Description: An issue in curl’s QUIC UDP receive function allows a malicious HTTP/3 server to trigger a remote denial of service against a curl or libcurl client. Because the helper function discards zero-length UDP datagrams before counting them toward the per-call packet budget, a connected QUIC peer can continuously stream empty datagrams to indefinitely stall the client.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00577, EPSS Percentile is 0.44268 |
altlinux: CVE-2026-11352 was patched at 2026-06-24, 2026-06-30
ubuntu: CVE-2026-11352 was patched at 2026-07-30
74.
Denial of Service - Curl (CVE-2026-11586) - High [553]
Description: By default, curl automatically responds to WebSocket PING frames. Because curl lacks an upper bound on memory allocation for unacknowledged frames, a malicious server can exhaust all available memory by flooding curl with rapid, sequential PING messages.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00491, EPSS Percentile is 0.39537 |
altlinux: CVE-2026-11586 was patched at 2026-06-24, 2026-06-30
ubuntu: CVE-2026-11586 was patched at 2026-07-30
75.
Denial of Service - Faraday (CVE-2026-54297) - High [553]
Description: Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. From 1.0.0 until 1.10.6 and 2.14.3, Faraday::NestedParamsEncoder, the default nested query parameter encoder/decoder in Faraday, decodes nested query strings without enforcing a maximum nesting depth. A crafted query string causes Faraday to build a deeply nested Ruby Hash structure. The internal dehash routine then recursively walks this attacker-controlled structure without a depth limit. At sufficient depth, Ruby raises an uncaught SystemStackError (stack level too deep), crashing the calling thread or worker. This can lead to denial of service in applications that pass attacker-controlled query strings to Faraday's nested query parsing or URL-building paths. This vulnerability is fixed in 1.10.6 and 2.14.3.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:faraday_project:faraday (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00433, EPSS Percentile is 0.35629 |
debian: CVE-2026-54297 was patched at 2026-07-14
76.
Denial of Service - OpenTelemetry (CVE-2026-29181) - High [553]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | OpenTelemetry is a collection of APIs, SDKs, and tools. Use it to instrument, generate, collect, and export telemetry data (metrics, logs and traces) to help you analyze your software's performance and behavior | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00572, EPSS Percentile is 0.44016 |
altlinux: CVE-2026-29181 was patched at 2026-07-10, 2026-07-13
77.
Denial of Service - immutable (CVE-2026-59880) - High [553]
Description: Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, Immutable.Map and Immutable.Set keep keys that share the same 32-bit hash in a HashCollisionNode collision bucket that is scanned linearly, allowing an attacker who controls keys inserted into a Map, such as through Immutable.Map(obj), Immutable.fromJS(obj), state.merge(userObject), or mergeDeep, to craft many colliding keys and degrade insertion and lookup to consume disproportionate CPU. This issue is fixed in versions 4.3.9 and 5.1.8.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:immutable-js:immutable (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00432, EPSS Percentile is 0.35541 |
debian: CVE-2026-59880 was patched at 2026-07-14
78.
Denial of Service - rabbitmq_server (CVE-2026-57212) - High [553]
Description: RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_management HTTP API accepts oversized valid JSON bodies on with_decode and direct_request paths because read_complete_body checks the accumulated size before the final chunk but not the final combined size. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:broadcom:rabbitmq_server (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00433, EPSS Percentile is 0.35601 |
debian: CVE-2026-57212 was patched at 2026-07-14
79.
Denial of Service - soup_sieve (CVE-2026-49476) - High [553]
Description: Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve allocates unbounded memory when compiling large comma-separated selector lists, allowing an attacker who can supply a crafted selector string to soupsieve.compile() or Beautiful Soup .select() / .select_one() to allocate hundreds of megabytes of heap memory from a relatively small input and cause denial of service. This issue is fixed in version 2.8.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:facelessuser:soup_sieve (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00522, EPSS Percentile is 0.41353 |
debian: CVE-2026-49476 was patched at 2026-07-14
80.
Denial of Service - soup_sieve (CVE-2026-49477) - High [553]
Description: Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in soupsieve/css_parser.py, allowing an attacker who can supply untrusted CSS selector strings to soupsieve.compile() or Beautiful Soup .select() / .select_one() to cause CPU exhaustion and denial of service. This issue is fixed in version 2.8.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:facelessuser:soup_sieve (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00522, EPSS Percentile is 0.41354 |
debian: CVE-2026-49477 was patched at 2026-07-14
81.
Path Traversal - Caddy (CVE-2026-52844) - High [553]
Description: Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outside /private/*, but file_server later resolves the same request path as private\secret.txt on disk. An unauthenticated remote client can bypass Caddy path-scoped auth/deny routes protecting /private/*. This vulnerability is fixed in 2.11.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:caddyserver:caddy (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00478, EPSS Percentile is 0.38738 |
altlinux: CVE-2026-52844 was patched at 2026-07-02, 2026-07-03
debian: CVE-2026-52844 was patched at 2026-07-14
82.
Security Feature Bypass - Setuptools (CVE-2026-59890) - High [553]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Setuptools is a fully-featured, actively-maintained, and stable library designed to facilitate packaging Python projects | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00405, EPSS Percentile is 0.3328 |
altlinux: CVE-2026-59890 was patched at 2026-07-07
83.
Information Disclosure - Curl (CVE-2026-9545) - High [552]
Description: In this scenario, libcurl first uses a proper HTTP/3 server for the initial transfers, and when it makes a second transfer to the same site it has been replaced by the attacker's impostor machine - without a valid certificate. When libcurl returns to the hostname the second time with a cached SSL session (`CURLOPT_SSL_SESSIONID_CACHE` is not disabled) and early data enabled (the `CURLSSLOPT_EARLYDATA` bit is set in `CURLOPT_SSL_OPTIONS`), libcurl might send off the second request's bytes on that new connection *before* enforcing the certificate verification failure. Potentially leaking sensitive information.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00268, EPSS Percentile is 0.18863 |
altlinux: CVE-2026-9545 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-9545 was patched at 2026-07-14
ubuntu: CVE-2026-9545 was patched at 2026-07-30
84.
Memory Corruption - Linux Kernel (CVE-2026-53264) - High [548]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:HORKIMHAB:CVE-2026-53264 website | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10732 |
altlinux: CVE-2026-53264 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53264 was patched at 2026-07-14
85.
Cross Site Scripting - DOMPurify (CVE-2026-47423) - High [547]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0027, EPSS Percentile is 0.19008 |
debian: CVE-2026-47423 was patched at 2026-07-14
86.
Incorrect Calculation - FreeRDP (CVE-2026-57156) - High [546]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00418, EPSS Percentile is 0.34357 |
altlinux: CVE-2026-57156 was patched at 2026-07-28
debian: CVE-2026-57156 was patched at 2026-07-14
ubuntu: CVE-2026-57156 was patched at 2026-07-30
87.
Memory Corruption - FreeRDP (CVE-2026-57158) - High [546]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00459, EPSS Percentile is 0.37533 |
altlinux: CVE-2026-57158 was patched at 2026-07-28
debian: CVE-2026-57158 was patched at 2026-07-14
ubuntu: CVE-2026-57158 was patched at 2026-07-30
88.
Cross Site Scripting - MediaWiki (CVE-2026-58037) - High [545]
Description: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:SHINTHINK:CVE-2026-58025 website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00169, EPSS Percentile is 0.06579 |
debian: CVE-2026-58037 was patched at 2026-07-05, 2026-07-14
89.
Denial of Service - Mistune (CVE-2026-59922) - High [541]
Description: Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work in src/mistune/plugins/formatting.py when the strikethrough, mark, or insert plugin scans for matching markers from each possible start position, allowing
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:mistune_project:mistune (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00418, EPSS Percentile is 0.34399 |
debian: CVE-2026-59922 was patched at 2026-07-14
90.
Denial of Service - Mistune (CVE-2026-59928) - High [541]
Description: Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadratic work in src/mistune/block_parser.py and the ref_links environment dictionary handling, allowing
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:mistune_project:mistune (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00413, EPSS Percentile is 0.33931 |
debian: CVE-2026-59928 was patched at 2026-07-14
91.
Denial of Service - Pillow (CVE-2026-54059) - High [541]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Pillow is a Python imaging library that adds image processing capabilities to Python, supporting formats such as PNG, JPEG, GIF, TIFF, and BMP. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0041, EPSS Percentile is 0.33652 |
almalinux: CVE-2026-54059 was patched at 2026-07-14
altlinux: CVE-2026-54059 was patched at 2026-07-27
debian: CVE-2026-54059 was patched at 2026-07-14
oraclelinux: CVE-2026-54059 was patched at 2026-07-14
redhat: CVE-2026-54059 was patched at 2026-07-14
92.
Denial of Service - Pillow (CVE-2026-54060) - High [541]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Pillow is a Python imaging library that adds image processing capabilities to Python, supporting formats such as PNG, JPEG, GIF, TIFF, and BMP. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00418, EPSS Percentile is 0.34398 |
almalinux: CVE-2026-54060 was patched at 2026-07-14
altlinux: CVE-2026-54060 was patched at 2026-07-27
debian: CVE-2026-54060 was patched at 2026-07-14
oraclelinux: CVE-2026-54060 was patched at 2026-07-14
redhat: CVE-2026-54060 was patched at 2026-07-14
93.
Denial of Service - Pillow (CVE-2026-55379) - High [541]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Pillow is a Python imaging library that adds image processing capabilities to Python, supporting formats such as PNG, JPEG, GIF, TIFF, and BMP. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00421, EPSS Percentile is 0.3472 |
almalinux: CVE-2026-55379 was patched at 2026-07-14
altlinux: CVE-2026-55379 was patched at 2026-07-27
debian: CVE-2026-55379 was patched at 2026-07-14
oraclelinux: CVE-2026-55379 was patched at 2026-07-14
redhat: CVE-2026-55379 was patched at 2026-07-14
94.
Denial of Service - Pillow (CVE-2026-55380) - High [541]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Pillow is a Python imaging library that adds image processing capabilities to Python, supporting formats such as PNG, JPEG, GIF, TIFF, and BMP. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00418, EPSS Percentile is 0.34399 |
almalinux: CVE-2026-55380 was patched at 2026-07-14
altlinux: CVE-2026-55380 was patched at 2026-07-27
debian: CVE-2026-55380 was patched at 2026-07-14
oraclelinux: CVE-2026-55380 was patched at 2026-07-14
redhat: CVE-2026-55380 was patched at 2026-07-14
95.
Denial of Service - Pillow (CVE-2026-59200) - High [541]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Pillow is a Python imaging library that adds image processing capabilities to Python, supporting formats such as PNG, JPEG, GIF, TIFF, and BMP. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00385, EPSS Percentile is 0.31295 |
altlinux: CVE-2026-59200 was patched at 2026-07-27
debian: CVE-2026-59200 was patched at 2026-07-14
96.
Denial of Service - Pillow (CVE-2026-59204) - High [541]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Pillow is a Python imaging library that adds image processing capabilities to Python, supporting formats such as PNG, JPEG, GIF, TIFF, and BMP. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00393, EPSS Percentile is 0.32087 |
altlinux: CVE-2026-59204 was patched at 2026-07-27
debian: CVE-2026-59204 was patched at 2026-07-14
97.
Denial of Service - httplib2 (CVE-2026-59939) - High [541]
Description: httplib2 is a comprehensive HTTP client library for Python. Prior to 0.32.0, httplib2 performs unbounded decompression of HTTP response bodies encoded with Content-Encoding: gzip or deflate in _decompressContent in httplib2/init.py, allowing a malicious or compromised HTTP server to return a small compressed payload that expands to an arbitrarily large size in memory and causes MemoryError or OOM-kill in the client process. This issue is fixed in version 0.32.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:httplib2_project:httplib2 (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0041, EPSS Percentile is 0.33652 |
debian: CVE-2026-59939 was patched at 2026-07-14
redhat: CVE-2026-59939 was patched at 2026-07-30
ubuntu: CVE-2026-59939 was patched at 2026-07-30
98.
Denial of Service - js-yaml (CVE-2026-59869) - High [541]
Description: js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 before 3.15.0 and from 4.0.0 before 4.3.0, js-yaml can spend quadratic CPU time parsing a document whose size grows only linearly when a chain of mappings uses merge keys where each mapping merges the previous one. This issue is fixed in versions 3.15.0 and 4.3.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nodeca:js-yaml (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00423, EPSS Percentile is 0.34855 |
debian: CVE-2026-59869 was patched at 2026-07-14
99.
Denial of Service - rtklib (CVE-2026-56787) - High [541]
Description: RTKLIB through 2.4.3 contains an off-by-one out-of-bounds read vulnerability in the decode_ssr3 function at src/rtcm3.c:1446 that allows remote attackers to trigger a global buffer overflow via crafted RTCM3 SSR messages with attacker-controlled signal mode fields. Remote attackers can exploit this vulnerability by sending malicious SSR correction streams over NTRIP or serial connections to cause
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:rtklib:rtklib (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00335, EPSS Percentile is 0.26129 |
debian: CVE-2026-56787 was patched at 2026-07-14
100.
Denial of Service - tar (CVE-2026-59871) - High [541]
Description: node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, node-tar coerces all-digit PAX path and linkpath values in src/pax.ts to JavaScript numbers, causing downstream path handling such as normalizeWindowsPath(entry.path).split('/') to throw an uncaught TypeError. This issue is fixed in version 7.5.18.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:isaacs:tar (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0041, EPSS Percentile is 0.33653 |
debian: CVE-2026-59871 was patched at 2026-07-14
101.
Denial of Service - tar (CVE-2026-59873) - High [541]
Description: node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.19, node-tar does not enforce hard upper bounds on total decompressed data, entry counts, or decompression ratio in extraction and parsing paths such as src/extract.ts, allowing a small crafted gzip bomb to exhaust disk space and CPU. This issue is fixed in version 7.5.19.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:isaacs:tar (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00424, EPSS Percentile is 0.34911 |
debian: CVE-2026-59873 was patched at 2026-07-14
redhat: CVE-2026-59873 was patched at 2026-07-28
102.
Denial of Service - tar (CVE-2026-59874) - High [541]
Description: node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.18, tar.replace accepts a checksum-valid tar header with a negative base-256 encoded entry size, causing the archive scanner to make no progress while repeatedly parsing the same header. This issue is fixed in version 7.5.18.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:isaacs:tar (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00418, EPSS Percentile is 0.34399 |
debian: CVE-2026-59874 was patched at 2026-07-14
redhat: CVE-2026-59874 was patched at 2026-07-28
103.
Memory Corruption - Curl (CVE-2026-10536) - High [541]
Description: A use-after-free vulnerability exists in libcurl when an application configures an HTTP/2 stream-dependency tree via `CURLOPT_STREAM_DEPENDS` or `CURLOPT_STREAM_DEPENDS_E`, subsequently invokes `curl_easy_reset()`, and finally terminates the handle with `curl_easy_cleanup()`. During this final cleanup phase, libcurl attempts to access and modify an internal structure that was already freed during the reset operation.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com, BDU:PublicExploit websites | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00507, EPSS Percentile is 0.40473 |
altlinux: CVE-2026-10536 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-10536 was patched at 2026-06-24
ubuntu: CVE-2026-10536 was patched at 2026-07-30
104.
Memory Corruption - Curl (CVE-2026-8925) - High [541]
Description: The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00592, EPSS Percentile is 0.44935 |
altlinux: CVE-2026-8925 was patched at 2026-06-24, 2026-06-30
ubuntu: CVE-2026-8925 was patched at 2026-07-30
105.
Path Traversal - extract-zip (CVE-2026-56876) - High [541]
Description: extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip will extract the symlink without validation, allowing it to point outside the extraction directory. Depending on how extract-zip is used, an attacker could read or write to arbitrary files.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:max-mapper:extract-zip (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00391, EPSS Percentile is 0.31824 |
debian: CVE-2026-56876 was patched at 2026-07-14
106.
Security Feature Bypass - Cacti (CVE-2026-40941) - High [541]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05494 |
altlinux: CVE-2026-40941 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-40941 was patched at 2026-07-14
107.
Server-Side Request Forgery - PHP Secure Communications Library (CVE-2026-55599) - High [541]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.6 | 14 | phpseclib provides pure-PHP implementations of SSH2, SFTP, RSA, DSA, Elliptic Curves, AES, ChaCha20, X. 509, CSR, CRL, SPKAC | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05215 |
debian: CVE-2026-55599 was patched at 2026-06-24
108.
Security Feature Bypass - Envoy (CVE-2026-47778) - High [539]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07424 |
altlinux: CVE-2026-47778 was patched at 2026-06-25, 2026-07-02
109.
Cross Site Scripting - DOMPurify (CVE-2026-49458) - High [535]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00384, EPSS Percentile is 0.31087 |
debian: CVE-2026-49458 was patched at 2026-07-14
110.
Cross Site Scripting - DOMPurify (CVE-2026-49978) - High [535]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00334, EPSS Percentile is 0.25946 |
debian: CVE-2026-49978 was patched at 2026-07-14
111.
Denial of Service - Wireshark (CVE-2026-15169) - High [534]
Description: UMTS FP protocol dissector crash in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00225, EPSS Percentile is 0.1325 |
altlinux: CVE-2026-15169 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15169 was patched at 2026-07-14
112.
Incorrect Calculation - FreeRDP (CVE-2026-55827) - High [534]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00339, EPSS Percentile is 0.26515 |
altlinux: CVE-2026-55827 was patched at 2026-06-20, 2026-06-22, 2026-06-24
debian: CVE-2026-55827 was patched at 2026-07-14
ubuntu: CVE-2026-55827 was patched at 2026-07-30
113.
Path Traversal - Gogs (CVE-2026-23633) - High [533]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Path Traversal | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00456, EPSS Percentile is 0.37288 |
altlinux: CVE-2026-23633 was patched at 2026-06-25
114.
Denial of Service - LXD (CVE-2026-9639) - High [529]
Description: Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:canonical:lxd (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0042, EPSS Percentile is 0.34605 |
debian: CVE-2026-9639 was patched at 2026-06-28, 2026-07-14
115.
Denial of Service - concurrent_ruby (CVE-2026-54904) - High [529]
Description: concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::AtomicReference#update can enter a permanent busy retry loop when the current value is Float::NAN. The issue is caused by the interaction between AtomicReference#update, which retries until compare_and_set(old_value, new_value) succeeds; Numeric compare_and_set, which checks old == old_value before attempting the underlying atomic swap.; and Ruby NaN semantics, where Float::NAN == Float::NAN is always false. As a result, once an AtomicReference contains Float::NAN, calling #update repeatedly evaluates the caller's block and never returns. In services that store externally derived numeric values in an AtomicReference, this can cause CPU exhaustion or permanent request/job hangs. This vulnerability is fixed in 1.3.7.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:rubyconcurrency:concurrent_ruby (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00317, EPSS Percentile is 0.24073 |
debian: CVE-2026-54904 was patched at 2026-07-14
116.
Information Disclosure - rabbitmq_server (CVE-2026-57221) - High [529]
Description: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, RabbitMQ does not perform authorization checks on passive queue.declare and exchange.declare AMQP 0-9-1 operations, allowing any authenticated user who can connect to a virtual host to enumerate queue and exchange names and read queue message and consumer counts. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Product detected by a:broadcom:rabbitmq_server (does NOT exist in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0041, EPSS Percentile is 0.33732 |
debian: CVE-2026-57221 was patched at 2026-07-14
117.
Path Traversal - Cacti (CVE-2026-40084) - High [529]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00386, EPSS Percentile is 0.31368 |
altlinux: CVE-2026-40084 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-40084 was patched at 2026-07-14
118.
Server-Side Request Forgery - Canonical LXD (CVE-2026-28385) - High [529]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.6 | 14 | Canonical LXD is a system container and VM manager for Linux. LXD-UI is the web UI component of LXD that provides a browser-based interface for creating, managing and starting containers and instances. | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00183, EPSS Percentile is 0.0819 |
debian: CVE-2026-28385 was patched at 2026-07-14
119.
Memory Corruption - Envoy (CVE-2026-47204) - High [527]
Description: Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.22471 |
altlinux: CVE-2026-47204 was patched at 2026-06-25, 2026-07-02
120.
Memory Corruption - Linux Kernel (CVE-2026-52910) - High [525]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06151 |
altlinux: CVE-2026-52910 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-52910 was patched at 2026-06-21, 2026-06-24, 2026-07-14
121.
Server-Side Request Forgery - incus (CVE-2026-35527) - High [524]
Description: Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a user-supplied URL before validating the request against project restrictions such as restricted.images.servers. The imgPostURLInfo function constructs and sends a HEAD request directly from the attacker-supplied source URL to resolve image metadata, and this network interaction occurs before the flow reaches the point where the import would be rejected by policy. Although the actual image download is blocked by the project restriction, an authenticated user can coerce the daemon into making blind HEAD requests to arbitrary destinations. These requests include server metadata in custom headers (Incus-Server-Architectures, Incus-Server-Version), which discloses information about the host environment to the attacker-controlled endpoint. This blind SSRF primitive can be used to probe internal services, unroutable address space, or cloud metadata endpoints reachable from the host. This vulnerability pattern is similar to CVE-2026-24767. This issue has been fixed in version 7.0.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.5 | 14 | Product detected by a:linuxcontainers:incus (does NOT exist in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00271, EPSS Percentile is 0.19333 |
redos: CVE-2026-35527 was patched at 2026-06-22
122.
Cross Site Scripting - DOMPurify (CVE-2026-49459) - High [523]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | DOMPurify is a DOM-only, super-fast, uber-tolerant XSS sanitizer for HTML, MathML and SVG | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22724 |
debian: CVE-2026-49459 was patched at 2026-07-14
123.
Cross Site Scripting - Mistune (CVE-2026-59923) - High [523]
Description: Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, HTMLRenderer.safe_url() does not block percent-encoded javascript URIs, allowing attacker-supplied Markdown links or images to bypass URL protections and execute script in rendered HTML. This issue is fixed in version 3.3.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Product detected by a:mistune_project:mistune (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00239, EPSS Percentile is 0.15064 |
debian: CVE-2026-59923 was patched at 2026-07-14
124.
Denial of Service - Gogs (CVE-2026-22592) - High [521]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00336, EPSS Percentile is 0.26235 |
altlinux: CVE-2026-22592 was patched at 2026-06-25
125.
Incorrect Calculation - Pillow (CVE-2026-59197) - High [517]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Pillow is a Python imaging library that adds image processing capabilities to Python, supporting formats such as PNG, JPEG, GIF, TIFF, and BMP. | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00436, EPSS Percentile is 0.35874 |
altlinux: CVE-2026-59197 was patched at 2026-07-27
debian: CVE-2026-59197 was patched at 2026-07-14
redhat: CVE-2026-59197 was patched at 2026-07-29
126.
Incorrect Calculation - immutable (CVE-2026-59879) - High [517]
Description: Immutable.js provides many Persistent Immutable data structures. Prior to 4.3.9 and 5.1.8, List#set, List#setSize, List#setIn, List#updateIn, and the functional set, setIn, and updateIn mishandle an index or size in the range 2 ** 30 to 2 ** 31 in setListBounds in src/List.js, causing an empty List to enter an uncatchable infinite loop, a populated List to allocate without bound until process abort, or setSize to silently wrap large values. This issue is fixed in versions 4.3.9 and 5.1.8.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:immutable-js:immutable (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00438, EPSS Percentile is 0.36029 |
debian: CVE-2026-59879 was patched at 2026-07-14
127.
Path Traversal - Mistune (CVE-2026-59924) - High [517]
Description: Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Include.parse() joins and normalizes user-supplied include paths without verifying that the result remains within the intended markdown directory, allowing crafted include paths to access files outside that directory when markdown files are processed using md.read(). This issue is fixed in version 3.3.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:mistune_project:mistune (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00399, EPSS Percentile is 0.3275 |
debian: CVE-2026-59924 was patched at 2026-07-14
128.
Memory Corruption - Envoy (CVE-2026-47207) - High [515]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00293, EPSS Percentile is 0.21534 |
altlinux: CVE-2026-47207 was patched at 2026-06-25, 2026-07-02
129.
Memory Corruption - FFmpeg (CVE-2026-58049) - High [515]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00227, EPSS Percentile is 0.13554 |
debian: CVE-2026-58049 was patched at 2026-07-14
130.
Cross Site Scripting - CarrierWave (CVE-2026-44587) - High [511]
Description: CarrierWave is a framework to upload files from Ruby applications. In versions prior to 2.2.7 and 3.1.3, the content_type_denylist check fails to escape regex metacharacters in string entries, causing the denylist to silently not match the content types it is intended to block. In lib/carrierwave/uploader/content_type_denylist.rb:57, denylist entries are interpolated directly into a regex without Regexp.quote or anchoring, so an entry such as image/svg+xml becomes the pattern /image\/svg+xml/, in which + is treated as a quantifier rather than a literal character and therefore never matches the real MIME type image/svg+xml. This is inconsistent with the allowlist implementation, which correctly applies both Regexp.quote and a \A anchor. Other content types containing regex metacharacters, such as application/xhtml+xml, are affected as well. As a result, any application that relies on content_type_denylist to block image/svg+xml, most commonly to prevent stored XSS, is silently unprotected. An attacker can upload an SVG file containing arbitrary JavaScript; if the application serves that SVG inline from its own origin, the script executes in the victim's browser, resulting in stored XSS. This issue has been fixed in versions 2.2.7 and 3.1.3.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Product detected by a:carrierwave_project:carrierwave (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00223, EPSS Percentile is 0.13106 |
debian: CVE-2026-44587 was patched at 2026-06-24
131.
Cross Site Scripting - VBScript (CVE-2026-59929) - High [511]
Description: Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the safe_url filter in src/mistune/renderers/html.py blocks only javascript:,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | VBScript | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00225, EPSS Percentile is 0.13345 |
debian: CVE-2026-59929 was patched at 2026-07-14
132.
Cross Site Scripting - rabbitmq_server (CVE-2026-57213) - High [511]
Description: RabbitMQ is a messaging and streaming broker. Prior to 3.13.14, 4.0.19, 4.1.10, and 4.2.5, the rabbitmq_federation_management plugin renders the consumer_tag field on the Federation Status page without HTML escaping, allowing a user who can configure a federation upstream or policy to execute JavaScript in the browser of a user viewing that page. This issue is fixed in versions 3.13.14, 4.0.19, 4.1.10, and 4.2.5.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Product detected by a:broadcom:rabbitmq_server (does NOT exist in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00252, EPSS Percentile is 0.16674 |
debian: CVE-2026-57213 was patched at 2026-07-14
133.
Denial of Service - Wireshark (CVE-2026-15165) - High [510]
Description: TLS ECH decryptor crash in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.05314 |
altlinux: CVE-2026-15165 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15165 was patched at 2026-07-14
134.
Denial of Service - Wireshark (CVE-2026-15166) - High [510]
Description: IEEE 802.11 protocol dissector crash in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.05315 |
altlinux: CVE-2026-15166 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15166 was patched at 2026-07-14
135.
Denial of Service - Wireshark (CVE-2026-15167) - High [510]
Description: DBS Etherwatch file parser crash in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.com, BDU:PublicExploit websites | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00171, EPSS Percentile is 0.06731 |
altlinux: CVE-2026-15167 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15167 was patched at 2026-07-14
136.
Denial of Service - Wireshark (CVE-2026-15170) - High [510]
Description: Z39.50 protocol dissector crash in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.05315 |
altlinux: CVE-2026-15170 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15170 was patched at 2026-07-14
137.
Memory Corruption - FreeRDP (CVE-2026-57157) - High [510]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | FreeRDP is a free implementation of the Remote Desktop Protocol (RDP), released under the Apache license | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00368, EPSS Percentile is 0.29463 |
altlinux: CVE-2026-57157 was patched at 2026-07-28
debian: CVE-2026-57157 was patched at 2026-07-14
ubuntu: CVE-2026-57157 was patched at 2026-07-30
138.
Denial of Service - Mistune (CVE-2026-59927) - High [505]
Description: Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the Include directive in src/mistune/directives/include.py detects only direct self-includes and not indirect cycles, allowing two markdown files that include each other to trigger unbounded recursion, raise RecursionError, and crash the rendering request. This issue is fixed in version 3.3.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:mistune_project:mistune (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00352, EPSS Percentile is 0.27853 |
debian: CVE-2026-59927 was patched at 2026-07-14
139.
Denial of Service - js-yaml (CVE-2026-53550) - High [505]
Description: js-yaml is a JavaScript YAML parser and dumper. Prior to 4.2.0 and 3.15.0, a crafted YAML document can trigger algorithmic CPU exhaustion in js-yaml merge-key processing (<<) by repeating the same alias many times in a merge sequence. This causes quadratic parse-time behavior relative to input size and can block a Node.js worker/event loop for seconds with a relatively small payload (tens of KB), resulting in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nodeca:js-yaml (does NOT exist in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00378, EPSS Percentile is 0.30497 |
debian: CVE-2026-53550 was patched at 2026-07-14
140.
Denial of Service - markdown-it (CVE-2026-48988) - High [505]
Description: markdown-it is a Markdown parser. Versions 14.1.1 and below contain a denial-of-service vulnerability when typographer: true is enabled, due to quadratic (O(n^2)) processing in the smartquotes rule. The issue stems from repeatedly modifying strings with replaceAt(), which performs O(n) slicing and concatenation per quote character. This can cause excessive CPU consumption when parsing quote-heavy, user-supplied markdown and may let attackers degrade or disrupt service availability. Although typographer is disabled by default, many production apps enable it for smart typography, making the issue relevant. This issue has been fixed in version 14.2.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:markdown-it_project:markdown-it (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00379, EPSS Percentile is 0.30585 |
debian: CVE-2026-48988 was patched at 2026-06-24
141.
Incorrect Calculation - libssh2 (CVE-2026-58050) - High [505]
Description: libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on 32-bit platforms the multiplication overflows to an undersized buffer. A malicious SSH server can then drive the attribute-parsing loop to write past the allocation, causing a heap buffer overflow in a connecting libssh2 client.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:libssh2:libssh2 (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00361, EPSS Percentile is 0.28767 |
debian: CVE-2026-58050 was patched at 2026-07-14
ubuntu: CVE-2026-58050 was patched at 2026-07-30
142.
Memory Corruption - Pillow (CVE-2026-54058) - High [505]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Pillow is a Python imaging library that adds image processing capabilities to Python, supporting formats such as PNG, JPEG, GIF, TIFF, and BMP. | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00384, EPSS Percentile is 0.31148 |
debian: CVE-2026-54058 was patched at 2026-07-14
redhat: CVE-2026-54058 was patched at 2026-07-29
143.
Memory Corruption - Pillow (CVE-2026-59199) - High [505]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Pillow is a Python imaging library that adds image processing capabilities to Python, supporting formats such as PNG, JPEG, GIF, TIFF, and BMP. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00385, EPSS Percentile is 0.31294 |
altlinux: CVE-2026-59199 was patched at 2026-07-27
debian: CVE-2026-59199 was patched at 2026-07-14
144.
Memory Corruption - Pillow (CVE-2026-59205) - High [505]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Pillow is a Python imaging library that adds image processing capabilities to Python, supporting formats such as PNG, JPEG, GIF, TIFF, and BMP. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00385, EPSS Percentile is 0.31295 |
altlinux: CVE-2026-59205 was patched at 2026-07-27
debian: CVE-2026-59205 was patched at 2026-07-14
145.
Cross Site Scripting - Gogs (CVE-2026-26022) - High [503]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00306, EPSS Percentile is 0.22978 |
altlinux: CVE-2026-26022 was patched at 2026-06-25
146.
Memory Corruption - Envoy (CVE-2026-47205) - High [503]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00274, EPSS Percentile is 0.19622 |
altlinux: CVE-2026-47205 was patched at 2026-06-25, 2026-07-02
147.
Open Redirect - Cacti (CVE-2026-40080) - High [502]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.75 | 15 | Open Redirect | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00192, EPSS Percentile is 0.09179 |
altlinux: CVE-2026-40080 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-40080 was patched at 2026-07-14
148.
Server-Side Request Forgery - swift (CVE-2026-50221) - High [500]
Description: In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Device, X-Delete-At-Host, X-Delete-At-Device) from client requests before forwarding them to object-servers. An authenticated user with write access can inject these headers to redirect container update requests to an attacker-controlled server, enabling server-side request forgery. The SSRF requests expose internal cluster metadata including storage policy indexes, partition mappings, device names, and when at rest encryption is enabled, cipher text and initialization vectors for the container-level encryption key. The attacker can also cause "ghost listings" in arbitrary containers via the shard-range redirect mechanism.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:launchpad.net website | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.5 | 14 | Product detected by a:openstack:swift (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04188 |
debian: CVE-2026-50221 was patched at 2026-06-24
149.
Denial of Service - Wireshark (CVE-2026-15171) - High [498]
Description: SSH protocol dissector crash in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02301 |
altlinux: CVE-2026-15171 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15171 was patched at 2026-07-14
150.
Denial of Service - Wireshark (CVE-2026-15172) - High [498]
Description: FMP/NOTIFY protocol dissector crash in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02367 |
altlinux: CVE-2026-15172 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15172 was patched at 2026-07-14
151.
Path Traversal - Jetty (CVE-2026-8384) - High [498]
Description: In Eclipse
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.eclipse.org website | |
| 0.7 | 15 | Path Traversal | |
| 0.6 | 14 | Jetty is a Java based web server and servlet engine | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00228, EPSS Percentile is 0.13761 |
debian: CVE-2026-8384 was patched at 2026-07-14
152.
Path Traversal - Rclone (CVE-2026-59732) - High [498]
Description: Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Path Traversal | |
| 0.6 | 14 | Rclone is a command-line program to sync files and directories to and from different cloud storage providers, supporting over 40 cloud storage products including S3, Google Drive, Dropbox, OneDrive, and many more. | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00213, EPSS Percentile is 0.11722 |
altlinux: CVE-2026-59732 was patched at 2026-07-13, 2026-07-16
debian: CVE-2026-59732 was patched at 2026-07-14
153.
Security Feature Bypass - Gogs (CVE-2026-25120) - High [497]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 0.3 | 10 | CVSS Base Score is 2.7. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00271, EPSS Percentile is 0.19186 |
altlinux: CVE-2026-25120 was patched at 2026-06-25
154.
Denial of Service - onnx (CVE-2026-44512) - High [494]
Description: Open Neural Network Exchange (ONNX) is an open standard for machine learning interoperability. From 1.9.0 before 1.22.0, onnx.version_converter.convert_version() can dereference a null pointer in Upsample_6_7::adapt_upsample_6_7() in onnx/version_converter/adapters/upsample_6_7.h when processing an untrusted model with an Upsample node that has zero inputs, causing an unrecoverable
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:linuxfoundation:onnx (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00183, EPSS Percentile is 0.08209 |
altlinux: CVE-2026-44512 was patched at 2026-07-06
debian: CVE-2026-44512 was patched at 2026-07-14
155.
Denial of Service - rtklib (CVE-2026-56788) - High [494]
Description: RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in getcodepri function when processing unrecognized RINEX observation codes, allowing attackers to trigger
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:rtklib:rtklib (does NOT exist in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00144, EPSS Percentile is 0.04186 |
debian: CVE-2026-56788 was patched at 2026-07-14
156.
Memory Corruption - Pillow (CVE-2026-59198) - High [494]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Pillow is a Python imaging library that adds image processing capabilities to Python, supporting formats such as PNG, JPEG, GIF, TIFF, and BMP. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00313, EPSS Percentile is 0.23731 |
altlinux: CVE-2026-59198 was patched at 2026-07-27
debian: CVE-2026-59198 was patched at 2026-07-14
157.
Security Feature Bypass - Mistune (CVE-2026-59930) - High [494]
Description: Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, the toc plugin and TableOfContents directive generate heading IDs as predictable toc_N values without slugifying the heading text, allowing attacker-controlled id="toc_N" content to collide with generated anchors and redirect same-page navigation, CSS selectors, or JavaScript handlers. This issue is fixed in version 3.3.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:mistune_project:mistune (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03683 |
debian: CVE-2026-59930 was patched at 2026-07-14
158.
Open Redirect - Authlib (CVE-2026-41479) - High [491]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.75 | 15 | Open Redirect | |
| 0.5 | 14 | Authlib is a Python library for building OAuth and OpenID Connect clients and servers, providing tools for secure authentication, token management, and authorization flows. | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00183, EPSS Percentile is 0.08127 |
debian: CVE-2026-41479 was patched at 2026-06-24
159.
Cross Site Scripting - Caddy (CVE-2026-52846) - High [488]
Description: Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as <<>img src=x onerror=alert()>, can bypass the tag-stripping logic, potentially leaving dangerous content in the output if it is later rendered as HTML. This may allow client-side
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Product detected by a:caddyserver:caddy (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00174, EPSS Percentile is 0.0718 |
altlinux: CVE-2026-52846 was patched at 2026-07-02, 2026-07-03
debian: CVE-2026-52846 was patched at 2026-07-14
160.
Information Disclosure - Wireshark (CVE-2026-15168) - High [486]
Description: BLF file parser in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.com, BDU:PublicExploit websites | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02882 |
altlinux: CVE-2026-15168 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15168 was patched at 2026-07-14
161.
Denial of Service - TLS (CVE-2026-13117) - High [482]
Description: An incomplete guard in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to trigger a use-after-free during
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | TLS | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-13117 was patched at 2026-07-03, 2026-07-14
ubuntu: CVE-2026-13117 was patched at 2026-07-30
162.
Denial of Service - wireshark (CVE-2026-15164) - High [482]
Description: Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.com website | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:wireshark:wireshark (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02301 |
altlinux: CVE-2026-15164 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15164 was patched at 2026-07-14
163.
Incorrect Calculation - nmap (CVE-2026-58058) - High [482]
Description: Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation underflows to a large value. A scanned target or on-path attacker returning a crafted IPv6 response with a truncated extension header can trigger out-of-bounds reads and a crash during raw IPv6 scans.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:nmap:nmap (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00278, EPSS Percentile is 0.20106 |
debian: CVE-2026-58058 was patched at 2026-07-14
164.
Information Disclosure - idna (CVE-2026-57053) - High [482]
Description: GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:lists.gnu.org website | |
| 0.83 | 15 | Information Disclosure | |
| 0.65 | 14 | idna is a Python library implementing Internationalized Domain Names in Applications (IDNA), providing support for Unicode domain name encoding and decoding according to the IDNA standard. It is widely used by Python networking, HTTP, and DNS-related software. | |
| 0.2 | 10 | CVSS Base Score is 2.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00147, EPSS Percentile is 0.04434 |
altlinux: CVE-2026-57053 was patched at 2026-07-14, 2026-07-17, 2026-07-20
debian: CVE-2026-57053 was patched at 2026-06-24
ubuntu: CVE-2026-57053 was patched at 2026-07-30
165.
Memory Corruption - Curl (CVE-2026-9080) - High [482]
Description: Calling `curl_easy_pause()` within the event-based `CURLMOPT_SOCKETFUNCTION` callback triggers a use-after-free vulnerability, where libcurl attempts to store a flag using a dangling struct pointer immediately after that pointer's memory has been freed.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.2185 |
altlinux: CVE-2026-9080 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-9080 was patched at 2026-07-14
ubuntu: CVE-2026-9080 was patched at 2026-07-30
166.
Memory Corruption - libssh2 (CVE-2026-58051) - High [482]
Description: libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free operating on an uninitialized entry. A malicious SSH server offering the publickey subsystem can use a malformed response to make cleanup free an uninitialized, attacker-influenceable attrs pointer in a connecting libssh2 client.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:libssh2:libssh2 (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00277, EPSS Percentile is 0.19929 |
debian: CVE-2026-58051 was patched at 2026-07-14
ubuntu: CVE-2026-58051 was patched at 2026-07-30
167.
Memory Corruption - rtklib (CVE-2026-56789) - High [482]
Description: RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in the readrnxobsb function in src/rinex.c that allows attackers to trigger
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:rtklib:rtklib (does NOT exist in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00249, EPSS Percentile is 0.16408 |
debian: CVE-2026-56789 was patched at 2026-07-14
168.
Path Traversal - pymdown_extensions (CVE-2026-46338) - High [482]
Description: PyMdown Extensions is a set of extensions for the Python-Markdown markdown project. From 10.0.1 until 10.21.3, pymdownx.snippets uses a string-prefix containment check in SnippetPreprocessor.get_snippet_path() in pymdownx/snippets.py when `restrict_base_path: True`, allowing markdown snippet directives to read files from sibling paths that share the same base_path prefix, such as docs and docs_internal. This is a regression of CVE-2023-32309. This issue is fixed in version 10.21.3.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:facelessuser:pymdown_extensions (does NOT exist in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00258, EPSS Percentile is 0.17455 |
debian: CVE-2026-46338 was patched at 2026-07-14
169.
Security Feature Bypass - 7-Zip (CVE-2026-58052) - High [482]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | 7-Zip is a free and open-source file archiver, a utility used to place groups of files within compressed containers known as "archives" | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01961 |
debian: CVE-2026-58052 was patched at 2026-07-14
170.
Remote Code Execution - HashiCorp Nomad (CVE-2026-7474) - High [476]
Description: HashiCorp Nomad and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | HashiCorp Nomad is a workload scheduler and orchestrator designed to deploy and manage applications, including containerized and non-containerized workloads, across various infrastructure platforms | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.9 | 10 | EPSS Probability is 0.06892, EPSS Percentile is 0.93398 |
redos: CVE-2026-7474 was patched at 2026-07-09
171.
Spoofing - Curl (CVE-2026-9547) - High [476]
Description: When a libcurl-based application performs transfers via `SCP://` or `SFTP://` and utilizes the `CURLOPT_SSH_KEYFUNCTION` callback, it may silently accept an untrusted server. This vulnerability occurs when a server presents a host key type that does not match the specific key type already recorded for that host in the `known_hosts` file. Instead of rejecting the mismatch, the callback mechanism fails to properly enforce the restriction, allowing the connection to succeed without warning and risking a potential man-in-the-middle attack.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:hackerone.com website | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Product detected by a:haxx:curl (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25037 |
altlinux: CVE-2026-9547 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-9547 was patched at 2026-07-14
ubuntu: CVE-2026-9547 was patched at 2026-07-30
172.
Memory Corruption - libsoup (CVE-2026-12549) - High [470]
Description: The fix for CVE-2026-2443 was regressed by a subsequent rework commit that replaced specific overflow checks with a general signed comparison. When a client sends a Range request with a suffix length exceeding the content size, the resulting negative start value is not properly clamped, leading to malformed HTTP 206 responses and log flooding.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:gitlab.gnome.org website | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:gnome:libsoup (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00411, EPSS Percentile is 0.33779 |
debian: CVE-2026-12549 was patched at 2026-07-14
173.
Information Disclosure - op-tee (CVE-2026-41516) - High [469]
Description: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.5.0 and prior to version 4.11.0, the RSA PKCS#1 v1.5 decryption implementation in the Hisilicon HPRE crypto driver uses non-constant-time `memcmp()` for label hash verification and has multiple distinguishable error paths. This creates a Bleichenbacher-style padding oracle that allows an attacker to recover RSA PKCS#1 v1.5 plaintext. Version 4.11.0 contains a patch. As a workaround, disable Hisilicon HPRE RSA driver with `CFG_HISILICON_ACC_V3=n`.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Product detected by o:trustedfirmware:op-tee (does NOT exist in CPE dict) | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00133, EPSS Percentile is 0.03264 |
debian: CVE-2026-41516 was patched at 2026-07-14
174.
Remote Code Execution - Chromium (CVE-2026-13870) - High [466]
Description: Use after free in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00473, EPSS Percentile is 0.3843 |
altlinux: CVE-2026-13870 was patched at 2026-07-03
debian: CVE-2026-13870 was patched at 2026-07-05, 2026-07-14
175.
Remote Code Execution - Chromium (CVE-2026-13967) - High [466]
Description: Heap buffer overflow in V8 in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00466, EPSS Percentile is 0.37955 |
altlinux: CVE-2026-13967 was patched at 2026-07-03
debian: CVE-2026-13967 was patched at 2026-07-05, 2026-07-14
176.
Remote Code Execution - Chromium (CVE-2026-14121) - High [466]
Description: Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00339, EPSS Percentile is 0.26544 |
altlinux: CVE-2026-14121 was patched at 2026-07-03
debian: CVE-2026-14121 was patched at 2026-07-05, 2026-07-14
177.
Authentication Bypass - Node.js (CVE-2026-48618) - High [460]
Description: A flaw in Node.js TLS hostname handling can cause Node.js unicode dot separator handling can lead to tls wildcard-depth authentication bypass due to resolver and verifier hostname normalization mismat. This can lead to confidentiality impact or bypass of the intended security boundary under affected configurations. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:nodejs:node.js (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.9 | 10 | EPSS Probability is 0.03231, EPSS Percentile is 0.86986 |
almalinux: CVE-2026-48618 was patched at 2026-07-06, 2026-07-15, 2026-07-20
altlinux: CVE-2026-48618 was patched at 2026-07-23
debian: CVE-2026-48618 was patched at 2026-06-24
oraclelinux: CVE-2026-48618 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-48618 was patched at 2026-07-06, 2026-07-15, 2026-07-20
178.
Authentication Bypass - Apache Tomcat (CVE-2026-55956) - High [458]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.7 | 10 | EPSS Probability is 0.01531, EPSS Percentile is 0.72238 |
altlinux: CVE-2026-55956 was patched at 2026-06-24, 2026-07-10, 2026-07-20
debian: CVE-2026-55956 was patched at 2026-07-14
redhat: CVE-2026-55956 was patched at 2026-07-22
179.
Authentication Bypass - Gitea (CVE-2026-20706) - High [454]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00493, EPSS Percentile is 0.39625 |
redos: CVE-2026-20706 was patched at 2026-07-14
180.
Remote Code Execution - Chromium (CVE-2026-13033) - High [454]
Description: Out of bounds read and write in Blink>InterestGroups in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00344, EPSS Percentile is 0.27035 |
debian: CVE-2026-13033 was patched at 2026-06-25, 2026-07-14
181.
Remote Code Execution - Chromium (CVE-2026-13038) - High [454]
Description: Use after free in Autofill in Google Chrome on Windows prior to 149.0.7827.197 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00344, EPSS Percentile is 0.27035 |
debian: CVE-2026-13038 was patched at 2026-06-25, 2026-07-14
182.
Remote Code Execution - Chromium (CVE-2026-13786) - High [454]
Description: Use after free in Ozone in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0039, EPSS Percentile is 0.31715 |
altlinux: CVE-2026-13786 was patched at 2026-07-03
debian: CVE-2026-13786 was patched at 2026-07-05, 2026-07-14
183.
Remote Code Execution - Chromium (CVE-2026-13787) - High [454]
Description: Use after free in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0043, EPSS Percentile is 0.35315 |
altlinux: CVE-2026-13787 was patched at 2026-07-03
debian: CVE-2026-13787 was patched at 2026-07-05, 2026-07-14
184.
Remote Code Execution - Chromium (CVE-2026-13788) - High [454]
Description: Use after free in Fullscreen in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00418, EPSS Percentile is 0.34416 |
altlinux: CVE-2026-13788 was patched at 2026-07-03
debian: CVE-2026-13788 was patched at 2026-07-05, 2026-07-14
185.
Remote Code Execution - Chromium (CVE-2026-13794) - High [454]
Description: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00474, EPSS Percentile is 0.38511 |
altlinux: CVE-2026-13794 was patched at 2026-07-03
debian: CVE-2026-13794 was patched at 2026-07-05, 2026-07-14
186.
Remote Code Execution - Chromium (CVE-2026-13805) - High [454]
Description: Use after free in GFX in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00361, EPSS Percentile is 0.28783 |
altlinux: CVE-2026-13805 was patched at 2026-07-03
debian: CVE-2026-13805 was patched at 2026-07-05, 2026-07-14
187.
Remote Code Execution - Chromium (CVE-2026-13811) - High [454]
Description: Use after free in IME in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00361, EPSS Percentile is 0.28783 |
altlinux: CVE-2026-13811 was patched at 2026-07-03
debian: CVE-2026-13811 was patched at 2026-07-05, 2026-07-14
188.
Remote Code Execution - Chromium (CVE-2026-13815) - High [454]
Description: Use after free in Blink in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0039, EPSS Percentile is 0.31714 |
altlinux: CVE-2026-13815 was patched at 2026-07-03
debian: CVE-2026-13815 was patched at 2026-07-05, 2026-07-14
189.
Remote Code Execution - Chromium (CVE-2026-13821) - High [454]
Description: Use after free in Canvas in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00361, EPSS Percentile is 0.28781 |
altlinux: CVE-2026-13821 was patched at 2026-07-03
debian: CVE-2026-13821 was patched at 2026-07-05, 2026-07-14
190.
Remote Code Execution - Chromium (CVE-2026-13830) - High [454]
Description: Use after free in Chromoting in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0033, EPSS Percentile is 0.25533 |
altlinux: CVE-2026-13830 was patched at 2026-07-03
debian: CVE-2026-13830 was patched at 2026-07-05, 2026-07-14
191.
Remote Code Execution - Chromium (CVE-2026-13845) - High [454]
Description: Use after free in DOM in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00361, EPSS Percentile is 0.2878 |
altlinux: CVE-2026-13845 was patched at 2026-07-03
debian: CVE-2026-13845 was patched at 2026-07-05, 2026-07-14
192.
Remote Code Execution - Chromium (CVE-2026-13848) - High [454]
Description: Use after free in Forms in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00361, EPSS Percentile is 0.2878 |
altlinux: CVE-2026-13848 was patched at 2026-07-03
debian: CVE-2026-13848 was patched at 2026-07-05, 2026-07-14
193.
Remote Code Execution - Chromium (CVE-2026-13885) - High [454]
Description: Use after free in Skia in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00374, EPSS Percentile is 0.3014 |
altlinux: CVE-2026-13885 was patched at 2026-07-03
debian: CVE-2026-13885 was patched at 2026-07-05, 2026-07-14
194.
Remote Code Execution - Chromium (CVE-2026-13888) - High [454]
Description: Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00361, EPSS Percentile is 0.28782 |
altlinux: CVE-2026-13888 was patched at 2026-07-03
debian: CVE-2026-13888 was patched at 2026-07-05, 2026-07-14
195.
Remote Code Execution - Chromium (CVE-2026-13898) - High [454]
Description: Use after free in Cast Receiver in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00414, EPSS Percentile is 0.34049 |
altlinux: CVE-2026-13898 was patched at 2026-07-03
debian: CVE-2026-13898 was patched at 2026-07-05, 2026-07-14
196.
Remote Code Execution - Chromium (CVE-2026-13899) - High [454]
Description: Use after free in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00414, EPSS Percentile is 0.34048 |
altlinux: CVE-2026-13899 was patched at 2026-07-03
debian: CVE-2026-13899 was patched at 2026-07-05, 2026-07-14
197.
Remote Code Execution - Chromium (CVE-2026-13965) - High [454]
Description: Use after free in Oilpan in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00374, EPSS Percentile is 0.30141 |
altlinux: CVE-2026-13965 was patched at 2026-07-03
debian: CVE-2026-13965 was patched at 2026-07-05, 2026-07-14
198.
Remote Code Execution - Chromium (CVE-2026-14067) - High [454]
Description: Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00397, EPSS Percentile is 0.32466 |
altlinux: CVE-2026-14067 was patched at 2026-07-03
debian: CVE-2026-14067 was patched at 2026-07-05, 2026-07-14
199.
Remote Code Execution - Chromium (CVE-2026-14104) - High [454]
Description: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00398, EPSS Percentile is 0.32544 |
altlinux: CVE-2026-14104 was patched at 2026-07-03
debian: CVE-2026-14104 was patched at 2026-07-05, 2026-07-14
200.
Remote Code Execution - Chromium (CVE-2026-14383) - High [454]
Description: Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00348, EPSS Percentile is 0.27515 |
altlinux: CVE-2026-14383 was patched at 2026-07-03
debian: CVE-2026-14383 was patched at 2026-07-05, 2026-07-14
201.
Remote Code Execution - Chromium (CVE-2026-14392) - High [454]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00276, EPSS Percentile is 0.19847 |
altlinux: CVE-2026-14392 was patched at 2026-07-03
debian: CVE-2026-14392 was patched at 2026-07-05, 2026-07-14
202.
Remote Code Execution - Chromium (CVE-2026-14397) - High [454]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00243, EPSS Percentile is 0.15602 |
altlinux: CVE-2026-14397 was patched at 2026-07-03
debian: CVE-2026-14397 was patched at 2026-07-05, 2026-07-14
203.
Remote Code Execution - Chromium (CVE-2026-14405) - High [454]
Description: Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00307, EPSS Percentile is 0.23081 |
altlinux: CVE-2026-14405 was patched at 2026-07-03
debian: CVE-2026-14405 was patched at 2026-07-05, 2026-07-14
204.
Remote Code Execution - Chromium (CVE-2026-15767) - High [454]
Description: Heap buffer overflow in libyuv in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00346, EPSS Percentile is 0.27209 |
altlinux: CVE-2026-15767 was patched at 2026-07-15
debian: CVE-2026-15767 was patched at 2026-07-14, 2026-07-16
205.
Remote Code Execution - Chromium (CVE-2026-15776) - High [454]
Description: Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0035, EPSS Percentile is 0.27687 |
altlinux: CVE-2026-15776 was patched at 2026-07-15
debian: CVE-2026-15776 was patched at 2026-07-14, 2026-07-16
206.
Memory Corruption - dhcpcd (CVE-2025-70102) - High [449]
Description: A NULL pointer dereference occurs in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.45 | 14 | dhcpcd is an open-source DHCP and network configuration client used on Linux, BSD, and other Unix-like operating systems to automatically configure network interfaces, IP addresses, routes, and DNS settings. | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00169, EPSS Percentile is 0.06571 |
debian: CVE-2025-70102 was patched at 2026-06-24, 2026-07-14, 2026-07-15
207.
Security Feature Bypass - Chromium (CVE-2026-13776) - High [448]
Description: Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00352, EPSS Percentile is 0.27927 |
altlinux: CVE-2026-13776 was patched at 2026-07-03
debian: CVE-2026-13776 was patched at 2026-07-05, 2026-07-14
208.
Security Feature Bypass - Chromium (CVE-2026-13789) - High [448]
Description: Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00354, EPSS Percentile is 0.2812 |
altlinux: CVE-2026-13789 was patched at 2026-07-08
debian: CVE-2026-13789 was patched at 2026-07-05, 2026-07-14
209.
Security Feature Bypass - Chromium (CVE-2026-13792) - High [448]
Description: Use after free in Touchbar in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25034 |
altlinux: CVE-2026-13792 was patched at 2026-07-03
debian: CVE-2026-13792 was patched at 2026-07-05, 2026-07-14
210.
Security Feature Bypass - Chromium (CVE-2026-13798) - High [448]
Description: Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00352, EPSS Percentile is 0.27863 |
altlinux: CVE-2026-13798 was patched at 2026-07-03
debian: CVE-2026-13798 was patched at 2026-07-05, 2026-07-14
211.
Security Feature Bypass - Chromium (CVE-2026-13843) - High [448]
Description: Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25029 |
altlinux: CVE-2026-13843 was patched at 2026-07-03
debian: CVE-2026-13843 was patched at 2026-07-05, 2026-07-14
212.
Security Feature Bypass - Chromium (CVE-2026-13846) - High [448]
Description: Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25034 |
altlinux: CVE-2026-13846 was patched at 2026-07-03
debian: CVE-2026-13846 was patched at 2026-07-05, 2026-07-14
213.
Security Feature Bypass - Chromium (CVE-2026-13869) - High [448]
Description: Use after free in Device in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25035 |
altlinux: CVE-2026-13869 was patched at 2026-07-03
debian: CVE-2026-13869 was patched at 2026-07-05, 2026-07-14
214.
Security Feature Bypass - Chromium (CVE-2026-13901) - High [448]
Description: Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.27193 |
altlinux: CVE-2026-13901 was patched at 2026-07-03
debian: CVE-2026-13901 was patched at 2026-07-05, 2026-07-14
215.
Security Feature Bypass - Chromium (CVE-2026-13909) - High [448]
Description: Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25031 |
altlinux: CVE-2026-13909 was patched at 2026-07-03
debian: CVE-2026-13909 was patched at 2026-07-05, 2026-07-14
216.
Security Feature Bypass - Chromium (CVE-2026-13920) - High [448]
Description: Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25035 |
altlinux: CVE-2026-13920 was patched at 2026-07-03
debian: CVE-2026-13920 was patched at 2026-07-05, 2026-07-14
217.
Security Feature Bypass - Chromium (CVE-2026-13934) - High [448]
Description: Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25033 |
altlinux: CVE-2026-13934 was patched at 2026-07-03
debian: CVE-2026-13934 was patched at 2026-07-05, 2026-07-14
218.
Command Injection - Cacti (CVE-2026-40079) - High [447]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.01137, EPSS Percentile is 0.63368 |
altlinux: CVE-2026-40079 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-40079 was patched at 2026-07-14
219.
Authentication Bypass - MinIO (CVE-2026-33322) - High [446]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | MinIO is a high-performance, S3-compatible object storage system designed for large-scale data infrastructure. It supports cloud-native workloads and provides APIs for storing, retrieving, and managing unstructured data such as photos, videos, log files, and backups, with a focus on scalability, speed, and simplicity. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0041, EPSS Percentile is 0.33654 |
redos: CVE-2026-33322 was patched at 2026-07-14
220.
Incorrect Calculation - Oj (CVE-2026-54900) - High [445]
Description: Oj (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:HORKIMHAB:CVE-2026-54900 website | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.35 | 14 | Oj (Optimized JSON) is a high-performance JSON parser and object serialization library packaged as a Ruby gem, designed to provide fast JSON encoding and decoding for Ruby applications. | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.1683 |
debian: CVE-2026-54900 was patched at 2026-07-14
221.
Memory Corruption - Oj (CVE-2026-54902) - High [445]
Description: Oj (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on Vulners:PublicExploit:GitHub:HORKIMHAB:CVE-2026-54900 website | |
| 0.5 | 15 | Memory Corruption | |
| 0.35 | 14 | Oj (Optimized JSON) is a high-performance JSON parser and object serialization library packaged as a Ruby gem, designed to provide fast JSON encoding and decoding for Ruby applications. | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16829 |
debian: CVE-2026-54902 was patched at 2026-07-14
222.
Remote Code Execution - Perl (CVE-2011-10043) - High [445]
Description: Module::Load versions before 0.22 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00447, EPSS Percentile is 0.36709 |
debian: CVE-2011-10043 was patched at 2026-07-14
223.
Remote Code Execution - Chromium (CVE-2026-13774) - High [442]
Description: Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00362, EPSS Percentile is 0.2889 |
altlinux: CVE-2026-13774 was patched at 2026-07-03
debian: CVE-2026-13774 was patched at 2026-07-05, 2026-07-14
224.
Remote Code Execution - Chromium (CVE-2026-13779) - High [442]
Description: Use after free in Chromoting in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00401, EPSS Percentile is 0.32856 |
altlinux: CVE-2026-13779 was patched at 2026-07-03
debian: CVE-2026-13779 was patched at 2026-07-05, 2026-07-14
225.
Remote Code Execution - Chromium (CVE-2026-13791) - High [442]
Description: Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00354, EPSS Percentile is 0.28111 |
altlinux: CVE-2026-13791 was patched at 2026-07-03
debian: CVE-2026-13791 was patched at 2026-07-05, 2026-07-14
226.
Remote Code Execution - Chromium (CVE-2026-13802) - High [442]
Description: Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.27834 |
altlinux: CVE-2026-13802 was patched at 2026-07-03
debian: CVE-2026-13802 was patched at 2026-07-05, 2026-07-14
227.
Remote Code Execution - Chromium (CVE-2026-13831) - High [442]
Description: Out of bounds read and write in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25316 |
altlinux: CVE-2026-13831 was patched at 2026-07-03
debian: CVE-2026-13831 was patched at 2026-07-05, 2026-07-14
228.
Remote Code Execution - Chromium (CVE-2026-13850) - High [442]
Description: Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00277, EPSS Percentile is 0.19971 |
altlinux: CVE-2026-13850 was patched at 2026-07-03
debian: CVE-2026-13850 was patched at 2026-07-05, 2026-07-14
229.
Remote Code Execution - Chromium (CVE-2026-13855) - High [442]
Description: Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25316 |
altlinux: CVE-2026-13855 was patched at 2026-07-03
debian: CVE-2026-13855 was patched at 2026-07-05, 2026-07-14
230.
Remote Code Execution - Chromium (CVE-2026-13884) - High [442]
Description: Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00288, EPSS Percentile is 0.21009 |
altlinux: CVE-2026-13884 was patched at 2026-07-03
debian: CVE-2026-13884 was patched at 2026-07-05, 2026-07-14
231.
Remote Code Execution - Chromium (CVE-2026-13925) - High [442]
Description: Inappropriate implementation in Downloads in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00375, EPSS Percentile is 0.30233 |
altlinux: CVE-2026-13925 was patched at 2026-07-03
debian: CVE-2026-13925 was patched at 2026-07-05, 2026-07-14
232.
Remote Code Execution - Chromium (CVE-2026-13968) - High [442]
Description: Insufficient validation of untrusted input in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00332, EPSS Percentile is 0.25826 |
altlinux: CVE-2026-13968 was patched at 2026-07-03
debian: CVE-2026-13968 was patched at 2026-07-05, 2026-07-14
233.
Remote Code Execution - Chromium (CVE-2026-14006) - High [442]
Description: Use after free in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.2135 |
altlinux: CVE-2026-14006 was patched at 2026-07-03
debian: CVE-2026-14006 was patched at 2026-07-05, 2026-07-14
234.
Remote Code Execution - Chromium (CVE-2026-14086) - High [442]
Description: Insufficient policy enforcement in HID in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00314, EPSS Percentile is 0.23859 |
altlinux: CVE-2026-14086 was patched at 2026-07-03
debian: CVE-2026-14086 was patched at 2026-07-05, 2026-07-14
235.
Remote Code Execution - Chromium (CVE-2026-14091) - High [442]
Description: Use after free in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.21385 |
altlinux: CVE-2026-14091 was patched at 2026-07-03
debian: CVE-2026-14091 was patched at 2026-07-05, 2026-07-14
236.
Remote Code Execution - Chromium (CVE-2026-14107) - High [442]
Description: Use after free in Scheduling in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.21385 |
altlinux: CVE-2026-14107 was patched at 2026-07-03
debian: CVE-2026-14107 was patched at 2026-07-05, 2026-07-14
237.
Remote Code Execution - Chromium (CVE-2026-14108) - High [442]
Description: Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.18898 |
altlinux: CVE-2026-14108 was patched at 2026-07-03
debian: CVE-2026-14108 was patched at 2026-07-05, 2026-07-14
238.
Remote Code Execution - Chromium (CVE-2026-14149) - High [442]
Description: Use after free in Audio in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.24963 |
altlinux: CVE-2026-14149 was patched at 2026-07-03
debian: CVE-2026-14149 was patched at 2026-07-05, 2026-07-14
239.
Remote Code Execution - Chromium (CVE-2026-14393) - High [442]
Description: Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00281, EPSS Percentile is 0.20395 |
altlinux: CVE-2026-14393 was patched at 2026-07-03
debian: CVE-2026-14393 was patched at 2026-07-05, 2026-07-14
240.
Remote Code Execution - Chromium (CVE-2026-14395) - High [442]
Description: Out of bounds write in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00264, EPSS Percentile is 0.18255 |
altlinux: CVE-2026-14395 was patched at 2026-07-03
debian: CVE-2026-14395 was patched at 2026-07-05, 2026-07-14
241.
Remote Code Execution - Chromium (CVE-2026-14403) - High [442]
Description: Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00258, EPSS Percentile is 0.17427 |
altlinux: CVE-2026-14403 was patched at 2026-07-03
debian: CVE-2026-14403 was patched at 2026-07-05, 2026-07-14
242.
Remote Code Execution - Chromium (CVE-2026-14407) - High [442]
Description: Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00319, EPSS Percentile is 0.24334 |
altlinux: CVE-2026-14407 was patched at 2026-07-03
debian: CVE-2026-14407 was patched at 2026-07-05, 2026-07-14
243.
Remote Code Execution - Chromium (CVE-2026-14430) - High [442]
Description: Integer overflow in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.21349 |
altlinux: CVE-2026-14430 was patched at 2026-07-03
debian: CVE-2026-14430 was patched at 2026-07-05, 2026-07-14
244.
Remote Code Execution - Chromium (CVE-2026-14432) - High [442]
Description: Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16148 |
altlinux: CVE-2026-14432 was patched at 2026-07-03
debian: CVE-2026-14432 was patched at 2026-07-05, 2026-07-14
245.
Remote Code Execution - Chromium (CVE-2026-15107) - High [442]
Description: Use after free in IndexedDB in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00242, EPSS Percentile is 0.1555 |
altlinux: CVE-2026-15107 was patched at 2026-07-09
debian: CVE-2026-15107 was patched at 2026-07-11, 2026-07-14
246.
Remote Code Execution - Chromium (CVE-2026-15116) - High [442]
Description: Use after free in Actor in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00242, EPSS Percentile is 0.1555 |
altlinux: CVE-2026-15116 was patched at 2026-07-09
debian: CVE-2026-15116 was patched at 2026-07-11, 2026-07-14
247.
Remote Code Execution - Chromium (CVE-2026-15118) - High [442]
Description: Use after free in Input in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00242, EPSS Percentile is 0.15549 |
altlinux: CVE-2026-15118 was patched at 2026-07-09
debian: CVE-2026-15118 was patched at 2026-07-11, 2026-07-14
248.
Remote Code Execution - Chromium (CVE-2026-15121) - High [442]
Description: Use after free in WebRTC in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00307, EPSS Percentile is 0.22998 |
altlinux: CVE-2026-15121 was patched at 2026-07-09
debian: CVE-2026-15121 was patched at 2026-07-11, 2026-07-14
249.
Remote Code Execution - Chromium (CVE-2026-15126) - High [442]
Description: Use after free in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00242, EPSS Percentile is 0.15549 |
altlinux: CVE-2026-15126 was patched at 2026-07-09
debian: CVE-2026-15126 was patched at 2026-07-11, 2026-07-14
250.
Remote Code Execution - Chromium (CVE-2026-15132) - High [442]
Description: Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0027, EPSS Percentile is 0.1901 |
altlinux: CVE-2026-15132 was patched at 2026-07-09
debian: CVE-2026-15132 was patched at 2026-07-11, 2026-07-14
251.
Remote Code Execution - Chromium (CVE-2026-15133) - High [442]
Description: Use after free in InterestGroups in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16148 |
altlinux: CVE-2026-15133 was patched at 2026-07-09
debian: CVE-2026-15133 was patched at 2026-07-11, 2026-07-14
252.
Remote Code Execution - Chromium (CVE-2026-15902) - High [442]
Description: Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00283, EPSS Percentile is 0.20581 |
altlinux: CVE-2026-15902 was patched at 2026-07-18
debian: CVE-2026-15902 was patched at 2026-07-14, 2026-07-22
253.
Remote Code Execution - Chromium (CVE-2026-15903) - High [442]
Description: Out of bounds read and write in V8 in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00314, EPSS Percentile is 0.2386 |
altlinux: CVE-2026-15903 was patched at 2026-07-18
debian: CVE-2026-15903 was patched at 2026-07-14, 2026-07-22
254.
Remote Code Execution - Xrdp (CVE-2026-41252) - High [440]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | xrdp is an open source remote desktop protocol server | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00609, EPSS Percentile is 0.45693 |
altlinux: CVE-2026-41252 was patched at 2026-07-08
debian: CVE-2026-41252 was patched at 2026-07-14
255.
Spoofing - Node.js (CVE-2026-48931) - High [440]
Description: A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Product detected by a:nodejs:node.js (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.27129 |
altlinux: CVE-2026-48931 was patched at 2026-07-23
debian: CVE-2026-48931 was patched at 2026-06-24
256.
Authentication Bypass - Chromium (CVE-2026-13897) - High [439]
Description: Insufficient policy enforcement in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00313, EPSS Percentile is 0.23743 |
altlinux: CVE-2026-13897 was patched at 2026-07-03
debian: CVE-2026-13897 was patched at 2026-07-05, 2026-07-14
257.
Authentication Bypass - OpenSSL (CVE-2026-45363) - High [439]
Description: ruby-jwt is a Ruby implementation of the RFC 7519 OAuth JSON Web Token standard. Prior to 2.10.3 and 3.2.0, JWT.decode(token, '', true, algorithm: 'HS256') accepts an attacker-forged token because
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00242, EPSS Percentile is 0.15496 |
debian: CVE-2026-45363 was patched at 2026-07-14
258.
Authentication Bypass - Safari (CVE-2026-43701) - High [439]
Description: The issue was addressed with improved checks. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.40063 |
almalinux: CVE-2026-43701 was patched at 2026-07-20
debian: CVE-2026-43701 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43701 was patched at 2026-07-20
redhat: CVE-2026-43701 was patched at 2026-07-20
259.
Authentication Bypass - Safari (CVE-2026-43713) - High [439]
Description: A permissions issue was addressed with additional restrictions. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00481, EPSS Percentile is 0.38907 |
almalinux: CVE-2026-43713 was patched at 2026-07-20
debian: CVE-2026-43713 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43713 was patched at 2026-07-20
redhat: CVE-2026-43713 was patched at 2026-07-20
260.
Security Feature Bypass - Chromium (CVE-2026-13028) - High [436]
Description: Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00287, EPSS Percentile is 0.2098 |
debian: CVE-2026-13028 was patched at 2026-06-25, 2026-07-14
261.
Security Feature Bypass - Chromium (CVE-2026-13032) - High [436]
Description: Use after free in WebGL in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00287, EPSS Percentile is 0.2098 |
debian: CVE-2026-13032 was patched at 2026-06-25, 2026-07-14
262.
Security Feature Bypass - Chromium (CVE-2026-13775) - High [436]
Description: Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.248 |
altlinux: CVE-2026-13775 was patched at 2026-07-03
debian: CVE-2026-13775 was patched at 2026-07-05, 2026-07-14
263.
Security Feature Bypass - Chromium (CVE-2026-13780) - High [436]
Description: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.248 |
altlinux: CVE-2026-13780 was patched at 2026-07-03
debian: CVE-2026-13780 was patched at 2026-07-05, 2026-07-14
264.
Security Feature Bypass - Chromium (CVE-2026-13781) - High [436]
Description: Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.248 |
altlinux: CVE-2026-13781 was patched at 2026-07-03
debian: CVE-2026-13781 was patched at 2026-07-05, 2026-07-14
265.
Security Feature Bypass - Chromium (CVE-2026-13782) - High [436]
Description: Use after free in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.22432 |
altlinux: CVE-2026-13782 was patched at 2026-07-03
debian: CVE-2026-13782 was patched at 2026-07-05, 2026-07-14
266.
Security Feature Bypass - Chromium (CVE-2026-13785) - High [436]
Description: Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.24799 |
altlinux: CVE-2026-13785 was patched at 2026-07-03
debian: CVE-2026-13785 was patched at 2026-07-05, 2026-07-14
267.
Security Feature Bypass - Chromium (CVE-2026-13796) - High [436]
Description: Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.22431 |
altlinux: CVE-2026-13796 was patched at 2026-07-03
debian: CVE-2026-13796 was patched at 2026-07-05, 2026-07-14
268.
Security Feature Bypass - Chromium (CVE-2026-13797) - High [436]
Description: Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.22431 |
altlinux: CVE-2026-13797 was patched at 2026-07-03
debian: CVE-2026-13797 was patched at 2026-07-05, 2026-07-14
269.
Security Feature Bypass - Chromium (CVE-2026-13817) - High [436]
Description: Insufficient validation of untrusted input in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25034 |
altlinux: CVE-2026-13817 was patched at 2026-07-03
debian: CVE-2026-13817 was patched at 2026-07-05, 2026-07-14
270.
Security Feature Bypass - Chromium (CVE-2026-13853) - High [436]
Description: Use after free in Journeys in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00288, EPSS Percentile is 0.2111 |
altlinux: CVE-2026-13853 was patched at 2026-07-03
debian: CVE-2026-13853 was patched at 2026-07-05, 2026-07-14
271.
Security Feature Bypass - Chromium (CVE-2026-13854) - High [436]
Description: Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00288, EPSS Percentile is 0.2111 |
altlinux: CVE-2026-13854 was patched at 2026-07-03
debian: CVE-2026-13854 was patched at 2026-07-05, 2026-07-14
272.
Security Feature Bypass - Chromium (CVE-2026-13859) - High [436]
Description: Inappropriate implementation in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00288, EPSS Percentile is 0.2111 |
altlinux: CVE-2026-13859 was patched at 2026-07-03
debian: CVE-2026-13859 was patched at 2026-07-05, 2026-07-14
273.
Security Feature Bypass - Chromium (CVE-2026-13861) - High [436]
Description: Use after free in Core in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00288, EPSS Percentile is 0.21111 |
altlinux: CVE-2026-13861 was patched at 2026-07-03
debian: CVE-2026-13861 was patched at 2026-07-05, 2026-07-14
274.
Security Feature Bypass - Chromium (CVE-2026-13878) - High [436]
Description: Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00288, EPSS Percentile is 0.2111 |
altlinux: CVE-2026-13878 was patched at 2026-07-03
debian: CVE-2026-13878 was patched at 2026-07-05, 2026-07-14
275.
Security Feature Bypass - Chromium (CVE-2026-13880) - High [436]
Description: Use after free in USB in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00288, EPSS Percentile is 0.21109 |
altlinux: CVE-2026-13880 was patched at 2026-07-03
debian: CVE-2026-13880 was patched at 2026-07-05, 2026-07-14
276.
Security Feature Bypass - Chromium (CVE-2026-13883) - High [436]
Description: Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00314, EPSS Percentile is 0.2385 |
altlinux: CVE-2026-13883 was patched at 2026-07-03
debian: CVE-2026-13883 was patched at 2026-07-05, 2026-07-14
277.
Security Feature Bypass - Chromium (CVE-2026-13903) - High [436]
Description: Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.27193 |
altlinux: CVE-2026-13903 was patched at 2026-07-03
debian: CVE-2026-13903 was patched at 2026-07-05, 2026-07-14
278.
Security Feature Bypass - Chromium (CVE-2026-13928) - High [436]
Description: Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.2503 |
altlinux: CVE-2026-13928 was patched at 2026-07-03
debian: CVE-2026-13928 was patched at 2026-07-05, 2026-07-14
279.
Security Feature Bypass - Chromium (CVE-2026-14017) - High [436]
Description: Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.17984 |
altlinux: CVE-2026-14017 was patched at 2026-07-03
debian: CVE-2026-14017 was patched at 2026-07-05, 2026-07-14
280.
Security Feature Bypass - Chromium (CVE-2026-14037) - High [436]
Description: Insufficient policy enforcement in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00252, EPSS Percentile is 0.16726 |
altlinux: CVE-2026-14037 was patched at 2026-07-03
debian: CVE-2026-14037 was patched at 2026-07-05, 2026-07-14
281.
Security Feature Bypass - Chromium (CVE-2026-14043) - High [436]
Description: Use after free in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.17983 |
altlinux: CVE-2026-14043 was patched at 2026-07-03
debian: CVE-2026-14043 was patched at 2026-07-05, 2026-07-14
282.
Security Feature Bypass - Chromium (CVE-2026-14044) - High [436]
Description: Use after free in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.17984 |
altlinux: CVE-2026-14044 was patched at 2026-07-03
debian: CVE-2026-14044 was patched at 2026-07-05, 2026-07-14
283.
Security Feature Bypass - Chromium (CVE-2026-14055) - High [436]
Description: Insufficient validation of untrusted input in Device Trust in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.17985 |
altlinux: CVE-2026-14055 was patched at 2026-07-03
debian: CVE-2026-14055 was patched at 2026-07-05, 2026-07-14
284.
Security Feature Bypass - Chromium (CVE-2026-14056) - High [436]
Description: Insufficient validation of untrusted input in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted video file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00242, EPSS Percentile is 0.15518 |
altlinux: CVE-2026-14056 was patched at 2026-07-03
debian: CVE-2026-14056 was patched at 2026-07-05, 2026-07-14
285.
Security Feature Bypass - Chromium (CVE-2026-14090) - High [436]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.17986 |
altlinux: CVE-2026-14090 was patched at 2026-07-03
debian: CVE-2026-14090 was patched at 2026-07-05, 2026-07-14
286.
Security Feature Bypass - Chromium (CVE-2026-14093) - High [436]
Description: Use after free in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00243, EPSS Percentile is 0.1564 |
altlinux: CVE-2026-14093 was patched at 2026-07-03
debian: CVE-2026-14093 was patched at 2026-07-05, 2026-07-14
287.
Security Feature Bypass - Chromium (CVE-2026-14095) - High [436]
Description: Insufficient policy enforcement in Browser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00243, EPSS Percentile is 0.15601 |
altlinux: CVE-2026-14095 was patched at 2026-07-03
debian: CVE-2026-14095 was patched at 2026-07-05, 2026-07-14
288.
Security Feature Bypass - Chromium (CVE-2026-14097) - High [436]
Description: Inappropriate implementation in WebAppInstalls in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00243, EPSS Percentile is 0.156 |
altlinux: CVE-2026-14097 was patched at 2026-07-03
debian: CVE-2026-14097 was patched at 2026-07-05, 2026-07-14
289.
Security Feature Bypass - Chromium (CVE-2026-14106) - High [436]
Description: Insufficient validation of untrusted input in Text in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00262, EPSS Percentile is 0.17953 |
altlinux: CVE-2026-14106 was patched at 2026-07-03
debian: CVE-2026-14106 was patched at 2026-07-05, 2026-07-14
290.
Security Feature Bypass - Chromium (CVE-2026-14109) - High [436]
Description: Insufficient policy enforcement in Mojo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.17985 |
altlinux: CVE-2026-14109 was patched at 2026-07-03
debian: CVE-2026-14109 was patched at 2026-07-05, 2026-07-14
291.
Security Feature Bypass - Chromium (CVE-2026-14113) - High [436]
Description: Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.16938 |
altlinux: CVE-2026-14113 was patched at 2026-07-03
debian: CVE-2026-14113 was patched at 2026-07-05, 2026-07-14
292.
Security Feature Bypass - Chromium (CVE-2026-14120) - High [436]
Description: Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00265, EPSS Percentile is 0.18295 |
altlinux: CVE-2026-14120 was patched at 2026-07-03
debian: CVE-2026-14120 was patched at 2026-07-05, 2026-07-14
293.
Security Feature Bypass - Chromium (CVE-2026-14382) - High [436]
Description: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00265, EPSS Percentile is 0.18295 |
altlinux: CVE-2026-14382 was patched at 2026-07-03
debian: CVE-2026-14382 was patched at 2026-07-05, 2026-07-14
294.
Security Feature Bypass - Chromium (CVE-2026-14387) - High [436]
Description: Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00276, EPSS Percentile is 0.19847 |
altlinux: CVE-2026-14387 was patched at 2026-07-03
debian: CVE-2026-14387 was patched at 2026-07-05, 2026-07-14
295.
Security Feature Bypass - Chromium (CVE-2026-14411) - High [436]
Description: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16819 |
altlinux: CVE-2026-14411 was patched at 2026-07-03
debian: CVE-2026-14411 was patched at 2026-07-05, 2026-07-14
296.
Security Feature Bypass - Chromium (CVE-2026-14416) - High [436]
Description: Out of bounds read in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00243, EPSS Percentile is 0.15603 |
altlinux: CVE-2026-14416 was patched at 2026-07-03
debian: CVE-2026-14416 was patched at 2026-07-05, 2026-07-14
297.
Security Feature Bypass - Chromium (CVE-2026-14420) - High [436]
Description: Out of bounds read and write in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16817 |
altlinux: CVE-2026-14420 was patched at 2026-07-03
debian: CVE-2026-14420 was patched at 2026-07-05, 2026-07-14
298.
Security Feature Bypass - Chromium (CVE-2026-15773) - High [436]
Description: Use after free in Core in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.21784 |
altlinux: CVE-2026-15773 was patched at 2026-07-15
debian: CVE-2026-15773 was patched at 2026-07-14, 2026-07-16
299.
Security Feature Bypass - Safari (CVE-2026-43725) - High [436]
Description: The issue was addressed with improved input validation. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00829, EPSS Percentile is 0.53908 |
almalinux: CVE-2026-43725 was patched at 2026-07-20
debian: CVE-2026-43725 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43725 was patched at 2026-07-20
redhat: CVE-2026-43725 was patched at 2026-07-20
300.
Security Feature Bypass - Kubernetes (CVE-2026-53492) - High [432]
Description: containerd is an open-source container runtime. In Versions prior to 2.3.2, 2.2.5 and 2.1.9, the CRI implementation improperly trusts Container Device Interface (CDI) annotations found within untrusted checkpoint image metadata during container restoration. When restoring a container from a checkpoint, containerd preserves CDI-related annotations from the checkpoint archive rather than relying solely on the pod's create-time specification. This allows a user with pod creation permissions to bypass standard
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.7 | 14 | Kubernetes is an open-source container orchestration system for automating software deployment, scaling, and management | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00347, EPSS Percentile is 0.27379 |
altlinux: CVE-2026-53492 was patched at 2026-06-19, 2026-07-14, 2026-07-15
ubuntu: CVE-2026-53492 was patched at 2026-07-30
301.
Remote Code Execution - Chromium (CVE-2026-13031) - High [430]
Description: Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14415 |
debian: CVE-2026-13031 was patched at 2026-06-25, 2026-07-14
302.
Remote Code Execution - Chromium (CVE-2026-13035) - High [430]
Description: Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00216, EPSS Percentile is 0.1213 |
debian: CVE-2026-13035 was patched at 2026-06-25, 2026-07-14
303.
Remote Code Execution - Chromium (CVE-2026-13807) - High [430]
Description: Use after free in Import in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22608 |
altlinux: CVE-2026-13807 was patched at 2026-07-03
debian: CVE-2026-13807 was patched at 2026-07-05, 2026-07-14
304.
Remote Code Execution - Chromium (CVE-2026-14032) - High [430]
Description: Use after free in Bluetooth in Google Chrome on Mac prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0027, EPSS Percentile is 0.19017 |
altlinux: CVE-2026-14032 was patched at 2026-07-03
debian: CVE-2026-14032 was patched at 2026-07-05, 2026-07-14
305.
Remote Code Execution - Chromium (CVE-2026-14064) - High [430]
Description: Use after free in PageInfo in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00275, EPSS Percentile is 0.19726 |
altlinux: CVE-2026-14064 was patched at 2026-07-03
debian: CVE-2026-14064 was patched at 2026-07-05, 2026-07-14
306.
Remote Code Execution - Chromium (CVE-2026-14111) - High [430]
Description: Use after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00318, EPSS Percentile is 0.24279 |
altlinux: CVE-2026-14111 was patched at 2026-07-03
debian: CVE-2026-14111 was patched at 2026-07-05, 2026-07-14
307.
Remote Code Execution - Chromium (CVE-2026-14409) - High [430]
Description: Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00265, EPSS Percentile is 0.18316 |
altlinux: CVE-2026-14409 was patched at 2026-07-03
debian: CVE-2026-14409 was patched at 2026-07-05, 2026-07-14
308.
Remote Code Execution - Chromium (CVE-2026-15125) - High [430]
Description: Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14373 |
altlinux: CVE-2026-15125 was patched at 2026-07-09
debian: CVE-2026-15125 was patched at 2026-07-11, 2026-07-14
309.
Remote Code Execution - Keycloak (CVE-2026-9086) - High [430]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00419, EPSS Percentile is 0.3452 |
altlinux: CVE-2026-9086 was patched at 2026-06-28, 2026-07-01, 2026-07-02
310.
Remote Code Execution - Mozilla Firefox (CVE-2026-14241) - High [430]
Description: Memory safety bugs present in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00252, EPSS Percentile is 0.16662 |
altlinux: CVE-2026-14241 was patched at 2026-07-02, 2026-07-07
311.
Authentication Bypass - Jetty (CVE-2026-49877) - High [429]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Jetty is a Java based web server and servlet engine | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0078, EPSS Percentile is 0.52312 |
debian: CVE-2026-49877 was patched at 2026-07-14
312.
Spoofing - Cacti (CVE-2026-40082) - High [428]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com, BDU:PublicExploit websites | |
| 0.4 | 15 | Spoofing | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13856 |
altlinux: CVE-2026-40082 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-40082 was patched at 2026-07-14
313.
Authentication Bypass - Chromium (CVE-2026-13864) - High [427]
Description: Insufficient policy enforcement in WebHID in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform privilege escalation via a crafted Chrome Extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00294, EPSS Percentile is 0.21671 |
altlinux: CVE-2026-13864 was patched at 2026-07-03
debian: CVE-2026-13864 was patched at 2026-07-05, 2026-07-14
314.
Authentication Bypass - Keycloak (CVE-2026-9800) - High [427]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00308, EPSS Percentile is 0.23099 |
altlinux: CVE-2026-9800 was patched at 2026-06-28, 2026-07-01, 2026-07-02
315.
Code Injection - Vim (CVE-2026-55895) - High [426]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.95 | 14 | Highly configurable command-line text editor used in development and system administration. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04922 |
altlinux: CVE-2026-55895 was patched at 2026-06-30, 2026-07-06
debian: CVE-2026-55895 was patched at 2026-07-14
ubuntu: CVE-2026-55895 was patched at 2026-07-30
316.
Code Injection - Vim (CVE-2026-57456) - High [426]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.95 | 14 | Highly configurable command-line text editor used in development and system administration. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03982 |
altlinux: CVE-2026-57456 was patched at 2026-06-30, 2026-07-06
debian: CVE-2026-57456 was patched at 2026-07-14
redhat: CVE-2026-57456 was patched at 2026-07-29
ubuntu: CVE-2026-57456 was patched at 2026-07-30
317.
Code Injection - Vim (CVE-2026-59858) - High [426]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.95 | 14 | Highly configurable command-line text editor used in development and system administration. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00137, EPSS Percentile is 0.03588 |
altlinux: CVE-2026-59858 was patched at 2026-06-30, 2026-07-06
debian: CVE-2026-59858 was patched at 2026-07-14
redhat: CVE-2026-59858 was patched at 2026-07-29
ubuntu: CVE-2026-59858 was patched at 2026-07-30
318.
Remote Code Execution - Envoy (CVE-2026-48706) - High [426]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00376, EPSS Percentile is 0.30358 |
altlinux: CVE-2026-48706 was patched at 2026-06-25, 2026-07-02
319.
Security Feature Bypass - Angular (CVE-2026-50168) - High [426]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00193, EPSS Percentile is 0.09334 |
debian: CVE-2026-50168 was patched at 2026-06-24
320.
Denial of Service - FreeIPA (CVE-2026-11610) - High [425]
Description: A heap buffer overflow flaw was found in the SASL I/O layer of 389 Directory Server (389-ds-base). After a successful SASL bind with integrity protection (SSF > 0), an authenticated attacker can send a specially crafted oversized LDAP UNBIND packet that is copied into a 512-byte heap receive buffer without a bounds check in sasl_io_recv() in sasl_io.c. This allows up to approximately 2 megabytes of attacker-controlled data to overflow the buffer, causing a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | FreeIPA is a free and open source identity management system | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00627, EPSS Percentile is 0.46545 |
almalinux: CVE-2026-11610 was patched at 2026-07-07
debian: CVE-2026-11610 was patched at 2026-07-14
oraclelinux: CVE-2026-11610 was patched at 2026-07-07, 2026-07-08, 2026-07-16
redhat: CVE-2026-11610 was patched at 2026-07-07, 2026-07-08
321.
Information Disclosure - Angular (CVE-2026-50170) - High [425]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00268, EPSS Percentile is 0.18791 |
debian: CVE-2026-50170 was patched at 2026-06-24
322.
Security Feature Bypass - Chromium (CVE-2026-13777) - High [425]
Description: Insufficient validation of untrusted input in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.2243 |
altlinux: CVE-2026-13777 was patched at 2026-07-03
debian: CVE-2026-13777 was patched at 2026-07-05, 2026-07-14
323.
Security Feature Bypass - Chromium (CVE-2026-13851) - High [425]
Description: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00286, EPSS Percentile is 0.2083 |
altlinux: CVE-2026-13851 was patched at 2026-07-03
debian: CVE-2026-13851 was patched at 2026-07-05, 2026-07-14
324.
Security Feature Bypass - Chromium (CVE-2026-13852) - High [425]
Description: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass discretionary access control via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00286, EPSS Percentile is 0.20831 |
altlinux: CVE-2026-13852 was patched at 2026-07-03
debian: CVE-2026-13852 was patched at 2026-07-05, 2026-07-14
325.
Security Feature Bypass - Chromium (CVE-2026-13872) - High [425]
Description: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.18927 |
altlinux: CVE-2026-13872 was patched at 2026-07-03
debian: CVE-2026-13872 was patched at 2026-07-05, 2026-07-14
326.
Security Feature Bypass - Chromium (CVE-2026-13882) - High [425]
Description: Race in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.13987 |
altlinux: CVE-2026-13882 was patched at 2026-07-03
debian: CVE-2026-13882 was patched at 2026-07-05, 2026-07-14
327.
Security Feature Bypass - Chromium (CVE-2026-14009) - High [425]
Description: Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16778 |
altlinux: CVE-2026-14009 was patched at 2026-07-03
debian: CVE-2026-14009 was patched at 2026-07-05, 2026-07-14
328.
Security Feature Bypass - Chromium (CVE-2026-14036) - High [425]
Description: Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.17985 |
altlinux: CVE-2026-14036 was patched at 2026-07-03
debian: CVE-2026-14036 was patched at 2026-07-05, 2026-07-14
329.
Security Feature Bypass - Chromium (CVE-2026-14038) - High [425]
Description: Insufficient validation of untrusted input in New Tab Page in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00257, EPSS Percentile is 0.17345 |
altlinux: CVE-2026-14038 was patched at 2026-07-03
debian: CVE-2026-14038 was patched at 2026-07-05, 2026-07-14
330.
Security Feature Bypass - Chromium (CVE-2026-14041) - High [425]
Description: Insufficient policy enforcement in Serial in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.17984 |
altlinux: CVE-2026-14041 was patched at 2026-07-03
debian: CVE-2026-14041 was patched at 2026-07-05, 2026-07-14
331.
Security Feature Bypass - Chromium (CVE-2026-14078) - High [425]
Description: Insufficient validation of untrusted input in WebRTC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform privilege escalation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.17985 |
altlinux: CVE-2026-14078 was patched at 2026-07-03
debian: CVE-2026-14078 was patched at 2026-07-05, 2026-07-14
332.
Security Feature Bypass - Chromium (CVE-2026-14084) - High [425]
Description: Insufficient validation of untrusted input in Chromoting in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00242, EPSS Percentile is 0.15547 |
altlinux: CVE-2026-14084 was patched at 2026-07-03
debian: CVE-2026-14084 was patched at 2026-07-05, 2026-07-14
333.
Security Feature Bypass - Chromium (CVE-2026-14087) - High [425]
Description: Heap buffer overflow in WebNN in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0029, EPSS Percentile is 0.2125 |
altlinux: CVE-2026-14087 was patched at 2026-07-03
debian: CVE-2026-14087 was patched at 2026-07-05, 2026-07-14
334.
Security Feature Bypass - Chromium (CVE-2026-14101) - High [425]
Description: Insufficient policy enforcement in Sandbox in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14391 |
altlinux: CVE-2026-14101 was patched at 2026-07-03
debian: CVE-2026-14101 was patched at 2026-07-05, 2026-07-14
335.
Security Feature Bypass - Chromium (CVE-2026-14105) - High [425]
Description: Insufficient policy enforcement in Speech in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.07013 |
altlinux: CVE-2026-14105 was patched at 2026-07-03
debian: CVE-2026-14105 was patched at 2026-07-05, 2026-07-14
336.
Security Feature Bypass - Chromium (CVE-2026-14152) - High [425]
Description: Out of bounds read and write in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.1397 |
altlinux: CVE-2026-14152 was patched at 2026-07-03
debian: CVE-2026-14152 was patched at 2026-07-05, 2026-07-14
337.
Security Feature Bypass - Chromium (CVE-2026-14390) - High [425]
Description: Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14559 |
altlinux: CVE-2026-14390 was patched at 2026-07-03
debian: CVE-2026-14390 was patched at 2026-07-05, 2026-07-14
338.
Security Feature Bypass - Chromium (CVE-2026-14398) - High [425]
Description: Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.1206 |
altlinux: CVE-2026-14398 was patched at 2026-07-03
debian: CVE-2026-14398 was patched at 2026-07-05, 2026-07-14
339.
Security Feature Bypass - Chromium (CVE-2026-14417) - High [425]
Description: Use after free in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00207, EPSS Percentile is 0.10902 |
altlinux: CVE-2026-14417 was patched at 2026-07-03
debian: CVE-2026-14417 was patched at 2026-07-05, 2026-07-14
340.
Security Feature Bypass - Chromium (CVE-2026-14419) - High [425]
Description: Use after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.12059 |
altlinux: CVE-2026-14419 was patched at 2026-07-03
debian: CVE-2026-14419 was patched at 2026-07-05, 2026-07-14
341.
Security Feature Bypass - Chromium (CVE-2026-14423) - High [425]
Description: Type Confusion in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12746 |
altlinux: CVE-2026-14423 was patched at 2026-07-03
debian: CVE-2026-14423 was patched at 2026-07-05, 2026-07-14
342.
Security Feature Bypass - Chromium (CVE-2026-14424) - High [425]
Description: Use after free in Dawn in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.12059 |
altlinux: CVE-2026-14424 was patched at 2026-07-03
debian: CVE-2026-14424 was patched at 2026-07-05, 2026-07-14
343.
Security Feature Bypass - Chromium (CVE-2026-14425) - High [425]
Description: Use after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00218, EPSS Percentile is 0.12441 |
altlinux: CVE-2026-14425 was patched at 2026-07-03
debian: CVE-2026-14425 was patched at 2026-07-05, 2026-07-14
344.
Security Feature Bypass - Chromium (CVE-2026-15113) - High [425]
Description: Use after free in Autofill in Google Chrome on Android prior to 150.0.7871.115 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00202, EPSS Percentile is 0.10394 |
altlinux: CVE-2026-15113 was patched at 2026-07-09
debian: CVE-2026-15113 was patched at 2026-07-11, 2026-07-14
345.
Security Feature Bypass - Chromium (CVE-2026-15899) - High [425]
Description: Use after free in CameraCapture in Google Chrome on Mac prior to 150.0.7871.128 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00236, EPSS Percentile is 0.1479 |
altlinux: CVE-2026-15899 was patched at 2026-07-18
debian: CVE-2026-15899 was patched at 2026-07-14, 2026-07-22
346.
Security Feature Bypass - Chromium (CVE-2026-15900) - High [425]
Description: Use after free in GPU in Google Chrome on Android prior to 150.0.7871.128 allowed a remote attacker to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00236, EPSS Percentile is 0.1479 |
altlinux: CVE-2026-15900 was patched at 2026-07-18
debian: CVE-2026-15900 was patched at 2026-07-14, 2026-07-22
347.
Security Feature Bypass - Microsoft PowerShell (CVE-2026-26143) - High [425]
Description: Improper input validation in Microsoft
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | PowerShell or Microsoft PowerShell (formerly Windows PowerShell) is a task automation and configuration management program from Microsoft, consisting of a command-line shell and the associated scripting language | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00096, EPSS Percentile is 0.26497 |
redos: CVE-2026-26143 was patched at 2026-07-09
348.
Code Injection - Cacti (CVE-2026-39948) - High [423]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00501, EPSS Percentile is 0.40119 |
altlinux: CVE-2026-39948 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-39948 was patched at 2026-07-14
349.
Authentication Bypass - Apache Tomcat (CVE-2026-55955) - High [422]
Description: Improper Authentication vulnerability in Apache
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00467, EPSS Percentile is 0.38006 |
altlinux: CVE-2026-55955 was patched at 2026-06-24, 2026-07-10, 2026-07-20
debian: CVE-2026-55955 was patched at 2026-07-14
350.
Information Disclosure - Electron (CVE-2022-29247) - High [422]
Description: Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows a renderer with JS execution to obtain access to a new renderer process with `nodeIntegrationInSubFrames` enabled which in turn allows effective access to `ipcRenderer`. The `nodeIntegrationInSubFrames` option does not implicitly grant Node.js access. Rather, it depends on the existing sandbox setting. If an application is sandboxed, then `nodeIntegrationInSubFrames` just gives access to the sandboxed renderer APIs, which include `ipcRenderer`. If the application then additionally exposes IPC messages without IPC `senderFrame` validation that perform privileged actions or return confidential data this access to `ipcRenderer` can in turn compromise your application / user even with the sandbox enabled. Electron versions 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 contain a fix for this issue. As a workaround, ensure that all IPC message handlers appropriately validate `senderFrame`.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Product detected by a:electronjs:electron (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00976, EPSS Percentile is 0.58609 |
altlinux: CVE-2022-29247 was patched at 2026-06-20
351.
Remote Code Execution - Vim (CVE-2026-57453) - High [420]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.95 | 14 | Highly configurable command-line text editor used in development and system administration. | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0014, EPSS Percentile is 0.0385 |
altlinux: CVE-2026-57453 was patched at 2026-06-30, 2026-07-06
ubuntu: CVE-2026-57453 was patched at 2026-07-30
352.
Authentication Bypass - Gitea (CVE-2026-22555) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00305, EPSS Percentile is 0.22815 |
redos: CVE-2026-22555 was patched at 2026-07-14
353.
Remote Code Execution - Chromium (CVE-2026-13283) - High [419]
Description: Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13842 |
altlinux: CVE-2026-13283 was patched at 2026-06-29
debian: CVE-2026-13283 was patched at 2026-07-05, 2026-07-14
354.
Remote Code Execution - Chromium (CVE-2026-13778) - High [419]
Description: Use after free in WebUSB in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00203, EPSS Percentile is 0.1044 |
altlinux: CVE-2026-13778 was patched at 2026-07-03
debian: CVE-2026-13778 was patched at 2026-07-05, 2026-07-14
355.
Remote Code Execution - Chromium (CVE-2026-14400) - High [419]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00222, EPSS Percentile is 0.12965 |
altlinux: CVE-2026-14400 was patched at 2026-07-03
debian: CVE-2026-14400 was patched at 2026-07-05, 2026-07-14
356.
Remote Code Execution - Chromium (CVE-2026-14426) - High [419]
Description: Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00217, EPSS Percentile is 0.12224 |
altlinux: CVE-2026-14426 was patched at 2026-07-03
debian: CVE-2026-14426 was patched at 2026-07-05, 2026-07-14
357.
Authentication Bypass - Roundcube (CVE-2026-62644) - High [417]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Roundcube is a web-based IMAP email client | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00259, EPSS Percentile is 0.17561 |
altlinux: CVE-2026-62644 was patched at 2026-07-10, 2026-07-15
debian: CVE-2026-62644 was patched at 2026-07-14, 2026-07-19
358.
Denial of Service - Linux Kernel (CVE-2026-52946) - High [417]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00455, EPSS Percentile is 0.37233 |
altlinux: CVE-2026-52946 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-07, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-52946 was patched at 2026-07-14
359.
Remote Code Execution - DBI (CVE-2026-14380) - High [416]
Description: DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile. When a string is assigned to a DBI handle's Profile attribute, DBI splits it into path, package and arguments, and interpolates the package part in a string eval with no validation of the package name. Any caller-influenced value that reaches the Profile attribute is therefore arbitrary Perl
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:perl:dbi (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00479, EPSS Percentile is 0.38821 |
altlinux: CVE-2026-14380 was patched at 2026-07-21
debian: CVE-2026-14380 was patched at 2026-07-14
360.
Remote Code Execution - LibXFont (CVE-2026-56002) - High [416]
Description: A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8 allows attackers authenticated as X client
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:x:libxfont (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00428, EPSS Percentile is 0.35195 |
altlinux: CVE-2026-56002 was patched at 2026-07-08, 2026-07-09, 2026-07-14
debian: CVE-2026-56002 was patched at 2026-07-14, 2026-07-15
oraclelinux: CVE-2026-56002 was patched at 2026-07-28
redhat: CVE-2026-56002 was patched at 2026-07-28
ubuntu: CVE-2026-56002 was patched at 2026-07-30
361.
Remote Code Execution - ProFTPD (CVE-2026-63090) - High [416]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | ProFTPD is a highly configurable and modular open-source FTP server designed for Unix-like systems, offering advanced features such as virtual hosting, authentication modules, and flexible configuration similar to Apache. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00464, EPSS Percentile is 0.37841 |
debian: CVE-2026-63090 was patched at 2026-07-14
362.
Remote Code Execution - Xrdp (CVE-2026-44178) - High [416]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | xrdp is an open source remote desktop protocol server | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00512, EPSS Percentile is 0.40747 |
altlinux: CVE-2026-44178 was patched at 2026-07-08
debian: CVE-2026-44178 was patched at 2026-07-14
363.
Remote Code Execution - containerd (CVE-2026-50195) - High [416]
Description: containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a vulnerability in the CRI checkpoint import process where it fails to validate the image references specified within a checkpoint image's configuration. An attacker with permissions to create pods can use a crafted checkpoint image to force containerd to pull a malicious image and assign it an arbitrary local tag, thereby poisoning the node's local image cache. Subsequently, if other pods on the same node attempt to use the poisoned tag with an IfNotPresent (or Never) pull policy, they will unknowingly execute the attacker's malicious image instead of the legitimate one. This can lead to a compromise of the affected pods, allowing the attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:linuxfoundation:containerd (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00332, EPSS Percentile is 0.25831 |
altlinux: CVE-2026-50195 was patched at 2026-06-19, 2026-07-14, 2026-07-15
ubuntu: CVE-2026-50195 was patched at 2026-07-30
364.
Remote Code Execution - libreswan (CVE-2026-12413) - High [416]
Description: An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemon to crash and restart. Continued exploitation would cause a denial of service. The function reassemble_v2_incoming_fragments() would ignore unknown outer payloads but still store these in a fixed size array msg_digest.digest[PAYLIMIT]. An off-by-one error in the assertion PASSERT(logger, md->digest_roof < elemsof(md->digest)) causes the daemon to abort. No remote
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:libreswan:libreswan (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00598, EPSS Percentile is 0.45221 |
almalinux: CVE-2026-12413 was patched at 2026-07-27
debian: CVE-2026-12413 was patched at 2026-07-14
oraclelinux: CVE-2026-12413 was patched at 2026-07-27
redhat: CVE-2026-12413 was patched at 2026-07-27
365.
Remote Code Execution - youtube-dl (CVE-2026-50574) - High [416]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | youtube-dl is a free and open source software tool for downloading video and audio from YouTube and over 1,000 other video hosting websites | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00406, EPSS Percentile is 0.33381 |
altlinux: CVE-2026-50574 was patched at 2026-07-27
debian: CVE-2026-50574 was patched at 2026-07-14
366.
Authentication Bypass - Chromium (CVE-2026-13800) - High [415]
Description: Inappropriate implementation in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06453 |
altlinux: CVE-2026-13800 was patched at 2026-07-03
debian: CVE-2026-13800 was patched at 2026-07-05, 2026-07-14
367.
Authentication Bypass - Chromium (CVE-2026-13818) - High [415]
Description: Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0027, EPSS Percentile is 0.19022 |
altlinux: CVE-2026-13818 was patched at 2026-07-03
debian: CVE-2026-13818 was patched at 2026-07-05, 2026-07-14
368.
Authentication Bypass - Chromium (CVE-2026-13828) - High [415]
Description: Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00274, EPSS Percentile is 0.1964 |
altlinux: CVE-2026-13828 was patched at 2026-07-03
debian: CVE-2026-13828 was patched at 2026-07-05, 2026-07-14
369.
Authentication Bypass - Chromium (CVE-2026-13931) - High [415]
Description: Inappropriate implementation in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00262, EPSS Percentile is 0.17901 |
altlinux: CVE-2026-13931 was patched at 2026-07-03
debian: CVE-2026-13931 was patched at 2026-07-05, 2026-07-14
370.
Authentication Bypass - Chromium (CVE-2026-13932) - High [415]
Description: Inappropriate implementation in Sharing in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00285, EPSS Percentile is 0.20722 |
altlinux: CVE-2026-13932 was patched at 2026-07-03
debian: CVE-2026-13932 was patched at 2026-07-05, 2026-07-14
371.
Authentication Bypass - Chromium (CVE-2026-13936) - High [415]
Description: Inappropriate implementation in Passwords in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00285, EPSS Percentile is 0.20722 |
altlinux: CVE-2026-13936 was patched at 2026-07-03
debian: CVE-2026-13936 was patched at 2026-07-05, 2026-07-14
372.
Authentication Bypass - Chromium (CVE-2026-13937) - High [415]
Description: Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00296, EPSS Percentile is 0.21929 |
altlinux: CVE-2026-13937 was patched at 2026-07-03
debian: CVE-2026-13937 was patched at 2026-07-05, 2026-07-14
373.
Authentication Bypass - Chromium (CVE-2026-13953) - High [415]
Description: Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0027, EPSS Percentile is 0.19022 |
altlinux: CVE-2026-13953 was patched at 2026-07-03
debian: CVE-2026-13953 was patched at 2026-07-05, 2026-07-14
374.
Authentication Bypass - Chromium (CVE-2026-13954) - High [415]
Description: Insufficient policy enforcement in XML in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00296, EPSS Percentile is 0.2193 |
altlinux: CVE-2026-13954 was patched at 2026-07-03
debian: CVE-2026-13954 was patched at 2026-07-05, 2026-07-14
375.
Authentication Bypass - Chromium (CVE-2026-13964) - High [415]
Description: Insufficient policy enforcement in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00274, EPSS Percentile is 0.19585 |
altlinux: CVE-2026-13964 was patched at 2026-07-03
debian: CVE-2026-13964 was patched at 2026-07-05, 2026-07-14
376.
Authentication Bypass - Chromium (CVE-2026-13985) - High [415]
Description: Inappropriate implementation in MediaCapture in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17064 |
altlinux: CVE-2026-13985 was patched at 2026-07-03
debian: CVE-2026-13985 was patched at 2026-07-05, 2026-07-14
377.
Authentication Bypass - Chromium (CVE-2026-14019) - High [415]
Description: Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16145 |
altlinux: CVE-2026-14019 was patched at 2026-07-03
debian: CVE-2026-14019 was patched at 2026-07-05, 2026-07-14
378.
Authentication Bypass - Chromium (CVE-2026-14118) - High [415]
Description: Insufficient data validation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0025, EPSS Percentile is 0.16491 |
altlinux: CVE-2026-14118 was patched at 2026-07-03
debian: CVE-2026-14118 was patched at 2026-07-05, 2026-07-14
379.
Denial of Service - Angular (CVE-2026-54268) - High [414]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00327, EPSS Percentile is 0.25228 |
debian: CVE-2026-54268 was patched at 2026-06-24
380.
Authentication Bypass - rabbitmq_server (CVE-2026-57219) - High [413]
Description: RabbitMQ is a messaging and streaming broker. Prior to 3.13.15, 4.0.20, 4.1.11, and 4.2.6, the obsolete GET /api/auth endpoint can disclose the OAuth 2 client secret on RabbitMQ installations configured with management.oauth_client_secret, exposing credentials to unauthenticated callers when the management plugin and that OAuth configuration are enabled. This issue is fixed in versions 3.13.15, 4.0.20, 4.1.11, and 4.2.6.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:broadcom:rabbitmq_server (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00784, EPSS Percentile is 0.5244 |
debian: CVE-2026-57219 was patched at 2026-07-14
381.
Security Feature Bypass - Chromium (CVE-2026-13801) - High [413]
Description: Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.21749 |
altlinux: CVE-2026-13801 was patched at 2026-07-03
debian: CVE-2026-13801 was patched at 2026-07-05, 2026-07-14
382.
Security Feature Bypass - Chromium (CVE-2026-13803) - High [413]
Description: Type Confusion in Chrome Tabs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00321, EPSS Percentile is 0.24601 |
altlinux: CVE-2026-13803 was patched at 2026-07-03
debian: CVE-2026-13803 was patched at 2026-07-05, 2026-07-14
383.
Security Feature Bypass - Chromium (CVE-2026-13804) - High [413]
Description: Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.21748 |
altlinux: CVE-2026-13804 was patched at 2026-07-03
debian: CVE-2026-13804 was patched at 2026-07-05, 2026-07-14
384.
Security Feature Bypass - Chromium (CVE-2026-13806) - High [413]
Description: Insufficient validation of untrusted input in Accessibility in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0031, EPSS Percentile is 0.23432 |
altlinux: CVE-2026-13806 was patched at 2026-07-03
debian: CVE-2026-13806 was patched at 2026-07-05, 2026-07-14
385.
Security Feature Bypass - Chromium (CVE-2026-13813) - High [413]
Description: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00293, EPSS Percentile is 0.21616 |
altlinux: CVE-2026-13813 was patched at 2026-07-03
debian: CVE-2026-13813 was patched at 2026-07-05, 2026-07-14
386.
Security Feature Bypass - Chromium (CVE-2026-13823) - High [413]
Description: Use after free in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.21749 |
altlinux: CVE-2026-13823 was patched at 2026-07-03
debian: CVE-2026-13823 was patched at 2026-07-05, 2026-07-14
387.
Security Feature Bypass - Chromium (CVE-2026-13824) - High [413]
Description: Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00293, EPSS Percentile is 0.21616 |
altlinux: CVE-2026-13824 was patched at 2026-07-03
debian: CVE-2026-13824 was patched at 2026-07-05, 2026-07-14
388.
Security Feature Bypass - Chromium (CVE-2026-13829) - High [413]
Description: Insufficient validation of untrusted input in Settings in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00315, EPSS Percentile is 0.23865 |
altlinux: CVE-2026-13829 was patched at 2026-07-03
debian: CVE-2026-13829 was patched at 2026-07-05, 2026-07-14
389.
Security Feature Bypass - Chromium (CVE-2026-13832) - High [413]
Description: Use after free in Headless in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.21749 |
altlinux: CVE-2026-13832 was patched at 2026-07-03
debian: CVE-2026-13832 was patched at 2026-07-05, 2026-07-14
390.
Security Feature Bypass - Chromium (CVE-2026-13834) - High [413]
Description: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00315, EPSS Percentile is 0.23864 |
altlinux: CVE-2026-13834 was patched at 2026-07-03
debian: CVE-2026-13834 was patched at 2026-07-05, 2026-07-14
391.
Security Feature Bypass - Chromium (CVE-2026-13841) - High [413]
Description: Integer overflow in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.21748 |
altlinux: CVE-2026-13841 was patched at 2026-07-03
debian: CVE-2026-13841 was patched at 2026-07-05, 2026-07-14
392.
Security Feature Bypass - Chromium (CVE-2026-13856) - High [413]
Description: Insufficient validation of untrusted input in Speech in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00293, EPSS Percentile is 0.21616 |
altlinux: CVE-2026-13856 was patched at 2026-07-03
debian: CVE-2026-13856 was patched at 2026-07-05, 2026-07-14
393.
Security Feature Bypass - Chromium (CVE-2026-13891) - High [413]
Description: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00312, EPSS Percentile is 0.23573 |
altlinux: CVE-2026-13891 was patched at 2026-07-03
debian: CVE-2026-13891 was patched at 2026-07-05, 2026-07-14
394.
Security Feature Bypass - Chromium (CVE-2026-13919) - High [413]
Description: Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25328 |
altlinux: CVE-2026-13919 was patched at 2026-07-03
debian: CVE-2026-13919 was patched at 2026-07-05, 2026-07-14
395.
Security Feature Bypass - Chromium (CVE-2026-13921) - High [413]
Description: Insufficient validation of untrusted input in DeviceBoundSessionCredentials in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25328 |
altlinux: CVE-2026-13921 was patched at 2026-07-03
debian: CVE-2026-13921 was patched at 2026-07-05, 2026-07-14
396.
Security Feature Bypass - Chromium (CVE-2026-13930) - High [413]
Description: Insufficient policy enforcement in Actor in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25328 |
altlinux: CVE-2026-13930 was patched at 2026-07-03
debian: CVE-2026-13930 was patched at 2026-07-05, 2026-07-14
397.
Security Feature Bypass - Chromium (CVE-2026-13951) - High [413]
Description: Insufficient policy enforcement in USB in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.21749 |
altlinux: CVE-2026-13951 was patched at 2026-07-03
debian: CVE-2026-13951 was patched at 2026-07-05, 2026-07-14
398.
Security Feature Bypass - Chromium (CVE-2026-13974) - High [413]
Description: Integer overflow in Safe Browsing in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00266, EPSS Percentile is 0.18656 |
altlinux: CVE-2026-13974 was patched at 2026-07-03
debian: CVE-2026-13974 was patched at 2026-07-05, 2026-07-14
399.
Security Feature Bypass - Chromium (CVE-2026-14115) - High [413]
Description: Insufficient validation of untrusted input in Cast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00242, EPSS Percentile is 0.15463 |
altlinux: CVE-2026-14115 was patched at 2026-07-03
debian: CVE-2026-14115 was patched at 2026-07-05, 2026-07-14
400.
Security Feature Bypass - Chromium (CVE-2026-14122) - High [413]
Description: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00239, EPSS Percentile is 0.1518 |
altlinux: CVE-2026-14122 was patched at 2026-07-03
debian: CVE-2026-14122 was patched at 2026-07-05, 2026-07-14
401.
Security Feature Bypass - Chromium (CVE-2026-14427) - High [413]
Description: Heap buffer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00246, EPSS Percentile is 0.15915 |
altlinux: CVE-2026-14427 was patched at 2026-07-03
debian: CVE-2026-14427 was patched at 2026-07-05, 2026-07-14
402.
Security Feature Bypass - Chromium (CVE-2026-14428) - High [413]
Description: Insufficient validation of untrusted input in Dawn in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00249, EPSS Percentile is 0.16331 |
altlinux: CVE-2026-14428 was patched at 2026-07-03
debian: CVE-2026-14428 was patched at 2026-07-05, 2026-07-14
403.
Information Disclosure - Safari (CVE-2026-43732) - High [412]
Description: A path handling issue was addressed with improved validation. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00436, EPSS Percentile is 0.35887 |
almalinux: CVE-2026-43732 was patched at 2026-07-20
debian: CVE-2026-43732 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43732 was patched at 2026-07-20
redhat: CVE-2026-43732 was patched at 2026-07-20
404.
Code Injection - Cacti (CVE-2026-39893) - High [411]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00399, EPSS Percentile is 0.32642 |
altlinux: CVE-2026-39893 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-39893 was patched at 2026-07-14
405.
Code Injection - Cacti (CVE-2026-39955) - High [411]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00346, EPSS Percentile is 0.27201 |
altlinux: CVE-2026-39955 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-39955 was patched at 2026-07-14
406.
Code Injection - pgx (CVE-2026-41889) - High [411]
Description: pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, that string literal contains text that would be would be interpreted as a placeholder outside of a string literal, and the value of that placeholder is controllable by the attacker. This issue has been patched in version 5.9.2.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.5 | 14 | Product detected by a:jackc:pgx (does NOT exist in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00356, EPSS Percentile is 0.28284 |
altlinux: CVE-2026-41889 was patched at 2026-07-08, 2026-07-14, 2026-07-15
407.
Cross Site Scripting - Gitea (CVE-2026-28737) - High [410]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00337, EPSS Percentile is 0.26238 |
redos: CVE-2026-28737 was patched at 2026-07-14
408.
Denial of Service - Node.js (CVE-2026-48933) - High [410]
Description: A flaw in Node.js WebCrypto implementation can crash the process if the input of `subtle.encrypt()` is a multiple of 2GiB. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nodejs:node.js (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.9 | 10 | EPSS Probability is 0.03711, EPSS Percentile is 0.88641 |
almalinux: CVE-2026-48933 was patched at 2026-07-06, 2026-07-15, 2026-07-20
altlinux: CVE-2026-48933 was patched at 2026-07-23
debian: CVE-2026-48933 was patched at 2026-06-24
oraclelinux: CVE-2026-48933 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-48933 was patched at 2026-07-06, 2026-07-15, 2026-07-20
409.
Tampering - tar (CVE-2026-53655) - High [410]
Description: node-tar is a full-featured Tar for Node.js. Prior to 7.5.16, tar (node-tar) applies a PAX extended header's size= record (and other PAX overrides) to the next header entry of any type, including intermediary metadata headers such as a GNU long-name (L) or long-link (K) entry. Per POSIX pax, a PAX extended header (x) describes the next file entry, not the intermediary extension headers that may sit between the x header and the file it annotates. Because node-tar lets the PAX size override the byte length of an intervening L/K/x header, an attacker can desynchronize node-tar's stream cursor relative to every other mainstream tar implementation (GNU tar, libarchive/bsdtar, Python tarfile, and the now-fixed tar-rs / astral-tokio-tar). The result is a tar parser interpretation differential (CWE-436): a single crafted archive yields a different set of members under node-tar than under the reference tar tools. An attacker can use this to hide a member from one parser while it is visible to another, which defeats security tooling whose scanner and extractor disagree on archive contents (e.g. a malware/secret scanner that lists entries with one library while a downstream step extracts with another) This vulnerability is fixed in 7.5.16.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on NVD:PublicExploit:github.com website | |
| 0.3 | 15 | Tampering | |
| 0.5 | 14 | Product detected by a:isaacs:tar (does NOT exist in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00141, EPSS Percentile is 0.0393 |
debian: CVE-2026-53655 was patched at 2026-06-24
410.
Remote Code Execution - Python (CVE-2026-23879) - High [409]
Description: py7zr is a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00404, EPSS Percentile is 0.33202 |
debian: CVE-2026-23879 was patched at 2026-07-14
411.
Remote Code Execution - Python (CVE-2026-9323) - High [409]
Description: The urwid web display backend (urwid/display/web.py) generates web session identifiers (urwid_id) in Screen.start() by concatenating two random.randrange(10**9) calls that use
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00421, EPSS Percentile is 0.34613 |
debian: CVE-2026-9323 was patched at 2026-07-14
412.
Security Feature Bypass - Grafana (CVE-2026-28377) - High [409]
Description: A vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.85 | 14 | Grafana is an open-source analytics and monitoring platform that provides dashboards and visualization tools for metrics collected from various data sources. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05161 |
redos: CVE-2026-28377 was patched at 2026-06-25
413.
Cross Site Scripting - Angular (CVE-2026-50556) - High [408]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00236, EPSS Percentile is 0.14702 |
debian: CVE-2026-50556 was patched at 2026-06-24
414.
Memory Corruption - Mozilla Firefox (CVE-2026-15718) - High [407]
Description: We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00381, EPSS Percentile is 0.30825 |
altlinux: CVE-2026-15718 was patched at 2026-07-15, 2026-07-30
debian: CVE-2026-15718 was patched at 2026-07-22, 2026-07-30
oraclelinux: CVE-2026-15718 was patched at 2026-07-28
redhat: CVE-2026-15718 was patched at 2026-07-28
415.
Remote Code Execution - Chromium (CVE-2026-13037) - High [407]
Description: Use after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00105, EPSS Percentile is 0.01224 |
debian: CVE-2026-13037 was patched at 2026-06-25, 2026-07-14
416.
Memory Corruption - Linux Kernel (CVE-2026-53216) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00502, EPSS Percentile is 0.40187 |
altlinux: CVE-2026-53216 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53216 was patched at 2026-07-14
417.
Memory Corruption - Linux Kernel (CVE-2026-53246) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00442, EPSS Percentile is 0.36327 |
altlinux: CVE-2026-53246 was patched at 2026-06-19, 2026-06-22, 2026-07-06
debian: CVE-2026-53246 was patched at 2026-07-14
418.
Memory Corruption - Linux Kernel (CVE-2026-53247) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00467, EPSS Percentile is 0.3799 |
altlinux: CVE-2026-53247 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53247 was patched at 2026-07-14
419.
Memory Corruption - Linux Kernel (CVE-2026-53384) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00488, EPSS Percentile is 0.39361 |
debian: CVE-2026-53384 was patched at 2026-07-14, 2026-07-30
420.
Memory Corruption - Linux Kernel (CVE-2026-53399) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.40913 |
debian: CVE-2026-53399 was patched at 2026-07-14, 2026-07-21
421.
Memory Corruption - Linux Kernel (CVE-2026-63795) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00477, EPSS Percentile is 0.38688 |
debian: CVE-2026-63795 was patched at 2026-07-14, 2026-07-30
422.
Memory Corruption - Linux Kernel (CVE-2026-63800) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.40031 |
debian: CVE-2026-63800 was patched at 2026-07-14, 2026-07-30
423.
Memory Corruption - Linux Kernel (CVE-2026-63808) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.40032 |
debian: CVE-2026-63808 was patched at 2026-07-14, 2026-07-30
424.
Memory Corruption - Linux Kernel (CVE-2026-64025) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00444, EPSS Percentile is 0.36492 |
debian: CVE-2026-64025 was patched at 2026-07-14
ubuntu: CVE-2026-64025 was patched at 2026-07-30
425.
Memory Corruption - Linux Kernel (CVE-2026-64033) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00488, EPSS Percentile is 0.39362 |
debian: CVE-2026-64033 was patched at 2026-07-14
ubuntu: CVE-2026-64033 was patched at 2026-07-30
426.
Memory Corruption - Linux Kernel (CVE-2026-64061) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00444, EPSS Percentile is 0.36492 |
debian: CVE-2026-64061 was patched at 2026-07-14
ubuntu: CVE-2026-64061 was patched at 2026-07-30
427.
Memory Corruption - Linux Kernel (CVE-2026-64102) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.40031 |
debian: CVE-2026-64102 was patched at 2026-07-14
ubuntu: CVE-2026-64102 was patched at 2026-07-30
428.
Memory Corruption - Linux Kernel (CVE-2026-64113) - High [405]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.40032 |
debian: CVE-2026-64113 was patched at 2026-07-14
ubuntu: CVE-2026-64113 was patched at 2026-07-30
429.
Code Injection - pgAdmin (CVE-2025-12764) - High [404]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.6 | 14 | pgAdmin is the most popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00396, EPSS Percentile is 0.32343 |
redos: CVE-2025-12764 was patched at 2026-06-23
430.
Elevation of Privilege - Keycloak (CVE-2026-9795) - High [404]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00354, EPSS Percentile is 0.2812 |
altlinux: CVE-2026-9795 was patched at 2026-06-28, 2026-07-01, 2026-07-02
431.
Remote Code Execution - LibXFont (CVE-2026-56001) - High [404]
Description: A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by attackers able to access the X Server
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:x:libxfont (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00381, EPSS Percentile is 0.30792 |
altlinux: CVE-2026-56001 was patched at 2026-07-08, 2026-07-09, 2026-07-14
debian: CVE-2026-56001 was patched at 2026-07-12, 2026-07-14, 2026-07-15
oraclelinux: CVE-2026-56001 was patched at 2026-07-28
redhat: CVE-2026-56001 was patched at 2026-07-28
ubuntu: CVE-2026-56001 was patched at 2026-07-30
432.
Remote Code Execution - LibXFont (CVE-2026-56003) - High [404]
Description: A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeScaledProperties() before libXfont2 before 2.0.8 could be used by attackers using authenticated X clients
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:x:libxfont (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00373, EPSS Percentile is 0.30051 |
altlinux: CVE-2026-56003 was patched at 2026-07-08, 2026-07-09, 2026-07-14
debian: CVE-2026-56003 was patched at 2026-07-14, 2026-07-15
oraclelinux: CVE-2026-56003 was patched at 2026-07-28
redhat: CVE-2026-56003 was patched at 2026-07-28
ubuntu: CVE-2026-56003 was patched at 2026-07-30
433.
Remote Code Execution - nsd (CVE-2026-12244) - High [404]
Description: If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (uint16_t) variable that is used to allocate space needed for the RR wrap (because total size > 65535), causing a heap overflow. The attacker can perform a controlled (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:nlnetlabs:nsd (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25059 |
altlinux: CVE-2026-12244 was patched at 2026-06-26, 2026-06-29
ubuntu: CVE-2026-12244 was patched at 2026-07-30
434.
Authentication Bypass - Chromium (CVE-2026-13949) - High [403]
Description: Insufficient policy enforcement in Payments in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13821 |
altlinux: CVE-2026-13949 was patched at 2026-07-03
debian: CVE-2026-13949 was patched at 2026-07-05, 2026-07-14
435.
Authentication Bypass - Chromium (CVE-2026-14035) - High [403]
Description: Insufficient policy enforcement in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13817 |
altlinux: CVE-2026-14035 was patched at 2026-07-03
debian: CVE-2026-14035 was patched at 2026-07-05, 2026-07-14
436.
Authentication Bypass - Chromium (CVE-2026-14061) - High [403]
Description: Inappropriate implementation in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13817 |
altlinux: CVE-2026-14061 was patched at 2026-07-03
debian: CVE-2026-14061 was patched at 2026-07-05, 2026-07-14
437.
Authentication Bypass - Chromium (CVE-2026-14155) - High [403]
Description: Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11458 |
altlinux: CVE-2026-14155 was patched at 2026-07-03
debian: CVE-2026-14155 was patched at 2026-07-05, 2026-07-14
438.
Authentication Bypass - Chromium (CVE-2026-14156) - High [403]
Description: Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10077 |
altlinux: CVE-2026-14156 was patched at 2026-07-03
debian: CVE-2026-14156 was patched at 2026-07-05, 2026-07-14
439.
Security Feature Bypass - Apache ActiveMQ (CVE-2026-49432) - High [403]
Description: Improper Input Validation vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00577, EPSS Percentile is 0.44231 |
debian: CVE-2026-49432 was patched at 2026-07-14
440.
Security Feature Bypass - Apache ActiveMQ (CVE-2026-49434) - High [403]
Description: Improper Input Validation vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00466, EPSS Percentile is 0.3799 |
debian: CVE-2026-49434 was patched at 2026-07-14
441.
Authentication Bypass - Node.js (CVE-2026-48930) - High [401]
Description: A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:nodejs:node.js (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00324, EPSS Percentile is 0.24902 |
almalinux: CVE-2026-48930 was patched at 2026-07-06, 2026-07-15, 2026-07-20
altlinux: CVE-2026-48930 was patched at 2026-07-23
debian: CVE-2026-48930 was patched at 2026-06-24
oraclelinux: CVE-2026-48930 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-48930 was patched at 2026-07-06, 2026-07-15, 2026-07-20
442.
Denial of Service - OpenSSH (CVE-2026-60000) - High [401]
Description: sshd in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00441, EPSS Percentile is 0.3623 |
debian: CVE-2026-60000 was patched at 2026-07-14
ubuntu: CVE-2026-60000 was patched at 2026-07-30
443.
Memory Corruption - Safari (CVE-2026-43715) - High [401]
Description: A use-after-free issue was addressed with improved memory management. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00891, EPSS Percentile is 0.5585 |
almalinux: CVE-2026-43715 was patched at 2026-07-20
debian: CVE-2026-43715 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43715 was patched at 2026-07-20
redhat: CVE-2026-43715 was patched at 2026-07-20
444.
Remote Code Execution - shell-quote (CVE-2026-13311) - High [401]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.55 | 14 | shell-quote is a JavaScript/Node.js library for safely parsing and quoting POSIX shell commands. It is commonly used by CLI tools, build systems, and developer utilities to construct and parse shell command lines. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0036, EPSS Percentile is 0.28725 |
debian: CVE-2026-13311 was patched at 2026-07-14
445.
Security Feature Bypass - Chromium (CVE-2026-13025) - High [401]
Description: Race in DevTools in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.0833 |
debian: CVE-2026-13025 was patched at 2026-06-25, 2026-07-14
446.
Security Feature Bypass - Chromium (CVE-2026-13281) - High [401]
Description: Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.0753 |
altlinux: CVE-2026-13281 was patched at 2026-06-29
debian: CVE-2026-13281 was patched at 2026-07-05, 2026-07-14
447.
Security Feature Bypass - Chromium (CVE-2026-13790) - High [401]
Description: Side-channel information leakage in Scroll in Google Chrome prior to 150.0.7871.47 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00308, EPSS Percentile is 0.23123 |
altlinux: CVE-2026-13790 was patched at 2026-07-03
debian: CVE-2026-13790 was patched at 2026-07-05, 2026-07-14
448.
Security Feature Bypass - Chromium (CVE-2026-13793) - High [401]
Description: Insufficient policy enforcement in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0024, EPSS Percentile is 0.15228 |
altlinux: CVE-2026-13793 was patched at 2026-07-03
debian: CVE-2026-13793 was patched at 2026-07-05, 2026-07-14
449.
Security Feature Bypass - Chromium (CVE-2026-13795) - High [401]
Description: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0026, EPSS Percentile is 0.17635 |
altlinux: CVE-2026-13795 was patched at 2026-07-03
debian: CVE-2026-13795 was patched at 2026-07-05, 2026-07-14
450.
Security Feature Bypass - Chromium (CVE-2026-13809) - High [401]
Description: Side-channel information leakage in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00285, EPSS Percentile is 0.20765 |
altlinux: CVE-2026-13809 was patched at 2026-07-03
debian: CVE-2026-13809 was patched at 2026-07-05, 2026-07-14
451.
Security Feature Bypass - Chromium (CVE-2026-13816) - High [401]
Description: Insufficient validation of untrusted input in File Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00296, EPSS Percentile is 0.21854 |
altlinux: CVE-2026-13816 was patched at 2026-07-03
debian: CVE-2026-13816 was patched at 2026-07-05, 2026-07-14
452.
Security Feature Bypass - Chromium (CVE-2026-13820) - High [401]
Description: Out of bounds read in Skia in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00273, EPSS Percentile is 0.19479 |
altlinux: CVE-2026-13820 was patched at 2026-07-03
debian: CVE-2026-13820 was patched at 2026-07-05, 2026-07-14
453.
Security Feature Bypass - Chromium (CVE-2026-13833) - High [401]
Description: Uninitialized Use in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00297, EPSS Percentile is 0.22054 |
altlinux: CVE-2026-13833 was patched at 2026-07-03
debian: CVE-2026-13833 was patched at 2026-07-05, 2026-07-14
454.
Security Feature Bypass - Chromium (CVE-2026-13840) - High [401]
Description: Insufficient policy enforcement in Canvas in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0024, EPSS Percentile is 0.15228 |
altlinux: CVE-2026-13840 was patched at 2026-07-03
debian: CVE-2026-13840 was patched at 2026-07-05, 2026-07-14
455.
Security Feature Bypass - Chromium (CVE-2026-13847) - High [401]
Description: Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00308, EPSS Percentile is 0.23124 |
altlinux: CVE-2026-13847 was patched at 2026-07-03
debian: CVE-2026-13847 was patched at 2026-07-05, 2026-07-14
456.
Security Feature Bypass - Chromium (CVE-2026-13849) - High [401]
Description: Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to potentially perform a sandbox escape via a malicious file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.6. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00147, EPSS Percentile is 0.0443 |
altlinux: CVE-2026-13849 was patched at 2026-07-03
debian: CVE-2026-13849 was patched at 2026-07-05, 2026-07-14
457.
Security Feature Bypass - Chromium (CVE-2026-13862) - High [401]
Description: Insufficient policy enforcement in Web Authentication (Passkeys & Security Keys) in Google Chrome on iOS prior to 150.0.7871.47 allowed an attacker in a privileged network position to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17053 |
altlinux: CVE-2026-13862 was patched at 2026-07-03
debian: CVE-2026-13862 was patched at 2026-07-05, 2026-07-14
458.
Security Feature Bypass - Chromium (CVE-2026-13863) - High [401]
Description: Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00167, EPSS Percentile is 0.06396 |
altlinux: CVE-2026-13863 was patched at 2026-07-03
debian: CVE-2026-13863 was patched at 2026-07-05, 2026-07-14
459.
Security Feature Bypass - Chromium (CVE-2026-13866) - High [401]
Description: Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.18936 |
altlinux: CVE-2026-13866 was patched at 2026-07-03
debian: CVE-2026-13866 was patched at 2026-07-05, 2026-07-14
460.
Security Feature Bypass - Chromium (CVE-2026-13871) - High [401]
Description: Insufficient policy enforcement in GuestView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0028, EPSS Percentile is 0.20288 |
altlinux: CVE-2026-13871 was patched at 2026-07-03
debian: CVE-2026-13871 was patched at 2026-07-05, 2026-07-14
461.
Security Feature Bypass - Chromium (CVE-2026-13886) - High [401]
Description: Insufficient policy enforcement in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00248, EPSS Percentile is 0.1628 |
altlinux: CVE-2026-13886 was patched at 2026-07-03
debian: CVE-2026-13886 was patched at 2026-07-05, 2026-07-14
462.
Security Feature Bypass - Chromium (CVE-2026-13889) - High [401]
Description: Side-channel information leakage in WebAuthentication in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00305, EPSS Percentile is 0.22824 |
altlinux: CVE-2026-13889 was patched at 2026-07-03
debian: CVE-2026-13889 was patched at 2026-07-05, 2026-07-14
463.
Security Feature Bypass - Chromium (CVE-2026-13892) - High [401]
Description: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00282, EPSS Percentile is 0.20473 |
altlinux: CVE-2026-13892 was patched at 2026-07-03
debian: CVE-2026-13892 was patched at 2026-07-05, 2026-07-14
464.
Security Feature Bypass - Chromium (CVE-2026-13893) - High [401]
Description: Insufficient validation of untrusted input in WebUI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via malicious network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00294, EPSS Percentile is 0.21645 |
altlinux: CVE-2026-13893 was patched at 2026-07-03
debian: CVE-2026-13893 was patched at 2026-07-05, 2026-07-14
465.
Security Feature Bypass - Chromium (CVE-2026-13896) - High [401]
Description: Insufficient policy enforcement in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00248, EPSS Percentile is 0.1628 |
altlinux: CVE-2026-13896 was patched at 2026-07-03
debian: CVE-2026-13896 was patched at 2026-07-05, 2026-07-14
466.
Security Feature Bypass - Chromium (CVE-2026-13900) - High [401]
Description: Inappropriate implementation in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00298, EPSS Percentile is 0.22075 |
altlinux: CVE-2026-13900 was patched at 2026-07-03
debian: CVE-2026-13900 was patched at 2026-07-05, 2026-07-14
467.
Security Feature Bypass - Chromium (CVE-2026-13904) - High [401]
Description: Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00264, EPSS Percentile is 0.18168 |
altlinux: CVE-2026-13904 was patched at 2026-07-03
debian: CVE-2026-13904 was patched at 2026-07-05, 2026-07-14
468.
Security Feature Bypass - Chromium (CVE-2026-13910) - High [401]
Description: Insufficient policy enforcement in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00296, EPSS Percentile is 0.21854 |
altlinux: CVE-2026-13910 was patched at 2026-07-03
debian: CVE-2026-13910 was patched at 2026-07-05, 2026-07-14
469.
Security Feature Bypass - Chromium (CVE-2026-13913) - High [401]
Description: Insufficient policy enforcement in Autofill in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0024, EPSS Percentile is 0.15228 |
altlinux: CVE-2026-13913 was patched at 2026-07-03
debian: CVE-2026-13913 was patched at 2026-07-05, 2026-07-14
470.
Security Feature Bypass - Chromium (CVE-2026-13917) - High [401]
Description: Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00248, EPSS Percentile is 0.16279 |
altlinux: CVE-2026-13917 was patched at 2026-07-03
debian: CVE-2026-13917 was patched at 2026-07-05, 2026-07-14
471.
Security Feature Bypass - Chromium (CVE-2026-13922) - High [401]
Description: Side-channel information leakage in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00308, EPSS Percentile is 0.23126 |
altlinux: CVE-2026-13922 was patched at 2026-07-03
debian: CVE-2026-13922 was patched at 2026-07-05, 2026-07-14
472.
Security Feature Bypass - Chromium (CVE-2026-13924) - High [401]
Description: Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00315, EPSS Percentile is 0.23902 |
altlinux: CVE-2026-13924 was patched at 2026-07-03
debian: CVE-2026-13924 was patched at 2026-07-05, 2026-07-14
473.
Security Feature Bypass - Chromium (CVE-2026-13926) - High [401]
Description: Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00315, EPSS Percentile is 0.23902 |
altlinux: CVE-2026-13926 was patched at 2026-07-03
debian: CVE-2026-13926 was patched at 2026-07-05, 2026-07-14
474.
Security Feature Bypass - Chromium (CVE-2026-13927) - High [401]
Description: Insufficient validation of untrusted input in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00167, EPSS Percentile is 0.06396 |
altlinux: CVE-2026-13927 was patched at 2026-07-03
debian: CVE-2026-13927 was patched at 2026-07-05, 2026-07-14
475.
Security Feature Bypass - Chromium (CVE-2026-13935) - High [401]
Description: Side-channel information leakage in ComputePressure in Google Chrome prior to 150.0.7871.47 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00308, EPSS Percentile is 0.23124 |
altlinux: CVE-2026-13935 was patched at 2026-07-03
debian: CVE-2026-13935 was patched at 2026-07-05, 2026-07-14
476.
Security Feature Bypass - Chromium (CVE-2026-13962) - High [401]
Description: Insufficient data validation in PDF in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0028, EPSS Percentile is 0.20287 |
altlinux: CVE-2026-13962 was patched at 2026-07-03
debian: CVE-2026-13962 was patched at 2026-07-05, 2026-07-14
477.
Security Feature Bypass - Chromium (CVE-2026-14004) - High [401]
Description: Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.003, EPSS Percentile is 0.22263 |
altlinux: CVE-2026-14004 was patched at 2026-07-03
debian: CVE-2026-14004 was patched at 2026-07-05, 2026-07-14
478.
Security Feature Bypass - Chromium (CVE-2026-14007) - High [401]
Description: Insufficient policy enforcement in PermissionsPolicy in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00264, EPSS Percentile is 0.18154 |
altlinux: CVE-2026-14007 was patched at 2026-07-03
debian: CVE-2026-14007 was patched at 2026-07-05, 2026-07-14
479.
Security Feature Bypass - Chromium (CVE-2026-14021) - High [401]
Description: Insufficient policy enforcement in StorageAccessAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00257, EPSS Percentile is 0.17344 |
altlinux: CVE-2026-14021 was patched at 2026-07-03
debian: CVE-2026-14021 was patched at 2026-07-05, 2026-07-14
480.
Security Feature Bypass - Chromium (CVE-2026-14022) - High [401]
Description: Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00299, EPSS Percentile is 0.22228 |
altlinux: CVE-2026-14022 was patched at 2026-07-03
debian: CVE-2026-14022 was patched at 2026-07-05, 2026-07-14
481.
Security Feature Bypass - Chromium (CVE-2026-14023) - High [401]
Description: Insufficient validation of untrusted input in SanitizerAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00319, EPSS Percentile is 0.24372 |
altlinux: CVE-2026-14023 was patched at 2026-07-03
debian: CVE-2026-14023 was patched at 2026-07-05, 2026-07-14
482.
Security Feature Bypass - Chromium (CVE-2026-14033) - High [401]
Description: Insufficient policy enforcement in Media in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to bypass site isolation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00274, EPSS Percentile is 0.19572 |
altlinux: CVE-2026-14033 was patched at 2026-07-03
debian: CVE-2026-14033 was patched at 2026-07-05, 2026-07-14
483.
Security Feature Bypass - Chromium (CVE-2026-14050) - High [401]
Description: Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00257, EPSS Percentile is 0.17344 |
altlinux: CVE-2026-14050 was patched at 2026-07-03
debian: CVE-2026-14050 was patched at 2026-07-05, 2026-07-14
484.
Security Feature Bypass - Chromium (CVE-2026-14059) - High [401]
Description: Insufficient policy enforcement in Related-Website-Sets in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00257, EPSS Percentile is 0.17344 |
altlinux: CVE-2026-14059 was patched at 2026-07-03
debian: CVE-2026-14059 was patched at 2026-07-05, 2026-07-14
485.
Security Feature Bypass - Chromium (CVE-2026-14065) - High [401]
Description: Insufficient validation of untrusted input in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00319, EPSS Percentile is 0.24335 |
altlinux: CVE-2026-14065 was patched at 2026-07-03
debian: CVE-2026-14065 was patched at 2026-07-05, 2026-07-14
486.
Security Feature Bypass - Chromium (CVE-2026-14074) - High [401]
Description: Side-channel information leakage in WebAuthentication in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00287, EPSS Percentile is 0.20923 |
altlinux: CVE-2026-14074 was patched at 2026-07-03
debian: CVE-2026-14074 was patched at 2026-07-05, 2026-07-14
487.
Security Feature Bypass - Chromium (CVE-2026-14085) - High [401]
Description: Side-channel information leakage in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00257, EPSS Percentile is 0.17344 |
altlinux: CVE-2026-14085 was patched at 2026-07-03
debian: CVE-2026-14085 was patched at 2026-07-05, 2026-07-14
488.
Security Feature Bypass - Chromium (CVE-2026-14146) - High [401]
Description: Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.16977 |
altlinux: CVE-2026-14146 was patched at 2026-07-03
debian: CVE-2026-14146 was patched at 2026-07-05, 2026-07-14
489.
Security Feature Bypass - Chromium (CVE-2026-14151) - High [401]
Description: Inappropriate implementation in AI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12682 |
altlinux: CVE-2026-14151 was patched at 2026-07-03
debian: CVE-2026-14151 was patched at 2026-07-05, 2026-07-14
490.
Security Feature Bypass - Chromium (CVE-2026-14384) - High [401]
Description: Out of bounds read in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.18027 |
altlinux: CVE-2026-14384 was patched at 2026-07-03
debian: CVE-2026-14384 was patched at 2026-07-05, 2026-07-14
491.
Security Feature Bypass - Chromium (CVE-2026-14389) - High [401]
Description: Integer overflow in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14338 |
altlinux: CVE-2026-14389 was patched at 2026-07-03
debian: CVE-2026-14389 was patched at 2026-07-05, 2026-07-14
492.
Security Feature Bypass - Chromium (CVE-2026-14401) - High [401]
Description: Insufficient validation of untrusted input in ANGLE in Google Chrome on Android prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14914 |
altlinux: CVE-2026-14401 was patched at 2026-07-03
debian: CVE-2026-14401 was patched at 2026-07-05, 2026-07-14
493.
Security Feature Bypass - Chromium (CVE-2026-14412) - High [401]
Description: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14914 |
altlinux: CVE-2026-14412 was patched at 2026-07-03
debian: CVE-2026-14412 was patched at 2026-07-05, 2026-07-14
494.
Security Feature Bypass - Chromium (CVE-2026-14413) - High [401]
Description: Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00202, EPSS Percentile is 0.10365 |
altlinux: CVE-2026-14413 was patched at 2026-07-03
debian: CVE-2026-14413 was patched at 2026-07-05, 2026-07-14
495.
Security Feature Bypass - Chromium (CVE-2026-14429) - High [401]
Description: Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00228, EPSS Percentile is 0.13705 |
altlinux: CVE-2026-14429 was patched at 2026-07-03
debian: CVE-2026-14429 was patched at 2026-07-05, 2026-07-14
496.
Security Feature Bypass - Chromium (CVE-2026-15120) - High [401]
Description: Use after free in Core in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00183, EPSS Percentile is 0.08187 |
altlinux: CVE-2026-15120 was patched at 2026-07-09
debian: CVE-2026-15120 was patched at 2026-07-11, 2026-07-14
497.
Security Feature Bypass - Chromium (CVE-2026-15122) - High [401]
Description: Insufficient validation of untrusted input in Codecs in Google Chrome on Windows prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00196, EPSS Percentile is 0.09553 |
altlinux: CVE-2026-15122 was patched at 2026-07-09
debian: CVE-2026-15122 was patched at 2026-07-11, 2026-07-14
498.
Security Feature Bypass - Chromium (CVE-2026-15769) - High [401]
Description: Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14347 |
altlinux: CVE-2026-15769 was patched at 2026-07-15
debian: CVE-2026-15769 was patched at 2026-07-14, 2026-07-16
499.
Security Feature Bypass - Chromium (CVE-2026-15772) - High [401]
Description: Use after free in GPU in Google Chrome on Android prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00218, EPSS Percentile is 0.12446 |
altlinux: CVE-2026-15772 was patched at 2026-07-15
debian: CVE-2026-15772 was patched at 2026-07-14, 2026-07-16
500.
Security Feature Bypass - Chromium (CVE-2026-15774) - High [401]
Description: Use after free in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00218, EPSS Percentile is 0.12446 |
altlinux: CVE-2026-15774 was patched at 2026-07-15
debian: CVE-2026-15774 was patched at 2026-07-14, 2026-07-16
501.
Security Feature Bypass - Chromium (CVE-2026-15778) - High [401]
Description: Insufficient validation of untrusted input in Navigation in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16804 |
altlinux: CVE-2026-15778 was patched at 2026-07-15
debian: CVE-2026-15778 was patched at 2026-07-14, 2026-07-16
502.
Security Feature Bypass - Keycloak (CVE-2026-11800) - High [401]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00181, EPSS Percentile is 0.07926 |
altlinux: CVE-2026-11800 was patched at 2026-06-28, 2026-07-01, 2026-07-02
503.
Security Feature Bypass - OpenSSH (CVE-2026-59999) - High [401]
Description: In sshd in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05561 |
debian: CVE-2026-59999 was patched at 2026-07-14
ubuntu: CVE-2026-59999 was patched at 2026-07-30
504.
Remote Code Execution - Linux Kernel (CVE-2026-53334) - High [400]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02091 |
altlinux: CVE-2026-53334 was patched at 2026-06-19, 2026-06-22, 2026-07-06
505.
Remote Code Execution - Linux Kernel (CVE-2026-53335) - High [400]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02101 |
altlinux: CVE-2026-53335 was patched at 2026-06-19, 2026-06-22, 2026-07-06
506.
Security Feature Bypass - Jackson-databind (CVE-2026-54513) - Medium [398]
Description: jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.allowIfSubTypeIsArray() allowlists any array type based only on clazz.isArray(), without validating the array's component (element) type against the configured allowlist. A PTV built with allowIfSubTypeIsArray() plus an explicit concrete-type allowlist therefore still permits EvilType[] even though EvilType is not allowlisted. When Jackson deserializes the elements and no per-element type IDs are present, it instantiates the component type directly with no further PTV check, bypassing the allowlist. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:fasterxml:jackson-databind (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00712, EPSS Percentile is 0.49995 |
almalinux: CVE-2026-54513 was patched at 2026-07-16, 2026-07-22
debian: CVE-2026-54513 was patched at 2026-07-14
oraclelinux: CVE-2026-54513 was patched at 2026-07-20, 2026-07-23
redhat: CVE-2026-54513 was patched at 2026-07-16, 2026-07-22, 2026-07-23
507.
Server-Side Request Forgery - Roundcube (CVE-2026-62643) - Medium [398]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.6 | 14 | Roundcube is a web-based IMAP email client | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00246, EPSS Percentile is 0.16028 |
altlinux: CVE-2026-62643 was patched at 2026-07-10, 2026-07-15
debian: CVE-2026-62643 was patched at 2026-07-14, 2026-07-19
508.
Remote Code Execution - ImageMagick (CVE-2026-61861) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.24835 |
altlinux: CVE-2026-61861 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-61861 was patched at 2026-07-14
509.
Server-Side Request Forgery - Angular (CVE-2026-41423) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00305, EPSS Percentile is 0.22818 |
debian: CVE-2026-41423 was patched at 2026-06-24
510.
Server-Side Request Forgery - Angular (CVE-2026-46417) - Medium [397]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12768 |
debian: CVE-2026-46417 was patched at 2026-06-24
511.
Arbitrary File Writing - libzypp (CVE-2026-25707) - Medium [395]
Description: A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.95 | 15 | Arbitrary File Writing | |
| 0.5 | 14 | Product detected by a:opensuse:libzypp (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00421, EPSS Percentile is 0.34666 |
debian: CVE-2026-25707 was patched at 2026-07-14
512.
Denial of Service - HTTP/2 (CVE-2026-54340) - Medium [394]
Description: h2o is an HTTP server with support for HTTP/1.x,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | HTTP/2 is a major revision of the HTTP network protocol used by the World Wide Web | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00279, EPSS Percentile is 0.20146 |
debian: CVE-2026-54340 was patched at 2026-07-14
513.
Memory Corruption - GPAC (CVE-2026-15185) - Medium [394]
Description: A vulnerability was determined in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 1.0 | 17 | The existence of a publicly available exploit is mentioned on BDU:PublicExploit website | |
| 0.5 | 15 | Memory Corruption | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01616 |
debian: CVE-2026-15185 was patched at 2026-07-14
514.
Memory Corruption - Linux Kernel (CVE-2026-53198) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00435, EPSS Percentile is 0.35758 |
altlinux: CVE-2026-53198 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53198 was patched at 2026-07-14
515.
Memory Corruption - Linux Kernel (CVE-2026-53224) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00517, EPSS Percentile is 0.4111 |
altlinux: CVE-2026-53224 was patched at 2026-06-19, 2026-06-22, 2026-07-06
debian: CVE-2026-53224 was patched at 2026-07-14
516.
Memory Corruption - Linux Kernel (CVE-2026-53260) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00369, EPSS Percentile is 0.29552 |
altlinux: CVE-2026-53260 was patched at 2026-06-19
debian: CVE-2026-53260 was patched at 2026-07-14
517.
Memory Corruption - Linux Kernel (CVE-2026-53355) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00399, EPSS Percentile is 0.32659 |
altlinux: CVE-2026-53355 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53355 was patched at 2026-07-14
518.
Memory Corruption - Linux Kernel (CVE-2026-53383) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0069, EPSS Percentile is 0.49184 |
debian: CVE-2026-53383 was patched at 2026-07-14, 2026-07-30
519.
Memory Corruption - Linux Kernel (CVE-2026-63796) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00455, EPSS Percentile is 0.3727 |
debian: CVE-2026-63796 was patched at 2026-07-14, 2026-07-30
520.
Memory Corruption - Linux Kernel (CVE-2026-63801) - Medium [394]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00486, EPSS Percentile is 0.39225 |
debian: CVE-2026-63801 was patched at 2026-07-14, 2026-07-30
521.
Authentication Bypass - Gogs (CVE-2025-64175) - Medium [392]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00424, EPSS Percentile is 0.34894 |
altlinux: CVE-2025-64175 was patched at 2026-06-25
522.
Remote Code Execution - Kotlin (CVE-2026-53914) - Medium [392]
Description: In JetBrains Kotlin before 2.4.20
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:jetbrains:kotlin (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00196, EPSS Percentile is 0.09554 |
altlinux: CVE-2026-53914 was patched at 2026-06-26, 2026-07-06
523.
Remote Code Execution - jupyter_server (CVE-2026-44727) - Medium [392]
Description: Jupyter Server is the backend for Jupyter web applications. Prior to 2.20, the nbconvert HTTP handlers in jupyter_server render user-authored notebook HTML under the Jupyter origin without a sandbox directive in their Content-Security-Policy. Combined with nbconvert.HTMLExporter's default non-sanitizing behavior, a notebook carrying an HTML payload in a display_data output triggers stored XSS with cookie access, full /api/* authority, and kernel
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:jupyter:jupyter_server (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.0. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00305, EPSS Percentile is 0.22866 |
altlinux: CVE-2026-44727 was patched at 2026-06-18
debian: CVE-2026-44727 was patched at 2026-07-14
524.
Authentication Bypass - Chromium (CVE-2026-13914) - Medium [391]
Description: Inappropriate implementation in Passwords in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via a malicious file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.05967 |
altlinux: CVE-2026-13914 was patched at 2026-07-03
debian: CVE-2026-13914 was patched at 2026-07-05, 2026-07-14
525.
Authentication Bypass - Chromium (CVE-2026-13933) - Medium [391]
Description: Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00271, EPSS Percentile is 0.19329 |
altlinux: CVE-2026-13933 was patched at 2026-07-03
debian: CVE-2026-13933 was patched at 2026-07-05, 2026-07-14
526.
Denial of Service - Apache ActiveMQ (CVE-2026-53917) - Medium [391]
Description: Memory Allocation with Excessive Size Value vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.01177, EPSS Percentile is 0.64453 |
debian: CVE-2026-53917 was patched at 2026-07-14
527.
Security Feature Bypass - Perl (CVE-2026-11625) - Medium [391]
Description: Bytes::Random::Secure versions through 0.29 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00339, EPSS Percentile is 0.26502 |
debian: CVE-2026-11625 was patched at 2026-07-14
528.
Information Disclosure - Angular (CVE-2026-50169) - Medium [389]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06117 |
debian: CVE-2026-50169 was patched at 2026-06-24
529.
Information Disclosure - Angular (CVE-2026-54264) - Medium [389]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14632 |
debian: CVE-2026-54264 was patched at 2026-06-24
530.
Memory Corruption - OpenSSL (CVE-2026-9265) - Medium [389]
Description: Crypt::
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00632, EPSS Percentile is 0.4677 |
debian: CVE-2026-9265 was patched at 2026-06-24
531.
Security Feature Bypass - Chromium (CVE-2026-13822) - Medium [389]
Description: Inappropriate implementation in Extensions in Google Chrome on Android prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06055 |
altlinux: CVE-2026-13822 was patched at 2026-07-03
debian: CVE-2026-13822 was patched at 2026-07-05, 2026-07-14
532.
Security Feature Bypass - Chromium (CVE-2026-13826) - Medium [389]
Description: Inappropriate implementation in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.13986 |
altlinux: CVE-2026-13826 was patched at 2026-07-03
debian: CVE-2026-13826 was patched at 2026-07-05, 2026-07-14
533.
Security Feature Bypass - Chromium (CVE-2026-13838) - Medium [389]
Description: Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00224, EPSS Percentile is 0.13199 |
altlinux: CVE-2026-13838 was patched at 2026-07-03
debian: CVE-2026-13838 was patched at 2026-07-05, 2026-07-14
534.
Security Feature Bypass - Chromium (CVE-2026-13839) - Medium [389]
Description: Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00224, EPSS Percentile is 0.13199 |
altlinux: CVE-2026-13839 was patched at 2026-07-03
debian: CVE-2026-13839 was patched at 2026-07-05, 2026-07-14
535.
Security Feature Bypass - Chromium (CVE-2026-13868) - Medium [389]
Description: Inappropriate implementation in Network in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.12072 |
altlinux: CVE-2026-13868 was patched at 2026-07-03
debian: CVE-2026-13868 was patched at 2026-07-05, 2026-07-14
536.
Security Feature Bypass - Chromium (CVE-2026-13876) - Medium [389]
Description: Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to bypass content security policy via malicious network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00227, EPSS Percentile is 0.13575 |
altlinux: CVE-2026-13876 was patched at 2026-07-03
debian: CVE-2026-13876 was patched at 2026-07-05, 2026-07-14
537.
Security Feature Bypass - Chromium (CVE-2026-13881) - Medium [389]
Description: Inappropriate implementation in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.1152 |
altlinux: CVE-2026-13881 was patched at 2026-07-03
debian: CVE-2026-13881 was patched at 2026-07-05, 2026-07-14
538.
Security Feature Bypass - Chromium (CVE-2026-13887) - Medium [389]
Description: Inappropriate implementation in NFC in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.13986 |
altlinux: CVE-2026-13887 was patched at 2026-07-03
debian: CVE-2026-13887 was patched at 2026-07-05, 2026-07-14
539.
Security Feature Bypass - Chromium (CVE-2026-13894) - Medium [389]
Description: Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00212, EPSS Percentile is 0.11638 |
altlinux: CVE-2026-13894 was patched at 2026-07-03
debian: CVE-2026-13894 was patched at 2026-07-05, 2026-07-14
540.
Security Feature Bypass - Chromium (CVE-2026-13908) - Medium [389]
Description: Insufficient validation of untrusted input in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via malicious network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13878 |
altlinux: CVE-2026-13908 was patched at 2026-07-03
debian: CVE-2026-13908 was patched at 2026-07-05, 2026-07-14
541.
Security Feature Bypass - Chromium (CVE-2026-13990) - Medium [389]
Description: Insufficient validation of untrusted input in DataTransfer in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00194, EPSS Percentile is 0.09376 |
altlinux: CVE-2026-13990 was patched at 2026-07-03
debian: CVE-2026-13990 was patched at 2026-07-05, 2026-07-14
542.
Security Feature Bypass - Chromium (CVE-2026-14015) - Medium [389]
Description: Race in WebRTC in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10681 |
altlinux: CVE-2026-14015 was patched at 2026-07-03
debian: CVE-2026-14015 was patched at 2026-07-05, 2026-07-14
543.
Security Feature Bypass - Chromium (CVE-2026-14016) - Medium [389]
Description: Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00198, EPSS Percentile is 0.09821 |
altlinux: CVE-2026-14016 was patched at 2026-07-03
debian: CVE-2026-14016 was patched at 2026-07-05, 2026-07-14
544.
Security Feature Bypass - Chromium (CVE-2026-14060) - Medium [389]
Description: Insufficient validation of untrusted input in Chromoting in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform privilege escalation via a malicious file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02986 |
altlinux: CVE-2026-14060 was patched at 2026-07-03
debian: CVE-2026-14060 was patched at 2026-07-05, 2026-07-14
545.
Security Feature Bypass - Chromium (CVE-2026-14071) - Medium [389]
Description: Side-channel information leakage in WebAudio in Google Chrome prior to 150.0.7871.47 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00238, EPSS Percentile is 0.14981 |
altlinux: CVE-2026-14071 was patched at 2026-07-03
debian: CVE-2026-14071 was patched at 2026-07-05, 2026-07-14
546.
Security Feature Bypass - Chromium (CVE-2026-14081) - Medium [389]
Description: Insufficient policy enforcement in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00181, EPSS Percentile is 0.07967 |
altlinux: CVE-2026-14081 was patched at 2026-07-03
debian: CVE-2026-14081 was patched at 2026-07-05, 2026-07-14
547.
Security Feature Bypass - Chromium (CVE-2026-14082) - Medium [389]
Description: Race in Storage in Google Chrome prior to 150.0.7871.47 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00218, EPSS Percentile is 0.12364 |
altlinux: CVE-2026-14082 was patched at 2026-07-03
debian: CVE-2026-14082 was patched at 2026-07-05, 2026-07-14
548.
Security Feature Bypass - Chromium (CVE-2026-14096) - Medium [389]
Description: Inappropriate implementation in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13859 |
altlinux: CVE-2026-14096 was patched at 2026-07-03
debian: CVE-2026-14096 was patched at 2026-07-05, 2026-07-14
549.
Security Feature Bypass - Chromium (CVE-2026-14098) - Medium [389]
Description: Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00238, EPSS Percentile is 0.1498 |
altlinux: CVE-2026-14098 was patched at 2026-07-03
debian: CVE-2026-14098 was patched at 2026-07-05, 2026-07-14
550.
Security Feature Bypass - Chromium (CVE-2026-14100) - Medium [389]
Description: Insufficient data validation in NetworkCache in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00238, EPSS Percentile is 0.1498 |
altlinux: CVE-2026-14100 was patched at 2026-07-03
debian: CVE-2026-14100 was patched at 2026-07-05, 2026-07-14
551.
Security Feature Bypass - Chromium (CVE-2026-14396) - Medium [389]
Description: Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00238, EPSS Percentile is 0.1495 |
altlinux: CVE-2026-14396 was patched at 2026-07-03
debian: CVE-2026-14396 was patched at 2026-07-05, 2026-07-14
552.
Security Feature Bypass - Chromium (CVE-2026-15119) - Medium [389]
Description: Race in GetUserMedia in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who had compromised the renderer process to potentially
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00151, EPSS Percentile is 0.04804 |
altlinux: CVE-2026-15119 was patched at 2026-07-09
debian: CVE-2026-15119 was patched at 2026-07-11, 2026-07-14
553.
Security Feature Bypass - Chromium (CVE-2026-15768) - Medium [389]
Description: Insufficient policy enforcement in HTML-in-Canvas in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12781 |
altlinux: CVE-2026-15768 was patched at 2026-07-15
debian: CVE-2026-15768 was patched at 2026-07-14, 2026-07-16
554.
Security Feature Bypass - Chromium (CVE-2026-15775) - Medium [389]
Description: Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12781 |
altlinux: CVE-2026-15775 was patched at 2026-07-15
debian: CVE-2026-15775 was patched at 2026-07-14, 2026-07-16
555.
Security Feature Bypass - OpenSSL (CVE-2026-55961) - Medium [389]
Description: wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an object has empty signerInfos, so the underlying signed-data verification succeeds without authenticating any content. The compatibility-layer verify path now rejects the object when no signer signature has actually been verified, so a PKCS#7 carrying no valid signature is no longer reported as verified. This is enforced regardless of the PKCS7_NOVERIFY flag, which only suppresses signer certificate chain validation and was never intended to waive the requirement that a signature exist. Only affects
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00146, EPSS Percentile is 0.04366 |
debian: CVE-2026-55961 was patched at 2026-07-14
556.
Security Feature Bypass - OpenSSL (CVE-2026-6331) - Medium [389]
Description: HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-length tag could be accepted as valid during HMAC verification. In the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00148, EPSS Percentile is 0.04488 |
debian: CVE-2026-6331 was patched at 2026-07-14
557.
Information Disclosure - Chromium (CVE-2026-13810) - Medium [388]
Description: Inappropriate implementation in Input in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00308, EPSS Percentile is 0.23123 |
altlinux: CVE-2026-13810 was patched at 2026-07-03
debian: CVE-2026-13810 was patched at 2026-07-05, 2026-07-14
558.
Information Disclosure - Keycloak (CVE-2026-9083) - Medium [388]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00519, EPSS Percentile is 0.41188 |
altlinux: CVE-2026-9083 was patched at 2026-06-28, 2026-07-01, 2026-07-02
559.
Information Disclosure - Keycloak (CVE-2026-9705) - Medium [388]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00267, EPSS Percentile is 0.18757 |
altlinux: CVE-2026-9705 was patched at 2026-06-28, 2026-07-01, 2026-07-02
560.
Authentication Bypass - MediaWiki (CVE-2026-58029) - Medium [386]
Description: Vulnerability in Wikimedia Foundation
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12814 |
debian: CVE-2026-58029 was patched at 2026-07-05, 2026-07-14
561.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-35275) - Medium [386]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00147, EPSS Percentile is 0.04467 |
altlinux: CVE-2026-35275 was patched at 2026-06-29
562.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-46873) - Medium [386]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.0173 |
altlinux: CVE-2026-46873 was patched at 2026-06-29
563.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-46974) - Medium [386]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0014, EPSS Percentile is 0.03849 |
altlinux: CVE-2026-46974 was patched at 2026-06-29
564.
Security Feature Bypass - Electron (CVE-2022-29257) - Medium [386]
Description: Electron is a framework for writing cross-platform desktop applications using JavaScript (JS), HTML, and CSS. A vulnerability in versions prior to 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 allows attackers who have control over a given apps update server / update storage to serve maliciously crafted update packages that pass the code signing validation check but contain malicious code in some components. This kind of attack would require significant privileges in a potential victim's own auto updating infrastructure and the ease of that attack entirely depends on the potential victim's infrastructure security. Electron versions 18.0.0-beta.6, 17.2.0, 16.2.6, and 15.5.5 contain a fix for this issue. There are no known workarounds.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:electronjs:electron (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.2. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0085, EPSS Percentile is 0.54557 |
altlinux: CVE-2022-29257 was patched at 2026-06-20
565.
Code Injection - Calibre (CVE-2026-53511) - Medium [385]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.7 | 14 | Calibre is a cross-platform free and open-source suite of e-book software | |
| 0.8 | 10 | CVSS Base Score is 8.5. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00149, EPSS Percentile is 0.0464 |
debian: CVE-2026-53511 was patched at 2026-07-14
566.
Cross Site Scripting - Roundcube (CVE-2026-54433) - Medium [385]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Roundcube is a web-based IMAP email client | |
| 1.0 | 10 | CVSS Base Score is 10.0. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00312, EPSS Percentile is 0.2361 |
altlinux: CVE-2026-54433 was patched at 2026-07-10, 2026-07-15
debian: CVE-2026-54433 was patched at 2026-07-14, 2026-07-19
567.
Denial of Service - Grafana (CVE-2026-27878) - Medium [385]
Description: A TraceQL query in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.85 | 14 | Grafana is an open-source analytics and monitoring platform that provides dashboards and visualization tools for metrics collected from various data sources. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00411, EPSS Percentile is 0.33775 |
redos: CVE-2026-27878 was patched at 2026-06-26
568.
Denial of Service - Grafana (CVE-2026-28376) - Medium [385]
Description: The
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.85 | 14 | Grafana is an open-source analytics and monitoring platform that provides dashboards and visualization tools for metrics collected from various data sources. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25386 |
redos: CVE-2026-28376 was patched at 2026-07-07
569.
Cross Site Scripting - Angular (CVE-2026-50555) - Medium [384]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06411 |
debian: CVE-2026-50555 was patched at 2026-06-24
570.
Cross Site Scripting - Angular (CVE-2026-50557) - Medium [384]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00203, EPSS Percentile is 0.1048 |
debian: CVE-2026-50557 was patched at 2026-06-24
571.
Cross Site Scripting - Angular (CVE-2026-52725) - Medium [384]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14564 |
debian: CVE-2026-52725 was patched at 2026-06-24
572.
Cross Site Scripting - Angular (CVE-2026-54265) - Medium [384]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00203, EPSS Percentile is 0.1048 |
debian: CVE-2026-54265 was patched at 2026-06-24
573.
Cross Site Scripting - Angular (CVE-2026-54267) - Medium [384]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00181, EPSS Percentile is 0.0791 |
debian: CVE-2026-54267 was patched at 2026-06-24
574.
Denial of Service - Apache Traffic Server (CVE-2026-59173) - Medium [384]
Description: Uncontrolled Resource Consumption vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | The Apache Traffic Server is a modular, high-performance reverse proxy and forward proxy server, generally comparable to Nginx and Squid | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00505, EPSS Percentile is 0.40365 |
debian: CVE-2026-59173 was patched at 2026-07-14
575.
Denial of Service - Oracle MySQL (CVE-2026-46863) - Medium [384]
Description: Vulnerability in the MySQL Server, MySQL Cluster product of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | MySQL is an open-source relational database management system | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00471, EPSS Percentile is 0.38225 |
altlinux: CVE-2026-46863 was patched at 2026-06-30
ubuntu: CVE-2026-46863 was patched at 2026-07-30
576.
Information Disclosure - Asterisk (CVE-2026-57231) - Medium [383]
Description: Podman is a tool for managing OCI containers and pods. From 1.8.1 until 5.8.4, a container image that contains a environment variable with just a key and no value can trick podman into passing that variable from the host into the container. This is made worse by the fact that using an
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.7 | 14 | Asterisk is a free and open source framework for building communications applications and is sponsored by Sangoma | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00312, EPSS Percentile is 0.23595 |
almalinux: CVE-2026-57231 was patched at 2026-07-09, 2026-07-13
altlinux: CVE-2026-57231 was patched at 2026-07-28
debian: CVE-2026-57231 was patched at 2026-07-14
oraclelinux: CVE-2026-57231 was patched at 2026-07-10, 2026-07-15, 2026-07-23
redhat: CVE-2026-57231 was patched at 2026-07-09, 2026-07-13
577.
Authentication Bypass - Perl (CVE-2026-56016) - Medium [382]
Description: CGI::Session::ID::md5 versions before 4.49 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00361, EPSS Percentile is 0.28864 |
debian: CVE-2026-56016 was patched at 2026-07-14
578.
Authentication Bypass - Perl (CVE-2026-7017) - Medium [382]
Description: HTTP::Tiny versions before 0.095 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00257, EPSS Percentile is 0.17349 |
debian: CVE-2026-7017 was patched at 2026-07-14
579.
Authentication Bypass - Puma (CVE-2026-47737) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | Puma is a Ruby/Rack web server built for parallelism | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07536 |
debian: CVE-2026-47737 was patched at 2026-07-14
580.
Authentication Bypass - pgAdmin (CVE-2026-1707) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.6 | 14 | pgAdmin is the most popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00392, EPSS Percentile is 0.31948 |
redos: CVE-2026-1707 was patched at 2026-06-23
581.
Incorrect Calculation - Linux Kernel (CVE-2026-53176) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00732, EPSS Percentile is 0.50749 |
altlinux: CVE-2026-53176 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53176 was patched at 2026-07-14
582.
Memory Corruption - Linux Kernel (CVE-2026-53240) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0039, EPSS Percentile is 0.31757 |
altlinux: CVE-2026-53240 was patched at 2026-06-19, 2026-06-22, 2026-07-06
583.
Memory Corruption - Linux Kernel (CVE-2026-53248) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00353, EPSS Percentile is 0.28035 |
altlinux: CVE-2026-53248 was patched at 2026-06-19, 2026-06-22, 2026-07-06
584.
Memory Corruption - Linux Kernel (CVE-2026-53390) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0047, EPSS Percentile is 0.3819 |
debian: CVE-2026-53390 was patched at 2026-07-14, 2026-07-30
585.
Memory Corruption - Linux Kernel (CVE-2026-53391) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00517, EPSS Percentile is 0.41078 |
debian: CVE-2026-53391 was patched at 2026-07-14, 2026-07-30
586.
Memory Corruption - Linux Kernel (CVE-2026-53392) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00501, EPSS Percentile is 0.40113 |
debian: CVE-2026-53392 was patched at 2026-07-14, 2026-07-21
587.
Memory Corruption - Linux Kernel (CVE-2026-63915) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.27122 |
debian: CVE-2026-63915 was patched at 2026-07-14
ubuntu: CVE-2026-63915 was patched at 2026-07-30
588.
Memory Corruption - Linux Kernel (CVE-2026-63916) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.27122 |
debian: CVE-2026-63916 was patched at 2026-07-14
ubuntu: CVE-2026-63916 was patched at 2026-07-30
589.
Memory Corruption - Linux Kernel (CVE-2026-63946) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00327, EPSS Percentile is 0.25278 |
debian: CVE-2026-63946 was patched at 2026-07-14
ubuntu: CVE-2026-63946 was patched at 2026-07-30
590.
Memory Corruption - Linux Kernel (CVE-2026-63947) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00337, EPSS Percentile is 0.26273 |
debian: CVE-2026-63947 was patched at 2026-07-14
ubuntu: CVE-2026-63947 was patched at 2026-07-30
591.
Memory Corruption - Linux Kernel (CVE-2026-64116) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00511, EPSS Percentile is 0.40742 |
debian: CVE-2026-64116 was patched at 2026-07-14
ubuntu: CVE-2026-64116 was patched at 2026-07-30
592.
Memory Corruption - Linux Kernel (CVE-2026-64141) - Medium [382]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00441, EPSS Percentile is 0.36198 |
debian: CVE-2026-64141 was patched at 2026-07-14
ubuntu: CVE-2026-64141 was patched at 2026-07-30
593.
Elevation of Privilege - Chromium (CVE-2026-13827) - Medium [380]
Description: Use after free in Updater in Google Chrome on Mac prior to 150.0.7871.47 allowed a local attacker to perform
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00147, EPSS Percentile is 0.04433 |
altlinux: CVE-2026-13827 was patched at 2026-07-03
debian: CVE-2026-13827 was patched at 2026-07-05, 2026-07-14
594.
Elevation of Privilege - Chromium (CVE-2026-13844) - Medium [380]
Description: Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00147, EPSS Percentile is 0.04433 |
altlinux: CVE-2026-13844 was patched at 2026-07-03
debian: CVE-2026-13844 was patched at 2026-07-05, 2026-07-14
595.
Elevation of Privilege - Chromium (CVE-2026-14018) - Medium [380]
Description: Use after free in Updater in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00108, EPSS Percentile is 0.01391 |
altlinux: CVE-2026-14018 was patched at 2026-07-03
debian: CVE-2026-14018 was patched at 2026-07-05, 2026-07-14
596.
Elevation of Privilege - Chromium (CVE-2026-14094) - Medium [380]
Description: Use after free in Installer in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00092, EPSS Percentile is 0.00639 |
altlinux: CVE-2026-14094 was patched at 2026-07-03
debian: CVE-2026-14094 was patched at 2026-07-05, 2026-07-14
597.
Elevation of Privilege - Chromium (CVE-2026-14124) - Medium [380]
Description: Inappropriate implementation in CredentialProvider in Google Chrome on Windows prior to 150.0.7871.47 allowed a local attacker to perform OS-level
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00102, EPSS Percentile is 0.01088 |
altlinux: CVE-2026-14124 was patched at 2026-07-03
debian: CVE-2026-14124 was patched at 2026-07-05, 2026-07-14
598.
Elevation of Privilege - Keycloak (CVE-2026-9796) - Medium [380]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00186, EPSS Percentile is 0.08515 |
altlinux: CVE-2026-9796 was patched at 2026-07-11, 2026-07-13, 2026-07-14, 2026-07-16
599.
Remote Code Execution - Gawk (CVE-2026-40553) - Medium [380]
Description: Buffer overflow vulnerability has been found in "extension/readdir.c" program file of gawk (ftype() routine). This issue could be used to crash the program and potentially to achieve
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:fossies:gawk (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.21317 |
debian: CVE-2026-40553 was patched at 2026-07-14
ubuntu: CVE-2026-40553 was patched at 2026-07-30
600.
Authentication Bypass - Keycloak (CVE-2026-9689) - Medium [379]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00258, EPSS Percentile is 0.1746 |
altlinux: CVE-2026-9689 was patched at 2026-07-11, 2026-07-13, 2026-07-14, 2026-07-16
601.
Authentication Bypass - Keycloak (CVE-2026-9798) - Medium [379]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00262, EPSS Percentile is 0.17917 |
altlinux: CVE-2026-9798 was patched at 2026-07-11, 2026-07-13, 2026-07-14, 2026-07-16
602.
Authentication Bypass - Keycloak (CVE-2026-9799) - Medium [379]
Description: A flaw was found in org.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06288 |
altlinux: CVE-2026-9799 was patched at 2026-06-28, 2026-07-01, 2026-07-02
603.
Information Disclosure - Python (CVE-2026-49853) - Medium [379]
Description: Tornado is a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00365, EPSS Percentile is 0.29178 |
debian: CVE-2026-49853 was patched at 2026-07-14
604.
Security Feature Bypass - Perl (CVE-2026-13577) - Medium [379]
Description: Dancer2 versions through 2.1.0 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00289, EPSS Percentile is 0.21222 |
debian: CVE-2026-13577 was patched at 2026-07-14
605.
Security Feature Bypass - Perl (CVE-2026-14570) - Medium [379]
Description: Crypt::DSA versions before 1.22 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00315, EPSS Percentile is 0.23912 |
debian: CVE-2026-14570 was patched at 2026-07-14
606.
Information Disclosure - Angular (CVE-2026-50184) - Medium [377]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00151, EPSS Percentile is 0.04766 |
debian: CVE-2026-50184 was patched at 2026-06-24
607.
Memory Corruption - Safari (CVE-2026-43705) - Medium [377]
Description: A type confusion issue was addressed with improved checks. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00447, EPSS Percentile is 0.36707 |
almalinux: CVE-2026-43705 was patched at 2026-07-20
debian: CVE-2026-43705 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43705 was patched at 2026-07-20
redhat: CVE-2026-43705 was patched at 2026-07-20
608.
Security Feature Bypass - Chromium (CVE-2026-13875) - Medium [377]
Description: Insufficient validation of untrusted input in GPU in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0029, EPSS Percentile is 0.21278 |
altlinux: CVE-2026-13875 was patched at 2026-07-03
debian: CVE-2026-13875 was patched at 2026-07-05, 2026-07-14
609.
Security Feature Bypass - Chromium (CVE-2026-13877) - Medium [377]
Description: Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00281, EPSS Percentile is 0.20328 |
altlinux: CVE-2026-13877 was patched at 2026-07-03
debian: CVE-2026-13877 was patched at 2026-07-05, 2026-07-14
610.
Security Feature Bypass - Chromium (CVE-2026-13911) - Medium [377]
Description: Insufficient policy enforcement in Spellcheck in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.22401 |
altlinux: CVE-2026-13911 was patched at 2026-07-03
debian: CVE-2026-13911 was patched at 2026-07-05, 2026-07-14
611.
Security Feature Bypass - Chromium (CVE-2026-13929) - Medium [377]
Description: Insufficient policy enforcement in DevTools in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to bypass navigation restrictions via a malicious file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00181, EPSS Percentile is 0.07997 |
altlinux: CVE-2026-13929 was patched at 2026-07-03
debian: CVE-2026-13929 was patched at 2026-07-05, 2026-07-14
612.
Security Feature Bypass - Chromium (CVE-2026-13961) - Medium [377]
Description: Insufficient validation of untrusted input in DevTools in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00281, EPSS Percentile is 0.20328 |
altlinux: CVE-2026-13961 was patched at 2026-07-03
debian: CVE-2026-13961 was patched at 2026-07-05, 2026-07-14
613.
Security Feature Bypass - Chromium (CVE-2026-13976) - Medium [377]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07793 |
altlinux: CVE-2026-13976 was patched at 2026-07-03
debian: CVE-2026-13976 was patched at 2026-07-05, 2026-07-14
614.
Security Feature Bypass - Chromium (CVE-2026-14083) - Medium [377]
Description: Insufficient validation of untrusted input in HTML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00189, EPSS Percentile is 0.08854 |
altlinux: CVE-2026-14083 was patched at 2026-07-03
debian: CVE-2026-14083 was patched at 2026-07-05, 2026-07-14
615.
Security Feature Bypass - Chromium (CVE-2026-15771) - Medium [377]
Description: Insufficient validation of untrusted input in Media in Google Chrome on Windows prior to 150.0.7871.125 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00282, EPSS Percentile is 0.20499 |
altlinux: CVE-2026-15771 was patched at 2026-07-15
debian: CVE-2026-15771 was patched at 2026-07-14, 2026-07-16
616.
Security Feature Bypass - OpenSSL (CVE-2026-6091) - Medium [377]
Description: Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certificate rather than a trusted anchor. An attacker could present a chain that ends at an intermediate they control and have it accepted as valid. This affects the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02244 |
debian: CVE-2026-6091 was patched at 2026-07-14
617.
Information Disclosure - Chromium (CVE-2026-14062) - Medium [376]
Description: Inappropriate implementation in Views in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0024, EPSS Percentile is 0.15205 |
altlinux: CVE-2026-14062 was patched at 2026-07-03
debian: CVE-2026-14062 was patched at 2026-07-05, 2026-07-14
618.
Authentication Bypass - Minio (CVE-2026-34204) - Medium [375]
Description: MinIO is a high-performance object storage system. Prior to version RELEASE.2026-03-26T21-24-40Z, a flaw in extractMetadataFromMime() allows any authenticated user with s3:PutObject permission to inject internal server-side encryption metadata into objects by sending crafted X-
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Minio is a Multi-Cloud Object Storage framework | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02531 |
redos: CVE-2026-34204 was patched at 2026-07-14
619.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-46825) - Medium [375]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05537 |
altlinux: CVE-2026-46825 was patched at 2026-06-29
620.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-46877) - Medium [375]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00167, EPSS Percentile is 0.06304 |
altlinux: CVE-2026-46877 was patched at 2026-06-29
621.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-47050) - Medium [375]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00145, EPSS Percentile is 0.04279 |
altlinux: CVE-2026-47050 was patched at 2026-06-29
622.
Code Injection - Cacti (CVE-2026-39951) - Medium [375]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12763 |
altlinux: CVE-2026-39951 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-39951 was patched at 2026-07-14
623.
Command Injection - Unknown Product (CVE-2026-60102) - Medium [375]
Description: {'nvd_cve_data_all': 'Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShellCommand() method fails to sanitize command substitution sequences, allowing authenticated attackers to inject arbitrary shell commands through user-controlled filenames. Attackers can supply malicious filenames containing unescaped command substitution payloads through operations such as file upload, folder creation, rename, or deletion, which are interpolated into a double-quoted shell context and executed via proc_open() through /bin/sh -c before smbclient runs, resulting in arbitrary command execution on the underlying system.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShellCommand() method fails to sanitize command substitution sequences, allowing authenticated attackers to inject arbitrary shell commands through user-controlled filenames. Attackers can supply malicious filenames containing unescaped command substitution payloads through operations such as file upload, folder creation, rename, or deletion, which are interpolated into a double-quoted shell context and executed via proc_open() through /bin/sh -c before smbclient runs, resulting in arbitrary command execution on the underlying system.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.8 | 10 | EPSS Probability is 0.01761, EPSS Percentile is 0.75755 |
debian: CVE-2026-60102 was patched at 2026-07-14
624.
Path Traversal - DCMTK (CVE-2026-50003) - Medium [375]
Description: A malicious or compromised server can make a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | DCMTK (DICOM Toolkit) is an open-source collection of libraries and applications implementing large parts of the DICOM standard, including image processing, storage, and network services for medical imaging. | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00497, EPSS Percentile is 0.39881 |
debian: CVE-2026-50003 was patched at 2026-07-14
625.
Security Feature Bypass - freeswitch (CVE-2026-49840) - Medium [375]
Description: FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, esl_recv_event() parses Content-Length with atol() and passes the result straight to malloc(len + 1) with no sign or magnitude check. A malicious or man-in-the-middle ESL peer can send a frame with a negative Content-Length to corrupt the heap of, or crash, any process linked against libesl, before the client has authenticated to that peer. This issue has been patched in version 1.11.1.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:freeswitch:freeswitch (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0031, EPSS Percentile is 0.23368 |
altlinux: CVE-2026-49840 was patched at 2026-06-24, 2026-06-26, 2026-07-16
626.
Security Feature Bypass - undici (CVE-2026-6734) - Medium [375]
Description: Impact: When using Socks5ProxyAgent, undici reuses a single connection pool across different origins without verifying that the pool's origin matches the requested origin. All requests are dispatched through the pool connected to the first origin, regardless of the intended destination. This causes cross-origin request routing: credentials and request data intended for origin B are sent to origin A, responses from the wrong origin are trusted, and HTTPS requests may be silently downgraded to HTTP. Impacted users are applications that use Socks5ProxyAgent (directly or via setGlobalDispatcher) and make requests to more than one origin. This was introduced in undici 7.23.0 via PR #4385 and affects all versions through 8.1.0. Patches: Upgrade to undici v7.26.0 or v8.2.0. Workarounds: Use a separate Socks5ProxyAgent instance per origin, or avoid using Socks5ProxyAgent with multiple origins.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.27152 |
almalinux: CVE-2026-6734 was patched at 2026-07-06, 2026-07-15
debian: CVE-2026-6734 was patched at 2026-06-24
oraclelinux: CVE-2026-6734 was patched at 2026-07-07, 2026-07-20
redhat: CVE-2026-6734 was patched at 2026-07-06, 2026-07-15
627.
Security Feature Bypass - undici (CVE-2026-9697) - Medium [375]
Description: Impact: undici's ProxyAgent silently drops the requestTls option when configured with a SOCKS5 proxy URI (socks5:// or socks://). The target HTTPS connection through the SOCKS5 tunnel falls back to Node's default trust store, ignoring user-configured ca, cert, key, rejectUnauthorized, and servername settings. Applications that pin to an internal or corporate CA via requestTls.ca will, when their proxy URI is SOCKS5, get the default Mozilla CA bundle as the trust anchor instead. Any cert signed by any publicly-trusted CA for the target hostname is accepted, breaking the intended pin and enabling MITM read and tamper of the HTTPS exchange. Affected applications are those that use undici's ProxyAgent (or Socks5ProxyAgent directly) with SOCKS5 AND rely on requestTls for TLS scope restriction. The bug was introduced in undici 7.23.0 when SOCKS5 support was added. Patches: Upgrade to undici v7.28.0 or v8.5.0. Workarounds: No workaround is available within the SOCKS5 path. If a SOCKS5 proxy with TLS scope restriction is required and an upgrade is not yet possible, route the traffic through an HTTP-proxy ProxyAgent instead, where requestTls is honored correctly.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00459, EPSS Percentile is 0.37497 |
almalinux: CVE-2026-9697 was patched at 2026-07-06, 2026-07-15
debian: CVE-2026-9697 was patched at 2026-06-24
oraclelinux: CVE-2026-9697 was patched at 2026-07-07, 2026-07-20
redhat: CVE-2026-9697 was patched at 2026-07-06, 2026-07-15
628.
Information Disclosure - Xrdp (CVE-2026-41521) - Medium [374]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | xrdp is an open source remote desktop protocol server | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00392, EPSS Percentile is 0.31888 |
altlinux: CVE-2026-41521 was patched at 2026-07-08
debian: CVE-2026-41521 was patched at 2026-07-14
629.
Remote Code Execution - libxml2 (CVE-2026-11979) - Medium [373]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.6 | 14 | libxml2 is an XML toolkit implemented in C, originally developed for the GNOME Project | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00148, EPSS Percentile is 0.04536 |
debian: CVE-2026-11979 was patched at 2026-07-14
630.
Denial of Service - FFmpeg (CVE-2026-12706) - Medium [372]
Description: A use-after-free vulnerability was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | FFmpeg is a free and open-source software project consisting of a suite of libraries and programs for handling video, audio, and other multimedia files and streams | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00454, EPSS Percentile is 0.37178 |
debian: CVE-2026-12706 was patched at 2026-06-24
631.
Denial of Service - musl libc (CVE-2026-55213) - Medium [372]
Description: h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit edd7a120bfc4af11ac0cbebce2a43cc1f93f9af1, when h2o processes a QPACK instruction sent from the peer over HTTP/3, lib/http3/qpack.c might allocate an on-stack buffer as large as approximately 800 KB by calling alloca, which exceeds the default pthread stack size used by
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | musl libc is a lightweight, fast, and standards-conformant implementation of the C standard library, commonly used in embedded systems and Linux distributions such as Alpine Linux. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00344, EPSS Percentile is 0.27011 |
debian: CVE-2026-55213 was patched at 2026-07-14
632.
Information Disclosure - MediaWiki (CVE-2026-58033) - Medium [372]
Description: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17071 |
debian: CVE-2026-58033 was patched at 2026-07-05, 2026-07-14
633.
Security Feature Bypass - cpp-httplib (CVE-2026-54919) - Medium [372]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.7 | 14 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06013 |
debian: CVE-2026-54919 was patched at 2026-07-14
634.
Denial of Service - HTTP/2 (CVE-2026-44452) - Medium [370]
Description: h2o is an HTTP server with support for HTTP/1.x,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | HTTP/2 is a major revision of the HTTP network protocol used by the World Wide Web | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0025, EPSS Percentile is 0.16493 |
debian: CVE-2026-44452 was patched at 2026-07-14
635.
Denial of Service - Linux Kernel (CVE-2026-53250) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00104, EPSS Percentile is 0.01211 |
altlinux: CVE-2026-53250 was patched at 2026-06-19, 2026-06-22, 2026-07-06
debian: CVE-2026-53250 was patched at 2026-07-14
636.
Memory Corruption - Linux Kernel (CVE-2026-52929) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00389, EPSS Percentile is 0.31628 |
altlinux: CVE-2026-52929 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-52929 was patched at 2026-07-14
637.
Memory Corruption - Linux Kernel (CVE-2026-53165) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00344, EPSS Percentile is 0.27013 |
altlinux: CVE-2026-53165 was patched at 2026-06-19
638.
Memory Corruption - Linux Kernel (CVE-2026-53268) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00344, EPSS Percentile is 0.27009 |
altlinux: CVE-2026-53268 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53268 was patched at 2026-07-14
639.
Memory Corruption - Linux Kernel (CVE-2026-63831) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00243, EPSS Percentile is 0.15665 |
debian: CVE-2026-63831 was patched at 2026-07-14, 2026-07-30
640.
Memory Corruption - Linux Kernel (CVE-2026-63944) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00324, EPSS Percentile is 0.24903 |
debian: CVE-2026-63944 was patched at 2026-07-14
ubuntu: CVE-2026-63944 was patched at 2026-07-30
641.
Memory Corruption - Linux Kernel (CVE-2026-64010) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17084 |
debian: CVE-2026-64010 was patched at 2026-07-14
ubuntu: CVE-2026-64010 was patched at 2026-07-30
642.
Memory Corruption - Linux Kernel (CVE-2026-64096) - Medium [370]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17084 |
debian: CVE-2026-64096 was patched at 2026-07-14
ubuntu: CVE-2026-64096 was patched at 2026-07-30
643.
Remote Code Execution - Unknown Product (CVE-2026-14544) - Medium [369]
Description: {'nvd_cve_data_all': 'A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00864, EPSS Percentile is 0.55047 |
almalinux: CVE-2026-14544 was patched at 2026-07-15, 2026-07-16
oraclelinux: CVE-2026-14544 was patched at 2026-07-16
redhat: CVE-2026-14544 was patched at 2026-07-16
644.
Remote Code Execution - libreswan (CVE-2026-50721) - Medium [369]
Description: Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), did not correctly verify the length of the authentication hash when the SIG payload of an IKEv1 packet was encoded using PKCS #1 RSA Encryption as per RFC 2313. A remote attacker can use a variation on the Bleichenbacher attack to forge the SIG payload when small public exponents are being used (e.g., e=3), which could lead to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the SIG payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:libreswan:libreswan (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00386, EPSS Percentile is 0.31398 |
almalinux: CVE-2026-50721 was patched at 2026-07-27
debian: CVE-2026-50721 was patched at 2026-07-14
oraclelinux: CVE-2026-50721 was patched at 2026-07-27
redhat: CVE-2026-50721 was patched at 2026-07-27
645.
Remote Code Execution - libreswan (CVE-2026-50722) - Medium [369]
Description: Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_rsa(), did not correctly verify the DER encoding of the ASN.1 digest when the IKEv2 AUTH payload was encoded using RSASSA-PKCS1-v1_5 (RFC 8017). A remote attacker can use a variation on the Bleichenbacher attack to forge the AUTH payload when small public exponents are used (e.g., e=3), leading to impersonation. Additionally, a remote attacker, by encoding a shorter than expected hash in the AUTH payload, could trigger an assertion leading to denial-of-service. The daemon aborts and restarts; continued exploitation causes sustained denial of service. Remote
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Product detected by a:libreswan:libreswan (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00346, EPSS Percentile is 0.27292 |
almalinux: CVE-2026-50722 was patched at 2026-07-27
debian: CVE-2026-50722 was patched at 2026-07-14
oraclelinux: CVE-2026-50722 was patched at 2026-07-27
redhat: CVE-2026-50722 was patched at 2026-07-27
646.
Authentication Bypass - Chromium (CVE-2026-13984) - Medium [367]
Description: Incorrect security UI in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00183, EPSS Percentile is 0.08205 |
altlinux: CVE-2026-13984 was patched at 2026-07-03
debian: CVE-2026-13984 was patched at 2026-07-05, 2026-07-14
647.
Authentication Bypass - Chromium (CVE-2026-14034) - Medium [367]
Description: Inappropriate implementation in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14353 |
altlinux: CVE-2026-14034 was patched at 2026-07-03
debian: CVE-2026-14034 was patched at 2026-07-05, 2026-07-14
648.
Authentication Bypass - Chromium (CVE-2026-14052) - Medium [367]
Description: Insufficient policy enforcement in FileSystem in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.13949 |
altlinux: CVE-2026-14052 was patched at 2026-07-03
debian: CVE-2026-14052 was patched at 2026-07-05, 2026-07-14
649.
Authentication Bypass - Chromium (CVE-2026-14381) - Medium [367]
Description: Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00212, EPSS Percentile is 0.11611 |
altlinux: CVE-2026-14381 was patched at 2026-07-03
debian: CVE-2026-14381 was patched at 2026-07-05, 2026-07-14
650.
Denial of Service - Apache ActiveMQ (CVE-2026-50734) - Medium [367]
Description: Memory Allocation with Excessive Size Value vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00544, EPSS Percentile is 0.42588 |
debian: CVE-2026-50734 was patched at 2026-07-14
651.
Denial of Service - Apache ActiveMQ (CVE-2026-50750) - Medium [367]
Description: Denial of Service via Out of Memory vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00489, EPSS Percentile is 0.39391 |
debian: CVE-2026-50750 was patched at 2026-07-14
652.
Denial of Service - Apache ActiveMQ (CVE-2026-53916) - Medium [367]
Description: Memory Allocation with Excessive Size Value vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00544, EPSS Percentile is 0.42588 |
debian: CVE-2026-53916 was patched at 2026-07-14
653.
Denial of Service - ClamAV (CVE-2026-20213) - Medium [367]
Description: A vulnerability in the PE file format parser of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ClamAV (Clam AntiVirus) is a free software, cross-platform antimalware toolkit able to detect many types of malware, including viruses | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00563, EPSS Percentile is 0.43583 |
altlinux: CVE-2026-20213 was patched at 2026-07-03, 2026-07-15
debian: CVE-2026-20213 was patched at 2026-07-14
ubuntu: CVE-2026-20213 was patched at 2026-07-30
654.
Denial of Service - ClamAV (CVE-2026-20214) - Medium [367]
Description: A vulnerability in the FSG file format parser of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ClamAV (Clam AntiVirus) is a free software, cross-platform antimalware toolkit able to detect many types of malware, including viruses | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00563, EPSS Percentile is 0.43586 |
altlinux: CVE-2026-20214 was patched at 2026-07-03, 2026-07-15
debian: CVE-2026-20214 was patched at 2026-07-14
ubuntu: CVE-2026-20214 was patched at 2026-07-30
655.
Denial of Service - ClamAV (CVE-2026-20215) - Medium [367]
Description: A vulnerability in the 7z file format parser of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ClamAV (Clam AntiVirus) is a free software, cross-platform antimalware toolkit able to detect many types of malware, including viruses | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.40046 |
altlinux: CVE-2026-20215 was patched at 2026-07-03, 2026-07-15
debian: CVE-2026-20215 was patched at 2026-07-14
ubuntu: CVE-2026-20215 was patched at 2026-07-30
656.
Denial of Service - ClamAV (CVE-2026-20216) - Medium [367]
Description: A vulnerability in the InstallShield file format parser of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ClamAV (Clam AntiVirus) is a free software, cross-platform antimalware toolkit able to detect many types of malware, including viruses | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.40046 |
altlinux: CVE-2026-20216 was patched at 2026-07-03, 2026-07-15
debian: CVE-2026-20216 was patched at 2026-07-14
ubuntu: CVE-2026-20216 was patched at 2026-07-30
657.
Denial of Service - ClamAV (CVE-2026-20217) - Medium [367]
Description: A vulnerability in the PESpin file format parser of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ClamAV (Clam AntiVirus) is a free software, cross-platform antimalware toolkit able to detect many types of malware, including viruses | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.40045 |
altlinux: CVE-2026-20217 was patched at 2026-07-03, 2026-07-15
debian: CVE-2026-20217 was patched at 2026-07-14
ubuntu: CVE-2026-20217 was patched at 2026-07-30
658.
Denial of Service - ClamAV (CVE-2026-20243) - Medium [367]
Description: A vulnerability in the ALZ file format parser of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ClamAV (Clam AntiVirus) is a free software, cross-platform antimalware toolkit able to detect many types of malware, including viruses | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.40046 |
altlinux: CVE-2026-20243 was patched at 2026-07-03, 2026-07-15
debian: CVE-2026-20243 was patched at 2026-07-14
ubuntu: CVE-2026-20243 was patched at 2026-07-30
659.
Denial of Service - ClamAV (CVE-2026-20244) - Medium [367]
Description: A vulnerability in the DMG file format parser of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ClamAV (Clam AntiVirus) is a free software, cross-platform antimalware toolkit able to detect many types of malware, including viruses | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.005, EPSS Percentile is 0.40045 |
altlinux: CVE-2026-20244 was patched at 2026-07-03, 2026-07-15
debian: CVE-2026-20244 was patched at 2026-07-14
ubuntu: CVE-2026-20244 was patched at 2026-07-30
660.
Denial of Service - Perl (CVE-2026-56018) - Medium [367]
Description: JavaScript::Minifier::XS versions before 0.16 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00459, EPSS Percentile is 0.37521 |
debian: CVE-2026-56018 was patched at 2026-07-14
661.
Denial of Service - Python (CVE-2026-15308) - Medium [367]
Description: The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00551, EPSS Percentile is 0.42956 |
almalinux: CVE-2026-15308 was patched at 2026-07-14, 2026-07-15, 2026-07-16, 2026-07-20
debian: CVE-2026-15308 was patched at 2026-07-30
oraclelinux: CVE-2026-15308 was patched at 2026-07-15, 2026-07-16, 2026-07-21
redhat: CVE-2026-15308 was patched at 2026-07-14, 2026-07-15, 2026-07-20
662.
Denial of Service - Angular (CVE-2026-50171) - Medium [366]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05715 |
debian: CVE-2026-50171 was patched at 2026-06-24
663.
Authentication Bypass - DNSSEC (CVE-2026-52690) - Medium [365]
Description: Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | The Domain Name System Security Extensions (DNSSEC) is a feature of the Domain Name System (DNS) that authenticates responses to domain name lookups | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00339, EPSS Percentile is 0.26512 |
debian: CVE-2026-52690 was patched at 2026-06-25, 2026-07-14
664.
Authentication Bypass - nsd (CVE-2026-12490) - Medium [365]
Description: When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular port, when the other conditions of the provide-xfr rule match.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:nlnetlabs:nsd (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05256 |
altlinux: CVE-2026-12490 was patched at 2026-06-26, 2026-06-29
debian: CVE-2026-12490 was patched at 2026-07-14
ubuntu: CVE-2026-12490 was patched at 2026-07-30
665.
Denial of Service - Node.js (CVE-2026-48937) - Medium [365]
Description: A flaw in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00534, EPSS Percentile is 0.42002 |
altlinux: CVE-2026-48937 was patched at 2026-07-23
debian: CVE-2026-48937 was patched at 2026-06-24
666.
Denial of Service - OpenSSH (CVE-2026-60001) - Medium [365]
Description: sshd in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.21334 |
debian: CVE-2026-60001 was patched at 2026-07-14
ubuntu: CVE-2026-60001 was patched at 2026-07-30
667.
Denial of Service - OpenSSL (CVE-2026-58101) - Medium [365]
Description: Crypt::
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00204, EPSS Percentile is 0.10606 |
debian: CVE-2026-58101 was patched at 2026-07-14
668.
Incorrect Calculation - Chromium (CVE-2026-13938) - Medium [365]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25032 |
altlinux: CVE-2026-13938 was patched at 2026-07-03
debian: CVE-2026-13938 was patched at 2026-07-05, 2026-07-14
669.
Memory Corruption - Chromium (CVE-2026-13783) - Medium [365]
Description: Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.248 |
altlinux: CVE-2026-13783 was patched at 2026-07-03
debian: CVE-2026-13783 was patched at 2026-07-05, 2026-07-14
670.
Memory Corruption - Chromium (CVE-2026-13784) - Medium [365]
Description: Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00323, EPSS Percentile is 0.24799 |
altlinux: CVE-2026-13784 was patched at 2026-07-03
debian: CVE-2026-13784 was patched at 2026-07-05, 2026-07-14
671.
Memory Corruption - Chromium (CVE-2026-13835) - Medium [365]
Description: Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25032 |
altlinux: CVE-2026-13835 was patched at 2026-07-03
debian: CVE-2026-13835 was patched at 2026-07-05, 2026-07-14
672.
Memory Corruption - Chromium (CVE-2026-13915) - Medium [365]
Description: Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25033 |
altlinux: CVE-2026-13915 was patched at 2026-07-03
debian: CVE-2026-13915 was patched at 2026-07-05, 2026-07-14
673.
Memory Corruption - Chromium (CVE-2026-13918) - Medium [365]
Description: Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25034 |
altlinux: CVE-2026-13918 was patched at 2026-07-03
debian: CVE-2026-13918 was patched at 2026-07-05, 2026-07-14
674.
Memory Corruption - Chromium (CVE-2026-14385) - Medium [365]
Description: Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 150.0.7871.46 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00327, EPSS Percentile is 0.25276 |
altlinux: CVE-2026-14385 was patched at 2026-07-03
debian: CVE-2026-14385 was patched at 2026-07-05, 2026-07-14
675.
Memory Corruption - Chromium (CVE-2026-15112) - Medium [365]
Description: Use after free in Ozone in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00326, EPSS Percentile is 0.25156 |
altlinux: CVE-2026-15112 was patched at 2026-07-09
debian: CVE-2026-15112 was patched at 2026-07-11, 2026-07-14
676.
Memory Corruption - Chromium (CVE-2026-15764) - Medium [365]
Description: Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00483, EPSS Percentile is 0.39008 |
altlinux: CVE-2026-15764 was patched at 2026-07-15
debian: CVE-2026-15764 was patched at 2026-07-14, 2026-07-16
677.
Memory Corruption - Chromium (CVE-2026-15765) - Medium [365]
Description: Use after free in Ozone in Google Chrome prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00483, EPSS Percentile is 0.39009 |
altlinux: CVE-2026-15765 was patched at 2026-07-15
debian: CVE-2026-15765 was patched at 2026-07-14, 2026-07-16
678.
Memory Corruption - Chromium (CVE-2026-15901) - Medium [365]
Description: Use after free in Network in Google Chrome prior to 150.0.7871.128 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 1.0 | 10 | CVSS Base Score is 9.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.17986 |
altlinux: CVE-2026-15901 was patched at 2026-07-18
debian: CVE-2026-15901 was patched at 2026-07-14, 2026-07-22
679.
Memory Corruption - Safari (CVE-2026-43707) - Medium [365]
Description: A memory corruption issue was addressed with improved memory handling. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00686, EPSS Percentile is 0.49048 |
almalinux: CVE-2026-43707 was patched at 2026-07-20
debian: CVE-2026-43707 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43707 was patched at 2026-07-20
redhat: CVE-2026-43707 was patched at 2026-07-20
680.
Memory Corruption - Safari (CVE-2026-43716) - Medium [365]
Description: The issue was addressed with improved memory handling. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00598, EPSS Percentile is 0.45233 |
almalinux: CVE-2026-43716 was patched at 2026-07-20
debian: CVE-2026-43716 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43716 was patched at 2026-07-20
redhat: CVE-2026-43716 was patched at 2026-07-20
681.
Memory Corruption - Safari (CVE-2026-43745) - Medium [365]
Description: An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00664, EPSS Percentile is 0.48141 |
almalinux: CVE-2026-43745 was patched at 2026-07-20
debian: CVE-2026-43745 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43745 was patched at 2026-07-20
redhat: CVE-2026-43745 was patched at 2026-07-20
682.
Security Feature Bypass - Chromium (CVE-2026-13808) - Medium [365]
Description: Insufficient data validation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via physical access to the device. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 4.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00194, EPSS Percentile is 0.09355 |
altlinux: CVE-2026-13808 was patched at 2026-07-03
debian: CVE-2026-13808 was patched at 2026-07-05, 2026-07-14
683.
Security Feature Bypass - Chromium (CVE-2026-13812) - Medium [365]
Description: Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11463 |
altlinux: CVE-2026-13812 was patched at 2026-07-03
debian: CVE-2026-13812 was patched at 2026-07-05, 2026-07-14
684.
Security Feature Bypass - Chromium (CVE-2026-13959) - Medium [365]
Description: Insufficient validation of untrusted input in Blink in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15773 |
altlinux: CVE-2026-13959 was patched at 2026-07-03
debian: CVE-2026-13959 was patched at 2026-07-05, 2026-07-14
685.
Security Feature Bypass - Chromium (CVE-2026-14117) - Medium [365]
Description: Insufficient validation of untrusted input in DevTools in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14286 |
altlinux: CVE-2026-14117 was patched at 2026-07-03
debian: CVE-2026-14117 was patched at 2026-07-05, 2026-07-14
686.
Security Feature Bypass - Chromium (CVE-2026-14414) - Medium [365]
Description: Insufficient validation of untrusted input in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14561 |
altlinux: CVE-2026-14414 was patched at 2026-07-03
debian: CVE-2026-14414 was patched at 2026-07-05, 2026-07-14
687.
Authentication Bypass - Oracle VM VirtualBox (CVE-2026-46768) - Medium [363]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04732 |
altlinux: CVE-2026-46768 was patched at 2026-06-29
688.
Denial of Service - Node.js (CVE-2026-48619) - Medium [363]
Description: A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nodejs:node.js (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00639, EPSS Percentile is 0.47059 |
almalinux: CVE-2026-48619 was patched at 2026-07-06, 2026-07-15, 2026-07-20
altlinux: CVE-2026-48619 was patched at 2026-07-23
debian: CVE-2026-48619 was patched at 2026-06-24
oraclelinux: CVE-2026-48619 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-48619 was patched at 2026-07-06, 2026-07-15, 2026-07-20
689.
Denial of Service - libssh2 (CVE-2025-15661) - Medium [363]
Description: libssh2 through 1.11.1, fixed in commit 2dae302, contains an out-of-bounds heap read vulnerability in the sftp_symlink() function in src/sftp.c that allows a malicious SSH server or man-in-the-middle attacker to disclose heap memory contents or
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:libssh2:libssh2 (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.0103, EPSS Percentile is 0.6028 |
altlinux: CVE-2025-15661 was patched at 2026-07-09, 2026-07-14
debian: CVE-2025-15661 was patched at 2026-06-24, 2026-06-25
ubuntu: CVE-2025-15661 was patched at 2026-07-30
690.
Denial of Service - tempo (CVE-2026-21728) - Medium [363]
Description: Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search config, e.g. to 262144 (2^18). Alternatively, automatically restart the service.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:grafana:tempo (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00637, EPSS Percentile is 0.46973 |
redos: CVE-2026-21728 was patched at 2026-06-26
691.
Denial of Service - undici (CVE-2026-12151) - Medium [363]
Description: Impact: The undici WebSocket client enforces maxPayloadSize on the cumulative byte count of fragments in a message but does not enforce a limit on the number of fragments. A malicious WebSocket server can stream many small or empty continuation frames that each pass per-frame and cumulative-size validation, collectively causing unbounded memory growth in the client process. The result is memory exhaustion and a denial of service. Affected applications are those using the undici WebSocket client (new WebSocket(...)) or the WebSocketStream API that can be induced to connect to an attacker-controlled or compromised WebSocket endpoint. All releases starting at undici 6.17.0 are affected. Patches: Upgrade to undici >= 6.26.0, >= 7.28.0, or >= 8.5.0. Workarounds: No workaround is available. The fix must be applied through an upgrade.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00789, EPSS Percentile is 0.52627 |
almalinux: CVE-2026-12151 was patched at 2026-07-06, 2026-07-15, 2026-07-20
debian: CVE-2026-12151 was patched at 2026-06-24
oraclelinux: CVE-2026-12151 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-12151 was patched at 2026-07-06, 2026-07-15, 2026-07-20
692.
Security Feature Bypass - containerd (CVE-2026-53488) - Medium [363]
Description: containerd is an open-source container runtime. In versions prior to 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10 the CRI plugin propagates labels from an image config (LABEL instruction in Dockerfile) to a container without validation. This may result in executing an arbitrary command on the host, via a plugin that consumes container labels for some operations. This issue has been fixed in versions 1.7.33, 2.3.2, 2.2.5, 2.1.9, and 2.0.10.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:linuxfoundation:containerd (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07411 |
altlinux: CVE-2026-53488 was patched at 2026-06-19, 2026-07-14, 2026-07-15
debian: CVE-2026-53488 was patched at 2026-06-24
ubuntu: CVE-2026-53488 was patched at 2026-07-30
693.
Security Feature Bypass - etcd (CVE-2026-59818) - Medium [363]
Description: etcd is a distributed key-value store for the data of a distributed system. Prior to 3.5.32 and 3.6.13, when etcd is configured with --listen-client-http-urls to split HTTP and gRPC client endpoints onto separate listeners, the --client-crl-file Certificate Revocation List is not enforced on the gRPC listener, allowing a client with a revoked certificate to authenticate successfully over gRPC. This issue is fixed in versions 3.5.32 and 3.6.13.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:etcd:etcd (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00319, EPSS Percentile is 0.2437 |
altlinux: CVE-2026-59818 was patched at 2026-07-10, 2026-07-13
debian: CVE-2026-59818 was patched at 2026-07-14
694.
Security Feature Bypass - freeswitch (CVE-2026-49475) - Medium [363]
Description: FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, a STUN packet whose declared attribute length is shorter than the structure the parser casts to causes the parser to read and write past the end of the attribute, producing an out-of-bounds memory access on the per-leg media buffer. This issue has been patched in version 1.11.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:freeswitch:freeswitch (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00278, EPSS Percentile is 0.20108 |
altlinux: CVE-2026-49475 was patched at 2026-06-24, 2026-06-26, 2026-07-16
695.
Security Feature Bypass - nsd (CVE-2026-12246) - Medium [363]
Description: NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a maximum of 111 attacker controlled bytes.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:nlnetlabs:nsd (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.003, EPSS Percentile is 0.22267 |
altlinux: CVE-2026-12246 was patched at 2026-06-26, 2026-06-29
ubuntu: CVE-2026-12246 was patched at 2026-07-30
696.
Information Disclosure - Electron (CVE-2022-21718) - Medium [362]
Description: Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. A vulnerability in versions prior to `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` allows renderers to obtain access to a bluetooth device via the web bluetooth API if the app has not configured a custom `select-bluetooth-device` event handler. This has been patched and Electron versions `17.0.0-alpha.6`, `16.0.6`, `15.3.5`, `14.2.4`, and `13.6.6` contain the fix. Code from the GitHub Security Advisory can be added to the app to work around the issue.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Product detected by a:electronjs:electron (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00931, EPSS Percentile is 0.57114 |
altlinux: CVE-2022-21718 was patched at 2026-06-20
697.
Cross Site Scripting - Apache ActiveMQ (CVE-2026-52760) - Medium [361]
Description: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00472, EPSS Percentile is 0.38301 |
debian: CVE-2026-52760 was patched at 2026-07-14
698.
Denial of Service - musl libc (CVE-2026-44453) - Medium [360]
Description: h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Prior to commit 6b5370d, h2o is vulnerable to a Denial of Service attack when calling alloca under certain conditions. When serving static files, h2o builds the file path on stack, by calling alloca. The maximum size of the memory allocated using alloca can be as huge as ~600KB, which exceeds the default pthread stack size used by
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | musl libc is a lightweight, fast, and standards-conformant implementation of the C standard library, commonly used in embedded systems and Linux distributions such as Alpine Linux. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00279, EPSS Percentile is 0.2015 |
debian: CVE-2026-44453 was patched at 2026-07-14
699.
Information Disclosure - MediaWiki (CVE-2026-58024) - Medium [360]
Description: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00281, EPSS Percentile is 0.20389 |
debian: CVE-2026-58024 was patched at 2026-07-05, 2026-07-14
700.
Cross Site Scripting - Chromium (CVE-2026-13836) - Medium [359]
Description: Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00231, EPSS Percentile is 0.14094 |
altlinux: CVE-2026-13836 was patched at 2026-07-03
debian: CVE-2026-13836 was patched at 2026-07-05, 2026-07-14
701.
Cross Site Scripting - Chromium (CVE-2026-14000) - Medium [359]
Description: Inappropriate implementation in XML in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00171, EPSS Percentile is 0.0681 |
altlinux: CVE-2026-14000 was patched at 2026-07-03
debian: CVE-2026-14000 was patched at 2026-07-05, 2026-07-14
702.
Cross Site Scripting - Chromium (CVE-2026-14001) - Medium [359]
Description: Inappropriate implementation in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00171, EPSS Percentile is 0.06811 |
altlinux: CVE-2026-14001 was patched at 2026-07-03
debian: CVE-2026-14001 was patched at 2026-07-05, 2026-07-14
703.
Cross Site Scripting - Chromium (CVE-2026-14068) - Medium [359]
Description: Inappropriate implementation in Omnibox in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00189, EPSS Percentile is 0.08855 |
altlinux: CVE-2026-14068 was patched at 2026-07-03
debian: CVE-2026-14068 was patched at 2026-07-05, 2026-07-14
704.
Remote Code Execution - gitoxide (CVE-2026-40034) - Medium [359]
Description: gix-submodule before 0.29.0 (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.3 | 14 | gitoxide is an idiomatic, lean, fast & safe pure Rust implementation of Git, designed for correctness and performance, available both as a Rust library (gix crate) and command-line interface tools. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.27784 |
debian: CVE-2026-40034 was patched at 2026-07-14
705.
Denial of Service - Linux Kernel (CVE-2026-63806) - Medium [358]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00147, EPSS Percentile is 0.04447 |
debian: CVE-2026-63806 was patched at 2026-07-14
706.
Memory Corruption - Linux Kernel (CVE-2026-52924) - Medium [358]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00331, EPSS Percentile is 0.25664 |
altlinux: CVE-2026-52924 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-52924 was patched at 2026-07-14
707.
Memory Corruption - Linux Kernel (CVE-2026-53147) - Medium [358]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00268, EPSS Percentile is 0.18776 |
altlinux: CVE-2026-53147 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53147 was patched at 2026-07-14
708.
Memory Corruption - Linux Kernel (CVE-2026-53254) - Medium [358]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00268, EPSS Percentile is 0.18776 |
altlinux: CVE-2026-53254 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53254 was patched at 2026-07-14
709.
Memory Corruption - Linux Kernel (CVE-2026-53256) - Medium [358]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00248, EPSS Percentile is 0.16267 |
altlinux: CVE-2026-53256 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53256 was patched at 2026-07-14
710.
Memory Corruption - Linux Kernel (CVE-2026-53275) - Medium [358]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00232, EPSS Percentile is 0.14213 |
altlinux: CVE-2026-53275 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53275 was patched at 2026-07-14
711.
Memory Corruption - Linux Kernel (CVE-2026-64117) - Medium [358]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14491 |
debian: CVE-2026-64117 was patched at 2026-07-14
ubuntu: CVE-2026-64117 was patched at 2026-07-30
712.
Information Disclosure - util-linux (CVE-2026-13595) - Medium [357]
Description: A flaw was found in the libblkid library of
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.9 | 14 | Linux utility suite providing core system tools including mount. Vulnerability affects SUID mount binary due to TOCTOU race condition. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0011, EPSS Percentile is 0.01472 |
debian: CVE-2026-13595 was patched at 2026-07-14
713.
Remote Code Execution - GIMP (CVE-2026-58379) - Medium [357]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14311 |
almalinux: CVE-2026-58379 was patched at 2026-07-13
debian: CVE-2026-58379 was patched at 2026-07-14
oraclelinux: CVE-2026-58379 was patched at 2026-07-13
redhat: CVE-2026-58379 was patched at 2026-07-13
714.
Elevation of Privilege - Samba (CVE-2026-15779) - Medium [356]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.8 | 14 | Samba is a free software re-implementation of the SMB networking protocol, and was originally developed by Andrew Tridgell | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00104, EPSS Percentile is 0.01209 |
debian: CVE-2026-15779 was patched at 2026-07-14
ubuntu: CVE-2026-15779 was patched at 2026-07-30
715.
Authentication Bypass - Chromium (CVE-2026-14003) - Medium [355]
Description: Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to leak cross-origin data via a crafted Chrome Extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00148, EPSS Percentile is 0.0452 |
altlinux: CVE-2026-14003 was patched at 2026-07-03
debian: CVE-2026-14003 was patched at 2026-07-05, 2026-07-14
716.
Authentication Bypass - Node.js (CVE-2026-48617) - Medium [355]
Description: A flaw in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 0.2 | 10 | CVSS Base Score is 1.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0024, EPSS Percentile is 0.15281 |
altlinux: CVE-2026-48617 was patched at 2026-07-23
debian: CVE-2026-48617 was patched at 2026-06-24
717.
Denial of Service - Perl (CVE-2026-13401) - Medium [355]
Description: XML::Bare versions through 0.53 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00388, EPSS Percentile is 0.31568 |
debian: CVE-2026-13401 was patched at 2026-07-14
718.
Denial of Service - Perl (CVE-2026-14741) - Medium [355]
Description: HTTP::Date versions before 6.08 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00353, EPSS Percentile is 0.28009 |
debian: CVE-2026-14741 was patched at 2026-07-14
ubuntu: CVE-2026-14741 was patched at 2026-07-30
719.
Denial of Service - Perl (CVE-2026-14895) - Medium [355]
Description: String::Util versions before 1.36 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00387, EPSS Percentile is 0.31491 |
debian: CVE-2026-14895 was patched at 2026-07-14
720.
Denial of Service - Perl (CVE-2026-49146) - Medium [355]
Description: App::Ack versions before 3.10.0 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00375, EPSS Percentile is 0.30207 |
debian: CVE-2026-49146 was patched at 2026-07-14
721.
Denial of Service - Perl (CVE-2026-56017) - Medium [355]
Description: JavaScript::Minifier::XS versions before 0.16 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0039, EPSS Percentile is 0.31789 |
debian: CVE-2026-56017 was patched at 2026-07-14
722.
Denial of Service - Perl (CVE-2026-60081) - Medium [355]
Description: DBI::ProfileData versions before 1.651 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00379, EPSS Percentile is 0.30688 |
debian: CVE-2026-60081 was patched at 2026-07-14
723.
Denial of Service - Puma (CVE-2026-47736) - Medium [355]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Puma is a Ruby/Rack web server built for parallelism | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00346, EPSS Percentile is 0.27236 |
debian: CVE-2026-47736 was patched at 2026-07-14
724.
Denial of Service - Python (CVE-2026-49851) - Medium [355]
Description: Mistune is a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00346, EPSS Percentile is 0.27236 |
debian: CVE-2026-49851 was patched at 2026-07-14
725.
Security Feature Bypass - pgAdmin (CVE-2025-12765) - Medium [355]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | pgAdmin is the most popular and feature rich Open Source administration and development platform for PostgreSQL, the most advanced Open Source database in the world | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00196, EPSS Percentile is 0.09635 |
redos: CVE-2025-12765 was patched at 2026-06-23
726.
Denial of Service - Vim (CVE-2026-57451) - Medium [354]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.95 | 14 | Highly configurable command-line text editor used in development and system administration. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00116, EPSS Percentile is 0.0185 |
altlinux: CVE-2026-57451 was patched at 2026-06-30, 2026-07-06
debian: CVE-2026-57451 was patched at 2026-07-14
727.
Denial of Service - Vim (CVE-2026-57454) - Medium [354]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.95 | 14 | Highly configurable command-line text editor used in development and system administration. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01936 |
altlinux: CVE-2026-57454 was patched at 2026-06-30, 2026-07-06
728.
Open Redirect - Gitea (CVE-2026-25779) - Medium [354]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.75 | 15 | Open Redirect | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00248, EPSS Percentile is 0.16174 |
redos: CVE-2026-25779 was patched at 2026-07-14
729.
Memory Corruption - Chromium (CVE-2026-13799) - Medium [353]
Description: Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00326, EPSS Percentile is 0.25138 |
altlinux: CVE-2026-13799 was patched at 2026-07-03
debian: CVE-2026-13799 was patched at 2026-07-05, 2026-07-14
730.
Memory Corruption - Chromium (CVE-2026-13825) - Medium [353]
Description: Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00314, EPSS Percentile is 0.2385 |
altlinux: CVE-2026-13825 was patched at 2026-07-03
debian: CVE-2026-13825 was patched at 2026-07-05, 2026-07-14
731.
Memory Corruption - Chromium (CVE-2026-14005) - Medium [353]
Description: Use after free in Omnibox in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00243, EPSS Percentile is 0.15604 |
altlinux: CVE-2026-14005 was patched at 2026-07-03
debian: CVE-2026-14005 was patched at 2026-07-05, 2026-07-14
732.
Memory Corruption - Chromium (CVE-2026-14024) - Medium [353]
Description: Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00317, EPSS Percentile is 0.2408 |
altlinux: CVE-2026-14024 was patched at 2026-07-03
debian: CVE-2026-14024 was patched at 2026-07-05, 2026-07-14
733.
Memory Corruption - Chromium (CVE-2026-14025) - Medium [353]
Description: Use after free in Views in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00317, EPSS Percentile is 0.24081 |
altlinux: CVE-2026-14025 was patched at 2026-07-03
debian: CVE-2026-14025 was patched at 2026-07-05, 2026-07-14
734.
Memory Corruption - Chromium (CVE-2026-14027) - Medium [353]
Description: Use after free in SignIn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.17983 |
altlinux: CVE-2026-14027 was patched at 2026-07-03
debian: CVE-2026-14027 was patched at 2026-07-05, 2026-07-14
735.
Memory Corruption - Chromium (CVE-2026-14099) - Medium [353]
Description: Use after free in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17114 |
altlinux: CVE-2026-14099 was patched at 2026-07-03
debian: CVE-2026-14099 was patched at 2026-07-05, 2026-07-14
736.
Memory Corruption - Chromium (CVE-2026-14102) - Medium [353]
Description: Use after free in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00252, EPSS Percentile is 0.16726 |
altlinux: CVE-2026-14102 was patched at 2026-07-03
debian: CVE-2026-14102 was patched at 2026-07-05, 2026-07-14
737.
Memory Corruption - Chromium (CVE-2026-14415) - Medium [353]
Description: Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16818 |
altlinux: CVE-2026-14415 was patched at 2026-07-03
debian: CVE-2026-14415 was patched at 2026-07-05, 2026-07-14
738.
Memory Corruption - Chromium (CVE-2026-14422) - Medium [353]
Description: Out of bounds read and write in Tint in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00272, EPSS Percentile is 0.19359 |
altlinux: CVE-2026-14422 was patched at 2026-07-03
debian: CVE-2026-14422 was patched at 2026-07-05, 2026-07-14
739.
Memory Corruption - Chromium (CVE-2026-15129) - Medium [353]
Description: Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00298, EPSS Percentile is 0.22095 |
altlinux: CVE-2026-15129 was patched at 2026-07-09
debian: CVE-2026-15129 was patched at 2026-07-11, 2026-07-14
740.
Memory Corruption - OpenSSH (CVE-2026-60002) - Medium [353]
Description: ssh in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.9 | 10 | CVSS Base Score is 9.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.003, EPSS Percentile is 0.22286 |
almalinux: CVE-2026-60002 was patched at 2026-07-29
debian: CVE-2026-60002 was patched at 2026-07-14
oraclelinux: CVE-2026-60002 was patched at 2026-07-30
redhat: CVE-2026-60002 was patched at 2026-07-29
ubuntu: CVE-2026-60002 was patched at 2026-07-30
741.
Memory Corruption - Safari (CVE-2026-43720) - Medium [353]
Description: A use-after-free issue was addressed with improved memory management. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00544, EPSS Percentile is 0.42567 |
almalinux: CVE-2026-43720 was patched at 2026-07-20
debian: CVE-2026-43720 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43720 was patched at 2026-07-20
redhat: CVE-2026-43720 was patched at 2026-07-20
742.
Memory Corruption - Safari (CVE-2026-43731) - Medium [353]
Description: A use-after-free issue was addressed with improved memory management. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00256, EPSS Percentile is 0.17212 |
almalinux: CVE-2026-43731 was patched at 2026-07-20
debian: CVE-2026-43731 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43731 was patched at 2026-07-20
redhat: CVE-2026-43731 was patched at 2026-07-20
743.
Security Feature Bypass - Chromium (CVE-2026-13034) - Medium [353]
Description: Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00143, EPSS Percentile is 0.04083 |
debian: CVE-2026-13034 was patched at 2026-06-25, 2026-07-14
744.
Security Feature Bypass - Chromium (CVE-2026-13865) - Medium [353]
Description: Insufficient validation of untrusted input in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14867 |
altlinux: CVE-2026-13865 was patched at 2026-07-03
debian: CVE-2026-13865 was patched at 2026-07-05, 2026-07-14
745.
Security Feature Bypass - Chromium (CVE-2026-13946) - Medium [353]
Description: Inappropriate implementation in ScriptInjections in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00224, EPSS Percentile is 0.13111 |
altlinux: CVE-2026-13946 was patched at 2026-07-03
debian: CVE-2026-13946 was patched at 2026-07-05, 2026-07-14
746.
Security Feature Bypass - Chromium (CVE-2026-13952) - Medium [353]
Description: Inappropriate implementation in PerformanceAPIs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00224, EPSS Percentile is 0.13111 |
altlinux: CVE-2026-13952 was patched at 2026-07-03
debian: CVE-2026-13952 was patched at 2026-07-05, 2026-07-14
747.
Security Feature Bypass - Chromium (CVE-2026-13978) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00231, EPSS Percentile is 0.14055 |
altlinux: CVE-2026-13978 was patched at 2026-07-03
debian: CVE-2026-13978 was patched at 2026-07-05, 2026-07-14
748.
Security Feature Bypass - Chromium (CVE-2026-13991) - Medium [353]
Description: Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00169, EPSS Percentile is 0.0657 |
altlinux: CVE-2026-13991 was patched at 2026-07-03
debian: CVE-2026-13991 was patched at 2026-07-05, 2026-07-14
749.
Security Feature Bypass - Chromium (CVE-2026-13995) - Medium [353]
Description: Insufficient validation of untrusted input in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00222, EPSS Percentile is 0.12839 |
altlinux: CVE-2026-13995 was patched at 2026-07-03
debian: CVE-2026-13995 was patched at 2026-07-05, 2026-07-14
750.
Security Feature Bypass - Chromium (CVE-2026-13999) - Medium [353]
Description: Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.07372 |
altlinux: CVE-2026-13999 was patched at 2026-07-03
debian: CVE-2026-13999 was patched at 2026-07-05, 2026-07-14
751.
Security Feature Bypass - Chromium (CVE-2026-14020) - Medium [353]
Description: Insufficient validation of untrusted input in WebXR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00198, EPSS Percentile is 0.09848 |
altlinux: CVE-2026-14020 was patched at 2026-07-03
debian: CVE-2026-14020 was patched at 2026-07-05, 2026-07-14
752.
Security Feature Bypass - Chromium (CVE-2026-14039) - Medium [353]
Description: Insufficient policy enforcement in GetUserMedia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05754 |
altlinux: CVE-2026-14039 was patched at 2026-07-03
debian: CVE-2026-14039 was patched at 2026-07-05, 2026-07-14
753.
Security Feature Bypass - Chromium (CVE-2026-14045) - Medium [353]
Description: Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00201, EPSS Percentile is 0.10209 |
altlinux: CVE-2026-14045 was patched at 2026-07-03
debian: CVE-2026-14045 was patched at 2026-07-05, 2026-07-14
754.
Security Feature Bypass - Chromium (CVE-2026-14046) - Medium [353]
Description: Inappropriate implementation in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00181, EPSS Percentile is 0.07927 |
altlinux: CVE-2026-14046 was patched at 2026-07-03
debian: CVE-2026-14046 was patched at 2026-07-05, 2026-07-14
755.
Security Feature Bypass - Chromium (CVE-2026-14047) - Medium [353]
Description: Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to bypass content security policy via a crafted Chrome Extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00182, EPSS Percentile is 0.08042 |
altlinux: CVE-2026-14047 was patched at 2026-07-03
debian: CVE-2026-14047 was patched at 2026-07-05, 2026-07-14
756.
Security Feature Bypass - Chromium (CVE-2026-14053) - Medium [353]
Description: Insufficient policy enforcement in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0017, EPSS Percentile is 0.06696 |
altlinux: CVE-2026-14053 was patched at 2026-07-03
debian: CVE-2026-14053 was patched at 2026-07-05, 2026-07-14
757.
Security Feature Bypass - Chromium (CVE-2026-14054) - Medium [353]
Description: Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13861 |
altlinux: CVE-2026-14054 was patched at 2026-07-03
debian: CVE-2026-14054 was patched at 2026-07-05, 2026-07-14
758.
Security Feature Bypass - Chromium (CVE-2026-14057) - Medium [353]
Description: Inappropriate implementation in FedCM in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00188, EPSS Percentile is 0.08743 |
altlinux: CVE-2026-14057 was patched at 2026-07-03
debian: CVE-2026-14057 was patched at 2026-07-05, 2026-07-14
759.
Security Feature Bypass - Chromium (CVE-2026-14058) - Medium [353]
Description: Insufficient policy enforcement in Parser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00238, EPSS Percentile is 0.14943 |
altlinux: CVE-2026-14058 was patched at 2026-07-03
debian: CVE-2026-14058 was patched at 2026-07-05, 2026-07-14
760.
Security Feature Bypass - Chromium (CVE-2026-14066) - Medium [353]
Description: Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14483 |
altlinux: CVE-2026-14066 was patched at 2026-07-03
debian: CVE-2026-14066 was patched at 2026-07-05, 2026-07-14
761.
Security Feature Bypass - Chromium (CVE-2026-14073) - Medium [353]
Description: Insufficient validation of untrusted input in WebXR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00189, EPSS Percentile is 0.08808 |
altlinux: CVE-2026-14073 was patched at 2026-07-03
debian: CVE-2026-14073 was patched at 2026-07-05, 2026-07-14
762.
Security Feature Bypass - Chromium (CVE-2026-14075) - Medium [353]
Description: Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10167 |
altlinux: CVE-2026-14075 was patched at 2026-07-03
debian: CVE-2026-14075 was patched at 2026-07-05, 2026-07-14
763.
Security Feature Bypass - Chromium (CVE-2026-14076) - Medium [353]
Description: Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass content security policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00189, EPSS Percentile is 0.08808 |
altlinux: CVE-2026-14076 was patched at 2026-07-03
debian: CVE-2026-14076 was patched at 2026-07-05, 2026-07-14
764.
Security Feature Bypass - Chromium (CVE-2026-14079) - Medium [353]
Description: Insufficient policy enforcement in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00188, EPSS Percentile is 0.08743 |
altlinux: CVE-2026-14079 was patched at 2026-07-03
debian: CVE-2026-14079 was patched at 2026-07-05, 2026-07-14
765.
Security Feature Bypass - Chromium (CVE-2026-14080) - Medium [353]
Description: Insufficient validation of untrusted input in TabSwitcher in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via malicious network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00188, EPSS Percentile is 0.08743 |
altlinux: CVE-2026-14080 was patched at 2026-07-03
debian: CVE-2026-14080 was patched at 2026-07-05, 2026-07-14
766.
Security Feature Bypass - Chromium (CVE-2026-14089) - Medium [353]
Description: Insufficient validation of untrusted input in PopupBlocker in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00198, EPSS Percentile is 0.09848 |
altlinux: CVE-2026-14089 was patched at 2026-07-03
debian: CVE-2026-14089 was patched at 2026-07-05, 2026-07-14
767.
Security Feature Bypass - Chromium (CVE-2026-14116) - Medium [353]
Description: Insufficient validation of untrusted input in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.10789 |
altlinux: CVE-2026-14116 was patched at 2026-07-03
debian: CVE-2026-14116 was patched at 2026-07-05, 2026-07-14
768.
Security Feature Bypass - Chromium (CVE-2026-14127) - Medium [353]
Description: Inappropriate implementation in Printing in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00202, EPSS Percentile is 0.10407 |
altlinux: CVE-2026-14127 was patched at 2026-07-03
debian: CVE-2026-14127 was patched at 2026-07-05, 2026-07-14
769.
Security Feature Bypass - Chromium (CVE-2026-14130) - Medium [353]
Description: Incorrect security UI in Omnibox in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00202, EPSS Percentile is 0.10408 |
altlinux: CVE-2026-14130 was patched at 2026-07-03
debian: CVE-2026-14130 was patched at 2026-07-05, 2026-07-14
770.
Security Feature Bypass - Chromium (CVE-2026-14131) - Medium [353]
Description: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.0786 |
altlinux: CVE-2026-14131 was patched at 2026-07-03
debian: CVE-2026-14131 was patched at 2026-07-05, 2026-07-14
771.
Security Feature Bypass - Chromium (CVE-2026-14135) - Medium [353]
Description: Insufficient validation of untrusted input in Network in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06964 |
altlinux: CVE-2026-14135 was patched at 2026-07-03
debian: CVE-2026-14135 was patched at 2026-07-05, 2026-07-14
772.
Security Feature Bypass - Chromium (CVE-2026-14136) - Medium [353]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.0773 |
altlinux: CVE-2026-14136 was patched at 2026-07-03
debian: CVE-2026-14136 was patched at 2026-07-05, 2026-07-14
773.
Security Feature Bypass - Chromium (CVE-2026-14137) - Medium [353]
Description: Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07726 |
altlinux: CVE-2026-14137 was patched at 2026-07-03
debian: CVE-2026-14137 was patched at 2026-07-05, 2026-07-14
774.
Security Feature Bypass - Chromium (CVE-2026-14140) - Medium [353]
Description: Insufficient validation of untrusted input in Input in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00202, EPSS Percentile is 0.10408 |
altlinux: CVE-2026-14140 was patched at 2026-07-03
debian: CVE-2026-14140 was patched at 2026-07-05, 2026-07-14
775.
Security Feature Bypass - Chromium (CVE-2026-14418) - Medium [353]
Description: Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00186, EPSS Percentile is 0.08442 |
altlinux: CVE-2026-14418 was patched at 2026-07-03
debian: CVE-2026-14418 was patched at 2026-07-05, 2026-07-14
776.
Security Feature Bypass - Chromium (CVE-2026-15124) - Medium [353]
Description: Insufficient policy enforcement in Passwords in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06523 |
altlinux: CVE-2026-15124 was patched at 2026-07-09
debian: CVE-2026-15124 was patched at 2026-07-11, 2026-07-14
777.
Security Feature Bypass - Chromium (CVE-2026-15130) - Medium [353]
Description: Insufficient policy enforcement in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06849 |
altlinux: CVE-2026-15130 was patched at 2026-07-09
debian: CVE-2026-15130 was patched at 2026-07-11, 2026-07-14
778.
Security Feature Bypass - Chromium (CVE-2026-15131) - Medium [353]
Description: Inappropriate implementation in Navigation in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to bypass site isolation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06849 |
altlinux: CVE-2026-15131 was patched at 2026-07-09
debian: CVE-2026-15131 was patched at 2026-07-11, 2026-07-14
779.
Security Feature Bypass - OpenSSL (CVE-2026-55964) - Medium [353]
Description: Chain intermediate CA:TRUE without keyCertSign accepted as a signing CA. Intermediate CA certificates are required to have the keyCertSign key usage when a Key Usage extension is present, but chain-supplied temporary CAs (WOLFSSL_TEMP_CA) added while building a certificate path were previously exempted from this check, so an intermediate asserting CA:TRUE but lacking keyCertSign was accepted as a signing CA. The check now applies to chain-supplied temporary CAs as well; only operator-loaded root certificates (WOLFSSL_USER_CA) and self-signed roots remain exempt. Per RFC 5280 an absent Key Usage extension implies all usages, so the requirement is enforced only when the extension is actually present (extKeyUsageSet). Affects the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.02 |
debian: CVE-2026-55964 was patched at 2026-07-14
780.
Security Feature Bypass - RPC (CVE-2026-46611) - Medium [353]
Description: Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.0212 |
debian: CVE-2026-46611 was patched at 2026-07-14
781.
Information Disclosure - Chromium (CVE-2026-14012) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10732 |
altlinux: CVE-2026-14012 was patched at 2026-07-03
debian: CVE-2026-14012 was patched at 2026-07-05, 2026-07-14
782.
Information Disclosure - Chromium (CVE-2026-14049) - Medium [352]
Description: Inappropriate implementation in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00213, EPSS Percentile is 0.11761 |
altlinux: CVE-2026-14049 was patched at 2026-07-03
debian: CVE-2026-14049 was patched at 2026-07-05, 2026-07-14
783.
Information Disclosure - Chromium (CVE-2026-14112) - Medium [352]
Description: Inappropriate implementation in Enterprise in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.13498 |
altlinux: CVE-2026-14112 was patched at 2026-07-03
debian: CVE-2026-14112 was patched at 2026-07-05, 2026-07-14
784.
Remote Code Execution - Flatpak (CVE-2026-5674) - Medium [352]
Description: A flaw was found in PipeWire, a multimedia server. This vulnerability allows an attacker to escape sandboxed applications, such as
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | Flatpak is a utility for software deployment and package management for Linux | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02622 |
debian: CVE-2026-5674 was patched at 2026-07-14
debian: CVE-2026-56740 was patched at 2026-07-14
debian: CVE-2026-56741 was patched at 2026-07-14
oraclelinux: CVE-2026-5674 was patched at 2026-07-28
785.
Spoofing - Linux Kernel (CVE-2026-63889) - Medium [352]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00334, EPSS Percentile is 0.26007 |
debian: CVE-2026-63889 was patched at 2026-07-14
ubuntu: CVE-2026-63889 was patched at 2026-07-30
786.
Denial of Service - freeswitch (CVE-2026-49842) - Medium [351]
Description: FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's WebSocket frame loop intercepts a #-prefixed speed-test protocol (#SPU / #SPB / #SPE) before any authentication check. The declared payload size in #SPU was parsed with atoi() and only rejected non-positive values, so an unauthenticated peer could request up to INT_MAX bytes. The server then wrote roughly size * 10 bytes back during the download phase, on the order of 20 GB per request, yielding strong outbound bandwidth amplification from a short request. This issue has been patched in version 1.11.1.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:freeswitch:freeswitch (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00449, EPSS Percentile is 0.36841 |
altlinux: CVE-2026-49842 was patched at 2026-06-24, 2026-06-26, 2026-07-16
787.
Denial of Service - haproxy (CVE-2026-55204) - Medium [351]
Description: HAProxy through 3.4.0, fixed in commit 9a6d1fe, contains a null pointer dereference vulnerability in hpack_dht_insert() within src/hpack-tbl.c that fails to validate the return value of hpack_dht_defrag() when the memory pool is exhausted. An attacker can trigger HPACK dynamic table insertions under memory pressure to dereference a NULL pointer and crash HAProxy worker processes, causing
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:haproxy:haproxy (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00484, EPSS Percentile is 0.39082 |
debian: CVE-2026-55204 was patched at 2026-06-24
ubuntu: CVE-2026-55204 was patched at 2026-07-30
788.
Denial of Service - httpcomponents_core (CVE-2026-54399) - Medium [351]
Description: Uncontrolled Resource Consumption vulnerability in the HTTP/1.1 message parser in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending messages with excessive number of headers / excessive header length
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:apache:httpcomponents_core (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00565, EPSS Percentile is 0.43675 |
debian: CVE-2026-54399 was patched at 2026-07-14
789.
Denial of Service - httpcomponents_core (CVE-2026-54428) - Medium [351]
Description: Allocation of resources without limits or throttling in the HTTP/2 HPACK decoder in Apache HttpComponents Core (5.4.2 and earlier, 5.5-beta1 and earlier) allows an remote attacker to cause a denial of service through memory exhaustion by sending oversized compressed header blocks before the HTTP/2 SETTINGS acknowledgement causes the configured header list size limit to be applied.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:apache:httpcomponents_core (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00587, EPSS Percentile is 0.44708 |
debian: CVE-2026-54428 was patched at 2026-07-14
790.
Denial of Service - nats-server (CVE-2026-58210) - Medium [351]
Description: NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an unauthenticated MQTT client could cause the server to retain large incomplete MQTT CONNECT packets before authentication completed, consuming server memory while the parser waited for the advertised MQTT packet length. This issue is fixed in versions 2.14.3 and 2.12.12.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:linuxfoundation:nats-server (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00505, EPSS Percentile is 0.40353 |
altlinux: CVE-2026-58210 was patched at 2026-07-10, 2026-07-13, 2026-07-14
debian: CVE-2026-58210 was patched at 2026-07-14
791.
Denial of Service - sigstore_timestamp_authority (CVE-2026-49835) - Medium [351]
Description: Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and raw HTTP request method r.Method as Prometheus labels for latency and request count metric vectors before routing, allowing an unauthenticated remote attacker to issue requests with random paths such as /api/v1/timestamp/<uuid> or random HTTP methods and create unbounded permanent time-series entries that exhaust memory. This issue is fixed in version 2.1.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:linuxfoundation:sigstore_timestamp_authority (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00427, EPSS Percentile is 0.35159 |
debian: CVE-2026-49835 was patched at 2026-07-14
792.
Memory Corruption - njs (CVE-2026-8711) - Medium [351]
Description: NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoking the ngx.fetch() operation from NGINX JavaScript. An unauthenticated attacker can exploit this vulnerability by sending crafted HTTP requests. This may cause a heap
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:f5:njs (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00889, EPSS Percentile is 0.54674 |
redos: CVE-2026-8711 was patched at 2026-06-26, 2026-06-29
ubuntu: CVE-2026-8711 was patched at 2026-07-30
793.
Path Traversal - loki_datasource (CVE-2026-42129) - Medium [351]
Description: A user with Viewer permissions can use a path traversal in the Loki data source plugin to reach administrative Loki endpoints and read sensitive backend configuration and internal service information.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:grafana:loki_datasource (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00443, EPSS Percentile is 0.36371 |
redos: CVE-2026-42129 was patched at 2026-07-14
794.
Security Feature Bypass - Twig (CVE-2026-49981) - Medium [351]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Twig is a template language for PHP | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00212, EPSS Percentile is 0.11673 |
debian: CVE-2026-49981 was patched at 2026-07-14
795.
Security Feature Bypass - UltraJSON (CVE-2026-54911) - Medium [351]
Description: UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When set, they may accept malformed or truncated UTF-8 byte sequences, silently rewriting them into different Unicode characters instead of rejecting them. This leads to input validation bypass and data integrity issues. This vulnerability is fixed in 5.13.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:ultrajson_project:ultrajson (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00272, EPSS Percentile is 0.19437 |
debian: CVE-2026-54911 was patched at 2026-06-24
796.
Security Feature Bypass - wolfssl (CVE-2026-55960) - Medium [351]
Description: Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 certificate, bypassing chain validation. A raw public key has no chain, so ParseCertRelative() accepts it without performing any trust verification; it must therefore only be accepted when RPK was actually negotiated for that peer. The check now defaults the expected type to X.509 (per RFC 7250/8446) when no type was negotiated, comparing against the received server certificate type on the client and the selected client certificate type on the server, and rejects any mismatch, including an un-negotiated raw public key, with UNSUPPORTED_CERTIFICATE. Only affects builds with Raw Public Key support (HAVE_RPK) enabled - disabled by default in a standalone build, but included in --enable-all.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12608 |
debian: CVE-2026-55960 was patched at 2026-07-14
797.
Security Feature Bypass - wolfssl (CVE-2026-7511) - Medium [351]
Description: PKCS7_verify signer confusion allows forged signatures, where the signer associated with a signature is not correctly bound, permitting a forged signature to be accepted.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00171, EPSS Percentile is 0.06775 |
debian: CVE-2026-7511 was patched at 2026-07-14
798.
Security Feature Bypass - wolfssl (CVE-2026-7532) - Medium [351]
Description: iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defined. IP address name constraints are not enforced in that configuration, allowing a certificate to bypass an issuing CA's IP address constraints.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05146 |
debian: CVE-2026-7532 was patched at 2026-07-14
799.
Cross Site Scripting - Undertow (CVE-2025-12799) - Medium [350]
Description: A flaw was found in Jastow. Jastow is vulnerable to Cross-Site Scripting (XSS) attack. If using a set of combined configuration to allow unescaped characters in URL with embedded
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Undertow is a lightweight, high-performance Java web server and servlet container designed for both embedded and standalone deployments. It is the default web server in WildFly and is also used by Red Hat products including JBoss EAP and builds of Apache Camel. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16073 |
redhat: CVE-2025-12799 was patched at 2026-07-07
800.
Information Disclosure - MediaWiki (CVE-2026-58026) - Medium [348]
Description: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00232, EPSS Percentile is 0.14252 |
debian: CVE-2026-58026 was patched at 2026-07-05, 2026-07-14
801.
Cross Site Scripting - Chromium (CVE-2026-13977) - Medium [347]
Description: Inappropriate implementation in HTMLParser in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06825 |
altlinux: CVE-2026-13977 was patched at 2026-07-03
debian: CVE-2026-13977 was patched at 2026-07-05, 2026-07-14
802.
Cross Site Scripting - Chromium (CVE-2026-14145) - Medium [347]
Description: Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00148, EPSS Percentile is 0.04507 |
altlinux: CVE-2026-14145 was patched at 2026-07-03
debian: CVE-2026-14145 was patched at 2026-07-05, 2026-07-14
803.
Cross Site Scripting - Chromium (CVE-2026-14147) - Medium [347]
Description: Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00145, EPSS Percentile is 0.04237 |
altlinux: CVE-2026-14147 was patched at 2026-07-03
debian: CVE-2026-14147 was patched at 2026-07-05, 2026-07-14
804.
Cross Site Scripting - Chromium (CVE-2026-15127) - Medium [347]
Description: Inappropriate implementation in WebGL in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00139, EPSS Percentile is 0.03748 |
altlinux: CVE-2026-15127 was patched at 2026-07-09
debian: CVE-2026-15127 was patched at 2026-07-11, 2026-07-14
805.
Cross Site Scripting - Chromium (CVE-2026-15128) - Medium [347]
Description: Inappropriate implementation in Forms in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00139, EPSS Percentile is 0.03748 |
altlinux: CVE-2026-15128 was patched at 2026-07-09
debian: CVE-2026-15128 was patched at 2026-07-11, 2026-07-14
806.
Cross Site Scripting - PHP (CVE-2026-48822) - Medium [347]
Description: Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the Markdown-to-HTML conversion process used in the Bookmark Description field. An authenticated user can inject a malicious javascript: URI inside a Markdown link. The vulnerability originates in the filterProtocols method within BookmarkMarkdownFormatter.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02184 |
debian: CVE-2026-48822 was patched at 2026-06-24
807.
Denial of Service - Linux Kernel (CVE-2026-52948) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02997 |
altlinux: CVE-2026-52948 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-52948 was patched at 2026-07-14
808.
Denial of Service - Linux Kernel (CVE-2026-53169) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00107, EPSS Percentile is 0.01355 |
altlinux: CVE-2026-53169 was patched at 2026-06-19
809.
Denial of Service - Linux Kernel (CVE-2026-53181) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.024 |
altlinux: CVE-2026-53181 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53181 was patched at 2026-07-14
810.
Denial of Service - Linux Kernel (CVE-2026-53274) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02272 |
altlinux: CVE-2026-53274 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53274 was patched at 2026-07-14
811.
Denial of Service - Linux Kernel (CVE-2026-53337) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.01741 |
altlinux: CVE-2026-53337 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53337 was patched at 2026-07-14
812.
Incorrect Calculation - Linux Kernel (CVE-2026-53178) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10673 |
altlinux: CVE-2026-53178 was patched at 2026-06-19
debian: CVE-2026-53178 was patched at 2026-07-14
813.
Incorrect Calculation - Linux Kernel (CVE-2026-63881) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07469 |
debian: CVE-2026-63881 was patched at 2026-07-14
ubuntu: CVE-2026-63881 was patched at 2026-07-30
814.
Memory Corruption - Linux Kernel (CVE-2026-53175) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00313, EPSS Percentile is 0.23732 |
altlinux: CVE-2026-53175 was patched at 2026-06-19, 2026-06-22, 2026-07-06
815.
Memory Corruption - Linux Kernel (CVE-2026-53196) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00261, EPSS Percentile is 0.17838 |
altlinux: CVE-2026-53196 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53196 was patched at 2026-07-14
816.
Memory Corruption - Linux Kernel (CVE-2026-53230) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02614 |
altlinux: CVE-2026-53230 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53230 was patched at 2026-07-14
817.
Memory Corruption - Linux Kernel (CVE-2026-53253) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00259, EPSS Percentile is 0.17538 |
altlinux: CVE-2026-53253 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53253 was patched at 2026-07-14
818.
Memory Corruption - Linux Kernel (CVE-2026-63794) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.095 |
debian: CVE-2026-63794 was patched at 2026-07-14, 2026-07-30
819.
Memory Corruption - Linux Kernel (CVE-2026-63807) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0013, EPSS Percentile is 0.03007 |
debian: CVE-2026-63807 was patched at 2026-07-14, 2026-07-30
820.
Memory Corruption - Linux Kernel (CVE-2026-63894) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05508 |
debian: CVE-2026-63894 was patched at 2026-07-14
ubuntu: CVE-2026-63894 was patched at 2026-07-30
821.
Memory Corruption - Linux Kernel (CVE-2026-63906) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07274 |
debian: CVE-2026-63906 was patched at 2026-07-14
ubuntu: CVE-2026-63906 was patched at 2026-07-30
822.
Memory Corruption - Linux Kernel (CVE-2026-63918) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05508 |
debian: CVE-2026-63918 was patched at 2026-07-14
ubuntu: CVE-2026-63918 was patched at 2026-07-30
823.
Memory Corruption - Linux Kernel (CVE-2026-63930) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.05586 |
debian: CVE-2026-63930 was patched at 2026-07-14
ubuntu: CVE-2026-63930 was patched at 2026-07-30
824.
Memory Corruption - Linux Kernel (CVE-2026-63942) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06044 |
debian: CVE-2026-63942 was patched at 2026-07-14
ubuntu: CVE-2026-63942 was patched at 2026-07-30
825.
Memory Corruption - Linux Kernel (CVE-2026-63945) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.05587 |
debian: CVE-2026-63945 was patched at 2026-07-14
ubuntu: CVE-2026-63945 was patched at 2026-07-30
826.
Memory Corruption - Linux Kernel (CVE-2026-64115) - Medium [346]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00135, EPSS Percentile is 0.03382 |
debian: CVE-2026-64115 was patched at 2026-07-14
ubuntu: CVE-2026-64115 was patched at 2026-07-30
827.
Denial of Service - Perl (CVE-2026-14803) - Medium [344]
Description: Mojo::JSON versions before 9.47 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00331, EPSS Percentile is 0.25637 |
debian: CVE-2026-14803 was patched at 2026-07-14
828.
Denial of Service - Python (CVE-2026-57585) - Medium [344]
Description: MessagePack is the serializer implementation for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00279, EPSS Percentile is 0.20148 |
debian: CVE-2026-57585 was patched at 2026-07-14
829.
Path Traversal - Python (CVE-2026-54591) - Medium [344]
Description: AsyncSSH is a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00313, EPSS Percentile is 0.23714 |
debian: CVE-2026-54591 was patched at 2026-07-14
830.
Security Feature Bypass - Python (CVE-2026-4360) - Medium [344]
Description: In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected system that extracts content from untrusted tar files could end up writing files with an unexpected uid/gid despite the user passing filter='data' to the extract() function.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0027, EPSS Percentile is 0.19011 |
debian: CVE-2026-4360 was patched at 2026-07-14
831.
Cross Site Scripting - MediaWiki (CVE-2026-58032) - Medium [342]
Description: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00191, EPSS Percentile is 0.09088 |
debian: CVE-2026-58032 was patched at 2026-07-05, 2026-07-14
832.
Elevation of Privilege - .NET (CVE-2026-45490) - Medium [342]
Description: Improper authorization in .NET allows an authorized attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Product detected by a:microsoft:.net (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00219, EPSS Percentile is 0.12171 |
redos: CVE-2026-45490 was patched at 2026-07-09
833.
Elevation of Privilege - Aptio V UEFI Firmware Integrator Tools (CVE-2023-28737) - Medium [342]
Description: Improper initialization in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allow an authenticated user to potentially enable
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Product detected by a:intel:aptio_v_uefi_firmware_integrator_tools (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00199, EPSS Percentile is 0.09926 |
redos: CVE-2023-28737 was patched at 2026-06-29
834.
Memory Corruption - Vim (CVE-2026-55693) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.95 | 14 | Highly configurable command-line text editor used in development and system administration. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02553 |
altlinux: CVE-2026-55693 was patched at 2026-06-30, 2026-07-06
debian: CVE-2026-55693 was patched at 2026-07-14
redhat: CVE-2026-55693 was patched at 2026-07-29
ubuntu: CVE-2026-55693 was patched at 2026-07-30
835.
Memory Corruption - Vim (CVE-2026-57455) - Medium [342]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.95 | 14 | Highly configurable command-line text editor used in development and system administration. | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.02034 |
altlinux: CVE-2026-57455 was patched at 2026-06-30, 2026-07-06
debian: CVE-2026-57455 was patched at 2026-07-14
redhat: CVE-2026-57455 was patched at 2026-07-29
ubuntu: CVE-2026-57455 was patched at 2026-07-30
836.
Authentication Bypass - Xrdp (CVE-2026-55626) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | xrdp is an open source remote desktop protocol server | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02652 |
altlinux: CVE-2026-55626 was patched at 2026-07-08
debian: CVE-2026-55626 was patched at 2026-07-14
837.
Authentication Bypass - freeswitch (CVE-2026-49843) - Medium [341]
Description: FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's JSON-RPC handler bound the connection to the client-supplied sessid on the first frame, before the authentication gate. Binding inserts the connection into the global session hash and, on a key collision, drops the prior occupant of that slot — sending it a verto.punt, detaching its calls, and closing its socket. An unauthenticated network attacker who knows a target session UUID could therefore evict the legitimate client. This issue has been patched in version 1.11.1.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:freeswitch:freeswitch (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00284, EPSS Percentile is 0.20679 |
altlinux: CVE-2026-49843 was patched at 2026-06-24, 2026-06-26, 2026-07-16
838.
Authentication Bypass - wolfSSL (CVE-2026-55962) - Medium [341]
Description: TLS 1.3 post-handshake authentication (PHA) issue where a server could accept a client's Finished message without the client having sent a Certificate and CertificateVerify. The post-handshake-auth exemption that allows an empty/absent peer certificate was only intended for the initial handshake, but it was also being applied while a post-handshake CertificateRequest was still outstanding. The check is now scoped to the initial handshake only: on the server, once a post-handshake CertificateRequest has been sent (certReqCtx is set), a peer certificate and a valid CertificateVerify are required again before the Finished is accepted, with empty-certificate handling following the configured verify mode (FAIL_IF_NO_PEER_CERT) just as during first-handshake client authentication. Only affects TLS 1.3 servers built with post-handshake authentication support (WOLFSSL_POST_HANDSHAKE_AUTH / --enable-postauth, included in --enable-all) that enable WOLFSSL_VERIFY_POST_HANDSHAKE and request a client certificate after the handshake via
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | wolfSSL is a small, portable, embedded SSL/TLS library targeted for use by embedded systems developers | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00143, EPSS Percentile is 0.0413 |
debian: CVE-2026-55962 was patched at 2026-07-14
839.
Memory Corruption - Chromium (CVE-2026-13026) - Medium [341]
Description: Use after free in Digital Credentials in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00199, EPSS Percentile is 0.09998 |
debian: CVE-2026-13026 was patched at 2026-06-25, 2026-07-14
840.
Memory Corruption - Chromium (CVE-2026-13027) - Medium [341]
Description: Use after free in FileSystem in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00199, EPSS Percentile is 0.09999 |
debian: CVE-2026-13027 was patched at 2026-06-25, 2026-07-14
841.
Memory Corruption - Chromium (CVE-2026-13814) - Medium [341]
Description: Use after free in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.21748 |
altlinux: CVE-2026-13814 was patched at 2026-07-03
debian: CVE-2026-13814 was patched at 2026-07-05, 2026-07-14
842.
Memory Corruption - Chromium (CVE-2026-13819) - Medium [341]
Description: Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00316, EPSS Percentile is 0.24042 |
altlinux: CVE-2026-13819 was patched at 2026-07-03
debian: CVE-2026-13819 was patched at 2026-07-05, 2026-07-14
843.
Memory Corruption - Chromium (CVE-2026-14011) - Medium [341]
Description: Out of bounds read in SurfaceCapture in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00246, EPSS Percentile is 0.1598 |
altlinux: CVE-2026-14011 was patched at 2026-07-03
debian: CVE-2026-14011 was patched at 2026-07-05, 2026-07-14
844.
Memory Corruption - Chromium (CVE-2026-14040) - Medium [341]
Description: Use after free in BrowserTag in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00218, EPSS Percentile is 0.12432 |
altlinux: CVE-2026-14040 was patched at 2026-07-03
debian: CVE-2026-14040 was patched at 2026-07-05, 2026-07-14
845.
Memory Corruption - Chromium (CVE-2026-14394) - Medium [341]
Description: Use after free in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14559 |
altlinux: CVE-2026-14394 was patched at 2026-07-03
debian: CVE-2026-14394 was patched at 2026-07-05, 2026-07-14
846.
Memory Corruption - Chromium (CVE-2026-15110) - Medium [341]
Description: Use after free in Extensions in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00154, EPSS Percentile is 0.0511 |
altlinux: CVE-2026-15110 was patched at 2026-07-09
debian: CVE-2026-15110 was patched at 2026-07-11, 2026-07-14
847.
Memory Corruption - Chromium (CVE-2026-15114) - Medium [341]
Description: Out of bounds read and write in Codecs in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit heap corruption via a crafted video file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00187, EPSS Percentile is 0.08575 |
altlinux: CVE-2026-15114 was patched at 2026-07-09
debian: CVE-2026-15114 was patched at 2026-07-11, 2026-07-14
848.
Memory Corruption - Chromium (CVE-2026-15123) - Medium [341]
Description: Inappropriate implementation in DOM in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to potentially exploit
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00202, EPSS Percentile is 0.10395 |
altlinux: CVE-2026-15123 was patched at 2026-07-09
debian: CVE-2026-15123 was patched at 2026-07-11, 2026-07-14
849.
Memory Corruption - Chromium (CVE-2026-15777) - Medium [341]
Description: Use after free in UI in Google Chrome on Linux prior to 150.0.7871.125 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00257, EPSS Percentile is 0.1732 |
altlinux: CVE-2026-15777 was patched at 2026-07-15
debian: CVE-2026-15777 was patched at 2026-07-14, 2026-07-16
850.
Memory Corruption - Chromium (CVE-2026-15904) - Medium [341]
Description: Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871.128 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00236, EPSS Percentile is 0.1479 |
altlinux: CVE-2026-15904 was patched at 2026-07-18
debian: CVE-2026-15904 was patched at 2026-07-14, 2026-07-22
851.
Memory Corruption - OpenSSL (CVE-2026-58102) - Medium [341]
Description: Crypt::
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00214, EPSS Percentile is 0.11875 |
debian: CVE-2026-58102 was patched at 2026-07-14
852.
Memory Corruption - Safari (CVE-2026-43676) - Medium [341]
Description: An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00364, EPSS Percentile is 0.29102 |
almalinux: CVE-2026-43676 was patched at 2026-07-20
debian: CVE-2026-43676 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43676 was patched at 2026-07-20
redhat: CVE-2026-43676 was patched at 2026-07-20
853.
Memory Corruption - Safari (CVE-2026-43712) - Medium [341]
Description: The issue was addressed with improved memory handling. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0036, EPSS Percentile is 0.28694 |
almalinux: CVE-2026-43712 was patched at 2026-07-20
debian: CVE-2026-43712 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43712 was patched at 2026-07-20
redhat: CVE-2026-43712 was patched at 2026-07-20
854.
Memory Corruption - Safari (CVE-2026-43727) - Medium [341]
Description: A use-after-free issue was addressed with improved memory management. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00326, EPSS Percentile is 0.25105 |
almalinux: CVE-2026-43727 was patched at 2026-07-20
debian: CVE-2026-43727 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43727 was patched at 2026-07-20
redhat: CVE-2026-43727 was patched at 2026-07-20
855.
Memory Corruption - Safari (CVE-2026-43740) - Medium [341]
Description: The issue was addressed with improved memory handling. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00362, EPSS Percentile is 0.28923 |
almalinux: CVE-2026-43740 was patched at 2026-07-20
debian: CVE-2026-43740 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43740 was patched at 2026-07-20
redhat: CVE-2026-43740 was patched at 2026-07-20
856.
Memory Corruption - Safari (CVE-2026-43742) - Medium [341]
Description: A use-after-free issue was addressed with improved memory management. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00384, EPSS Percentile is 0.31175 |
almalinux: CVE-2026-43742 was patched at 2026-07-20
debian: CVE-2026-43742 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43742 was patched at 2026-07-20
redhat: CVE-2026-43742 was patched at 2026-07-20
857.
Path Traversal - PHP (CVE-2026-59948) - Medium [341]
Description: Composer is a dependency Manager for the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03618 |
debian: CVE-2026-59948 was patched at 2026-07-14
858.
Security Feature Bypass - Chromium (CVE-2026-13021) - Medium [341]
Description: Inappropriate implementation in DeviceBoundSessionCredentials in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00143, EPSS Percentile is 0.04083 |
debian: CVE-2026-13021 was patched at 2026-06-25, 2026-07-14
859.
Security Feature Bypass - Chromium (CVE-2026-13024) - Medium [341]
Description: Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00146, EPSS Percentile is 0.04343 |
debian: CVE-2026-13024 was patched at 2026-06-25, 2026-07-14
860.
Security Feature Bypass - Chromium (CVE-2026-13939) - Medium [341]
Description: Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00222, EPSS Percentile is 0.12984 |
altlinux: CVE-2026-13939 was patched at 2026-07-03
debian: CVE-2026-13939 was patched at 2026-07-05, 2026-07-14
861.
Security Feature Bypass - Chromium (CVE-2026-13942) - Medium [341]
Description: Inappropriate implementation in Video Capture in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00169, EPSS Percentile is 0.06552 |
altlinux: CVE-2026-13942 was patched at 2026-07-03
debian: CVE-2026-13942 was patched at 2026-07-05, 2026-07-14
862.
Security Feature Bypass - Chromium (CVE-2026-13944) - Medium [341]
Description: Inappropriate implementation in DataTransfer in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00199, EPSS Percentile is 0.09959 |
altlinux: CVE-2026-13944 was patched at 2026-07-03
debian: CVE-2026-13944 was patched at 2026-07-05, 2026-07-14
863.
Security Feature Bypass - Chromium (CVE-2026-13945) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06203 |
altlinux: CVE-2026-13945 was patched at 2026-07-03
debian: CVE-2026-13945 was patched at 2026-07-05, 2026-07-14
864.
Security Feature Bypass - Chromium (CVE-2026-13948) - Medium [341]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06203 |
altlinux: CVE-2026-13948 was patched at 2026-07-03
debian: CVE-2026-13948 was patched at 2026-07-05, 2026-07-14
865.
Security Feature Bypass - Chromium (CVE-2026-13955) - Medium [341]
Description: Insufficient validation of untrusted input in CustomTabs in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI spoofing via a malicious file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00154, EPSS Percentile is 0.05068 |
altlinux: CVE-2026-13955 was patched at 2026-07-03
debian: CVE-2026-13955 was patched at 2026-07-05, 2026-07-14
866.
Security Feature Bypass - Chromium (CVE-2026-13963) - Medium [341]
Description: Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00199, EPSS Percentile is 0.09959 |
altlinux: CVE-2026-13963 was patched at 2026-07-03
debian: CVE-2026-13963 was patched at 2026-07-05, 2026-07-14
867.
Security Feature Bypass - Chromium (CVE-2026-14092) - Medium [341]
Description: Insufficient policy enforcement in Privacy in Google Chrome prior to 150.0.7871.47 allowed an attacker in a privileged network position to leak cross-origin data via malicious network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00148, EPSS Percentile is 0.04501 |
altlinux: CVE-2026-14092 was patched at 2026-07-03
debian: CVE-2026-14092 was patched at 2026-07-05, 2026-07-14
868.
Security Feature Bypass - Chromium (CVE-2026-14150) - Medium [341]
Description: Insufficient validation of untrusted input in Speech in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04893 |
altlinux: CVE-2026-14150 was patched at 2026-07-03
debian: CVE-2026-14150 was patched at 2026-07-05, 2026-07-14
869.
Remote Code Execution - Spring Framework (CVE-2025-11226) - Medium [340]
Description: ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.18 in Java applications, allows an attacker to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.4 | 14 | The Spring Framework is an application framework and inversion of control container for the Java platform | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00181, EPSS Percentile is 0.07906 |
debian: CVE-2025-11226 was patched at 2026-07-14
870.
Code Injection - Alinto SOGo (CVE-2026-39178) - Medium [339]
Description: A SQL injection vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.5 | 14 | SOGo is an open source groupware and webmail server developed by Alinto, providing email, calendar, and contact management through a web-based interface and standard protocols. | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.0534 |
debian: CVE-2026-39178 was patched at 2026-07-14
871.
Code Injection - Alinto SOGo (CVE-2026-39179) - Medium [339]
Description: A SQL injection vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0.5 | 14 | SOGo is an open source groupware and webmail server developed by Alinto, providing email, calendar, and contact management through a web-based interface and standard protocols. | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.0534 |
debian: CVE-2026-39179 was patched at 2026-07-14
872.
Denial of Service - Libarchive (CVE-2026-14164) - Medium [339]
Description: A double free issue has been identified in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Multi-format archive and compression library | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00353, EPSS Percentile is 0.28009 |
debian: CVE-2026-14164 was patched at 2026-07-14
ubuntu: CVE-2026-14164 was patched at 2026-07-30
873.
Denial of Service - Pypdf (CVE-2026-59935) - Medium [339]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00367, EPSS Percentile is 0.29437 |
debian: CVE-2026-59935 was patched at 2026-07-14
874.
Denial of Service - Pypdf (CVE-2026-59936) - Medium [339]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0034, EPSS Percentile is 0.26681 |
debian: CVE-2026-59936 was patched at 2026-07-14
875.
Denial of Service - Pypdf (CVE-2026-59937) - Medium [339]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0034, EPSS Percentile is 0.26681 |
debian: CVE-2026-59937 was patched at 2026-07-14
876.
Denial of Service - Starlette (CVE-2026-54283) - Medium [339]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00397, EPSS Percentile is 0.32519 |
debian: CVE-2026-54283 was patched at 2026-06-24
877.
Denial of Service - Xrdp (CVE-2026-54538) - Medium [339]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | xrdp is an open source remote desktop protocol server | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00384, EPSS Percentile is 0.31145 |
altlinux: CVE-2026-54538 was patched at 2026-07-08
debian: CVE-2026-54538 was patched at 2026-07-14
878.
Denial of Service - libjpeg (CVE-2026-13708) - Medium [339]
Description: Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol. i_readjpeg_wiol walks the marker list
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | libjpeg | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00375, EPSS Percentile is 0.30207 |
debian: CVE-2026-13708 was patched at 2026-07-14
879.
Denial of Service - pyasn1 (CVE-2026-59884) - Medium [339]
Description: pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER decoder shared by the CER and DER codecs parses long-form tags by accumulating continuation octets without an upper bound on the tag ID size, allowing a crafted input to force construction of an arbitrarily large integer with CPU cost growing quadratically and to trigger unhandled ValueError exceptions in Python 3.11+ error formatting paths. Any application decoding untrusted BER, CER, or DER input is affected. This issue is fixed in version 0.6.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:pyasn1:pyasn1 (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00349, EPSS Percentile is 0.27624 |
altlinux: CVE-2026-59884 was patched at 2026-07-10, 2026-07-13
debian: CVE-2026-59884 was patched at 2026-07-14
880.
Denial of Service - pyasn1 (CVE-2026-59885) - Medium [339]
Description: pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, CER, and DER decoders process OBJECT IDENTIFIER and RELATIVE-OID values in quadratic time relative to the number of arcs, so a small crafted payload containing an OID with many arcs consumes excessive CPU per decode() call and can deny service to applications that decode untrusted ASN.1 data. The corresponding encoders have the same quadratic behavior when an application re-encodes previously decoded attacker-supplied values. This issue is fixed in version 0.6.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:pyasn1:pyasn1 (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00335, EPSS Percentile is 0.26044 |
altlinux: CVE-2026-59885 was patched at 2026-07-10, 2026-07-13
debian: CVE-2026-59885 was patched at 2026-07-14
881.
Denial of Service - pyasn1 (CVE-2026-59886) - Medium [339]
Description: pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ.Real type converted its mantissa, base, and exponent value to a Python float using exact big-integer exponentiation. A BER, CER, or DER encoded REAL value only a few bytes long can carry a very large exponent, causing float conversion through prettyPrint(), str(), comparison, arithmetic, int(), or an explicit float() call to consume excessive CPU and memory and hang applications that decode untrusted ASN.1 data and then print, log, or compare decoded objects. This issue is fixed in version 0.6.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:pyasn1:pyasn1 (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00335, EPSS Percentile is 0.26044 |
altlinux: CVE-2026-59886 was patched at 2026-07-10, 2026-07-13
debian: CVE-2026-59886 was patched at 2026-07-14
882.
Denial of Service - wolfssl (CVE-2026-55958) - Medium [339]
Description: Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In tsip_StoreMessage() the capacity check guarding the fixed message bag (MSGBAG_SIZE) sets an error code but fails to return, so execution falls through to an XMEMCPY that writes past the end of the buffer once the accumulated TLS 1.3 handshake transcript exceeds MSGBAG_SIZE (8 KB), corrupting adjacent heap state and potentially causing a remote
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00412, EPSS Percentile is 0.33924 |
debian: CVE-2026-55958 was patched at 2026-07-14
883.
Security Feature Bypass - sigstore-go (CVE-2026-49834) - Medium [339]
Description: sigstore-go is a Go library for Sigstore signing and verification. Prior to 1.2.0, a verifier configured with WithTransparencyLog(N>1) or WithSignedCertificateTimestamps(N>1) counts verified witnesses per entry or per validation path rather than per log authority, allowing a single compromised transparency log or CT log to satisfy multi-log threshold requirements and defeat the multi-log policy. This issue is fixed in version 1.2.0.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:sigstore:sigstore-go (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00111, EPSS Percentile is 0.01553 |
debian: CVE-2026-49834 was patched at 2026-07-14
884.
Security Feature Bypass - wolfSSL (CVE-2026-8720) - Medium [339]
Description: wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when the key length exceeds the block size, producing a MAC that is independent of the input. When the supplied key is longer than the BLAKE2 block size the key-hashing branch reinitialized the running hash state, discarding the accumulated message data, so the resulting MAC depended only on the key and not on the message being authenticated. This bug is specific to the HMAC-BLAKE2 APIs that were added in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | wolfSSL is a small, portable, embedded SSL/TLS library targeted for use by embedded systems developers | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00111, EPSS Percentile is 0.01525 |
debian: CVE-2026-8720 was patched at 2026-07-14
885.
Security Feature Bypass - wolfssl (CVE-2026-6329) - Medium [339]
Description: PKCS#12 MAC verification uses an attacker-controlled comparison length, weakening the integrity check on the MAC and allowing a mismatched MAC to be accepted. The PKCS#12 verify path compared the locally computed HMAC against the MAC parsed from the PKCS#12 structure using a length taken directly from the attacker-supplied input, without first verifying that it equals the length of the digest actually produced by the configured algorithm. A truncated or zero-length stored MAC could therefore be accepted, defeating the integrity protection of the MAC.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.05667 |
debian: CVE-2026-6329 was patched at 2026-07-14
886.
Security Feature Bypass - wolfssl (CVE-2026-6731) - Medium [339]
Description: X.509 name constraint bypass via the Subject Common Name when treated as a DNS-type name. A certificate whose Subject CN violates an issuing CA's DNS name constraints could be accepted.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.0253 |
debian: CVE-2026-6731 was patched at 2026-07-14
887.
Arbitrary File Reading - Hugo (CVE-2026-58403) - Medium [338]
Description: Hugo is a static site generator. From v0.123.0 through v0.163.0, Hugo's virtual filesystem is designed so that files under a mount cannot reach outside the mount tree, but a regression caused RootMappingFs.statRoot to call Stat, which follows symlinks, instead of Lstat, so a direct os.ReadFile "somefile" where somefile was a symlink pointing outside the mount would return the target's contents. This effectively let a symlink planted inside a theme or local mount
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.5 | 14 | Product detected by a:gohugo:hugo (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00318, EPSS Percentile is 0.24241 |
altlinux: CVE-2026-58403 was patched at 2026-07-01
debian: CVE-2026-58403 was patched at 2026-07-14
888.
Information Disclosure - youtube-dl (CVE-2026-50019) - Medium [338]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | youtube-dl is a free and open source software tool for downloading video and audio from YouTube and over 1,000 other video hosting websites | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00268, EPSS Percentile is 0.1881 |
altlinux: CVE-2026-50019 was patched at 2026-07-27
debian: CVE-2026-50019 was patched at 2026-07-14
889.
Arbitrary File Reading - Oj (CVE-2026-49145) - Medium [337]
Description: App::Ack versions through 3.10.0 for Perl
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.35 | 14 | Oj (Optimized JSON) is a high-performance JSON parser and object serialization library packaged as a Ruby gem, designed to provide fast JSON encoding and decoding for Ruby applications. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00329, EPSS Percentile is 0.25469 |
debian: CVE-2026-49145 was patched at 2026-07-14
890.
Denial of Service - Kubernetes (CVE-2026-47262) - Medium [336]
Description: containerd is an open-source container runtime. Versions prior to 1.7.33, 2.0.10, 2.1.9, 2.2.5 and 2.3.2, contain a vulnerability that allows a maliciously crafted image to cause a Denial of Service (DoS) condition. When creating a container from this image, memory exhaustion occurs, leading to an Out Of Memory (OOM) kill of the containerd process. This renders the container runtime API unavailable and can disrupt clients such as the Docker Engine or
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | Kubernetes is an open-source container orchestration system for automating software deployment, scaling, and management | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00265, EPSS Percentile is 0.18293 |
altlinux: CVE-2026-47262 was patched at 2026-06-19, 2026-07-14, 2026-07-15
debian: CVE-2026-47262 was patched at 2026-06-24
ubuntu: CVE-2026-47262 was patched at 2026-07-30
891.
Information Disclosure - SQLite (CVE-2026-50813) - Medium [336]
Description: An issue in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.7 | 14 | SQLite is a database engine written in the C programming language | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0011, EPSS Percentile is 0.01486 |
debian: CVE-2026-50813 was patched at 2026-07-14
ubuntu: CVE-2026-50813 was patched at 2026-07-30
892.
Cross Site Scripting - Chromium (CVE-2026-13957) - Medium [335]
Description: Incorrect security UI in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0017, EPSS Percentile is 0.06667 |
altlinux: CVE-2026-13957 was patched at 2026-07-03
debian: CVE-2026-13957 was patched at 2026-07-05, 2026-07-14
893.
Memory Corruption - Linux Kernel (CVE-2026-31688) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00017, EPSS Percentile is 0.04292 |
oraclelinux: CVE-2026-31688 was patched at 2026-07-02
894.
Memory Corruption - Linux Kernel (CVE-2026-52935) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02173 |
altlinux: CVE-2026-52935 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-52935 was patched at 2026-07-14
895.
Memory Corruption - Linux Kernel (CVE-2026-52947) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00135, EPSS Percentile is 0.03381 |
altlinux: CVE-2026-52947 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-52947 was patched at 2026-07-14
896.
Memory Corruption - Linux Kernel (CVE-2026-53136) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02974 |
altlinux: CVE-2026-53136 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53136 was patched at 2026-07-14
897.
Memory Corruption - Linux Kernel (CVE-2026-53137) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00143, EPSS Percentile is 0.04136 |
altlinux: CVE-2026-53137 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53137 was patched at 2026-07-14
898.
Memory Corruption - Linux Kernel (CVE-2026-53156) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02602 |
altlinux: CVE-2026-53156 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53156 was patched at 2026-07-14
899.
Memory Corruption - Linux Kernel (CVE-2026-53157) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02641 |
altlinux: CVE-2026-53157 was patched at 2026-06-19, 2026-06-22, 2026-07-04, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53157 was patched at 2026-07-05, 2026-07-14, 2026-07-30
900.
Memory Corruption - Linux Kernel (CVE-2026-53160) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02642 |
altlinux: CVE-2026-53160 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53160 was patched at 2026-07-14
901.
Memory Corruption - Linux Kernel (CVE-2026-53161) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.0264 |
altlinux: CVE-2026-53161 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53161 was patched at 2026-07-14
902.
Memory Corruption - Linux Kernel (CVE-2026-53172) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.0219 |
altlinux: CVE-2026-53172 was patched at 2026-06-19
903.
Memory Corruption - Linux Kernel (CVE-2026-53173) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.0219 |
altlinux: CVE-2026-53173 was patched at 2026-06-19
904.
Memory Corruption - Linux Kernel (CVE-2026-53192) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02606 |
altlinux: CVE-2026-53192 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53192 was patched at 2026-07-14
905.
Memory Corruption - Linux Kernel (CVE-2026-53193) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00141, EPSS Percentile is 0.03896 |
altlinux: CVE-2026-53193 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53193 was patched at 2026-07-14
906.
Memory Corruption - Linux Kernel (CVE-2026-53195) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00143, EPSS Percentile is 0.04031 |
altlinux: CVE-2026-53195 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53195 was patched at 2026-07-14
907.
Memory Corruption - Linux Kernel (CVE-2026-53209) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02971 |
altlinux: CVE-2026-53209 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53209 was patched at 2026-07-14
908.
Memory Corruption - Linux Kernel (CVE-2026-53212) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02649 |
altlinux: CVE-2026-53212 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53212 was patched at 2026-07-14
909.
Memory Corruption - Linux Kernel (CVE-2026-53233) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02908 |
altlinux: CVE-2026-53233 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53233 was patched at 2026-07-14
910.
Memory Corruption - Linux Kernel (CVE-2026-53234) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00131, EPSS Percentile is 0.03128 |
altlinux: CVE-2026-53234 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53234 was patched at 2026-07-14
911.
Memory Corruption - Linux Kernel (CVE-2026-53239) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.0265 |
altlinux: CVE-2026-53239 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53239 was patched at 2026-07-14
912.
Memory Corruption - Linux Kernel (CVE-2026-53242) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02976 |
altlinux: CVE-2026-53242 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53242 was patched at 2026-07-14
913.
Memory Corruption - Linux Kernel (CVE-2026-53259) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00115, EPSS Percentile is 0.01828 |
altlinux: CVE-2026-53259 was patched at 2026-06-19, 2026-06-22, 2026-07-06
914.
Memory Corruption - Linux Kernel (CVE-2026-53272) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01935 |
altlinux: CVE-2026-53272 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53272 was patched at 2026-07-14
915.
Memory Corruption - Linux Kernel (CVE-2026-53273) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01965 |
altlinux: CVE-2026-53273 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53273 was patched at 2026-07-14
916.
Memory Corruption - Linux Kernel (CVE-2026-53276) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01607 |
altlinux: CVE-2026-53276 was patched at 2026-06-19
917.
Memory Corruption - Linux Kernel (CVE-2026-53341) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.0214 |
altlinux: CVE-2026-53341 was patched at 2026-06-19, 2026-06-22, 2026-07-04, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53341 was patched at 2026-07-05, 2026-07-14
918.
Memory Corruption - Linux Kernel (CVE-2026-53381) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00139, EPSS Percentile is 0.03718 |
debian: CVE-2026-53381 was patched at 2026-07-14, 2026-07-30
919.
Memory Corruption - Linux Kernel (CVE-2026-53388) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00133, EPSS Percentile is 0.03218 |
debian: CVE-2026-53388 was patched at 2026-07-14, 2026-07-30
920.
Memory Corruption - Linux Kernel (CVE-2026-53389) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02606 |
debian: CVE-2026-53389 was patched at 2026-07-14
921.
Memory Corruption - Linux Kernel (CVE-2026-53400) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00099, EPSS Percentile is 0.00977 |
debian: CVE-2026-53400 was patched at 2026-07-14
922.
Memory Corruption - Linux Kernel (CVE-2026-53401) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02999 |
debian: CVE-2026-53401 was patched at 2026-07-14
923.
Memory Corruption - Linux Kernel (CVE-2026-63797) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03672 |
debian: CVE-2026-63797 was patched at 2026-07-14
924.
Memory Corruption - Linux Kernel (CVE-2026-63802) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02606 |
debian: CVE-2026-63802 was patched at 2026-07-14
925.
Memory Corruption - Linux Kernel (CVE-2026-63803) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00133, EPSS Percentile is 0.03218 |
debian: CVE-2026-63803 was patched at 2026-07-14, 2026-07-30
926.
Memory Corruption - Linux Kernel (CVE-2026-63804) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00137, EPSS Percentile is 0.0358 |
debian: CVE-2026-63804 was patched at 2026-07-14
927.
Memory Corruption - Linux Kernel (CVE-2026-63815) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00132, EPSS Percentile is 0.03185 |
debian: CVE-2026-63815 was patched at 2026-07-14, 2026-07-21
928.
Memory Corruption - Linux Kernel (CVE-2026-63827) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02528 |
debian: CVE-2026-63827 was patched at 2026-07-14, 2026-07-30
929.
Memory Corruption - Linux Kernel (CVE-2026-63920) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05573 |
debian: CVE-2026-63920 was patched at 2026-07-14
ubuntu: CVE-2026-63920 was patched at 2026-07-30
930.
Memory Corruption - Linux Kernel (CVE-2026-64004) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.0297 |
debian: CVE-2026-64004 was patched at 2026-07-14
ubuntu: CVE-2026-64004 was patched at 2026-07-30
931.
Memory Corruption - Linux Kernel (CVE-2026-64011) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.0264 |
debian: CVE-2026-64011 was patched at 2026-07-14
ubuntu: CVE-2026-64011 was patched at 2026-07-30
932.
Memory Corruption - Linux Kernel (CVE-2026-64017) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02192 |
debian: CVE-2026-64017 was patched at 2026-07-14
redhat: CVE-2026-64017 was patched at 2026-07-28
ubuntu: CVE-2026-64017 was patched at 2026-07-30
933.
Memory Corruption - Linux Kernel (CVE-2026-64029) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02604 |
debian: CVE-2026-64029 was patched at 2026-07-14
ubuntu: CVE-2026-64029 was patched at 2026-07-30
934.
Memory Corruption - Linux Kernel (CVE-2026-64032) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02633 |
debian: CVE-2026-64032 was patched at 2026-07-14
ubuntu: CVE-2026-64032 was patched at 2026-07-30
935.
Memory Corruption - Linux Kernel (CVE-2026-64073) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00132, EPSS Percentile is 0.03191 |
debian: CVE-2026-64073 was patched at 2026-07-14
ubuntu: CVE-2026-64073 was patched at 2026-07-30
936.
Memory Corruption - Linux Kernel (CVE-2026-64097) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02967 |
debian: CVE-2026-64097 was patched at 2026-07-14
ubuntu: CVE-2026-64097 was patched at 2026-07-30
937.
Memory Corruption - Linux Kernel (CVE-2026-64099) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03347 |
debian: CVE-2026-64099 was patched at 2026-07-14
ubuntu: CVE-2026-64099 was patched at 2026-07-30
938.
Memory Corruption - Linux Kernel (CVE-2026-64123) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02646 |
debian: CVE-2026-64123 was patched at 2026-07-14
ubuntu: CVE-2026-64123 was patched at 2026-07-30
939.
Memory Corruption - Linux Kernel (CVE-2026-64188) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01965 |
debian: CVE-2026-64188 was patched at 2026-07-14, 2026-07-30
940.
Memory Corruption - Linux Kernel (CVE-2026-64189) - Medium [334]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02283 |
debian: CVE-2026-64189 was patched at 2026-07-14, 2026-07-21
941.
Memory Corruption - Windows Kernel (CVE-2026-42450) - Medium [334]
Description: OpenColorIO is a color management framework for visual effects and animation. Prior to version 2.5.2, `FileFormatSpi3D.cpp:163` uses `sscanf` with `%s` into 64-byte stack buffers when parsing LUT data lines. Input comes from `lineBuffer[4096]`, so a crafted .spi3d file can overflow by ~4000 bytes on non-
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | Windows Kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02129 |
debian: CVE-2026-42450 was patched at 2026-07-14
942.
Arbitrary File Reading - Horde IMP (CVE-2026-58451) - Medium [333]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Arbitrary File Reading | |
| 0.4 | 14 | IMP is the Internet Messaging Program. It is written in PHP and provides webmail access to IMAP and POP3 accounts. It uses the best-of-class Horde/Imap_Client library to provide fast, robust connections to the remote IMAP/POP3 server. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00409, EPSS Percentile is 0.33614 |
debian: CVE-2026-58451 was patched at 2026-07-14
943.
Remote Code Execution - GIMP (CVE-2026-58381) - Medium [333]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | GIMP is an open-source image manipulation program used for photo editing, graphic design, and digital art creation. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.01989 |
debian: CVE-2026-58381 was patched at 2026-07-14
944.
Server-Side Request Forgery - Hugo (CVE-2026-58404) - Medium [333]
Description: Hugo is a static site generator. From v0.162.0 through v0.163.0, the default security.http.urls policy denies requests to loopback, internal, and cloud-metadata IPv4 literals, but the deny rule only matched dotted-decimal notation, so alternate IPv4 encodings of the same addresses, including integer, hex, or octal, passed the policy. When a template passes an untrusted or data-derived URL to resources.GetRemote and the host platform uses the cgo system resolver, these encodings resolve to the blocked address, allowing build-time server-side requests to loopback and internal services, including the cloud-metadata endpoint in hosted or CI builds; the same check is reused on redirects, so the gap also applies to each redirect hop. This issue is fixed in v0.163.1.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.5 | 14 | Product detected by a:gohugo:hugo (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00208, EPSS Percentile is 0.11041 |
altlinux: CVE-2026-58404 was patched at 2026-07-01
945.
Server-Side Request Forgery - zeep (CVE-2026-58501) - Medium [333]
Description: Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid_external is defined but not enforced when parsing WSDL or XSD documents, allowing transitive xsd:import, xsd:include, wsdl:import, and lxml entity or DTD references to fetch attacker-chosen HTTP or HTTPS URLs. This issue is fixed in version 4.3.3.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.5 | 14 | Product detected by a:python-zeep:zeep (does NOT exist in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00267, EPSS Percentile is 0.18734 |
debian: CVE-2026-58501 was patched at 2026-07-14
946.
Authentication Bypass - JOSE (CVE-2026-49852) - Medium [332]
Description: joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.3 | 14 | JavaScript module for JSON Object Signing and Encryption (JOSE) | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00143, EPSS Percentile is 0.0407 |
debian: CVE-2026-49852 was patched at 2026-07-14
947.
Denial of Service - ImageMagick (CVE-2026-61870) - Medium [332]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00191, EPSS Percentile is 0.09098 |
altlinux: CVE-2026-61870 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-61870 was patched at 2026-07-14
948.
Denial of Service - Python (CVE-2026-47183) - Medium [332]
Description: Zeroconf is a pure
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00241, EPSS Percentile is 0.15442 |
debian: CVE-2026-47183 was patched at 2026-07-14
949.
Denial of Service - Python (CVE-2026-47184) - Medium [332]
Description: Zeroconf is a pure
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00241, EPSS Percentile is 0.15442 |
debian: CVE-2026-47184 was patched at 2026-07-14
950.
Denial of Service - Roundcube (CVE-2026-62641) - Medium [332]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Roundcube is a web-based IMAP email client | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00252, EPSS Percentile is 0.16722 |
altlinux: CVE-2026-62641 was patched at 2026-07-10, 2026-07-15
debian: CVE-2026-62641 was patched at 2026-07-14, 2026-07-19
951.
Denial of Service - Roundcube (CVE-2026-62642) - Medium [332]
Description: In
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Roundcube is a web-based IMAP email client | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00277, EPSS Percentile is 0.19922 |
altlinux: CVE-2026-62642 was patched at 2026-07-10, 2026-07-15
debian: CVE-2026-62642 was patched at 2026-07-14, 2026-07-19
952.
Denial of Service - Wireshark (CVE-2026-15163) - Medium [332]
Description: Multiple protocol dissector infinite loops in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.08309 |
altlinux: CVE-2026-15163 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15163 was patched at 2026-07-14
953.
Memory Corruption - Perl (CVE-2026-57074) - Medium [332]
Description: XML::Bare versions through 0.53 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00403, EPSS Percentile is 0.33051 |
debian: CVE-2026-57074 was patched at 2026-07-14
954.
Memory Corruption - Perl (CVE-2026-57075) - Medium [332]
Description: YAML::Syck versions before 1.47 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00374, EPSS Percentile is 0.30149 |
debian: CVE-2026-57075 was patched at 2026-07-14
955.
Memory Corruption - Perl (CVE-2026-60082) - Medium [332]
Description: DBI versions before 1.651 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00387, EPSS Percentile is 0.31428 |
debian: CVE-2026-60082 was patched at 2026-07-14
956.
Path Traversal - Perl (CVE-2026-15392) - Medium [332]
Description: DBD::File versions before 1.651 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.0592 |
debian: CVE-2026-15392 was patched at 2026-07-14
957.
Security Feature Bypass - Jetty (CVE-2026-6790) - Medium [332]
Description: In Eclipse
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Jetty is a Java based web server and servlet engine | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00196, EPSS Percentile is 0.09663 |
debian: CVE-2026-6790 was patched at 2026-07-14
958.
Security Feature Bypass - Perl (CVE-2026-13082) - Medium [332]
Description: GD::SecurityImage versions through 1.75 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00216, EPSS Percentile is 0.1217 |
debian: CVE-2026-13082 was patched at 2026-07-14
959.
Cross Site Scripting - MediaWiki (CVE-2026-58028) - Medium [330]
Description: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.7 | 14 | MediaWiki is a free server-based wiki software, licensed under the GNU General Public License (GPL) | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00171, EPSS Percentile is 0.06748 |
debian: CVE-2026-58028 was patched at 2026-07-05, 2026-07-14
960.
Authentication Bypass - Node.js (CVE-2026-48928) - Medium [329]
Description: A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:nodejs:node.js (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00216, EPSS Percentile is 0.12141 |
almalinux: CVE-2026-48928 was patched at 2026-07-06, 2026-07-15, 2026-07-20
altlinux: CVE-2026-48928 was patched at 2026-07-23
debian: CVE-2026-48928 was patched at 2026-06-24
oraclelinux: CVE-2026-48928 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-48928 was patched at 2026-07-06, 2026-07-15, 2026-07-20
961.
Incorrect Calculation - Chromium (CVE-2026-14070) - Medium [329]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00259, EPSS Percentile is 0.17572 |
altlinux: CVE-2026-14070 was patched at 2026-07-03
debian: CVE-2026-14070 was patched at 2026-07-05, 2026-07-14
962.
Memory Corruption - Chromium (CVE-2026-13029) - Medium [329]
Description: Use after free in Web Authentication in Google Chrome prior to 149.0.7827.197 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00162, EPSS Percentile is 0.05792 |
debian: CVE-2026-13029 was patched at 2026-06-25, 2026-07-14
963.
Memory Corruption - Chromium (CVE-2026-13858) - Medium [329]
Description: Out of bounds read in FFmpeg in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00284, EPSS Percentile is 0.20676 |
altlinux: CVE-2026-13858 was patched at 2026-07-03
debian: CVE-2026-13858 was patched at 2026-07-05, 2026-07-14
964.
Memory Corruption - Chromium (CVE-2026-13873) - Medium [329]
Description: Out of bounds read in Layout in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.21744 |
altlinux: CVE-2026-13873 was patched at 2026-07-03
debian: CVE-2026-13873 was patched at 2026-07-05, 2026-07-14
965.
Memory Corruption - Chromium (CVE-2026-13906) - Medium [329]
Description: Out of bounds read in Codecs in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00318, EPSS Percentile is 0.24261 |
altlinux: CVE-2026-13906 was patched at 2026-07-03
debian: CVE-2026-13906 was patched at 2026-07-05, 2026-07-14
966.
Memory Corruption - Chromium (CVE-2026-14103) - Medium [329]
Description: Use after free in SSL in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00257, EPSS Percentile is 0.17309 |
altlinux: CVE-2026-14103 was patched at 2026-07-03
debian: CVE-2026-14103 was patched at 2026-07-05, 2026-07-14
967.
Memory Corruption - Chromium (CVE-2026-14386) - Medium [329]
Description: Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.18027 |
altlinux: CVE-2026-14386 was patched at 2026-07-03
debian: CVE-2026-14386 was patched at 2026-07-05, 2026-07-14
968.
Memory Corruption - Chromium (CVE-2026-14388) - Medium [329]
Description: Out of bounds read in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.18027 |
altlinux: CVE-2026-14388 was patched at 2026-07-03
debian: CVE-2026-14388 was patched at 2026-07-05, 2026-07-14
969.
Memory Corruption - Chromium (CVE-2026-15111) - Medium [329]
Description: Use after free in Views in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00183, EPSS Percentile is 0.08187 |
altlinux: CVE-2026-15111 was patched at 2026-07-09
debian: CVE-2026-15111 was patched at 2026-07-11, 2026-07-14
970.
Memory Corruption - Chromium (CVE-2026-15117) - Medium [329]
Description: Use after free in Payments in Google Chrome prior to 150.0.7871.115 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00183, EPSS Percentile is 0.08187 |
altlinux: CVE-2026-15117 was patched at 2026-07-09
debian: CVE-2026-15117 was patched at 2026-07-11, 2026-07-14
971.
Memory Corruption - Safari (CVE-2026-39872) - Medium [329]
Description: The issue was addressed with improved memory handling. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15783 |
almalinux: CVE-2026-39872 was patched at 2026-07-20
debian: CVE-2026-39872 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-39872 was patched at 2026-07-20
redhat: CVE-2026-39872 was patched at 2026-07-20
972.
Memory Corruption - Safari (CVE-2026-43663) - Medium [329]
Description: The issue was addressed with improved memory handling. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15783 |
almalinux: CVE-2026-43663 was patched at 2026-07-20
debian: CVE-2026-43663 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43663 was patched at 2026-07-20
redhat: CVE-2026-43663 was patched at 2026-07-20
973.
Memory Corruption - Safari (CVE-2026-43699) - Medium [329]
Description: A use-after-free issue was addressed with improved memory management. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00285, EPSS Percentile is 0.20735 |
almalinux: CVE-2026-43699 was patched at 2026-07-20
debian: CVE-2026-43699 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43699 was patched at 2026-07-20
redhat: CVE-2026-43699 was patched at 2026-07-20
974.
Memory Corruption - Safari (CVE-2026-43734) - Medium [329]
Description: A use-after-free issue was addressed with improved memory management. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00285, EPSS Percentile is 0.20734 |
almalinux: CVE-2026-43734 was patched at 2026-07-20
debian: CVE-2026-43734 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43734 was patched at 2026-07-20
redhat: CVE-2026-43734 was patched at 2026-07-20
975.
Path Traversal - PHP (CVE-2026-59946) - Medium [329]
Description: Composer is a dependency Manager for the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03977 |
debian: CVE-2026-59946 was patched at 2026-07-14
976.
Security Feature Bypass - Chromium (CVE-2026-13022) - Medium [329]
Description: Inappropriate implementation in Autofill in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03626 |
debian: CVE-2026-13022 was patched at 2026-06-25, 2026-07-14
977.
Security Feature Bypass - Chromium (CVE-2026-15115) - Medium [329]
Description: Insufficient validation of untrusted input in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.115 allowed a local attacker to bypass same origin policy via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00089, EPSS Percentile is 0.00501 |
altlinux: CVE-2026-15115 was patched at 2026-07-09
debian: CVE-2026-15115 was patched at 2026-07-11, 2026-07-14
978.
Unknown Vulnerability Type - Mozilla Firefox (CVE-2026-15719) - Medium [329]
Description: {'nvd_cve_data_all': 'We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'We are aware that exploit code for this is public however we are not aware of any attacks in the wild abusing this flaw. This vulnerability was fixed in Firefox 152.0.6, Firefox ESR 115.38, Firefox ESR 140.13, and Thunderbird 140.13.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0.5 | 17 | The existence of a private exploit is mentioned on BDU:PrivateExploit website | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Mozilla Firefox, or simply Firefox, is a free and open-source web browser developed by the Mozilla Foundation and its subsidiary, the Mozilla Corporation | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00339, EPSS Percentile is 0.26455 |
altlinux: CVE-2026-15719 was patched at 2026-07-15, 2026-07-30
debian: CVE-2026-15719 was patched at 2026-07-22, 2026-07-30
oraclelinux: CVE-2026-15719 was patched at 2026-07-28
redhat: CVE-2026-15719 was patched at 2026-07-28
979.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63886) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Validate CHAP_R length before base64 decode chap_server_compute_hash() allocates client_digest as kzalloc(chap->digest_size) and then, for BASE64-encoded responses, passes chap_r directly to chap_base64_decode() without checking whether the input length could produce more than digest_size bytes of output. chap_base64_decode() writes to the destination unconditionally as long as there is input to consume. With MAX_RESPONSE_LENGTH set to 128 and the "0b" prefix stripped by extract_param(), up to 127 base64 characters can reach the decoder. 127 characters decode to 95 bytes. For SHA-256 (digest_size=32) this overflows client_digest by 63 bytes; for MD5 (digest_size=16) the overflow is 79 bytes. The length check at line 344 fires after the write has already happened. The HEX branch in the same switch statement already validates the length up front. Apply the same approach to the BASE64 branch: strip trailing base64 padding characters, then reject any input whose data length exceeds DIV_ROUND_UP(digest_size * 4, 3) before calling the decoder. Stripping trailing '=' before the comparison handles both padded and unpadded encodings. chap_base64_decode() already returns early on '=', so the full original string is still passed to the decoder unchanged. The mutual CHAP path decodes CHAP_C into initiatorchg_binhex, which is kzalloc(CHAP_CHALLENGE_STR_LEN). extract_param() caps initiatorchg at CHAP_CHALLENGE_STR_LEN characters, so at most CHAP_CHALLENGE_STR_LEN-1 base64 characters reach the decoder. The maximum decoded size, DIV_ROUND_UP((CHAP_CHALLENGE_STR_LEN-1) * 3, 4), is less than CHAP_CHALLENGE_STR_LEN, so no overflow is possible there. A comment is added at the call site to document this.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: iscsi: Validate CHAP_R length before base64 decode\n\nchap_server_compute_hash() allocates client_digest as\nkzalloc(chap->digest_size) and then, for BASE64-encoded responses,\npasses chap_r directly to chap_base64_decode() without checking whether\nthe input length could produce more than digest_size bytes of output.\n\nchap_base64_decode() writes to the destination unconditionally as long\nas there is input to consume. With MAX_RESPONSE_LENGTH set to 128 and\nthe "0b" prefix stripped by extract_param(), up to 127 base64 characters\ncan reach the decoder. 127 characters decode to 95 bytes. For SHA-256\n(digest_size=32) this overflows client_digest by 63 bytes; for MD5\n(digest_size=16) the overflow is 79 bytes.\n\nThe length check at line 344 fires after the write has already happened.\n\nThe HEX branch in the same switch statement already validates the length\nup front. Apply the same approach to the BASE64 branch: strip trailing\nbase64 padding characters, then reject any input whose data length\nexceeds DIV_ROUND_UP(digest_size * 4, 3) before calling the decoder.\n\nStripping trailing '=' before the comparison handles both padded and\nunpadded encodings. chap_base64_decode() already returns early on '=',\nso the full original string is still passed to the decoder unchanged.\n\nThe mutual CHAP path decodes CHAP_C into initiatorchg_binhex, which is\nkzalloc(CHAP_CHALLENGE_STR_LEN). extract_param() caps initiatorchg at\nCHAP_CHALLENGE_STR_LEN characters, so at most CHAP_CHALLENGE_STR_LEN-1\nbase64 characters reach the decoder. The maximum decoded size,\nDIV_ROUND_UP((CHAP_CHALLENGE_STR_LEN-1) * 3, 4), is less than\nCHAP_CHALLENGE_STR_LEN, so no overflow is possible there. A comment is\nadded at the call site to document this.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00664, EPSS Percentile is 0.48129 |
debian: CVE-2026-63886 was patched at 2026-07-14
ubuntu: CVE-2026-63886 was patched at 2026-07-30
980.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63887) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_encode_text_output() concatenates "key=value\\0" records into login->rsp_buf, an 8192-byte kzalloc(MAX_KEY_VALUE_PAIRS) buffer allocated in iscsit_alloc_login_setup_buffer(). The three sprintf() call sites in this function (lines 1398, 1411, 1424 in v7.1-rc2) never check the remaining buffer capacity: \t*length += sprintf(output_buf, "%s=%s", er->key, er->value); \t*length += 1; \toutput_buf = textbuf + *length; The 8192-byte ceiling at iscsi_target_check_login_request() bounds the *input* Login PDU payload, but a single PDU can carry up to 2048 minimal four-byte "a=b\\0" pairs, each unknown key expanding to a 16-byte "a=NotUnderstood\\0" output record via iscsi_add_notunderstood_response(). 2048 * 16 = 32 KiB of output into an 8 KiB buffer, producing a ~24 KiB heap overrun in the kmalloc-8k slab. The fix introduces a static iscsi_encode_text_record() helper that uses snprintf() with a per-call bounds check against the remaining buffer, and threads a u32 textbuf_size parameter through iscsi_encode_text_output(). Both call sites in iscsi_target_handle_csg_zero() (PHASE_SECURITY) and iscsi_target_handle_csg_one() (PHASE_OPERATIONAL) pass MAX_KEY_VALUE_PAIRS. On overflow the encoder logs the condition, calls iscsi_release_extra_responses() to drop queued records, and returns -1; both caller sites now emit ISCSI_STATUS_CLS_INITIATOR_ERR / ISCSI_LOGIN_STATUS_INIT_ERR via iscsit_tx_login_rsp() before returning, so the initiator sees an explicit failed-login response rather than a silent connection drop. (Prior to this patch only the PHASE_OPERATIONAL caller did that; the PHASE_SECURITY caller is converted to the same shape.)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf\n\niscsi_encode_text_output() concatenates "key=value\\0" records into\nlogin->rsp_buf, an 8192-byte kzalloc(MAX_KEY_VALUE_PAIRS) buffer\nallocated in iscsit_alloc_login_setup_buffer(). The three sprintf() call\nsites in this function (lines 1398, 1411, 1424 in v7.1-rc2) never check\nthe remaining buffer capacity:\n\n\t*length += sprintf(output_buf, "%s=%s", er->key, er->value);\n\t*length += 1;\n\toutput_buf = textbuf + *length;\n\nThe 8192-byte ceiling at iscsi_target_check_login_request() bounds the\n*input* Login PDU payload, but a single PDU can carry up to 2048 minimal\nfour-byte "a=b\\0" pairs, each unknown key expanding to a 16-byte\n"a=NotUnderstood\\0" output record via iscsi_add_notunderstood_response().\n2048 * 16 = 32 KiB of output into an 8 KiB buffer, producing a ~24 KiB\nheap overrun in the kmalloc-8k slab.\n\nThe fix introduces a static iscsi_encode_text_record() helper that uses\nsnprintf() with a per-call bounds check against the remaining buffer,\nand threads a u32 textbuf_size parameter through\niscsi_encode_text_output(). Both call sites in\niscsi_target_handle_csg_zero() (PHASE_SECURITY) and\niscsi_target_handle_csg_one() (PHASE_OPERATIONAL) pass\nMAX_KEY_VALUE_PAIRS. On overflow the encoder logs the condition, calls\niscsi_release_extra_responses() to drop queued records, and returns -1;\nboth caller sites now emit ISCSI_STATUS_CLS_INITIATOR_ERR /\nISCSI_LOGIN_STATUS_INIT_ERR via iscsit_tx_login_rsp() before returning,\nso the initiator sees an explicit failed-login response rather than a\nsilent connection drop. (Prior to this patch only the PHASE_OPERATIONAL\ncaller did that; the PHASE_SECURITY caller is converted to the same\nshape.)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00745, EPSS Percentile is 0.51172 |
debian: CVE-2026-63887 was patched at 2026-07-14
ubuntu: CVE-2026-63887 was patched at 2026-07-30
981.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63888) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() Two latent bugs in the Text-phase handler, both present since the original LIO integration in commit e48354ce078c ("iscsi-target: Add iSCSI fabric support for target v4.1"): 1) DataDigest CRC buffer overread (4 bytes past text_in). text_in is kzalloc()'d at ALIGN(payload_length, 4). rx_size is then incremented by ISCSI_CRC_LEN to make room for the received DataDigest in the iovec, but the same (now-bumped) rx_size is passed as the buffer length to iscsit_crc_buf(): if (conn->conn_ops->DataDigest) { ... rx_size += ISCSI_CRC_LEN; } ... if (conn->conn_ops->DataDigest) { data_crc = iscsit_crc_buf(text_in, rx_size, 0, NULL); iscsit_crc_buf() walks rx_size bytes of text_in with crc32c(), so when DataDigest is negotiated it reads 4 bytes past the end of the text_in allocation. KASAN reproduces this directly on the unpatched mainline tree as slab-out-of-bounds in crc32c() called from the Text PDU path. The OOB bytes feed crc32c() and are then compared against the initiator-supplied checksum, so the value does not flow back to the attacker, but the kernel does read past the buffer on every Text PDU with DataDigest=CRC32C. Fix by passing the actual padded payload length (ALIGN(payload_length, 4)) that was used for the kzalloc(). 2) Stale cmd->text_in_ptr re-free (double-free) on ERL>0 bad DataDigest drop. On DataDigest mismatch with ErrorRecoveryLevel > 0 the handler silently drops the PDU and lets the initiator plug the CmdSN gap: kfree(text_in); return 0; cmd->text_in_ptr still points at the freed buffer. The next Text Request on the same ITT re-enters iscsit_setup_text_cmd(), which unconditionally does kfree(cmd->text_in_ptr); cmd->text_in_ptr = NULL; freeing the same pointer a second time. Session teardown via iscsit_release_cmd() has the same shape and hits the same double-free if the connection is dropped before a second Text Request arrives. On an unmodified mainline tree the bug-1 CRC overread fires first on the initial valid Text Request and perturbs the subsequent state, so #4 was isolated by building a kernel with only the bug-1 hunk of this patch applied plus temporary printk() observability around the three relevant kfree() sites. The observability prints are not part of this patch. On that build, a three-PDU Text Request sequence after login produces two back-to-back splats: BUG: KASAN: double-free in iscsit_setup_text_cmd+0x?? BUG: KASAN: double-free in iscsit_release_cmd+0x?? showing the same pointer freed in the ERL>0 drop path and again in iscsit_setup_text_cmd() (next Text Request on the same ITT) and once more in iscsit_release_cmd() (session teardown). On distro kernels with CONFIG_SLAB_FREELIST_HARDENED=y (default) the double-free becomes a remote kernel BUG(); on non-hardened kernels it corrupts the slab freelist. Fix by clearing cmd->text_in_ptr after the kfree() in the ERL>0 drop path. With both hunks applied #4 is directly observable on the stock tree without observability printks; fixing bug-1 alone would mask #4 less, not more, so the hunks are submitted together. Both fixes are one-liners. The Text PDU state machine is unchanged and the wire protocol is unaffected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd()\n\nTwo latent bugs in the Text-phase handler, both present since the\noriginal LIO integration in commit e48354ce078c ("iscsi-target: Add\niSCSI fabric support for target v4.1"):\n\n1) DataDigest CRC buffer overread (4 bytes past text_in).\n\n text_in is kzalloc()'d at ALIGN(payload_length, 4). rx_size is then\n incremented by ISCSI_CRC_LEN to make room for the received DataDigest\n in the iovec, but the same (now-bumped) rx_size is passed as the\n buffer length to iscsit_crc_buf():\n\n if (conn->conn_ops->DataDigest) {\n ...\n rx_size += ISCSI_CRC_LEN;\n }\n ...\n if (conn->conn_ops->DataDigest) {\n data_crc = iscsit_crc_buf(text_in, rx_size, 0, NULL);\n\n iscsit_crc_buf() walks rx_size bytes of text_in with crc32c(), so\n when DataDigest is negotiated it reads 4 bytes past the end of the\n text_in allocation. KASAN reproduces this directly on the unpatched\n mainline tree as slab-out-of-bounds in crc32c() called from the Text\n PDU path. The OOB bytes feed crc32c() and are then compared against\n the initiator-supplied checksum, so the value does not flow back to\n the attacker, but the kernel does read past the buffer on every Text\n PDU with DataDigest=CRC32C.\n\n Fix by passing the actual padded payload length\n (ALIGN(payload_length, 4)) that was used for the kzalloc().\n\n2) Stale cmd->text_in_ptr re-free (double-free) on ERL>0 bad DataDigest\n drop.\n\n On DataDigest mismatch with ErrorRecoveryLevel > 0 the handler\n silently drops the PDU and lets the initiator plug the CmdSN gap:\n\n kfree(text_in);\n return 0;\n\n cmd->text_in_ptr still points at the freed buffer. The next Text\n Request on the same ITT re-enters iscsit_setup_text_cmd(), which\n unconditionally does\n\n kfree(cmd->text_in_ptr);\n cmd->text_in_ptr = NULL;\n\n freeing the same pointer a second time. Session teardown via\n iscsit_release_cmd() has the same shape and hits the same double-free\n if the connection is dropped before a second Text Request arrives.\n\n On an unmodified mainline tree the bug-1 CRC overread fires first on\n the initial valid Text Request and perturbs the subsequent state, so\n #4 was isolated by building a kernel with only the bug-1 hunk of this\n patch applied plus temporary printk() observability around the three\n relevant kfree() sites. The observability prints are not part of\n this patch. On that build, a three-PDU Text Request sequence after\n login produces two back-to-back splats:\n\n BUG: KASAN: double-free in iscsit_setup_text_cmd+0x??\n BUG: KASAN: double-free in iscsit_release_cmd+0x??\n\n showing the same pointer freed in the ERL>0 drop path and again in\n iscsit_setup_text_cmd() (next Text Request on the same ITT) and once\n more in iscsit_release_cmd() (session teardown). On distro kernels\n with CONFIG_SLAB_FREELIST_HARDENED=y (default) the double-free\n becomes a remote kernel BUG(); on non-hardened kernels it corrupts\n the slab freelist.\n\n Fix by clearing cmd->text_in_ptr after the kfree() in the ERL>0 drop\n path. With both hunks applied #4 is directly observable on the stock\n tree without observability printks; fixing bug-1 alone would mask #4\n less, not more, so the hunks are submitted together.\n\nBoth fixes are one-liners. The Text PDU state machine is unchanged and\nthe wire protocol is unaffected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00745, EPSS Percentile is 0.51172 |
debian: CVE-2026-63888 was patched at 2026-07-14
ubuntu: CVE-2026-63888 was patched at 2026-07-30
982.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63912) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfrm: esp: restore combined single-frag length gate The ESP out-of-place fast path appends the trailer in esp_output_head() before esp_output_tail() allocates the destination page frag. The head-side gate currently checks skb->data_len and tailen separately, but the tail code allocates a single destination frag from the combined post-trailer skb->data_len. Reject the page-frag fast path when the combined aligned length exceeds a page. Otherwise skb_page_frag_refill() may fall back to a single page while the destination sg still spans the combined skb->data_len. Restore this combined-length page gate for both IPv4 and IPv6.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: esp: restore combined single-frag length gate\n\nThe ESP out-of-place fast path appends the trailer in esp_output_head()\nbefore esp_output_tail() allocates the destination page frag. The\nhead-side gate currently checks skb->data_len and tailen separately, but\nthe tail code allocates a single destination frag from the combined\npost-trailer skb->data_len.\n\nReject the page-frag fast path when the combined aligned length exceeds a\npage. Otherwise skb_page_frag_refill() may fall back to a single page while\nthe destination sg still spans the combined skb->data_len.\n\nRestore this combined-length page gate for both IPv4 and IPv6.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00704, EPSS Percentile is 0.49691 |
debian: CVE-2026-63912 was patched at 2026-07-14
ubuntu: CVE-2026-63912 was patched at 2026-07-30
983.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63922) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh after handling HAO option ip6_parse_tlv() caches skb_network_header(skb) in nh while walking IPv6 TLVs. ipv6_dest_hao() may call pskb_expand_head() for a cloned skb, which can move the skb head and invalidate the cached network header pointer. Refresh nh after ipv6_dest_hao() returns so any trailing padding or TLVs are parsed from the current skb head. This matches the existing pattern used in ip6_parse_tlv() after helpers that can modify skb header storage.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: exthdrs: refresh nh after handling HAO option\n\nip6_parse_tlv() caches skb_network_header(skb) in nh while walking\nIPv6 TLVs.\n\nipv6_dest_hao() may call pskb_expand_head() for a cloned skb, which can\nmove the skb head and invalidate the cached network header pointer.\nRefresh nh after ipv6_dest_hao() returns so any trailing padding or TLVs\nare parsed from the current skb head.\n\nThis matches the existing pattern used in ip6_parse_tlv() after helpers\nthat can modify skb header storage.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00695, EPSS Percentile is 0.49363 |
debian: CVE-2026-63922 was patched at 2026-07-14
ubuntu: CVE-2026-63922 was patched at 2026-07-30
984.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63924) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo() ipv6_hop_jumbo() calls pskb_trim_rcsum(), which can change skb pointers. Let's recompute nh pointer to make sure any change won't mess things up.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: exthdrs: refresh nh pointer after ipv6_hop_jumbo()\n\nipv6_hop_jumbo() calls pskb_trim_rcsum(), which can change skb pointers.\nLet's recompute nh pointer to make sure any change won't mess things up.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00695, EPSS Percentile is 0.49363 |
debian: CVE-2026-63924 was patched at 2026-07-14
ubuntu: CVE-2026-63924 was patched at 2026-07-30
985.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63978) - Medium [328]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/handshake: Drain pending requests at net namespace exit The arguments to list_splice_init() in handshake_net_exit() are reversed. The call moves the local empty "requests" list onto hn->hn_requests, leaving the local list empty, so the subsequent drain loop runs zero iterations. Pending handshake requests that had not yet been accepted are not torn down when the net namespace is destroyed; each one keeps a reference on a socket file and on the handshake_req allocation. Pass the source and destination in the documented order (list_splice_init(list, head) moves list onto head) so the pending list is transferred to the local scratch list and drained through handshake_complete(). Fixing the splice direction exposes a list-corruption race. After the splice each req->hr_list still has non-empty link pointers, threading the stack-local scratch list rather than hn_requests. A concurrent handshake_req_cancel() -- for example, from sunrpc's TLS timeout on a kernel socket whose netns reference was not taken -- finds the request through the rhashtable, calls remove_pending(), and sees !list_empty(&req->hr_list). __remove_pending_locked() then list_del_init()s an entry off the scratch list while the drain iterates, corrupting it. The same call arriving after the drain loop has run list_del() on an entry hits LIST_POISON instead. Have remove_pending() check HANDSHAKE_F_NET_DRAINING under hn_lock and report not-found when drain is in progress. The drain has already taken ownership; handshake_complete()'s existing test_and_set on HANDSHAKE_F_REQ_COMPLETED still arbitrates between drain and cancel for who calls the consumer's hp_done. Use list_del_init() rather than list_del() in the drain so req->hr_list does not carry LIST_POISON after drain releases the entry. The DRAINING guard in remove_pending() makes cancel return false, but cancel still falls through to test_and_set_bit on HANDSHAKE_F_REQ_COMPLETED and drops the request's hr_file reference. Without another pin, if that is the last reference, sk_destruct frees the request while it is still linked on the drain loop's local list. Pin each request's hr_file under hn_lock before releasing the list, and drop that drain pin after the loop finishes with the request.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/handshake: Drain pending requests at net namespace exit\n\nThe arguments to list_splice_init() in handshake_net_exit() are\nreversed. The call moves the local empty "requests" list onto\nhn->hn_requests, leaving the local list empty, so the subsequent\ndrain loop runs zero iterations. Pending handshake requests that\nhad not yet been accepted are not torn down when the net namespace\nis destroyed; each one keeps a reference on a socket file and on\nthe handshake_req allocation.\n\nPass the source and destination in the documented order\n(list_splice_init(list, head) moves list onto head) so the pending\nlist is transferred to the local scratch list and drained through\nhandshake_complete().\n\nFixing the splice direction exposes a list-corruption race. After\nthe splice each req->hr_list still has non-empty link pointers,\nthreading the stack-local scratch list rather than hn_requests.\nA concurrent handshake_req_cancel() -- for example, from sunrpc's\nTLS timeout on a kernel socket whose netns reference was not\ntaken -- finds the request through the rhashtable, calls\nremove_pending(), and sees !list_empty(&req->hr_list).\n__remove_pending_locked() then list_del_init()s an entry off the\nscratch list while the drain iterates, corrupting it. The same\ncall arriving after the drain loop has run list_del() on an\nentry hits LIST_POISON instead.\n\nHave remove_pending() check HANDSHAKE_F_NET_DRAINING under\nhn_lock and report not-found when drain is in progress. The\ndrain has already taken ownership; handshake_complete()'s existing\ntest_and_set on HANDSHAKE_F_REQ_COMPLETED still arbitrates\nbetween drain and cancel for who calls the consumer's hp_done. Use\nlist_del_init() rather than list_del() in the drain so req->hr_list\ndoes not carry LIST_POISON after drain releases the entry.\n\nThe DRAINING guard in remove_pending() makes cancel return false,\nbut cancel still falls through to test_and_set_bit on\nHANDSHAKE_F_REQ_COMPLETED and drops the request's hr_file reference.\nWithout another pin, if that is the last reference, sk_destruct frees\nthe request while it is still linked on the drain loop's local list.\nPin each request's hr_file under hn_lock before releasing the list,\nand drop that drain pin after the loop finishes with the request.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00598, EPSS Percentile is 0.4521 |
debian: CVE-2026-63978 was patched at 2026-07-14
ubuntu: CVE-2026-63978 was patched at 2026-07-30
986.
Denial of Service - Gawk (CVE-2026-40469) - Medium [327]
Description: Integer overflow vulnerability has been found in "builtin.c" program file of gawk (do_sub() routine). This issue could be used to overwrite gawk heap metadata and objects causing the program
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:fossies:gawk (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00213, EPSS Percentile is 0.11802 |
debian: CVE-2026-40469 was patched at 2026-07-14
ubuntu: CVE-2026-40469 was patched at 2026-07-30
987.
Denial of Service - ProFTPD (CVE-2026-53994) - Medium [327]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | ProFTPD is a highly configurable and modular open-source FTP server designed for Unix-like systems, offering advanced features such as virtual hosting, authentication modules, and flexible configuration similar to Apache. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00406, EPSS Percentile is 0.33324 |
debian: CVE-2026-53994 was patched at 2026-07-14
988.
Denial of Service - fzf (CVE-2026-53432) - Medium [327]
Description: fzf is vulnerable to Integer Overflow leading
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:junegunn:fzf (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0024, EPSS Percentile is 0.15313 |
debian: CVE-2026-53432 was patched at 2026-07-14
989.
Denial of Service - grafana (CVE-2026-33378) - Medium [327]
Description: Using the $__timeGroup macro, one can achieve an OOM by overloading the server. This requires a SQL datasource. If the server is set up to auto-restart, the impact is minimal or non-existent, as the attack can take upwards of half an hour to crash the server.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:grafana:grafana (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25385 |
redos: CVE-2026-33378 was patched at 2026-07-08
990.
Denial of Service - openvpn (CVE-2026-13698) - Medium [327]
Description: A memory leak in OpenVPN version 2.5.0 through 2.5.11, 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers with a valid tls-crypt-v2 client key to potentially cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:openvpn:openvpn (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00314, EPSS Percentile is 0.23786 |
debian: CVE-2026-13698 was patched at 2026-07-03, 2026-07-14
ubuntu: CVE-2026-13698 was patched at 2026-07-30
991.
Incorrect Calculation - perl (CVE-2026-13221) - Medium [327]
Description: Perl versions through 5.43.9 produce silently incorrect regular expression matches when an alternation of more than 65535 fixed string branches is compiled into a trie in Perl_study_chunk. When such branches are combined into a trie, the delta between the first branch and the shared tail is stored in a 16-bit field. A branch count above 65535 overflows the field, and the trie's match decision table is truncated with no warning or error. A pattern of this shape produces false positive matches (matching strings it should not) and false negative matches (failing to match strings it should). When such a pattern gates an access or filtering decision, the result is wrong.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:perl:perl (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00432, EPSS Percentile is 0.35546 |
debian: CVE-2026-13221 was patched at 2026-07-14
992.
Incorrect Calculation - storable (CVE-2026-57433) - Medium [327]
Description: Storable versions before 3.41 for Perl have a signed integer overflow when deserializing a crafted SX_HOOK record. retrieve_hook_common reads a signed 32-bit item count from an SX_HOOK record and calls av_extend with that count plus one. A count of I32_MAX wraps the addition to a negative value. A crafted blob passed to thaw or retrieve triggers the overflow; av_extend receives the negative count and dies with a panic, terminating the deserialization.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:nwclark:storable (does NOT exist in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00357, EPSS Percentile is 0.28413 |
debian: CVE-2026-57433 was patched at 2026-07-14
993.
Memory Corruption - DBI (CVE-2026-14739) - Medium [327]
Description: DBI versions before 1.650 for Perl have a heap overflow when preparsing SQL statements with an extreme number of placeholders. The fix for CVE-2026-10879 did not allocate enough memory to handle approximately 1.2-million placeholders. DBI version 1.650 sets a hard limit of 99,999 placeholders.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:perl:dbi (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00391, EPSS Percentile is 0.31872 |
altlinux: CVE-2026-14739 was patched at 2026-07-21
debian: CVE-2026-14739 was patched at 2026-07-14
994.
Memory Corruption - wolfssl (CVE-2026-7531) - Medium [327]
Description: Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server sending a truncated PQC hybrid KeyShare can still trigger the error cleanup path to operate on freed memory.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00347, EPSS Percentile is 0.27319 |
debian: CVE-2026-7531 was patched at 2026-07-14
995.
Security Feature Bypass - Xrdp (CVE-2026-44978) - Medium [327]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | xrdp is an open source remote desktop protocol server | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00314, EPSS Percentile is 0.23851 |
altlinux: CVE-2026-44978 was patched at 2026-07-08
debian: CVE-2026-44978 was patched at 2026-07-14
996.
Security Feature Bypass - simplesamlphp (CVE-2026-49284) - Medium [327]
Description: SimpleSAMLphp versions before 1.18.6 contain an information disclosure vulnerability. Prior to 2.4.7 and 2.5.2, SimpleSAMLphp's SAML SP ACS path does not enforce the IdP selected for an SP-initiated login when unsigned Response/InResponseTo is combined with a signed assertion lacking SubjectConfirmationData/InResponseTo, allowing a response issued by one trusted IdP to be bound to SP state created for another IdP and bypass flows that route users to a specific IdP, including deployments that set enable_unsolicited to false. This issue is fixed in versions 2.4.7 and 2.5.2.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:simplesamlphp:simplesamlphp (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00153, EPSS Percentile is 0.04948 |
debian: CVE-2026-49284 was patched at 2026-07-14
997.
Security Feature Bypass - wolfssl (CVE-2026-6330) - Medium [327]
Description: The ML-KEM ARM64 NEON ciphertext comparison only compares half of the input, breaking the Fujisaki-Okamoto transform's implicit rejection and weakening IND-CCA2 security on that code path. The constant-time comparison effectively ignored part of the re-encrypted ciphertext, so a decapsulating party could fail to detect a manipulated ciphertext and proceed without the standard's required implicit rejection.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00135, EPSS Percentile is 0.03391 |
debian: CVE-2026-6330 was patched at 2026-07-14
998.
Information Disclosure - mediawiki (CVE-2026-58027) - Medium [326]
Description: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation AbuseFilter. This vulnerability is associated with program files includes/Api/QueryAbuseFilters.Php. This issue affects AbuseFilter: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | Product detected by a:mediawiki:mediawiki (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14386 |
debian: CVE-2026-58027 was patched at 2026-07-05, 2026-07-14
999.
Incorrect Calculation - Linux Kernel (CVE-2026-53143) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00143, EPSS Percentile is 0.04033 |
altlinux: CVE-2026-53143 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53143 was patched at 2026-07-14
1000.
Incorrect Calculation - Linux Kernel (CVE-2026-53277) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00107, EPSS Percentile is 0.01315 |
altlinux: CVE-2026-53277 was patched at 2026-06-19, 2026-06-22, 2026-07-06
debian: CVE-2026-53277 was patched at 2026-07-14
ubuntu: CVE-2026-53277 was patched at 2026-07-30
1001.
Incorrect Calculation - Rust (CVE-2026-45784) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.9 | 14 | Rust is a modern, high-performance systems programming language focused on safety, concurrency, and memory management. | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03333 |
debian: CVE-2026-45784 was patched at 2026-07-14
1002.
Memory Corruption - Django (CVE-2026-53877) - Medium [322]
Description: An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | Django is a high-level Python web framework that encourages rapid development and clean, pragmatic design. It provides built-in tools for database models, authentication, URL routing, templates, and security features, making it one of the most widely used frameworks for building scalable and maintainable web applications. | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00281, EPSS Percentile is 0.20342 |
altlinux: CVE-2026-53877 was patched at 2026-07-27
debian: CVE-2026-53877 was patched at 2026-07-14
1003.
Memory Corruption - Linux Kernel (CVE-2026-52917) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02657 |
altlinux: CVE-2026-52917 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-52917 was patched at 2026-07-14
1004.
Memory Corruption - Linux Kernel (CVE-2026-52942) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02633 |
altlinux: CVE-2026-52942 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-52942 was patched at 2026-07-14
1005.
Memory Corruption - Linux Kernel (CVE-2026-53138) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.0266 |
altlinux: CVE-2026-53138 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53138 was patched at 2026-07-14, 2026-07-30
1006.
Memory Corruption - Linux Kernel (CVE-2026-53145) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00099, EPSS Percentile is 0.00957 |
altlinux: CVE-2026-53145 was patched at 2026-06-19, 2026-06-22, 2026-07-06
1007.
Memory Corruption - Linux Kernel (CVE-2026-53148) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00135, EPSS Percentile is 0.03405 |
altlinux: CVE-2026-53148 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53148 was patched at 2026-07-14
1008.
Memory Corruption - Linux Kernel (CVE-2026-53149) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.0266 |
altlinux: CVE-2026-53149 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53149 was patched at 2026-07-14
1009.
Memory Corruption - Linux Kernel (CVE-2026-53179) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02614 |
altlinux: CVE-2026-53179 was patched at 2026-06-19, 2026-06-22, 2026-07-06
debian: CVE-2026-53179 was patched at 2026-07-05, 2026-07-14
1010.
Memory Corruption - Linux Kernel (CVE-2026-53185) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00095, EPSS Percentile is 0.00799 |
altlinux: CVE-2026-53185 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53185 was patched at 2026-07-14
1011.
Memory Corruption - Linux Kernel (CVE-2026-53187) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.0252 |
altlinux: CVE-2026-53187 was patched at 2026-06-19, 2026-06-22, 2026-07-06
1012.
Memory Corruption - Linux Kernel (CVE-2026-53202) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00143, EPSS Percentile is 0.04033 |
altlinux: CVE-2026-53202 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53202 was patched at 2026-07-14
1013.
Memory Corruption - Linux Kernel (CVE-2026-53203) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00143, EPSS Percentile is 0.04033 |
altlinux: CVE-2026-53203 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53203 was patched at 2026-07-14
1014.
Memory Corruption - Linux Kernel (CVE-2026-53205) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02614 |
altlinux: CVE-2026-53205 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53205 was patched at 2026-07-14
1015.
Memory Corruption - Linux Kernel (CVE-2026-53255) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01948 |
altlinux: CVE-2026-53255 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53255 was patched at 2026-07-14
1016.
Memory Corruption - Linux Kernel (CVE-2026-53330) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02518 |
altlinux: CVE-2026-53330 was patched at 2026-06-19, 2026-06-22, 2026-07-06
debian: CVE-2026-53330 was patched at 2026-07-14
1017.
Memory Corruption - Linux Kernel (CVE-2026-53346) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00116, EPSS Percentile is 0.01905 |
altlinux: CVE-2026-53346 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53346 was patched at 2026-07-14
1018.
Memory Corruption - Linux Kernel (CVE-2026-53402) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02877 |
debian: CVE-2026-53402 was patched at 2026-07-14, 2026-07-21
1019.
Memory Corruption - Linux Kernel (CVE-2026-53403) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00187, EPSS Percentile is 0.08615 |
debian: CVE-2026-53403 was patched at 2026-07-14, 2026-07-30
1020.
Memory Corruption - Linux Kernel (CVE-2026-64126) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00135, EPSS Percentile is 0.03401 |
debian: CVE-2026-64126 was patched at 2026-07-14
ubuntu: CVE-2026-64126 was patched at 2026-07-30
1021.
Security Feature Bypass - Linux Kernel (CVE-2026-64155) - Medium [322]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06993 |
debian: CVE-2026-64155 was patched at 2026-07-14
ubuntu: CVE-2026-64155 was patched at 2026-07-30
1022.
Cross Site Scripting - Thunderbird (CVE-2026-57963) - Medium [321]
Description: An attacker who can send HTML chat messages (via Matrix or XMPP) can inject arbitrary styled content, phishing links, and CSS that manipulates the chat UI. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Product detected by a:mozilla:thunderbird (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00191, EPSS Percentile is 0.09092 |
altlinux: CVE-2026-57963 was patched at 2026-07-02
debian: CVE-2026-57963 was patched at 2026-07-14
1023.
Cross Site Scripting - prometheus (CVE-2026-40179) - Medium [321]
Description: Prometheus is an open-source monitoring system and time series database. Versions 3.0 through 3.5.1 and 3.6.0 through 3.11.1 have stored cross-site scripting vulnerabilities in multiple components of the Prometheus web UI where metric names and label values are injected into innerHTML without escaping. In both the Mantine UI and old React UI, chart tooltips on the Graph page render metric names containing HTML/JavaScript without sanitization. In the old React UI, the Metric Explorer fuzzy search results use dangerouslySetInnerHTML without escaping, and heatmap cell tooltips interpolate le label values without sanitization. With Prometheus v3.x defaulting to UTF-8 metric and label name validation, characters like <, >, and " are now valid in metric names and labels. An attacker who can inject metrics via a compromised scrape target, remote write, or OTLP receiver endpoint can execute arbitrary JavaScript in the browser of any Prometheus user who views the metric in the Graph UI, potentially enabling configuration exfiltration, data deletion, or Prometheus shutdown depending on enabled flags. This issue has been fixed in versions 3.5.2 and 3.11.2. If developers are unable to immediately update, the following workarounds are recommended: ensure that the remote write receiver (--web.enable-remote-write-receiver) and the OTLP receiver (--web.enable-otlp-receiver) are not exposed to untrusted sources; verify that all scrape targets are trusted and not under attacker control; avoid enabling admin or mutating API endpoints (e.g., --web.enable-admin-api or --web.enable-lifecycle) in environments where untrusted data may be ingested; and refrain from clicking untrusted links, particularly those containing functions such as label_replace, as they may generate poisoned label names and values.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Product detected by a:prometheus:prometheus (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00259, EPSS Percentile is 0.17585 |
altlinux: CVE-2026-40179 was patched at 2026-06-29, 2026-07-29
1024.
Remote Code Execution - Libarchive (CVE-2026-15028) - Medium [321]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.5 | 14 | Multi-format archive and compression library | |
| 0.4 | 10 | CVSS Base Score is 3.9. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00203, EPSS Percentile is 0.10488 |
debian: CVE-2026-15028 was patched at 2026-07-14
ubuntu: CVE-2026-15028 was patched at 2026-07-30
1025.
Denial of Service - ImageMagick (CVE-2026-61465) - Medium [320]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06952 |
altlinux: CVE-2026-61465 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-61465 was patched at 2026-07-14
1026.
Denial of Service - Python (CVE-2026-48045) - Medium [320]
Description: Zeroconf is a pure
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.13939 |
debian: CVE-2026-48045 was patched at 2026-07-14
1027.
Memory Corruption - Perl (CVE-2026-12844) - Medium [320]
Description: List::SomeUtils::XS versions before 0.59 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00398, EPSS Percentile is 0.32576 |
debian: CVE-2026-12844 was patched at 2026-07-14
1028.
Memory Corruption - Python (CVE-2025-26240) - Medium [320]
Description: In JazzCore
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00392, EPSS Percentile is 0.31955 |
debian: CVE-2025-26240 was patched at 2026-06-24
1029.
Memory Corruption - libxml2 (CVE-2026-57236) - Medium [320]
Description: Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, calling Document#encoding= with an invalid encoding (e.g., a non-string, or a string containing a null byte) raises an exception, but only after freeing the document's current encoding string without replacing it. The document is left referencing freed memory, so the next call to Document#encoding reads invalid memory, which can cause a segfault or leak freed bytes into a Ruby String. Affects the CRuby (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | libxml2 is an XML toolkit implemented in C, originally developed for the GNOME Project | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00341, EPSS Percentile is 0.26708 |
debian: CVE-2026-57236 was patched at 2026-07-14
1030.
Information Disclosure - ImageMagick (CVE-2026-53467) - Medium [319]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00198, EPSS Percentile is 0.0982 |
altlinux: CVE-2026-53467 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-53467 was patched at 2026-07-07, 2026-07-14
1031.
Memory Corruption - Vim (CVE-2026-55892) - Medium [319]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.95 | 14 | Highly configurable command-line text editor used in development and system administration. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02181 |
altlinux: CVE-2026-55892 was patched at 2026-06-30, 2026-07-06
debian: CVE-2026-55892 was patched at 2026-07-14
ubuntu: CVE-2026-55892 was patched at 2026-07-30
1032.
Memory Corruption - Vim (CVE-2026-57452) - Medium [319]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.95 | 14 | Highly configurable command-line text editor used in development and system administration. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.0199 |
altlinux: CVE-2026-57452 was patched at 2026-06-30, 2026-07-06
debian: CVE-2026-57452 was patched at 2026-07-14
ubuntu: CVE-2026-57452 was patched at 2026-07-30
1033.
Memory Corruption - Vim (CVE-2026-59857) - Medium [319]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.95 | 14 | Highly configurable command-line text editor used in development and system administration. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00107, EPSS Percentile is 0.01368 |
altlinux: CVE-2026-59857 was patched at 2026-06-30, 2026-07-06
debian: CVE-2026-59857 was patched at 2026-07-14
ubuntu: CVE-2026-59857 was patched at 2026-07-30
1034.
Authentication Bypass - Unknown Product (CVE-2026-14476) - Medium [317]
Description: {'nvd_cve_data_all': 'A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A path traversal flaw was found in SSSD's AD GPO provider. The ad_gpo_extract_smb_components() function does not sanitize .. sequences in the gPCFileSysPath LDAP attribute, allowing an attacker with AD GPO management access to write files outside the GPO cache directory as root. On default RHEL configurations with SELinux enforcing, this can be used to inject Kerberos configuration leading to authentication bypass.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.0. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00522, EPSS Percentile is 0.41368 |
almalinux: CVE-2026-14476 was patched at 2026-07-20
debian: CVE-2026-14476 was patched at 2026-07-14
oraclelinux: CVE-2026-14476 was patched at 2026-07-20, 2026-07-22
redhat: CVE-2026-14476 was patched at 2026-07-20, 2026-07-28
1035.
Authentication Bypass - freeswitch (CVE-2026-49848) - Medium [317]
Description: FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, mod_verto's check_auth userauth branch wrote request-supplied userVariables into the connection state before comparing the supplied password. The writes are append-only and the connection is not closed on a failed compare, so values declared on bad-password attempts persisted on the same WebSocket and carried into a subsequent successful login on that connection. This issue has been patched in version 1.11.1.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:freeswitch:freeswitch (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06843 |
altlinux: CVE-2026-49848 was patched at 2026-06-24, 2026-06-26, 2026-07-16
1036.
Denial of Service - Chromium (CVE-2026-14110) - Medium [317]
Description: Inappropriate implementation in DarkMode in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00194, EPSS Percentile is 0.09435 |
altlinux: CVE-2026-14110 was patched at 2026-07-03
debian: CVE-2026-14110 was patched at 2026-07-05, 2026-07-14
1037.
Denial of Service - Chromium (CVE-2026-14142) - Medium [317]
Description: Inappropriate implementation in Extensions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.07029 |
altlinux: CVE-2026-14142 was patched at 2026-07-03
debian: CVE-2026-14142 was patched at 2026-07-05, 2026-07-14
1038.
Incorrect Calculation - Chromium (CVE-2026-14069) - Medium [317]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00238, EPSS Percentile is 0.14949 |
altlinux: CVE-2026-14069 was patched at 2026-07-03
debian: CVE-2026-14069 was patched at 2026-07-05, 2026-07-14
1039.
Memory Corruption - Chromium (CVE-2026-13282) - Medium [317]
Description: Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00162, EPSS Percentile is 0.05899 |
altlinux: CVE-2026-13282 was patched at 2026-06-29
debian: CVE-2026-13282 was patched at 2026-07-05, 2026-07-14
1040.
Memory Corruption - Chromium (CVE-2026-13879) - Medium [317]
Description: Use after free in Bluetooth in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious peripheral. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.1264 |
altlinux: CVE-2026-13879 was patched at 2026-07-03
debian: CVE-2026-13879 was patched at 2026-07-05, 2026-07-14
1041.
Memory Corruption - Chromium (CVE-2026-14148) - Medium [317]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12735 |
altlinux: CVE-2026-14148 was patched at 2026-07-03
debian: CVE-2026-14148 was patched at 2026-07-05, 2026-07-14
1042.
Memory Corruption - Chromium (CVE-2026-15905) - Medium [317]
Description: Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowed a local attacker to potentially exploit heap corruption via a malicious file. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00109, EPSS Percentile is 0.01429 |
altlinux: CVE-2026-15905 was patched at 2026-07-18
debian: CVE-2026-15905 was patched at 2026-07-14, 2026-07-22
1043.
Memory Corruption - Safari (CVE-2026-43726) - Medium [317]
Description: A use-after-free issue was addressed with improved memory management. This issue is fixed in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00238, EPSS Percentile is 0.14941 |
almalinux: CVE-2026-43726 was patched at 2026-07-20
debian: CVE-2026-43726 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43726 was patched at 2026-07-20
redhat: CVE-2026-43726 was patched at 2026-07-20
1044.
Code Injection - Unknown Product (CVE-2025-61018) - Medium [316]
Description: {'nvd_cve_data_all': 'An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00476, EPSS Percentile is 0.38628 |
debian: CVE-2025-61018 was patched at 2026-07-14
1045.
Code Injection - Unknown Product (CVE-2025-61020) - Medium [316]
Description: {'nvd_cve_data_all': 'An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00476, EPSS Percentile is 0.38629 |
debian: CVE-2025-61020 was patched at 2026-07-14
1046.
Code Injection - Unknown Product (CVE-2025-61023) - Medium [316]
Description: {'nvd_cve_data_all': 'An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00476, EPSS Percentile is 0.38628 |
debian: CVE-2025-61023 was patched at 2026-07-14
1047.
Code Injection - Unknown Product (CVE-2025-61028) - Medium [316]
Description: {'nvd_cve_data_all': 'An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00476, EPSS Percentile is 0.38628 |
debian: CVE-2025-61028 was patched at 2026-07-14
1048.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53151) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix the ACK parser to extract the SACK table for parsing Fix modification of the received skbuff in rxrpc_input_soft_acks() and a potential incorrect access of the buffer in a fragmented UDP packet (the packet would probably have to be deliberately pre-generated as fragmented) when AF_RXRPC tries to extract the contents of the SACK table by copying out the contents of the SACK table into a buffer before attempting to parse AF_RXRPC assumes that it can just call skb_condense() and then validly access the SACK table from skb->data and that it will be a flat buffer - but skb_condense() can silently fail to do anything under some circumstances. Note that whilst rxrpc_input_soft_acks() should be able to parse extended ACKs, the rest of AF_RXRPC doesn't currently support that. Further, there's then no need to call skb_condense() in rxrpc_input_ack(), so don't.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix the ACK parser to extract the SACK table for parsing\n\nFix modification of the received skbuff in rxrpc_input_soft_acks() and a\npotential incorrect access of the buffer in a fragmented UDP packet (the\npacket would probably have to be deliberately pre-generated as fragmented)\nwhen AF_RXRPC tries to extract the contents of the SACK table by copying\nout the contents of the SACK table into a buffer before attempting to parse\n\nAF_RXRPC assumes that it can just call skb_condense() and then validly\naccess the SACK table from skb->data and that it will be a flat buffer -\nbut skb_condense() can silently fail to do anything under some\ncircumstances.\n\nNote that whilst rxrpc_input_soft_acks() should be able to parse extended\nACKs, the rest of AF_RXRPC doesn't currently support that.\n\nFurther, there's then no need to call skb_condense() in rxrpc_input_ack(),\nso don't.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00457, EPSS Percentile is 0.3739 |
altlinux: CVE-2026-53151 was patched at 2026-06-19, 2026-06-22, 2026-07-04, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53151 was patched at 2026-07-05, 2026-07-14
1049.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53215) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: refill RX buffers before XDP or skb use The RX error path returns the current descriptor buffer to the hardware BM pool. That is only valid while the driver still owns the buffer. mvpp2_rx_refill() can fail after the current buffer has been handed to XDP or attached to an skb. In those cases mvpp2_run_xdp() may have recycled, redirected, or queued the page for XDP_TX, and an skb free also retires the data buffer. Returning such a buffer to BM lets hardware DMA into memory that is no longer owned by the RX ring. Refill the BM pool before handing the current buffer to XDP or to the skb. If the allocation fails there, drop the packet and return the still-owned current buffer to BM, preserving the pool depth. Once the refill succeeds, later local drops retire/free the current buffer instead of returning it to BM.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mvpp2: refill RX buffers before XDP or skb use\n\nThe RX error path returns the current descriptor buffer to the hardware\nBM pool. That is only valid while the driver still owns the buffer.\n\nmvpp2_rx_refill() can fail after the current buffer has been handed to\nXDP or attached to an skb. In those cases mvpp2_run_xdp() may have\nrecycled, redirected, or queued the page for XDP_TX, and an skb free also\nretires the data buffer. Returning such a buffer to BM lets hardware DMA\ninto memory that is no longer owned by the RX ring.\n\nRefill the BM pool before handing the current buffer to XDP or to the\nskb. If the allocation fails there, drop the packet and return the\nstill-owned current buffer to BM, preserving the pool depth. Once the\nrefill succeeds, later local drops retire/free the current buffer instead\nof returning it to BM.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00502, EPSS Percentile is 0.40186 |
altlinux: CVE-2026-53215 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53215 was patched at 2026-07-14
1050.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53221) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup() In vti6_tnl_lookup(), when an exact match for a tunnel fails, the code falls back to searching for wildcard tunnels: - Tunnels matching the packet's local address, with any remote address wildcard remote). - Tunnels matching the packet's remote address, with any local address (wildcard local). However, vti6 stores all these different types of tunnels in the same hash table (ip6n->tnls_r_l) prone to hash collisions. The bug is that the fallback search loops in vti6_tnl_lookup() were missing checks to ensure that the candidate tunnel actually has a wildcard address.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nip6_vti: fix incorrect tunnel matching in vti6_tnl_lookup()\n\nIn vti6_tnl_lookup(), when an exact match for a tunnel fails,\nthe code falls back to searching for wildcard tunnels:\n\n- Tunnels matching the packet's local address, with any remote address\n wildcard remote).\n\n- Tunnels matching the packet's remote address, with any local address\n (wildcard local).\n\nHowever, vti6 stores all these different types of tunnels in the same\nhash table (ip6n->tnls_r_l) prone to hash collisions.\n\nThe bug is that the fallback search loops in vti6_tnl_lookup() were\nmissing checks to ensure that the candidate tunnel actually has\na wildcard address.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.40911 |
altlinux: CVE-2026-53221 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53221 was patched at 2026-07-14
1051.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53228) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offloads ipip6_tunnel_xmit() caches the inner IPv6 header pointer at function entry and continues using it after iptunnel_handle_offloads(). For GSO skbs, iptunnel_handle_offloads() calls skb_header_unclone(). When the skb header is cloned, skb_header_unclone() can call pskb_expand_head(), which may move the skb head. The pskb_expand_head() contract requires pointers into the skb header to be reloaded after the call. If the later skb_realloc_headroom() branch is not taken, SIT uses the stale iph6 pointer to read the inner hop limit and DS field. That can read from a freed skb head after the old head's remaining clone is released. Reload iph6 after the offload helper succeeds and before subsequent reads from the inner IPv6 header. Keep the existing reload after skb_realloc_headroom(), since that branch can also replace the skb.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: sit: reload inner IPv6 header after GSO offloads\n\nipip6_tunnel_xmit() caches the inner IPv6 header pointer at function\nentry and continues using it after iptunnel_handle_offloads().\n\nFor GSO skbs, iptunnel_handle_offloads() calls skb_header_unclone().\nWhen the skb header is cloned, skb_header_unclone() can call\npskb_expand_head(), which may move the skb head. The pskb_expand_head()\ncontract requires pointers into the skb header to be reloaded after the\ncall.\n\nIf the later skb_realloc_headroom() branch is not taken, SIT uses the\nstale iph6 pointer to read the inner hop limit and DS field. That can\nread from a freed skb head after the old head's remaining clone is\nreleased.\n\nReload iph6 after the offload helper succeeds and before subsequent\nreads from the inner IPv6 header. Keep the existing reload after\nskb_realloc_headroom(), since that branch can also replace the skb.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.40914 |
altlinux: CVE-2026-53228 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53228 was patched at 2026-07-14
1052.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53398) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix SECINFO_NO_NAME decode error cleanup nfsd4_decode_secinfo_no_name() currently initializes sin_exp after decoding sin_style. If the XDR stream is truncated, the decoder returns nfserr_bad_xdr before sin_exp is initialized. Since commit 3fdc54646234 ("NFSD: Reduce amount of struct nfsd4_compoundargs that needs clearing"), the inline iops array is not cleared between RPC calls. A failed SECINFO_NO_NAME decode can therefore leave sin_exp holding stale union contents from a previous operation. The error response path still invokes nfsd4_secinfo_no_name_release(), which calls exp_put() on a non-NULL sin_exp. Initialize sin_exp before the first failable decode step, matching nfsd4_decode_secinfo().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nNFSD: Fix SECINFO_NO_NAME decode error cleanup\n\nnfsd4_decode_secinfo_no_name() currently initializes sin_exp after\ndecoding sin_style. If the XDR stream is truncated, the decoder returns\nnfserr_bad_xdr before sin_exp is initialized.\n\nSince commit 3fdc54646234 ("NFSD: Reduce amount of struct\nnfsd4_compoundargs that needs clearing"), the inline iops array is not\ncleared between RPC calls. A failed SECINFO_NO_NAME decode can therefore\nleave sin_exp holding stale union contents from a previous operation.\n\nThe error response path still invokes nfsd4_secinfo_no_name_release(),\nwhich calls exp_put() on a non-NULL sin_exp.\n\nInitialize sin_exp before the first failable decode step, matching\nnfsd4_decode_secinfo().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.40913 |
debian: CVE-2026-53398 was patched at 2026-07-14, 2026-07-30
1053.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63919) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfrm: input: hold netns during deferred transport reinjection Transport-mode reinjection stores a struct net pointer in skb->cb and uses it later from xfrm_trans_reinject(). That pointer must stay valid until the deferred callback runs. Take a netns reference when queueing deferred reinjection work and drop it after the callback completes. Use maybe_get_net() so the queueing path does not revive a namespace that is already being torn down. This keeps the existing workqueue design and fixes the netns lifetime handling in one place for all users of xfrm_trans_queue_net().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: input: hold netns during deferred transport reinjection\n\nTransport-mode reinjection stores a struct net pointer in skb->cb and\nuses it later from xfrm_trans_reinject(). That pointer must stay valid\nuntil the deferred callback runs.\n\nTake a netns reference when queueing deferred reinjection work and drop\nit after the callback completes. Use maybe_get_net() so the queueing\npath does not revive a namespace that is already being torn down.\n\nThis keeps the existing workqueue design and fixes the netns lifetime\nhandling in one place for all users of xfrm_trans_queue_net().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00633, EPSS Percentile is 0.46826 |
debian: CVE-2026-63919 was patched at 2026-07-14
ubuntu: CVE-2026-63919 was patched at 2026-07-30
1054.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63979) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/handshake: hand off the pinned file reference to accept_doit handshake_req_next() removes the request from the per-net pending list and drops hn_lock before handshake_nl_accept_doit() reads req->hr_sk->sk_socket and dereferences sock->file (once in FD_PREPARE() and again in get_file()). In that window a consumer running tls_handshake_cancel() followed by sockfd_put() (svc_sock_free) or __fput_sync() (xs_reset_transport) releases sock->file. sock_release() then runs sock_orphan(), zeroing sk_socket, and frees the struct socket. The accept-side code either reads NULL through sk_socket or chases freed memory. The submit-side sock_hold() does not prevent this. sk_refcnt protects struct sock, but struct socket and sock->file are independently refcounted via the file descriptor the consumer owns. Pinning sk leaves sock and sock->file unprotected. Retarget the accept-side dereferences at req->hr_file, which was pinned at submit time, instead of req->hr_sk->sk_socket->file. Pinning on its own is not sufficient: a consumer that cancels between handshake_req_next() returning and accept_doit reaching FD_PREPARE() takes the !remove_pending() branch in handshake_req_cancel() and drops hr_file before the accept side takes its own reference. Hand off an additional file reference inside handshake_req_next(), under hn_lock, so the accept side operates on a reference that no concurrent handshake_req_cancel() can revoke. FD_PREPARE() consumes that handed-off reference, either by transferring it to the new fd in fd_publish() or by dropping it in the cleanup destructor on error; the explicit get_file() that previously balanced FD_PREPARE() is therefore redundant and goes away. Update handshake_req_cancel_test2 and _test3 to simulate the FD_PREPARE() consumption with an fput() so the kunit file-count assertions stay balanced.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/handshake: hand off the pinned file reference to accept_doit\n\nhandshake_req_next() removes the request from the per-net\npending list and drops hn_lock before handshake_nl_accept_doit()\nreads req->hr_sk->sk_socket and dereferences sock->file (once in\nFD_PREPARE() and again in get_file()). In that window a\nconsumer running tls_handshake_cancel() followed by sockfd_put()\n(svc_sock_free) or __fput_sync() (xs_reset_transport) releases\nsock->file. sock_release() then runs sock_orphan(), zeroing\nsk_socket, and frees the struct socket. The accept-side code\neither reads NULL through sk_socket or chases freed memory.\n\nThe submit-side sock_hold() does not prevent this. sk_refcnt\nprotects struct sock, but struct socket and sock->file are\nindependently refcounted via the file descriptor the consumer\nowns. Pinning sk leaves sock and sock->file unprotected.\n\nRetarget the accept-side dereferences at req->hr_file, which was\npinned at submit time, instead of req->hr_sk->sk_socket->file.\nPinning on its own is not sufficient: a consumer that cancels\nbetween handshake_req_next() returning and accept_doit reaching\nFD_PREPARE() takes the !remove_pending() branch in\nhandshake_req_cancel() and drops hr_file before the accept side\ntakes its own reference. Hand off an additional file reference\ninside handshake_req_next(), under hn_lock, so the accept side\noperates on a reference that no concurrent handshake_req_cancel()\ncan revoke. FD_PREPARE() consumes that handed-off reference,\neither by transferring it to the new fd in fd_publish() or by\ndropping it in the cleanup destructor on error; the explicit\nget_file() that previously balanced FD_PREPARE() is therefore\nredundant and goes away.\n\nUpdate handshake_req_cancel_test2 and _test3 to simulate the\nFD_PREPARE() consumption with an fput() so the kunit file-count\nassertions stay balanced.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00516, EPSS Percentile is 0.41048 |
debian: CVE-2026-63979 was patched at 2026-07-14
ubuntu: CVE-2026-63979 was patched at 2026-07-30
1055.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63984) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress() ipv6_rpl_srh_decompress() computes: outhdr->hdrlen = (((n + 1) * sizeof(struct in6_addr)) >> 3); hdrlen is __u8. For n >= 127 the result exceeds 255 and silently truncates. With n=127 (cmpri=15, cmpre=15, pad=0, hdrlen=16): (128 * 16) >> 3 = 256, truncated to 0 as __u8 The caller in ipv6_rpl_srh_rcv() then places the compressed header at buf + ((ohdr->hdrlen + 1) << 3). With hdrlen=0 this is buf + 8, but the decompressed region occupies buf[0..2055] (8-byte header plus 128 full addresses). The compressed header overlaps the decompressed data, and ipv6_rpl_srh_compress() writes into this overlap, corrupting the routing header of the forwarded packet. The existing guard at exthdrs.c:546 checks (n + 1) > 255, which prevents n+1 from overflowing unsigned char (the segments_left field), but does not prevent the computed hdrlen from overflowing __u8. n=127 passes because 128 <= 255, yet hdrlen=256 does not fit. Tighten the bound to (n + 1) > 127. This caps n at 126, giving hdrlen = (127 * 16) >> 3 = 254, which fits in __u8. The compressed header then lands at buf + ((254 + 1) << 3) = buf + 2040, exactly past the decompressed region (buf[0..2039]). No overlap. 127 segments is well beyond any realistic RPL deployment.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: rpl: fix hdrlen overflow in ipv6_rpl_srh_decompress()\n\nipv6_rpl_srh_decompress() computes:\n\n outhdr->hdrlen = (((n + 1) * sizeof(struct in6_addr)) >> 3);\n\nhdrlen is __u8. For n >= 127 the result exceeds 255 and silently\ntruncates. With n=127 (cmpri=15, cmpre=15, pad=0, hdrlen=16):\n\n (128 * 16) >> 3 = 256, truncated to 0 as __u8\n\nThe caller in ipv6_rpl_srh_rcv() then places the compressed header\nat buf + ((ohdr->hdrlen + 1) << 3). With hdrlen=0 this is buf + 8,\nbut the decompressed region occupies buf[0..2055] (8-byte header\nplus 128 full addresses). The compressed header overlaps the\ndecompressed data, and ipv6_rpl_srh_compress() writes into this\noverlap, corrupting the routing header of the forwarded packet.\n\nThe existing guard at exthdrs.c:546 checks (n + 1) > 255, which\nprevents n+1 from overflowing unsigned char (the segments_left\nfield), but does not prevent the computed hdrlen from overflowing\n__u8. n=127 passes because 128 <= 255, yet hdrlen=256 does not\nfit.\n\nTighten the bound to (n + 1) > 127. This caps n at 126, giving\nhdrlen = (127 * 16) >> 3 = 254, which fits in __u8. The compressed\nheader then lands at buf + ((254 + 1) << 3) = buf + 2040, exactly\npast the decompressed region (buf[0..2039]). No overlap. 127\nsegments is well beyond any realistic RPL deployment.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.40912 |
debian: CVE-2026-63984 was patched at 2026-07-14
ubuntu: CVE-2026-63984 was patched at 2026-07-30
1056.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63993) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: vxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu() skb_tunnel_check_pmtu() can change skb->head. Reusing old_iph afer skb_tunnel_check_pmtu() can cause an UAF. Use instead ip_hdr(skb) as done in drivers/net/bareudp.c and drivers/net/geneve.c. Found by Sashiko.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvxlan: do not reuse cached ip_hdr() value after skb_tunnel_check_pmtu()\n\nskb_tunnel_check_pmtu() can change skb->head.\n\nReusing old_iph afer skb_tunnel_check_pmtu() can cause an UAF.\n\nUse instead ip_hdr(skb) as done in drivers/net/bareudp.c\nand drivers/net/geneve.c.\n\nFound by Sashiko.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.40912 |
debian: CVE-2026-63993 was patched at 2026-07-14
ubuntu: CVE-2026-63993 was patched at 2026-07-30
1057.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63994) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]() Sashiko found that iptunnel_pmtud_build_icmp() and iptunnel_pmtud_build_icmpv6() were caching ip_hdr() and ipv6_hdr() before an skb_cow() call which can reallocate skb->head. Fix this possible UAF by initializing the local variables after the skb_cow() call. Remove skb_reset_network_header() calls which were not needed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntunnels: load network headers after skb_cow() in iptunnel_pmtud_build_icmp[v6]()\n\nSashiko found that iptunnel_pmtud_build_icmp() and\niptunnel_pmtud_build_icmpv6() were caching ip_hdr() and ipv6_hdr()\nbefore an skb_cow() call which can reallocate skb->head.\n\nFix this possible UAF by initializing the local variables\nafter the skb_cow() call.\n\nRemove skb_reset_network_header() calls which were not needed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00521, EPSS Percentile is 0.41304 |
debian: CVE-2026-63994 was patched at 2026-07-14
ubuntu: CVE-2026-63994 was patched at 2026-07-30
1058.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64000) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: hsr: fix potential OOB access in supervision frame handling Ensure the entire TLV header is linearized before access by adding sizeof(struct hsr_sup_tlv) to the pskb_may_pull() calls. Without this, a truncated frame could cause an out-of-bounds access.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: hsr: fix potential OOB access in supervision frame handling\n\nEnsure the entire TLV header is linearized before access by adding\nsizeof(struct hsr_sup_tlv) to the pskb_may_pull() calls. Without this,\na truncated frame could cause an out-of-bounds access.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00491, EPSS Percentile is 0.39516 |
debian: CVE-2026-64000 was patched at 2026-07-14
ubuntu: CVE-2026-64000 was patched at 2026-07-30
1059.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64007) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr after skb_ensure_writable synproxy_tstamp_adjust() rewrites the TCP timestamp option in place and then patches the TCP checksum via inet_proto_csum_replace4() on the caller-supplied tcphdr pointer. Both ipv4_synproxy_hook() and ipv6_synproxy_hook() obtain that pointer with skb_header_pointer() before calling in, so it may either alias skb->head directly or point at the caller's on-stack _tcph buffer. Between obtaining the pointer and using it, the function calls skb_ensure_writable(skb, optend), which on a cloned or non-linear skb invokes pskb_expand_head() and frees the old skb->head. After that point the cached th is stale: caller (ipv[46]_synproxy_hook) th = skb_header_pointer(skb, ..., &_tcph) synproxy_tstamp_adjust(skb, protoff, th, ...) skb_ensure_writable(skb, optend) pskb_expand_head() /* kfree(old skb->head) */ ... inet_proto_csum_replace4(&th->check, ...) /* writes into freed head, or into the caller's stack copy leaving the on-wire checksum stale */ The option bytes are written through skb->data and are fine; only the checksum update goes through th and so lands in the wrong place. The result is either a write into freed slab memory or a packet leaving with a checksum that does not match its payload. Fix by re-deriving th from skb->data + protoff immediately after skb_ensure_writable() succeeds, so the subsequent checksum update targets the linear, writable header.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: synproxy: refresh tcphdr after skb_ensure_writable\n\nsynproxy_tstamp_adjust() rewrites the TCP timestamp option in place\nand then patches the TCP checksum via inet_proto_csum_replace4() on\nthe caller-supplied tcphdr pointer. Both ipv4_synproxy_hook() and\nipv6_synproxy_hook() obtain that pointer with skb_header_pointer()\nbefore calling in, so it may either alias skb->head directly or\npoint at the caller's on-stack _tcph buffer.\n\nBetween obtaining the pointer and using it, the function calls\nskb_ensure_writable(skb, optend), which on a cloned or non-linear\nskb invokes pskb_expand_head() and frees the old skb->head. After\nthat point the cached th is stale:\n\n caller (ipv[46]_synproxy_hook)\n th = skb_header_pointer(skb, ..., &_tcph)\n synproxy_tstamp_adjust(skb, protoff, th, ...)\n skb_ensure_writable(skb, optend)\n pskb_expand_head() /* kfree(old skb->head) */\n ...\n inet_proto_csum_replace4(&th->check, ...)\n /* writes into freed head, or\n into the caller's stack copy\n leaving the on-wire checksum\n stale */\n\nThe option bytes are written through skb->data and are fine; only\nthe checksum update goes through th and so lands in the wrong\nplace. The result is either a write into freed slab memory or a\npacket leaving with a checksum that does not match its payload.\n\nFix by re-deriving th from skb->data + protoff immediately after\nskb_ensure_writable() succeeds, so the subsequent checksum update\ntargets the linear, writable header.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.40912 |
debian: CVE-2026-64007 was patched at 2026-07-14
ubuntu: CVE-2026-64007 was patched at 2026-07-30
1060.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64046) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: tls: prevent chain-after-chain in plain text SG Sashiko points out that if end = 0 (start != 0) the current code will create a chain link to content type right after the wrap link: This would create a chain where the wrap link points directly to another chain link. The scatterlist API sg_next iterator does not recursively resolve consecutive chain links. meaning this is illegal input to crypto. The wrapping link is unnecessary if end = 0. end is the entry after the last one used so end = 0 means there's nothing pushed after the wrap: end start i v v v [ ]...[ ][ d ][ d ][ d ][ d ][rsv for wrap] Skip the wrapping in this case. TLS 1.3 can use the "wrapping slot" for it's chaining if end = 0. This avoids the chain-after-chain. Move the wrap chaining before marking END and chaining off content type, that feels like more logical ordering to me, but should not matter from functional perspective.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tls: prevent chain-after-chain in plain text SG\n\nSashiko points out that if end = 0 (start != 0) the current\ncode will create a chain link to content type right after\nthe wrap link:\n\n This would create a chain where the wrap link points directly\n to another chain link. The scatterlist API sg_next iterator\n does not recursively resolve consecutive chain links.\n\nmeaning this is illegal input to crypto.\n\nThe wrapping link is unnecessary if end = 0. end is the entry after\nthe last one used so end = 0 means there's nothing pushed after\nthe wrap:\n\n end start i\n v v v\n [ ]...[ ][ d ][ d ][ d ][ d ][rsv for wrap]\n\nSkip the wrapping in this case.\n\nTLS 1.3 can use the "wrapping slot" for it's chaining if end = 0.\nThis avoids the chain-after-chain.\n\nMove the wrap chaining before marking END and chaining off content\ntype, that feels like more logical ordering to me, but should not\nmatter from functional perspective.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.40912 |
debian: CVE-2026-64046 was patched at 2026-07-14
ubuntu: CVE-2026-64046 was patched at 2026-07-30
1061.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64047) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring When an sk_msg scatterlist ring wraps (sg.end < sg.start), tls_push_record() chains the tail portion of the ring to the head using sg_chain(). An extra entry in the sg array is reserved for this: struct sk_msg_sg { [...] /* The extra two elements: * 1) used for chaining the front and sections when the list becomes * partitioned (e.g. end < start). The crypto APIs require the * chaining; * 2) to chain tailer SG entries after the message. */ struct scatterlist data[MAX_MSG_FRAGS + 2]; The current code uses MAX_SKB_FRAGS + 1 as the ring size: sg_chain(&msg_pl->sg.data[msg_pl->sg.start], MAX_SKB_FRAGS - msg_pl->sg.start + 1, msg_pl->sg.data); This places the chain pointer at sg_chain(data[start], (MAX_SKB_FRAGS - msg_start + 1) .. = &data[start] + (MAX_SKB_FRAGS - msg_start + 1) - 1 = data[start + (MAX_SKB_FRAGS - start + 1) - 1] = data[MAX_SKB_FRAGS] instead of the true last entry. This is likely due to a "race" of the commit under Fixes landing close to commit 031097d9e079 ("bpf: sk_msg, zap ingress queue on psock down") Convert to ARRAY_SIZE and drop the data[start] / - start (as suggested by Sabrina).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: tls: fix off-by-one in sg_chain entry count for wrapped sk_msg ring\n\nWhen an sk_msg scatterlist ring wraps (sg.end < sg.start),\ntls_push_record() chains the tail portion of the ring to the head\nusing sg_chain(). An extra entry in the sg array is reserved for\nthis:\n\n struct sk_msg_sg {\n [...]\n /* The extra two elements:\n * 1) used for chaining the front and sections when the list becomes\n * partitioned (e.g. end < start). The crypto APIs require the\n * chaining;\n * 2) to chain tailer SG entries after the message.\n */\n struct scatterlist data[MAX_MSG_FRAGS + 2];\n\nThe current code uses MAX_SKB_FRAGS + 1 as the ring size:\n\n sg_chain(&msg_pl->sg.data[msg_pl->sg.start],\n MAX_SKB_FRAGS - msg_pl->sg.start + 1,\n msg_pl->sg.data);\n\nThis places the chain pointer at\n\n sg_chain(data[start], (MAX_SKB_FRAGS - msg_start + 1) .. =\n &data[start] + (MAX_SKB_FRAGS - msg_start + 1) - 1 =\n data[start + (MAX_SKB_FRAGS - start + 1) - 1] =\n data[MAX_SKB_FRAGS]\n\ninstead of the true last entry. This is likely due to a "race" of\nthe commit under Fixes landing close to\ncommit 031097d9e079 ("bpf: sk_msg, zap ingress queue on psock down")\n\nConvert to ARRAY_SIZE and drop the data[start] / - start (as suggested\nby Sabrina).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.40911 |
debian: CVE-2026-64047 was patched at 2026-07-14
ubuntu: CVE-2026-64047 was patched at 2026-07-30
1062.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64055) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Carry over frag counter The gmac_rx() NAPI poll function assembles packets in an SKB from a ring buffer. If the ring buffer gets completely emptied during a poll cycle, we exit gmac_rx(), but the packet is not yet completely assembled in the SKB, yet the fragment counter frag_nr is reset to zero on the next invocation. Solve this by making the RX fragment counter a part of the port struct, and carry it over between invocations. Reset the fragment counter only right after calling napi_gro_frags(), on error (after calling napi_free_frags()) or if stopping the port. Reset it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: cortina: Carry over frag counter\n\nThe gmac_rx() NAPI poll function assembles packets in an\nSKB from a ring buffer.\n\nIf the ring buffer gets completely emptied during a poll cycle,\nwe exit gmac_rx(), but the packet is not yet completely\nassembled in the SKB, yet the fragment counter frag_nr is\nreset to zero on the next invocation.\n\nSolve this by making the RX fragment counter a part of the\nport struct, and carry it over between invocations.\n\nReset the fragment counter only right after calling\nnapi_gro_frags(), on error (after calling napi_free_frags())\nor if stopping the port.\n\nReset it in some place where not strictly necessary just to\nemphasize what is going on.\n\nThis was found by Sashiko during normal patch review.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.40913 |
debian: CVE-2026-64055 was patched at 2026-07-14
ubuntu: CVE-2026-64055 was patched at 2026-07-30
1063.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64056) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: ethernet: cortina: Make RX SKB per-port The SKB used to assemble packets from fragments in gmac_rx() is static local, but the Gemini has two ethernet ports, meaning there can be races between the ports on a bad day if a device is using both. Make the RX SKB a per-port variable and carry it over between invocations in the port struct instead. Zero the pointer once we call napi_gro_frags(), on error (after calling napi_free_frags()) or if the port is stopped. Zero it in some place where not strictly necessary just to emphasize what is going on. This was found by Sashiko during normal patch review.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ethernet: cortina: Make RX SKB per-port\n\nThe SKB used to assemble packets from fragments in gmac_rx()\nis static local, but the Gemini has two ethernet ports, meaning\nthere can be races between the ports on a bad day if a device\nis using both.\n\nMake the RX SKB a per-port variable and carry it over between\ninvocations in the port struct instead.\n\nZero the pointer once we call napi_gro_frags(), on error (after\ncalling napi_free_frags()) or if the port is stopped.\n\nZero it in some place where not strictly necessary just to\nemphasize what is going on.\n\nThis was found by Sashiko during normal patch review.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00552, EPSS Percentile is 0.4298 |
debian: CVE-2026-64056 was patched at 2026-07-14
ubuntu: CVE-2026-64056 was patched at 2026-07-30
1064.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64066) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_read_to_pagecache() to pause on subreq failure Fix netfs_read_to_pagecache() so that it pauses the generation of new subrequests if an already-issued subrequest fails.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix netfs_read_to_pagecache() to pause on subreq failure\n\nFix netfs_read_to_pagecache() so that it pauses the generation of new\nsubrequests if an already-issued subrequest fails.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00442, EPSS Percentile is 0.36327 |
debian: CVE-2026-64066 was patched at 2026-07-14
ubuntu: CVE-2026-64066 was patched at 2026-07-30
1065.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64089) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative last_changeset_len batadv_piv_tt::last_changeset_len len was declared as s16, but the field is never intended to hold a negative value. When a value greater than 32767 is assigned, it wraps to a negative signed integer. In batadv_send_my_tt_response(), last_changeset_len is temporarily widened to s32. The incorrectly negative s16 value propagates into the s32, causing batadv_tt_prepare_tvlv_local_data() to allocate a full sized buffer but populates only a small portion of it with the collected changeset. All remaining bits are kept uninitialized. Using an u16 avoids this type confusion and ensures that no (negative) sign extension is performed in batadv_send_my_tt_response().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tt: fix negative last_changeset_len\n\nbatadv_piv_tt::last_changeset_len len was declared as s16, but the field is\nnever intended to hold a negative value. When a value greater than 32767 is\nassigned, it wraps to a negative signed integer.\n\nIn batadv_send_my_tt_response(), last_changeset_len is temporarily widened\nto s32. The incorrectly negative s16 value propagates into the s32, causing\nbatadv_tt_prepare_tvlv_local_data() to allocate a full sized buffer but\npopulates only a small portion of it with the collected changeset. All\nremaining bits are kept uninitialized.\n\nUsing an u16 avoids this type confusion and ensures that no (negative) sign\nextension is performed in batadv_send_my_tt_response().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00552, EPSS Percentile is 0.4298 |
debian: CVE-2026-64089 was patched at 2026-07-14
ubuntu: CVE-2026-64089 was patched at 2026-07-30
1066.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64091) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix TOCTOU race for reported vlans The local TT based TVLV is generated by first checking the number of VLANs which have at least one TT entry. A new buffer with the correct size for the VLANs is then allocated. Only then, the list of VLANs s used to fill the VLAN entries in the buffer. During this time, the meshif_vlan_list_lock is held. But the actual number of TT entries of each VLAN can still increase during this time - just not the number of VLANs in the list. But the prefilter used in the buffer size calculation might still cause an increase of the number of VLANs which need to be stored. Simply because a VLAN might now suddenly have at least one entry when it had none in the pre-alloc check - and then needs to occupy space which was not allocated. It is better to overestimate the buffer size at the beginning and then fill the buffer only with the VLANs which are not empty.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tt: fix TOCTOU race for reported vlans\n\nThe local TT based TVLV is generated by first checking the number of VLANs\nwhich have at least one TT entry. A new buffer with the correct size for\nthe VLANs is then allocated. Only then, the list of VLANs s used to fill\nthe VLAN entries in the buffer. During this time, the meshif_vlan_list_lock\nis held. But the actual number of TT entries of each VLAN can still\nincrease during this time - just not the number of VLANs in the list.\n\nBut the prefilter used in the buffer size calculation might still cause an\nincrease of the number of VLANs which need to be stored. Simply because a\nVLAN might now suddenly have at least one entry when it had none in the\npre-alloc check - and then needs to occupy space which was not allocated.\n\nIt is better to overestimate the buffer size at the beginning and then fill\nthe buffer only with the VLANs which are not empty.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00552, EPSS Percentile is 0.42981 |
debian: CVE-2026-64091 was patched at 2026-07-14
ubuntu: CVE-2026-64091 was patched at 2026-07-30
1067.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64125) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: bcmgenet: keep RBUF EEE/PM disabled Setting RBUF_EEE_EN | RBUF_PM_EN in RBUF_ENERGY_CTRL breaks the RX path on GENET hardware once MAC EEE becomes active. RX traffic stops flowing while the link stays up and the usual descriptor/RX error counters remain quiet. In that state the MAC still accepts frames (rbuf_ovflow_cnt keeps climbing) but RBUF no longer forwards them to DMA, so rx_packets is no longer incremented at the netdev level. On some boards the corruption ends up as a paging fault in skb_release_data via bcmgenet_rx_poll on an LPI exit. Reproduced on Pi 4B (BCM2711 + BCM54213PE) and confirmed by Florian Fainelli on an internal Broadcom 4908-family board with the same crash signature. RBUF_PM_EN is not publicly documented. This shows up more often now that phy_support_eee() enables EEE by default, but it also affects older kernels as soon as TX LPI is turned on via ethtool, so it is not specific to recent changes. Always clear RBUF_EEE_EN | RBUF_PM_EN in bcmgenet_eee_enable_set so the bits stay off across resets. UMAC and TBUF setup is left alone so TX-side EEE keeps working.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: bcmgenet: keep RBUF EEE/PM disabled\n\nSetting RBUF_EEE_EN | RBUF_PM_EN in RBUF_ENERGY_CTRL breaks the RX\npath on GENET hardware once MAC EEE becomes active. RX traffic stops\nflowing while the link stays up and the usual descriptor/RX error\ncounters remain quiet. In that state the MAC still accepts frames\n(rbuf_ovflow_cnt keeps climbing) but RBUF no longer forwards them to\nDMA, so rx_packets is no longer incremented at the netdev level. On\nsome boards the corruption ends up as a paging fault in\nskb_release_data via bcmgenet_rx_poll on an LPI exit.\n\nReproduced on Pi 4B (BCM2711 + BCM54213PE) and confirmed by Florian\nFainelli on an internal Broadcom 4908-family board with the same crash\nsignature. RBUF_PM_EN is not publicly documented.\n\nThis shows up more often now that phy_support_eee() enables EEE by\ndefault, but it also affects older kernels as soon as TX LPI is\nturned on via ethtool, so it is not specific to recent changes.\n\nAlways clear RBUF_EEE_EN | RBUF_PM_EN in bcmgenet_eee_enable_set so\nthe bits stay off across resets. UMAC and TBUF setup is left alone so\nTX-side EEE keeps working.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00552, EPSS Percentile is 0.4298 |
debian: CVE-2026-64125 was patched at 2026-07-14
ubuntu: CVE-2026-64125 was patched at 2026-07-30
1068.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64132) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv6: ioam: refresh hdr pointer before ioam6_event() Reported by Sashiko: In ipv6_hop_ioam(), the hdr pointer is initialized to point into the skb's linear data buffer. Later, the code calls skb_ensure_writable(), which might reallocate the buffer: \tif (skb_ensure_writable(skb, optoff + 2 + hdr->opt_len)) \t\tgoto drop; \t/* Trace pointer may have changed */ \ttrace = (struct ioam6_trace_hdr *)(skb_network_header(skb) \t\t\t\t\t + optoff + sizeof(*hdr)); \tioam6_fill_trace_data(skb, ns, trace, true); \tioam6_event(IOAM6_EVENT_TRACE, dev_net(skb->dev), \t\t GFP_ATOMIC, (void *)trace, hdr->opt_len - 2); If the skb is cloned or lacks sufficient linear headroom, skb_ensure_writable() will invoke pskb_expand_head(), which reallocates the skb's data buffer and frees the old one, invalidating pointers to it. While the code recalculates the trace pointer immediately after the call to skb_ensure_writable(), it fails to recalculate the hdr pointer. This patch fixes the above by recalculating the hdr pointer before passing hdr->opt_len to ioam6_event(), so that we avoid any UaF.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: ioam: refresh hdr pointer before ioam6_event()\n\nReported by Sashiko:\n\nIn ipv6_hop_ioam(), the hdr pointer is initialized to point into the\nskb's linear data buffer. Later, the code calls skb_ensure_writable(),\nwhich might reallocate the buffer:\n\n\tif (skb_ensure_writable(skb, optoff + 2 + hdr->opt_len))\n\t\tgoto drop;\n\n\t/* Trace pointer may have changed */\n\ttrace = (struct ioam6_trace_hdr *)(skb_network_header(skb)\n\t\t\t\t\t + optoff + sizeof(*hdr));\n\n\tioam6_fill_trace_data(skb, ns, trace, true);\n\n\tioam6_event(IOAM6_EVENT_TRACE, dev_net(skb->dev),\n\t\t GFP_ATOMIC, (void *)trace, hdr->opt_len - 2);\n\nIf the skb is cloned or lacks sufficient linear headroom,\nskb_ensure_writable() will invoke pskb_expand_head(), which reallocates\nthe skb's data buffer and frees the old one, invalidating pointers to\nit. While the code recalculates the trace pointer immediately after the\ncall to skb_ensure_writable(), it fails to recalculate the hdr pointer.\n\nThis patch fixes the above by recalculating the hdr pointer before\npassing hdr->opt_len to ioam6_event(), so that we avoid any UaF.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00491, EPSS Percentile is 0.39488 |
debian: CVE-2026-64132 was patched at 2026-07-14
ubuntu: CVE-2026-64132 was patched at 2026-07-30
1069.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64136) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: smb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked() Commit 96c4af418586 ("cifs: Fix locking usage for tcon fields") refactored cifs code to change cifs_tcp_ses_lock for tc_lock around tc_count changes. There was missing lock around tc_count increment inside smb2_find_smb_sess_tcon_unlocked().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: protect tc_count increment in smb2_find_smb_sess_tcon_unlocked()\n\nCommit 96c4af418586 ("cifs: Fix locking usage for tcon fields")\nrefactored cifs code to change cifs_tcp_ses_lock for tc_lock around\ntc_count changes.\n\nThere was missing lock around tc_count increment inside\nsmb2_find_smb_sess_tcon_unlocked().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00491, EPSS Percentile is 0.39488 |
debian: CVE-2026-64136 was patched at 2026-07-14
ubuntu: CVE-2026-64136 was patched at 2026-07-30
1070.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64142) - Medium [316]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ksmbd: close durable scavenger races against m_fp_list lookups ksmbd_durable_scavenger() has two related races against any walker that iterates f_ci->m_fp_list, including ksmbd_lookup_fd_inode() (used by ksmbd_vfs_rename) and the share-mode checks in fs/smb/server/smb_common.c. (1) fp->node list-head reuse. Durable-preserved handles can remain linked on f_ci->m_fp_list after session teardown so share-mode checks still see them while the handle is reconnectable. The scavenger collected expired handles by adding fp->node to a local scavenger_list after removing them from the global durable idr. Because fp->node is the same list_head used by m_fp_list, list_add(&fp->node, &scavenger_list) overwrites the m_fp_list links and corrupts both lists. CONFIG_DEBUG_LIST can report this on the share-mode walk path. (2) Refcount race against m_fp_list walkers. The scavenger qualifies an expired durable handle with atomic_read(&fp->refcount) > 1 and fp->conn under global_ft.lock, removes fp from global_ft, then drops global_ft.lock before unlinking fp from m_fp_list and freeing it. During that gap fp is still linked on m_fp_list with f_state == FP_INITED. ksmbd_lookup_fd_inode() under m_lock read calls ksmbd_fp_get() (atomic_inc_not_zero on refcount that is still 1) and takes a live reference; the scavenger then unlinks and frees fp while the holder owns a reference, leading to UAF on the holder's subsequent ksmbd_fd_put() and on any field reads performed by a concurrent share-mode walker that iterates m_fp_list without taking ksmbd_fp_get() (smb_check_perm_dleases-like paths). Fix both: * Stop reusing fp->node as a scavenger-private list node. Remove one expired handle from global_ft under global_ft.lock, take an explicit transient reference, drop the lock, unlink fp->node from m_fp_list under f_ci->m_lock, then drop both the durable lifetime and transient references with atomic_sub_and_test(2, &fp->refcount). If the scavenger is the last putter the close runs there; otherwise an in-flight holder that already raced through the m_fp_list lookup owns the final close via its ksmbd_fd_put() path. The one-at-a-time disposal can rescan the durable idr when multiple handles expire in the same pass, but durable scavenging is a background expiration path and the final full scan recomputes min_timeout before the next wait. * Clear fp->persistent_id inside __ksmbd_remove_durable_fd() right after idr_remove(), so a delayed final close from a holder that snatched fp does not re-issue idr_remove() on a persistent id that idr_alloc_cyclic() in ksmbd_open_durable_fd() may have already handed out to a brand-new durable handle. * Bypass the per-conn open_files_count decrement in __put_fd_final() when fp is detached from any session table (fp->conn cleared by session_fd_check() at durable preserve -- paired with the volatile_id clear at unpublish, so checking fp->conn alone is sufficient). The walker that owns the final close runs from an unrelated work->conn whose stats.open_files_count never tracked this durable fp; without this guard the holder would underflow that unrelated counter. The two races are folded into one patch because patch (1) alone cleans up the corrupted list but leaves a deterministic UAF window for m_fp_list walkers that the transient-reference and persistent_id discipline in (2) close; bisecting onto an intermediate state would land on a UAF that pre-patch chaos merely made less reproducible. Validation: * CONFIG_DEBUG_LIST coverage for the list_head reuse path. * KASAN-enabled direct SMB2 durable-handle coverage that exercised ksmbd_durable_scavenger() and non-NULL ksmbd_lookup_fd_inode() returns while durable handles expired under concurrent rename lookups, with no KASAN, UAF, list-corruption, ODEBUG, or WARNING reports. ---truncated---', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: close durable scavenger races against m_fp_list lookups\n\nksmbd_durable_scavenger() has two related races against any walker\nthat iterates f_ci->m_fp_list, including ksmbd_lookup_fd_inode()\n(used by ksmbd_vfs_rename) and the share-mode checks in\nfs/smb/server/smb_common.c.\n\n(1) fp->node list-head reuse. Durable-preserved handles can remain\nlinked on f_ci->m_fp_list after session teardown so share-mode checks\nstill see them while the handle is reconnectable. The scavenger\ncollected expired handles by adding fp->node to a local\nscavenger_list after removing them from the global durable idr.\nBecause fp->node is the same list_head used by m_fp_list,\nlist_add(&fp->node, &scavenger_list) overwrites the m_fp_list links\nand corrupts both lists. CONFIG_DEBUG_LIST can report this on the\nshare-mode walk path.\n\n(2) Refcount race against m_fp_list walkers. The scavenger qualifies\nan expired durable handle with atomic_read(&fp->refcount) > 1 and\nfp->conn under global_ft.lock, removes fp from global_ft, then drops\nglobal_ft.lock before unlinking fp from m_fp_list and freeing it.\nDuring that gap fp is still linked on m_fp_list with f_state ==\nFP_INITED. ksmbd_lookup_fd_inode() under m_lock read calls\nksmbd_fp_get() (atomic_inc_not_zero on refcount that is still 1) and\ntakes a live reference; the scavenger then unlinks and frees fp\nwhile the holder owns a reference, leading to UAF on the holder's\nsubsequent ksmbd_fd_put() and on any field reads performed by a\nconcurrent share-mode walker that iterates m_fp_list without taking\nksmbd_fp_get() (smb_check_perm_dleases-like paths).\n\nFix both:\n\n * Stop reusing fp->node as a scavenger-private list node. Remove\n one expired handle from global_ft under global_ft.lock, take an\n explicit transient reference, drop the lock, unlink fp->node\n from m_fp_list under f_ci->m_lock, then drop both the durable\n lifetime and transient references with atomic_sub_and_test(2,\n &fp->refcount). If the scavenger is the last putter the close\n runs there; otherwise an in-flight holder that already raced\n through the m_fp_list lookup owns the final close via its\n ksmbd_fd_put() path. The one-at-a-time disposal can rescan the\n durable idr when multiple handles expire in the same pass, but\n durable scavenging is a background expiration path and the final\n full scan recomputes min_timeout before the next wait.\n\n * Clear fp->persistent_id inside __ksmbd_remove_durable_fd() right\n after idr_remove(), so a delayed final close from a holder that\n snatched fp does not re-issue idr_remove() on a persistent id\n that idr_alloc_cyclic() in ksmbd_open_durable_fd() may have\n already handed out to a brand-new durable handle.\n\n * Bypass the per-conn open_files_count decrement in\n __put_fd_final() when fp is detached from any session table\n (fp->conn cleared by session_fd_check() at durable preserve --\n paired with the volatile_id clear at unpublish, so checking\n fp->conn alone is sufficient). The walker that owns the final\n close runs from an unrelated work->conn whose\n stats.open_files_count never tracked this durable fp; without\n this guard the holder would underflow that unrelated counter.\n\nThe two races are folded into one patch because patch (1) alone\ncleans up the corrupted list but leaves a deterministic UAF window\nfor m_fp_list walkers that the transient-reference and\npersistent_id discipline in (2) close; bisecting onto an\nintermediate state would land on a UAF that pre-patch chaos merely\nmade less reproducible.\n\nValidation:\n * CONFIG_DEBUG_LIST coverage for the list_head reuse path.\n * KASAN-enabled direct SMB2 durable-handle coverage that exercised\n ksmbd_durable_scavenger() and non-NULL ksmbd_lookup_fd_inode()\n returns while durable handles expired under concurrent rename\n lookups, with no KASAN, UAF, list-corruption, ODEBUG, or WARNING\n reports.\n---truncated---', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0048, EPSS Percentile is 0.38848 |
debian: CVE-2026-64142 was patched at 2026-07-14
ubuntu: CVE-2026-64142 was patched at 2026-07-30
1071.
Denial of Service - Xrdp (CVE-2026-55645) - Medium [315]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | xrdp is an open source remote desktop protocol server | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00283, EPSS Percentile is 0.20572 |
altlinux: CVE-2026-55645 was patched at 2026-07-08
debian: CVE-2026-55645 was patched at 2026-07-14
1072.
Denial of Service - busybox (CVE-2026-38752) - Medium [315]
Description: A stack overflow in the evaluate() function (editors/awk.c) of BusyBox commit 371fe9 allows attackers to cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:busybox:busybox (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00207, EPSS Percentile is 0.10952 |
debian: CVE-2026-38752 was patched at 2026-07-14
1073.
Denial of Service - busybox (CVE-2026-38754) - Medium [315]
Description: A heap overflow in the ifsbreakup() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:busybox:busybox (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00235, EPSS Percentile is 0.14637 |
debian: CVE-2026-38754 was patched at 2026-07-14
1074.
Denial of Service - busybox (CVE-2026-38755) - Medium [315]
Description: A heap overflow in the evalcommand() function (shell/ash.c) of Busybox v1.38.0 allows attackers to cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:busybox:busybox (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00207, EPSS Percentile is 0.10953 |
debian: CVE-2026-38755 was patched at 2026-07-14
1075.
Denial of Service - fzf (CVE-2026-53433) - Medium [315]
Description: fzf is vulnerable to a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:junegunn:fzf (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00212, EPSS Percentile is 0.11691 |
debian: CVE-2026-53433 was patched at 2026-07-14
1076.
Incorrect Calculation - haproxy (CVE-2026-55203) - Medium [315]
Description: HAProxy through 3.4.0, fixed in commit 5985276, contains an integer overflow vulnerability in the fcgi_conn structure's drl field that allows buffer misparse as new FCGI record headers. When contentLength is 65535 and paddingLength is 1 or more, the drl field wraps to 0, causing incorrect record consumption and allowing malicious FastCGI backends to desynchronize the FCGI framing parser, potentially causing request routing errors, response smuggling, or memory safety issues.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:haproxy:haproxy (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00347, EPSS Percentile is 0.27386 |
debian: CVE-2026-55203 was patched at 2026-06-24
ubuntu: CVE-2026-55203 was patched at 2026-07-30
1077.
Memory Corruption - DBI (CVE-2026-14740) - Medium [315]
Description: DBI versions before 1.650 for Perl read one byte out-of-bounds in preparse when deleting an initial SQL comment. The preparse method normalises SQL and removes comments. When the SQL starts with a comment line, the deletion of that line during normalisation led to an out-of-bounds read by one byte. The result is a fault on memory-hardened builds and nondeterministic newline retention on normal builds.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:perl:dbi (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00387, EPSS Percentile is 0.31428 |
altlinux: CVE-2026-14740 was patched at 2026-07-21
debian: CVE-2026-14740 was patched at 2026-07-14
1078.
Memory Corruption - socat (CVE-2026-56123) - Medium [315]
Description: socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:dest-unreach:socat (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00308, EPSS Percentile is 0.23142 |
debian: CVE-2026-56123 was patched at 2026-07-14
ubuntu: CVE-2026-56123 was patched at 2026-07-30
1079.
Security Feature Bypass - Guzzle (CVE-2026-55568) - Medium [315]
Description: Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication credentials (the Proxy-Authorization header, proxy userinfo in the proxy URL, or CURLOPT_PROXYUSERPWD) are sent without encryption, and the CONNECT target host and port for tunneled HTTPS requests are exposed. The built-in cURL handlers (GuzzleHttp\Handler\CurlHandler and GuzzleHttp\Handler\CurlMultiHandler, used by default whenever the PHP cURL extension is available) accept an https:// proxy. libcurl older than 7.50.2 silently treats an https:// proxy as a plaintext http:// proxy. The TLS connection to the proxy is never established, and the proxy leg is cleartext with no error or warning. An application is affected when it sends requests through one of the built-in cURL handlers, configures an https:// proxy expecting the proxy connection itself to be encrypted, and runs with libcurl older than 7.50.2. This vulnerability is fixed in 7.12.1.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:guzzlephp:guzzle (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00106, EPSS Percentile is 0.01293 |
debian: CVE-2026-55568 was patched at 2026-06-24
1080.
Security Feature Bypass - Guzzle (CVE-2026-55767) - Medium [315]
Description: Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes leading dots from the cookie domain, normalizing dot-only values to the empty string; SetCookie::validate() only rejected a strictly empty domain, so these cookies could be stored and the empty normalized domain was treated as matching any request host. An attacker-controlled origin that an application requests with a shared cookie jar can therefore set a cookie that Guzzle later sends to unrelated hosts using the same jar. This may allow cookie injection or session fixation against downstream services, depending on how those services interpret the injected cookie. This vulnerability is fixed in 7.12.1.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:guzzlephp:guzzle (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00111, EPSS Percentile is 0.01529 |
debian: CVE-2026-55767 was patched at 2026-06-24
1081.
Security Feature Bypass - Guzzle (CVE-2026-59883) - Medium [315]
Description: Guzzle is an extensible PHP HTTP client. Prior to 7.12.3, CookieJar did not restrict cookies scoped to IP-address or bare-numeric Domain values to the exact host that set them, because SetCookie::matchesDomain() applied ordinary suffix matching to domains such as 192.168.0.1, [::1], or 1, allowing cross-host cookie disclosure, cookie injection, or session fixation. This issue is fixed in version 7.12.3.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:guzzlephp:guzzle (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.01979 |
debian: CVE-2026-59883 was patched at 2026-07-14
1082.
Security Feature Bypass - Node.js (CVE-2026-48934) - Medium [315]
Description: A flaw in Node.js TLS host verification can cause an attacker to bypass certification validation. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:nodejs:node.js (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00258, EPSS Percentile is 0.17405 |
almalinux: CVE-2026-48934 was patched at 2026-07-06, 2026-07-15, 2026-07-20
altlinux: CVE-2026-48934 was patched at 2026-07-23
debian: CVE-2026-48934 was patched at 2026-06-24
oraclelinux: CVE-2026-48934 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-48934 was patched at 2026-07-06, 2026-07-15, 2026-07-20
1083.
Security Feature Bypass - Unknown Product (CVE-2026-54387) - Medium [315]
Description: {'nvd_cve_data_all': 'Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, forwarding both verbatim to the backend while using Content-Length to determine how many request body bytes to consume. Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backend to enable cache poisoning, access control bypass, and request hijacking.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Tinyproxy through 1.11.3, fixed in commit ff45d3b, fails to reconcile conflicting Content-Length and Transfer-Encoding: chunked headers, forwarding both verbatim to the backend while using Content-Length to determine how many request body bytes to consume. Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backend to enable cache poisoning, access control bypass, and request hijacking.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00439, EPSS Percentile is 0.36052 |
debian: CVE-2026-54387 was patched at 2026-06-24
1084.
Security Feature Bypass - Unknown Product (CVE-2026-54388) - Medium [315]
Description: {'nvd_cve_data_all': 'Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while using the first value to determine how many request body bytes to consume. Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backend to enable cache poisoning, access control bypass, and request hijacking.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Tinyproxy through 1.11.3, fixed in commit 364cdb6, fails to reject requests containing multiple Content-Length headers with differing values, forwarding all duplicate headers to the backend while using the first value to determine how many request body bytes to consume. Remote attackers can desynchronize the proxy and backend parser state, allowing injection of arbitrary HTTP requests to the backend to enable cache poisoning, access control bypass, and request hijacking.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00439, EPSS Percentile is 0.36052 |
debian: CVE-2026-54388 was patched at 2026-06-24
1085.
Security Feature Bypass - wolfssl (CVE-2026-6092) - Medium [315]
Description: When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fall back to MAC-then-Encrypt rather than enforcing Encrypt-then-MAC.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00209, EPSS Percentile is 0.11219 |
debian: CVE-2026-6092 was patched at 2026-07-14
1086.
Security Feature Bypass - wolfssl (CVE-2026-6450) - Medium [315]
Description: A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an unhandled critical extension to be accepted. This only affects builds with CRL support enabled and where a crafted CRL had a trusted signature when parsed.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07791 |
debian: CVE-2026-6450 was patched at 2026-07-14
1087.
Cross Site Scripting - Roundcube (CVE-2026-54432) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.6 | 14 | Roundcube is a web-based IMAP email client | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.1282 |
altlinux: CVE-2026-54432 was patched at 2026-07-10, 2026-07-15
debian: CVE-2026-54432 was patched at 2026-07-14, 2026-07-19
1088.
Information Disclosure - Xrdp (CVE-2026-42218) - Medium [314]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.5 | 14 | xrdp is an open source remote desktop protocol server | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0025, EPSS Percentile is 0.16488 |
altlinux: CVE-2026-42218 was patched at 2026-07-08
debian: CVE-2026-42218 was patched at 2026-07-14
1089.
Denial of Service - SQLite (CVE-2026-50812) - Medium [313]
Description: A NULL pointer dereference in the SQLite Session Extension in SQLite 3.53.1 and SQLite trunk builds before check-in e807d4e3798efd53 allows an attacker who can supply a malformed changeset blob to cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.7 | 14 | SQLite is a database engine written in the C programming language | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01627 |
debian: CVE-2026-50812 was patched at 2026-07-14
ubuntu: CVE-2026-50812 was patched at 2026-07-30
1090.
Information Disclosure - Oracle VM VirtualBox (CVE-2026-46815) - Medium [312]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.3 | 10 | CVSS Base Score is 3.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00162, EPSS Percentile is 0.0583 |
altlinux: CVE-2026-46815 was patched at 2026-06-29
1091.
Information Disclosure - Oracle VM VirtualBox (CVE-2026-46816) - Medium [312]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.3 | 10 | CVSS Base Score is 3.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00162, EPSS Percentile is 0.0583 |
altlinux: CVE-2026-46816 was patched at 2026-06-29
1092.
Information Disclosure - Oracle VM VirtualBox (CVE-2026-46977) - Medium [312]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.3 | 10 | CVSS Base Score is 3.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00162, EPSS Percentile is 0.05831 |
altlinux: CVE-2026-46977 was patched at 2026-06-29
1093.
Open Redirect - undici (CVE-2026-9679) - Medium [312]
Description: Impact: undici's cookie parser in parseSetCookie percent-decodes cookie values via qsUnescape, turning encoded sequences like %0D%0A, %00, %3B, and %3D into their literal byte equivalents. RFC 6265 §5.4 does not specify any decoding and browsers do not decode either. Applications that parse a Set-Cookie header and then forward the parsed value into a response header (proxies, middleware, SSR frameworks) become vulnerable to HTTP response header injection: an attacker-controlled upstream can inject arbitrary Set-Cookie, Location, or Cache-Control headers into the application's downstream response, enabling session fixation,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.75 | 15 | Open Redirect | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00257, EPSS Percentile is 0.17374 |
debian: CVE-2026-9679 was patched at 2026-06-24
1094.
Elevation of Privilege - Python (CVE-2026-12003) - Medium [311]
Description: To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python assumes it is running in a source tree and generates a different default sys.path. This code remains in release builds, so that release-ready builds can be built in-tree. On Windows, since builds are written to 'PCbuild/', the value of VPATH is set to '..\..', which results in a landmark of '..\..\Modules\setup.local'. This path is outside the install directory of Python, and may have different permissions, potentially allowing a low-privilege user to create the landmark and an alternative `Lib` folder that will be discovered by an otherwise restricted install. Such a setup occurs with the legacy default install location for all users (in the now superseded EXE installer), due to how Windows allows all users to create folders in the root directory of their OS drive. Our recommended mitigation on Windows is to migrate away from the legacy installer and use the new [Python install manager](https://www.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00136, EPSS Percentile is 0.03524 |
debian: CVE-2026-12003 was patched at 2026-06-24
1095.
Spoofing - Chromium (CVE-2026-14114) - Medium [311]
Description: Inappropriate implementation in WebAppInstalls in Google Chrome on Android prior to 150.0.7871.47 allowed a local attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06845 |
altlinux: CVE-2026-14114 was patched at 2026-07-03
debian: CVE-2026-14114 was patched at 2026-07-05, 2026-07-14
1096.
Incorrect Calculation - Linux Kernel (CVE-2026-53150) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02444 |
altlinux: CVE-2026-53150 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53150 was patched at 2026-07-14
1097.
Incorrect Calculation - Linux Kernel (CVE-2026-53263) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00115, EPSS Percentile is 0.0178 |
altlinux: CVE-2026-53263 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53263 was patched at 2026-07-14
1098.
Memory Corruption - Linux Kernel (CVE-2026-52938) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.001, EPSS Percentile is 0.0101 |
altlinux: CVE-2026-52938 was patched at 2026-06-27
1099.
Memory Corruption - Linux Kernel (CVE-2026-52939) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01913 |
altlinux: CVE-2026-52939 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-52939 was patched at 2026-07-14
1100.
Memory Corruption - Linux Kernel (CVE-2026-53135) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02417 |
altlinux: CVE-2026-53135 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53135 was patched at 2026-07-14
1101.
Memory Corruption - Linux Kernel (CVE-2026-53142) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02336 |
altlinux: CVE-2026-53142 was patched at 2026-06-19, 2026-06-22, 2026-07-04, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53142 was patched at 2026-07-05, 2026-07-14
1102.
Memory Corruption - Linux Kernel (CVE-2026-53144) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02335 |
altlinux: CVE-2026-53144 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53144 was patched at 2026-07-14
1103.
Memory Corruption - Linux Kernel (CVE-2026-53152) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02328 |
altlinux: CVE-2026-53152 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53152 was patched at 2026-07-14
1104.
Memory Corruption - Linux Kernel (CVE-2026-53158) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02403 |
altlinux: CVE-2026-53158 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53158 was patched at 2026-07-14, 2026-07-30
1105.
Memory Corruption - Linux Kernel (CVE-2026-53163) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02403 |
altlinux: CVE-2026-53163 was patched at 2026-06-19, 2026-06-22, 2026-07-04, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53163 was patched at 2026-07-05, 2026-07-14, 2026-07-30
1106.
Memory Corruption - Linux Kernel (CVE-2026-53177) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02401 |
altlinux: CVE-2026-53177 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53177 was patched at 2026-07-14
1107.
Memory Corruption - Linux Kernel (CVE-2026-53204) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00107, EPSS Percentile is 0.01359 |
altlinux: CVE-2026-53204 was patched at 2026-06-19
1108.
Memory Corruption - Linux Kernel (CVE-2026-53213) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02394 |
altlinux: CVE-2026-53213 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53213 was patched at 2026-07-14
1109.
Memory Corruption - Linux Kernel (CVE-2026-53214) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.0233 |
altlinux: CVE-2026-53214 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53214 was patched at 2026-07-14
1110.
Memory Corruption - Linux Kernel (CVE-2026-53220) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02354 |
altlinux: CVE-2026-53220 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53220 was patched at 2026-07-14
1111.
Memory Corruption - Linux Kernel (CVE-2026-53222) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00107, EPSS Percentile is 0.01359 |
altlinux: CVE-2026-53222 was patched at 2026-06-19
1112.
Memory Corruption - Linux Kernel (CVE-2026-53226) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02042 |
altlinux: CVE-2026-53226 was patched at 2026-06-19, 2026-06-22, 2026-07-06
debian: CVE-2026-53226 was patched at 2026-07-14, 2026-07-21
1113.
Memory Corruption - Linux Kernel (CVE-2026-53237) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02349 |
altlinux: CVE-2026-53237 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53237 was patched at 2026-07-14
1114.
Memory Corruption - Linux Kernel (CVE-2026-53252) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0013, EPSS Percentile is 0.03054 |
altlinux: CVE-2026-53252 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53252 was patched at 2026-07-14
1115.
Memory Corruption - Linux Kernel (CVE-2026-53271) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.01736 |
altlinux: CVE-2026-53271 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53271 was patched at 2026-07-14
1116.
Memory Corruption - Linux Kernel (CVE-2026-53325) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02706 |
altlinux: CVE-2026-53325 was patched at 2026-06-27, 2026-06-28, 2026-07-04, 2026-07-06, 2026-07-07, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53325 was patched at 2026-07-05, 2026-07-14, 2026-07-30
1117.
Memory Corruption - Linux Kernel (CVE-2026-53338) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01628 |
altlinux: CVE-2026-53338 was patched at 2026-06-19, 2026-06-22, 2026-07-06
1118.
Memory Corruption - Linux Kernel (CVE-2026-53339) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.01757 |
altlinux: CVE-2026-53339 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53339 was patched at 2026-07-14
1119.
Memory Corruption - Linux Kernel (CVE-2026-53344) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.001, EPSS Percentile is 0.01 |
altlinux: CVE-2026-53344 was patched at 2026-06-19
1120.
Memory Corruption - Linux Kernel (CVE-2026-53345) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.01701 |
altlinux: CVE-2026-53345 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53345 was patched at 2026-07-14
1121.
Memory Corruption - Linux Kernel (CVE-2026-53348) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.001, EPSS Percentile is 0.01 |
altlinux: CVE-2026-53348 was patched at 2026-06-19
1122.
Memory Corruption - Linux Kernel (CVE-2026-53350) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.01745 |
altlinux: CVE-2026-53350 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53350 was patched at 2026-07-14
1123.
Memory Corruption - Linux Kernel (CVE-2026-53382) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00132, EPSS Percentile is 0.03201 |
debian: CVE-2026-53382 was patched at 2026-07-14, 2026-07-30
1124.
Memory Corruption - Linux Kernel (CVE-2026-53385) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00132, EPSS Percentile is 0.03201 |
debian: CVE-2026-53385 was patched at 2026-07-14, 2026-07-30
1125.
Memory Corruption - Linux Kernel (CVE-2026-63798) - Medium [310]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02697 |
debian: CVE-2026-63798 was patched at 2026-07-14, 2026-07-30
1126.
Server-Side Request Forgery - Jackson-databind (CVE-2026-54514) - Medium [310]
Description: jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, port), which performs eager DNS name resolution for hostname inputs at deserialization time. An application that binds untrusted JSON into a type containing an InetSocketAddress field issues an attacker-chosen DNS query during readValue, before any application-level validation or connect logic. The fix uses InetSocketAddress.createUnresolved(host, port), deferring DNS to an explicit connect. This vulnerability is fixed in 2.18.8, 2.21.4, and 3.1.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.5 | 14 | Product detected by a:fasterxml:jackson-databind (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00219, EPSS Percentile is 0.12526 |
debian: CVE-2026-54514 was patched at 2026-07-14
1127.
Cross Site Scripting - Cacti (CVE-2026-39897) - Medium [309]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00167, EPSS Percentile is 0.06397 |
altlinux: CVE-2026-39897 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-39897 was patched at 2026-07-14
1128.
Cross Site Scripting - Cacti (CVE-2026-39900) - Medium [309]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00167, EPSS Percentile is 0.06397 |
altlinux: CVE-2026-39900 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-39900 was patched at 2026-07-14
1129.
Cross Site Scripting - Mistune (CVE-2026-59926) - Medium [309]
Description: Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, render_admonition() in src/mistune/directives/admonition.py concatenates the Admonition directive :class: option into the HTML class attribute without escaping, allowing attribute injection and cross-site scripting even when HTMLRenderer escape mode is enabled. This issue is fixed in version 3.2.1.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Product detected by a:mistune_project:mistune (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00189, EPSS Percentile is 0.08781 |
debian: CVE-2026-59926 was patched at 2026-07-14
1130.
Cross Site Scripting - grafana (CVE-2026-9029) - Medium [309]
Description: A user with Editor permissions can place a malicious script in the attribution field of a Geomap panel's XYZ tile layer via a template variable. The script then executes in the browser of any user who views the affected dashboard (stored cross-site scripting).
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Product detected by a:grafana:grafana (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00251, EPSS Percentile is 0.16587 |
redos: CVE-2026-9029 was patched at 2026-07-14
1131.
Cross Site Scripting - mediawiki (CVE-2026-58030) - Medium [309]
Description: Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation SyntaxHighlight_GeSHi. This vulnerability is associated with program files includes/SyntaxHighlight.Php. This issue affects SyntaxHighlight_GeSHi: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Product detected by a:mediawiki:mediawiki (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06923 |
debian: CVE-2026-58030 was patched at 2026-07-05, 2026-07-14
1132.
Remote Code Execution - Unknown Product (CVE-2026-56209) - Medium [309]
Description: {'nvd_cve_data_all': 'An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is fully deterministic and does not require a separate information leak. An attacker who can supply frames to a network-facing libaom encoder with SVC enabled could exploit this for denial of service or potential code execution.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an attacker to inject an arbitrary pointer into the cyclic refresh map field via crafted image pixel values. The encoder then writes approximately 1,200 bytes at the attacker-controlled address. This is fully deterministic and does not require a separate information leak. An attacker who can supply frames to a network-facing libaom encoder with SVC enabled could exploit this for denial of service or potential code execution.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00511, EPSS Percentile is 0.40695 |
debian: CVE-2026-56209 was patched at 2026-06-24
1133.
Denial of Service - ImageMagick (CVE-2026-55594) - Medium [308]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00241, EPSS Percentile is 0.15452 |
altlinux: CVE-2026-55594 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-55594 was patched at 2026-07-07, 2026-07-14
1134.
Denial of Service - Perl (CVE-2026-13705) - Medium [308]
Description: Imager versions before 1.032 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00136, EPSS Percentile is 0.03484 |
debian: CVE-2026-13705 was patched at 2026-07-14
1135.
Memory Corruption - ImageMagick (CVE-2026-61857) - Medium [308]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00266, EPSS Percentile is 0.18363 |
altlinux: CVE-2026-61857 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-61857 was patched at 2026-07-14
1136.
Path Traversal - Python (CVE-2026-29509) - Medium [308]
Description: Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00282, EPSS Percentile is 0.20426 |
debian: CVE-2026-29509 was patched at 2026-07-14
1137.
Denial of Service - dhcpcd (CVE-2026-14258) - Medium [307]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.45 | 14 | dhcpcd is an open-source DHCP and network configuration client used on Linux, BSD, and other Unix-like operating systems to automatically configure network interfaces, IP addresses, routes, and DNS settings. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00256, EPSS Percentile is 0.17221 |
debian: CVE-2026-14258 was patched at 2026-07-14
1138.
Remote Code Execution - libtiff (CVE-2026-12912) - Medium [307]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0.2 | 14 | libtiff is a widely used library for reading and writing TIFF (Tagged Image File Format) files, offering tools like tiff2ps. | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00232, EPSS Percentile is 0.14173 |
almalinux: CVE-2026-12912 was patched at 2026-07-20, 2026-07-21
debian: CVE-2026-12912 was patched at 2026-07-14, 2026-07-19
oraclelinux: CVE-2026-12912 was patched at 2026-07-20, 2026-07-21, 2026-07-28
redhat: CVE-2026-12912 was patched at 2026-07-21
1139.
Elevation of Privilege - sssd (CVE-2026-12610) - Medium [306]
Description: A flaw was found in sssd. When authenticating with a YubiKey, the SSSD PAM responder can crash due to a use-after-free vulnerability, where a memory pointer is incorrectly handled. A local attacker could exploit this flaw by manipulating smartcard or YubiKey contents, leading to a denial of service that disrupts authentication. This vulnerability also presents a potential for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0.5 | 14 | Product detected by a:fedoraproject:sssd (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 6.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02287 |
debian: CVE-2026-12610 was patched at 2026-07-14
1140.
Authentication Bypass - Node.js (CVE-2026-48935) - Medium [305]
Description: A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0.5 | 14 | Product detected by a:nodejs:node.js (exists in CPE dict) | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00185, EPSS Percentile is 0.08371 |
almalinux: CVE-2026-48935 was patched at 2026-07-06, 2026-07-15, 2026-07-20
altlinux: CVE-2026-48935 was patched at 2026-07-23
debian: CVE-2026-48935 was patched at 2026-06-24
oraclelinux: CVE-2026-48935 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-48935 was patched at 2026-07-06, 2026-07-15, 2026-07-20
1141.
Authentication Bypass - Unknown Product (CVE-2026-12199) - Medium [305]
Description: {'nvd_cve_data_all': 'A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when started in its default mode. The server listens on all interfaces and processes a specific unauthenticated GET request (`/SHUTDOWN%20THE%20SERVER`) to terminate the process immediately via `os._exit(0)`. This results in a denial of service, impacting service availability. The issue arises due to insufficient authentication and protection mechanisms for critical server functions.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when started in its default mode. The server listens on all interfaces and processes a specific unauthenticated GET request (`/SHUTDOWN%20THE%20SERVER`) to terminate the process immediately via `os._exit(0)`. This results in a denial of service, impacting service availability. The issue arises due to insufficient authentication and protection mechanisms for critical server functions.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00325, EPSS Percentile is 0.25018 |
debian: CVE-2026-12199 was patched at 2026-06-24
1142.
Authentication Bypass - Unknown Product (CVE-2026-55202) - Medium [305]
Description: {'nvd_cve_data_all': 'Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass detection via port manipulation. Remote attackers can trigger unauthorized access to internal proxy statistics or misroute requests as transparent proxy connections to circumvent access controls.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Tinyproxy through 1.11.3, fixed in commit 09312a1, fails to properly validate the Host header during stathost detection, allowing unauthenticated attackers to access the stats page by injecting a matching Host header or bypass detection via port manipulation. Remote attackers can trigger unauthorized access to internal proxy statistics or misroute requests as transparent proxy connections to circumvent access controls.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00381, EPSS Percentile is 0.30855 |
debian: CVE-2026-55202 was patched at 2026-06-24
1143.
Authentication Bypass - Unknown Product (CVE-2026-56091) - Medium [305]
Description: {'nvd_cve_data_all': 'When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause an authentication bypass. This vulnerability is similar to https://www.cve.org/CVERecord?id=CVE-2020-1957 https://www.cve.org/CVERecord , except that it affects the `shiro-guice` module instead of the `shiro-spring` module. This issue affects all Apache Shiro versions through 2.x, and 3.0.0-alpha-1 only when using `shiro-guice` module in a web servlet context. Upgrade to version 3.0.0 or later, which fixes the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'When using Apache Shiro with the shiro-guice module in a web servlet context, a specially crafted HTTP request may cause an authentication bypass.\nThis vulnerability is similar to https://vulners.com/cve/CVE-2020-1957 https://www.cve.org/CVERecord , except that it affects the `shiro-guice` module instead of the `shiro-spring` module.\n\nThis issue affects all Apache Shiro versions through 2.x, and 3.0.0-alpha-1 only when using `shiro-guice` module in a web servlet context.\n\nUpgrade to version 3.0.0 or later, which fixes the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00423, EPSS Percentile is 0.34801 |
debian: CVE-2026-56091 was patched at 2026-07-14
1144.
Denial of Service - FreeIPA (CVE-2026-14612) - Medium [305]
Description: Two off-by-one errors in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | FreeIPA is a free and open source identity management system | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.04014 |
debian: CVE-2026-14612 was patched at 2026-07-14
1145.
Denial of Service - Windows Resilient File System (ReFS) (CVE-2026-42546) - Medium [305]
Description: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.3.0 and prior to version 4.11.0, a resource leak exists in OP-TEE’s shared memory cleanup logic because the function `cleanup_shm_
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.8 | 14 | Windows component | |
| 0.4 | 10 | CVSS Base Score is 3.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00105, EPSS Percentile is 0.0125 |
debian: CVE-2026-42546 was patched at 2026-07-14
1146.
Memory Corruption - Chromium (CVE-2026-13890) - Medium [305]
Description: Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00272, EPSS Percentile is 0.1938 |
altlinux: CVE-2026-13890 was patched at 2026-07-03
debian: CVE-2026-13890 was patched at 2026-07-05, 2026-07-14
1147.
Memory Corruption - Chromium (CVE-2026-13975) - Medium [305]
Description: Out of bounds read in ANGLE in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00249, EPSS Percentile is 0.16305 |
altlinux: CVE-2026-13975 was patched at 2026-07-03
debian: CVE-2026-13975 was patched at 2026-07-05, 2026-07-14
1148.
Memory Corruption - Chromium (CVE-2026-14048) - Medium [305]
Description: Use after free in Chromecast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via a malicious peripheral. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02185 |
altlinux: CVE-2026-14048 was patched at 2026-07-03
debian: CVE-2026-14048 was patched at 2026-07-05, 2026-07-14
1149.
Memory Corruption - Chromium (CVE-2026-14119) - Medium [305]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00116, EPSS Percentile is 0.01877 |
altlinux: CVE-2026-14119 was patched at 2026-07-03
debian: CVE-2026-14119 was patched at 2026-07-05, 2026-07-14
1150.
Memory Corruption - Chromium (CVE-2026-14406) - Medium [305]
Description: Out of bounds read in V8 in Google Chrome prior to 150.0.7871.46 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0019, EPSS Percentile is 0.08893 |
altlinux: CVE-2026-14406 was patched at 2026-07-03
debian: CVE-2026-14406 was patched at 2026-07-05, 2026-07-14
1151.
Code Injection - Unknown Product (CVE-2025-61019) - Medium [304]
Description: {'nvd_cve_data_all': 'An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.27738 |
debian: CVE-2025-61019 was patched at 2026-07-14
1152.
Code Injection - Unknown Product (CVE-2025-61021) - Medium [304]
Description: {'nvd_cve_data_all': 'An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.27739 |
debian: CVE-2025-61021 was patched at 2026-07-14
1153.
Code Injection - Unknown Product (CVE-2025-61022) - Medium [304]
Description: {'nvd_cve_data_all': 'An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.27738 |
debian: CVE-2025-61022 was patched at 2026-07-14
1154.
Code Injection - Unknown Product (CVE-2025-61024) - Medium [304]
Description: {'nvd_cve_data_all': 'An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.27738 |
debian: CVE-2025-61024 was patched at 2026-07-14
1155.
Code Injection - Unknown Product (CVE-2025-61025) - Medium [304]
Description: {'nvd_cve_data_all': 'An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.27738 |
debian: CVE-2025-61025 was patched at 2026-07-14
1156.
Code Injection - Unknown Product (CVE-2025-61027) - Medium [304]
Description: {'nvd_cve_data_all': 'An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.27739 |
debian: CVE-2025-61027 was patched at 2026-07-14
1157.
Code Injection - Unknown Product (CVE-2025-61029) - Medium [304]
Description: {'nvd_cve_data_all': 'An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.27737 |
debian: CVE-2025-61029 was patched at 2026-07-14
1158.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53186) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: RDMA/srp: bound SRP_RSP sense copy by the received length srp_process_rsp() copies sense data from rsp->data + resp_data_len, where resp_data_len is the full 32-bit value supplied by the SRP target and is never checked against the number of bytes actually received (wc->byte_len). The copy length is bounded to SCSI_SENSE_BUFFERSIZE, so at most 96 bytes are copied, but the source offset is not bounded. A malicious or compromised SRP target on the InfiniBand/RoCE fabric that the initiator has logged into can return an SRP_RSP with SRP_RSP_FLAG_SNSVALID set and a large resp_data_len. The receive buffer is allocated at the target-chosen max_ti_iu_len, so the source of the sense copy lands past the bytes actually received; with resp_data_len near 0xFFFFFFFF it is gigabytes past the buffer and the read faults. Copy the sense data only if it has not been truncated, that is, only if the response header, the response data, and the sense region fit within the bytes actually received; otherwise drop the sense and log. The in-tree iSER and NVMe-RDMA receive paths already bound their parse by wc->byte_len; this brings ib_srp into line with them.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/srp: bound SRP_RSP sense copy by the received length\n\nsrp_process_rsp() copies sense data from rsp->data + resp_data_len,\nwhere resp_data_len is the full 32-bit value supplied by the SRP target\nand is never checked against the number of bytes actually received\n(wc->byte_len). The copy length is bounded to SCSI_SENSE_BUFFERSIZE, so\nat most 96 bytes are copied, but the source offset is not bounded.\n\nA malicious or compromised SRP target on the InfiniBand/RoCE fabric that\nthe initiator has logged into can return an SRP_RSP with\nSRP_RSP_FLAG_SNSVALID set and a large resp_data_len. The receive buffer\nis allocated at the target-chosen max_ti_iu_len, so the source of the\nsense copy lands past the bytes actually received; with resp_data_len\nnear 0xFFFFFFFF it is gigabytes past the buffer and the read faults.\n\nCopy the sense data only if it has not been truncated, that is, only if\nthe response header, the response data, and the sense region fit within\nthe bytes actually received; otherwise drop the sense and log. The\nin-tree iSER and NVMe-RDMA receive paths already bound their parse by\nwc->byte_len; this brings ib_srp into line with them.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.40914 |
altlinux: CVE-2026-53186 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53186 was patched at 2026-07-14
1159.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53225) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: sctp: fix uninit-value in __sctp_rcv_asconf_lookup() __sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF chunk can hold the ADDIP header and a parameter header, then calls af->from_addr_param(), which reads the full address (16 bytes for IPv6) trusting the parameter's declared length. An unauthenticated peer can send a truncated trailing ASCONF chunk that declares an IPv6 address parameter but stops after the 4-byte parameter header; reached from the no-association lookup path, from_addr_param() then reads uninitialized bytes past the parameter. Impact: an unauthenticated SCTP peer makes the receive path read up to 16 bytes of uninitialized memory past a truncated ASCONF address parameter. The sibling __sctp_rcv_init_lookup() bounds parameters with sctp_walk_params(); this path open-codes the fetch and omits the bound. Verify the whole address parameter lies within the chunk before from_addr_param() reads it, the same class of fix as commit 51e5ad549c43 ("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix uninit-value in __sctp_rcv_asconf_lookup()\n\n__sctp_rcv_asconf_lookup() in net/sctp/input.c only checks that the ASCONF\nchunk can hold the ADDIP header and a parameter header, then calls\naf->from_addr_param(), which reads the full address (16 bytes for IPv6)\ntrusting the parameter's declared length.\n\nAn unauthenticated peer can send a truncated trailing ASCONF chunk that\ndeclares an IPv6 address parameter but stops after the 4-byte parameter\nheader; reached from the no-association lookup path, from_addr_param() then\nreads uninitialized bytes past the parameter.\n\nImpact: an unauthenticated SCTP peer makes the receive path read up to 16\nbytes of uninitialized memory past a truncated ASCONF address parameter.\n\nThe sibling __sctp_rcv_init_lookup() bounds parameters with\nsctp_walk_params(); this path open-codes the fetch and omits the bound.\nVerify the whole address parameter lies within the chunk before\nfrom_addr_param() reads it, the same class of fix as commit 51e5ad549c43\n("net: sctp: fix KMSAN uninit-value in sctp_inq_pop").', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.40911 |
altlinux: CVE-2026-53225 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53225 was patched at 2026-07-14
1160.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63825) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: gcov: use atomic counter updates to fix concurrent access crashes GCC's GCOV instrumentation can merge global branch counters with loop induction variables as an optimization. In inflate_fast(), the inner copy loops get transformed so that the GCOV counter value is loaded multiple times to compute the loop base address, start index, and end bound. Since GCOV counters are global (not per-CPU), concurrent execution on different CPUs causes the counter to change between loads, producing inconsistent values and out-of-bounds memory writes. The crash manifests during IPComp (IP Payload Compression) processing when inflate_fast() runs concurrently on multiple CPUs: BUG: unable to handle page fault for address: ffffd0a3c0902ffa RIP: inflate_fast+1431 Call Trace: zlib_inflate __deflate_decompress crypto_comp_decompress ipcomp_decompress [xfrm_ipcomp] ipcomp_input [xfrm_ipcomp] xfrm_input At the crash point, the compiler generated three loads from the same global GCOV counter (__gcov0.inflate_fast+216) to compute base, start, and end for an indexed loop. Another CPU modified the counter between loads, making the values inconsistent - the write went 3.4 MB past a 65 KB buffer. Add -fprofile-update=prefer-atomic to CFLAGS_GCOV at the global level in the top-level Makefile, guarded by a try-run compile test. The test compiles a minimal program with and without -fprofile-update=prefer-atomic using the full KBUILD_CFLAGS, then compares undefined symbols in the resulting object files. If prefer-atomic introduces new undefined references (such as __atomic_fetch_add_8 on i386 or __aarch64_ldadd8_relax on arm64 with outline-atomics), the flag is not added -- the kernel does not link against libatomic. On architectures where GCC inlines 64-bit atomic counter updates (x86_64, s390, ...) the test passes and the flag is enabled, preventing the compiler from merging counters with loop induction variables and fixing the observed concurrent-access crash. On architectures where the flag would introduce libatomic dependencies, it is silently omitted and behaviour is no worse than before this patch. Move the CFLAGS_GCOV block from its original position (before the arch Makefile include) to after the core KBUILD_CFLAGS assignments but before the scripts/Makefile.gcc-plugins include. This placement ensures the try-run test sees arch-specific flags (-m32, -march=, -mno-outline-atomics) while avoiding GCC plugin flags (-fplugin=) that would break the test on clean builds when plugin shared objects do not yet exist.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ngcov: use atomic counter updates to fix concurrent access crashes\n\nGCC's GCOV instrumentation can merge global branch counters with loop\ninduction variables as an optimization. In inflate_fast(), the inner copy\nloops get transformed so that the GCOV counter value is loaded multiple\ntimes to compute the loop base address, start index, and end bound. Since\nGCOV counters are global (not per-CPU), concurrent execution on different\nCPUs causes the counter to change between loads, producing inconsistent\nvalues and out-of-bounds memory writes.\n\nThe crash manifests during IPComp (IP Payload Compression) processing when\ninflate_fast() runs concurrently on multiple CPUs:\n\n BUG: unable to handle page fault for address: ffffd0a3c0902ffa\n RIP: inflate_fast+1431\n Call Trace:\n zlib_inflate\n __deflate_decompress\n crypto_comp_decompress\n ipcomp_decompress [xfrm_ipcomp]\n ipcomp_input [xfrm_ipcomp]\n xfrm_input\n\nAt the crash point, the compiler generated three loads from the same\nglobal GCOV counter (__gcov0.inflate_fast+216) to compute base, start, and\nend for an indexed loop. Another CPU modified the counter between loads,\nmaking the values inconsistent - the write went 3.4 MB past a 65 KB\nbuffer.\n\nAdd -fprofile-update=prefer-atomic to CFLAGS_GCOV at the global level in\nthe top-level Makefile, guarded by a try-run compile test. The test\ncompiles a minimal program with and without -fprofile-update=prefer-atomic\nusing the full KBUILD_CFLAGS, then compares undefined symbols in the\nresulting object files. If prefer-atomic introduces new undefined\nreferences (such as __atomic_fetch_add_8 on i386 or __aarch64_ldadd8_relax\non arm64 with outline-atomics), the flag is not added -- the kernel does\nnot link against libatomic.\n\nOn architectures where GCC inlines 64-bit atomic counter updates (x86_64,\ns390, ...) the test passes and the flag is enabled, preventing the\ncompiler from merging counters with loop induction variables and fixing\nthe observed concurrent-access crash.\n\nOn architectures where the flag would introduce libatomic dependencies, it\nis silently omitted and behaviour is no worse than before this patch.\n\nMove the CFLAGS_GCOV block from its original position (before the arch\nMakefile include) to after the core KBUILD_CFLAGS assignments but before\nthe scripts/Makefile.gcc-plugins include. This placement ensures the\ntry-run test sees arch-specific flags (-m32, -march=,\n-mno-outline-atomics) while avoiding GCC plugin flags (-fplugin=) that\nwould break the test on clean builds when plugin shared objects do not yet\nexist.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00414, EPSS Percentile is 0.34112 |
debian: CVE-2026-63825 was patched at 2026-07-14
1161.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63857) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: airoha: Do not read uninitialized fragment address in airoha_dev_xmit() The transmit loop in airoha_dev_xmit() reads fragment address and length during its final iteration, when the loop index equals skb_shinfo(skb)->nr_frags, at which point the fragment data is uninitialized. While these values are never consumed, the read itself is unsafe and may trigger a page fault. Fix this by avoiding the fragment read on the last iteration. Additionally, move the skb pointer from the first to the last used packet descriptor, so that airoha_qdma_tx_napi_poll() defers freeing the skb until the final descriptor is processed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: airoha: Do not read uninitialized fragment address in airoha_dev_xmit()\n\nThe transmit loop in airoha_dev_xmit() reads fragment address and length\nduring its final iteration, when the loop index equals\nskb_shinfo(skb)->nr_frags, at which point the fragment data is\nuninitialized. While these values are never consumed, the read itself is\nunsafe and may trigger a page fault. Fix this by avoiding the fragment\nread on the last iteration.\nAdditionally, move the skb pointer from the first to the last used packet\ndescriptor, so that airoha_qdma_tx_napi_poll() defers freeing the skb\nuntil the final descriptor is processed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00347, EPSS Percentile is 0.27389 |
debian: CVE-2026-63857 was patched at 2026-07-14
ubuntu: CVE-2026-63857 was patched at 2026-07-30
1162.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63909) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops Commit d07b26f39246 ("ksmbd: require minimum ACE size in smb_check_perm_dacl()") introduced a transposed bounds check: if (offsetof(struct smb_ace, sid) + aces_size < CIFS_SID_BASE_SIZE) Since offsetof(..sid) is 8 and CIFS_SID_BASE_SIZE is 8, this evaluates to `aces_size < 0`. Because `aces_size` is always non-negative, this check becomes dead code and never breaks the loop. Worse, that commit removed the old 4-byte guard, meaning the loop now reads `ace->size` (offset 2) even when `aces_size` is 0-3 bytes. This re-opens a 2-byte heap out-of-bounds (OOB) read past the pntsd allocation during subsequent SMB2_CREATE operations. Fix this by properly transposing the comparison to require at least 16 bytes (8-byte offset + 8-byte SID base), matching the correct form used in smb_inherit_dacl().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: OOB read regression in smb_check_perm_dacl() ACE-walk loops\n\nCommit d07b26f39246 ("ksmbd: require minimum ACE size in\nsmb_check_perm_dacl()") introduced a transposed bounds check:\n\n if (offsetof(struct smb_ace, sid) + aces_size < CIFS_SID_BASE_SIZE)\n\nSince offsetof(..sid) is 8 and CIFS_SID_BASE_SIZE is 8, this evaluates\nto `aces_size < 0`. Because `aces_size` is always non-negative, this\ncheck becomes dead code and never breaks the loop.\n\nWorse, that commit removed the old 4-byte guard, meaning the loop now\nreads `ace->size` (offset 2) even when `aces_size` is 0-3 bytes. This\nre-opens a 2-byte heap out-of-bounds (OOB) read past the pntsd allocation\nduring subsequent SMB2_CREATE operations.\n\nFix this by properly transposing the comparison to require at least\n16 bytes (8-byte offset + 8-byte SID base), matching the correct form\nused in smb_inherit_dacl().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00628, EPSS Percentile is 0.46603 |
debian: CVE-2026-63909 was patched at 2026-07-14
ubuntu: CVE-2026-63909 was patched at 2026-07-30
1163.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63913) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check An unintended behavior in the TCP conntrack state machine allows a connection to be forced into the CLOSE state using an RST packet with an invalid sequence number. Specifically, after a SYN packet is observed, an RST with an invalid SEQ can transition the conntrack entry to TCP_CONNTRACK_CLOSE, regardless of whether the RST corresponds to the expected reply direction. The relevant code path assumes the RST is a response to an outgoing SYN, but does not validate packet direction or ensure that a matching SYN was actually sent in the opposite direction. As a result, a crafted packet sequence consisting of a SYN followed by an invalid-sequence RST can prematurely terminate an active NAT entry. This makes connection teardown easier than intended. So, tighten the state transition logic to ensure that RST-triggered CLOSE transitions only occur when the RST is a valid response to a previously observed SYN in the correct direction.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check\n\nAn unintended behavior in the TCP conntrack state machine allows a\nconnection to be forced into the CLOSE state using an RST packet with an\ninvalid sequence number.\n\nSpecifically, after a SYN packet is observed, an RST with an invalid SEQ\ncan transition the conntrack entry to TCP_CONNTRACK_CLOSE, regardless of\nwhether the RST corresponds to the expected reply direction. The relevant\ncode path assumes the RST is a response to an outgoing SYN, but does not\nvalidate packet direction or ensure that a matching SYN was actually sent\nin the opposite direction.\n\nAs a result, a crafted packet sequence consisting of a SYN followed by an\ninvalid-sequence RST can prematurely terminate an active NAT entry. This\nmakes connection teardown easier than intended.\n\nSo, tighten the state transition logic to ensure that RST-triggered\nCLOSE transitions only occur when the RST is a valid response to a\npreviously observed SYN in the correct direction.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00618, EPSS Percentile is 0.46163 |
debian: CVE-2026-63913 was patched at 2026-07-14
ubuntu: CVE-2026-63913 was patched at 2026-07-30
1164.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63968) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible infinite loop in fib6_select_path() Found while auditing the same pattern Sashiko reported in rt6_fill_node() [1]. Apply the same fix as commit f8d8ce1b515a ("ipv6: fix possible infinite loop in fib6_info_uses_dev()"). Writers holding tb6_lock can list_del_rcu(&first->fib6_siblings) without waiting for RCU readers; first->fib6_siblings.next then still points into the old ring and this softirq-side walker never reaches &first->fib6_siblings as its terminator. fib6_purge_rt() always WRITE_ONCE()s first->fib6_nsiblings to 0 before list_del_rcu(), so an inside-loop check is a reliable detach signal. [1] https://sashiko.dev/#/patchset/20260526020227.4857-1-jiayuan.chen%40linux.dev', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix possible infinite loop in fib6_select_path()\n\nFound while auditing the same pattern Sashiko reported in\nrt6_fill_node() [1]. Apply the same fix as\ncommit f8d8ce1b515a ("ipv6: fix possible infinite loop in fib6_info_uses_dev()").\n\nWriters holding tb6_lock can list_del_rcu(&first->fib6_siblings)\nwithout waiting for RCU readers; first->fib6_siblings.next then\nstill points into the old ring and this softirq-side walker never\nreaches &first->fib6_siblings as its terminator. fib6_purge_rt()\nalways WRITE_ONCE()s first->fib6_nsiblings to 0 before\nlist_del_rcu(), so an inside-loop check is a reliable detach signal.\n\n[1] https://sashiko.dev/#/patchset/20260526020227.4857-1-jiayuan.chen%40linux.dev', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00647, EPSS Percentile is 0.47407 |
debian: CVE-2026-63968 was patched at 2026-07-14
ubuntu: CVE-2026-63968 was patched at 2026-07-30
1165.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63976) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: l2cap: clear chan->ident on ECRED reconfiguration success l2cap_ecred_reconf_rsp() returns early on success without clearing chan->ident. Every other L2CAP response handler (l2cap_ecred_conn_rsp, l2cap_le_connect_rsp, l2cap_config_rsp) clears chan->ident after a successful transaction to prevent the channel from matching subsequent responses with the recycled ident value. A remote attacker that completed a reconfiguration as the peer can replay a failure response with the stale ident, causing the kernel to match and destroy the already-established channel via l2cap_chan_del(chan, ECONNRESET). Clear chan->ident for all matching channels on success, and harden the failure path by using l2cap_chan_hold_unless_zero() consistent with other L2CAP handlers (l2cap_le_command_rej, __l2cap_get_chan_by_ident).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: l2cap: clear chan->ident on ECRED reconfiguration success\n\nl2cap_ecred_reconf_rsp() returns early on success without clearing\nchan->ident. Every other L2CAP response handler (l2cap_ecred_conn_rsp,\nl2cap_le_connect_rsp, l2cap_config_rsp) clears chan->ident after a\nsuccessful transaction to prevent the channel from matching subsequent\nresponses with the recycled ident value.\n\nA remote attacker that completed a reconfiguration as the peer can\nreplay a failure response with the stale ident, causing the kernel to\nmatch and destroy the already-established channel via\nl2cap_chan_del(chan, ECONNRESET).\n\nClear chan->ident for all matching channels on success, and harden the\nfailure path by using l2cap_chan_hold_unless_zero() consistent with\nother L2CAP handlers (l2cap_le_command_rej, __l2cap_get_chan_by_ident).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00443, EPSS Percentile is 0.36427 |
debian: CVE-2026-63976 was patched at 2026-07-14
ubuntu: CVE-2026-63976 was patched at 2026-07-30
1166.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63992) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tunnels: do not assume transport header in iptunnel_pmtud_check_icmp() In some cases, iptunnel_pmtud_check_icmp() can be called while skb transport header is not set. This triggers an out-of-bound access, because (typeof(skb->transport_header))~0U is 65535. Access the icmp header based on IPv4 network header, after making sure icmp->type is present in skb linear part. Note that iptunnel_pmtud_check_icmpv6()) is fine.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntunnels: do not assume transport header in iptunnel_pmtud_check_icmp()\n\nIn some cases, iptunnel_pmtud_check_icmp() can be called while\nskb transport header is not set.\n\nThis triggers an out-of-bound access, because\n(typeof(skb->transport_header))~0U is 65535.\n\nAccess the icmp header based on IPv4 network header,\nafter making sure icmp->type is present in skb linear part.\n\nNote that iptunnel_pmtud_check_icmpv6()) is fine.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00514, EPSS Percentile is 0.40915 |
debian: CVE-2026-63992 was patched at 2026-07-14
ubuntu: CVE-2026-63992 was patched at 2026-07-30
1167.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64067) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing barriers when accessing stream->subrequests locklessly The list of subrequests attached to stream->subrequests is accessed without locks by netfs_collect_read_results() and netfs_collect_write_results(), and then they access subreq->flags without taking a barrier after getting the subreq pointer from the list. Relatedly, the functions that build the list don't use any sort of write barrier when constructing the list to make sure that the NETFS_SREQ_IN_PROGRESS flag is perceived to be set first if no lock is taken. Fix this by: (1) Add a new list_add_tail_release() function that uses a release barrier to set the pointer to the new member of the list. (2) Add a new list_first_entry_or_null_acquire() function that uses an acquire barrier to read the pointer to the first member in a list (or return NULL). (3) Use list_add_tail_release() when adding a subreq to ->subrequests. (4) Use list_first_entry_or_null_acquire() when initially accessing the front of the list (when an item is removed, the pointer to the new front iterm is obtained under the same lock).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix missing barriers when accessing stream->subrequests locklessly\n\nThe list of subrequests attached to stream->subrequests is accessed without\nlocks by netfs_collect_read_results() and netfs_collect_write_results(),\nand then they access subreq->flags without taking a barrier after getting\nthe subreq pointer from the list. Relatedly, the functions that build the\nlist don't use any sort of write barrier when constructing the list to make\nsure that the NETFS_SREQ_IN_PROGRESS flag is perceived to be set first if\nno lock is taken.\n\nFix this by:\n\n (1) Add a new list_add_tail_release() function that uses a release barrier\n to set the pointer to the new member of the list.\n\n (2) Add a new list_first_entry_or_null_acquire() function that uses an\n acquire barrier to read the pointer to the first member in a list (or\n return NULL).\n\n (3) Use list_add_tail_release() when adding a subreq to ->subrequests.\n\n (4) Use list_first_entry_or_null_acquire() when initially accessing the\n front of the list (when an item is removed, the pointer to the new\n front iterm is obtained under the same lock).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0038, EPSS Percentile is 0.30692 |
debian: CVE-2026-64067 was patched at 2026-07-14
ubuntu: CVE-2026-64067 was patched at 2026-07-30
1168.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64068) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfs: Fix missing locking around retry adding new subreqs Fix netfs_retry_read_subrequests() and netfs_retry_write_stream() to take the appropriate lock when adding extra subrequests into stream->subrequests.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix missing locking around retry adding new subreqs\n\nFix netfs_retry_read_subrequests() and netfs_retry_write_stream() to take\nthe appropriate lock when adding extra subrequests into\nstream->subrequests.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0038, EPSS Percentile is 0.30692 |
debian: CVE-2026-64068 was patched at 2026-07-14
ubuntu: CVE-2026-64068 was patched at 2026-07-30
1169.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64160) - Medium [304]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential for tearing in ->remote_i_size and ->zero_point Fix potential tearing in using ->remote_i_size and ->zero_point by copying i_size_read() and i_size_write() and using the same seqcount as for i_size. We need to make sure that netfslib and the filesystems that use it always hold i_lock whilst updating any of the sizes to prevent i_size_seqcount from getting corrupted.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix potential for tearing in ->remote_i_size and ->zero_point\n\nFix potential tearing in using ->remote_i_size and ->zero_point by copying\ni_size_read() and i_size_write() and using the same seqcount as for i_size.\n\nWe need to make sure that netfslib and the filesystems that use it always\nhold i_lock whilst updating any of the sizes to prevent i_size_seqcount\nfrom getting corrupted.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00407, EPSS Percentile is 0.3348 |
debian: CVE-2026-64160 was patched at 2026-07-14
ubuntu: CVE-2026-64160 was patched at 2026-07-30
1170.
Unknown Vulnerability Type - Sudo (CVE-2026-14474) - Medium [304]
Description: {'nvd_cve_data_all': 'A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in SSSD's LDAP sudo provider. When the ldap_sudo_search_base option is not explicitly configured, SSSD searches the entire LDAP directory tree for sudoRole objects. An authenticated attacker with write access to any subtree can inject a sudoRole object granting root-level sudo privileges on all SSSD-enrolled hosts.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | Sudo is a widely used Unix/Linux utility that allows permitted users to execute commands with elevated (typically root) privileges while providing extensive logging and fine-grained security controls. It is a foundational component in most Linux and BSD distributions. | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00447, EPSS Percentile is 0.36724 |
almalinux: CVE-2026-14474 was patched at 2026-07-20
debian: CVE-2026-14474 was patched at 2026-07-14
oraclelinux: CVE-2026-14474 was patched at 2026-07-20, 2026-07-22
redhat: CVE-2026-14474 was patched at 2026-07-20, 2026-07-28
1171.
XXE Injection - nokogiri (CVE-2026-57234) - Medium [304]
Description: Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, the NONET parse option, which Nokogiri turns on by default for Nokogiri::XML::Schema (see CVE-2020-26247), was not correctly enforced on the JRuby implementation. As a result, a schema parsed with default options could still cause external resources to be fetched over the network, potentially enabling SSRF or
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | XXE Injection | |
| 0.5 | 14 | Product detected by a:nokogiri:nokogiri (exists in CPE dict) | |
| 0.3 | 10 | CVSS Base Score is 2.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06278 |
debian: CVE-2026-57234 was patched at 2026-07-14
1172.
Denial of Service - Pypdf (CVE-2026-57204) - Medium [303]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.10876 |
debian: CVE-2026-57204 was patched at 2026-07-14
1173.
Denial of Service - aardvark-dns (CVE-2026-35406) - Medium [303]
Description: Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable infinite error loop at 100% CPU. This vulnerability is fixed in 1.17.1.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:containers:aardvark-dns (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00013, EPSS Percentile is 0.02058 |
almalinux: CVE-2026-35406 was patched at 2026-07-07, 2026-07-08
oraclelinux: CVE-2026-35406 was patched at 2026-07-07, 2026-07-16
redhat: CVE-2026-35406 was patched at 2026-07-07
1174.
Denial of Service - busybox (CVE-2026-38753) - Medium [303]
Description: A use-after-free in the awk_sub() function (editors/awk.c) of Busybox v1.38.0 allows attackers to cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:busybox:busybox (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00145, EPSS Percentile is 0.04296 |
debian: CVE-2026-38753 was patched at 2026-07-14
1175.
Memory Corruption - Gzip (CVE-2026-41992) - Medium [303]
Description: GNU gzip contains a global
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:gnu:gzip (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00335, EPSS Percentile is 0.26104 |
debian: CVE-2026-41992 was patched at 2026-07-14
ubuntu: CVE-2026-41992 was patched at 2026-07-30
1176.
Memory Corruption - NGINX (CVE-2026-56434) - Medium [303]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0045, EPSS Percentile is 0.36929 |
altlinux: CVE-2026-56434 was patched at 2026-07-17, 2026-07-21, 2026-07-22
debian: CVE-2026-56434 was patched at 2026-07-14
ubuntu: CVE-2026-56434 was patched at 2026-07-30
1177.
Memory Corruption - Wget (CVE-2026-58469) - Medium [303]
Description: GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a heap buffer underread vulnerability in the clean_metalink_string() function within src/metalink.c that allows a malicious server to trigger memory corruption by serving a Metalink document containing a whitespace-only URL. Attackers can cause the function to decrement a pointer past the start of the buffer when processing an all-whitespace Metalink URL, potentially leading to abnormal program behavior.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:gnu:wget (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00351, EPSS Percentile is 0.27777 |
debian: CVE-2026-58469 was patched at 2026-07-14
ubuntu: CVE-2026-58469 was patched at 2026-07-30
1178.
Memory Corruption - freeswitch (CVE-2026-45771) - Medium [303]
Description: FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH's bundled XML parser expands nested <!ENTITY> declarations without a depth or count bound, so a small DTD can describe a body that expands exponentially ("billion laughs"). The PIDF body of a SIP PUBLISH is fed to this parser before any digest check, letting an unauthenticated network attacker force unbounded CPU and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:freeswitch:freeswitch (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00343, EPSS Percentile is 0.26974 |
altlinux: CVE-2026-45771 was patched at 2026-06-24, 2026-06-26, 2026-07-16
1179.
Memory Corruption - nokogiri (CVE-2026-57235) - Medium [303]
Description: Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::NodeSet#[] (and its alias #slice) checked the requested index against the node set's bounds using a 32-bit-truncated copy of the index. A large negative index could pass the check and then be used at full width, reading outside the node set's storage. On CRuby this is an out-of-bounds read that typically crashes the process; on JRuby it is not memory-unsafe but returns an incorrect node. This vulnerability is fixed in 1.19.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:nokogiri:nokogiri (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00341, EPSS Percentile is 0.26708 |
debian: CVE-2026-57235 was patched at 2026-07-14
1180.
Memory Corruption - nokogiri (CVE-2026-57434) - Medium [303]
Description: Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri contains a bug when calling certain methods on allocated-but-uninitialized native wrapper classes that inherit from Nokogiri::XML::Node. This caused a NULL pointer dereference that could crash the process. This vulnerability is fixed in 1.19.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:nokogiri:nokogiri (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00358, EPSS Percentile is 0.28472 |
debian: CVE-2026-57434 was patched at 2026-07-14
1181.
Memory Corruption - nokogiri (CVE-2026-57435) - Medium [303]
Description: Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri’s CRuby native extension could leave a Ruby wrapper pointing to freed memory when replacing the value of an XML attribute. If Ruby code had already accessed an attribute child node, Nokogiri::XML::Attr#value= could free the underlying native child node while the wrapper remained reachable through the document node cache. A later use of the freed child node or a Ruby GC mark could dereference an invalid pointer, causing an invalid read and a possible segfault. This vulnerability is fixed in 1.19.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:nokogiri:nokogiri (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00368, EPSS Percentile is 0.2945 |
debian: CVE-2026-57435 was patched at 2026-07-14
1182.
Memory Corruption - tiff (CVE-2026-46604) - Medium [303]
Description: The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:golang:tiff (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00342, EPSS Percentile is 0.26795 |
debian: CVE-2026-46604 was patched at 2026-07-14
1183.
Memory Corruption - wolfssl (CVE-2026-6094) - Medium [303]
Description: Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.21751 |
debian: CVE-2026-6094 was patched at 2026-07-14
1184.
Denial of Service - Oj (CVE-2026-54592) - Medium [302]
Description: Oj (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.35 | 14 | Oj (Optimized JSON) is a high-performance JSON parser and object serialization library packaged as a Ruby gem, designed to provide fast JSON encoding and decoding for Ruby applications. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.18043 |
debian: CVE-2026-54592 was patched at 2026-07-14
1185.
Cross Site Scripting - Gogs (CVE-2026-26195) - Medium [301]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00189, EPSS Percentile is 0.08821 |
altlinux: CVE-2026-26195 was patched at 2026-06-25
1186.
Information Disclosure - Oracle VM VirtualBox (CVE-2026-46874) - Medium [300]
Description: Vulnerability in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.7 | 14 | Oracle VM VirtualBox is a hosted hypervisor for x86 virtualization developed by Oracle Corporation | |
| 0.3 | 10 | CVSS Base Score is 3.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02944 |
altlinux: CVE-2026-46874 was patched at 2026-06-29
1187.
Open Redirect - webob (CVE-2026-44889) - Medium [300]
Description: WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect target to the request URI using Python's urljoin, and since Python 3.10 the underlying urlsplit strips ASCII tab, carriage return, and newline characters before parsing, so a redirect target containing such characters can be reinterpreted as a protocol-relative URL whose authority is an attacker-controlled host. This bypasses the CVE-2024-42353 fix that escaped a leading double slash, allowing an attacker who influences the redirect location to send users to an arbitrary external site instead of the intended one. This vulnerability is fixed in 1.8.10.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.75 | 15 | Open Redirect | |
| 0.5 | 14 | Product detected by a:pylonsproject:webob (does NOT exist in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00162, EPSS Percentile is 0.05801 |
altlinux: CVE-2026-44889 was patched at 2026-07-01
debian: CVE-2026-44889 was patched at 2026-06-24
1188.
Spoofing - Chromium (CVE-2026-13988) - Medium [300]
Description: Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00218, EPSS Percentile is 0.1244 |
altlinux: CVE-2026-13988 was patched at 2026-07-03
debian: CVE-2026-13988 was patched at 2026-07-05, 2026-07-14
1189.
Spoofing - Chromium (CVE-2026-13989) - Medium [300]
Description: Inappropriate implementation in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00204, EPSS Percentile is 0.10594 |
altlinux: CVE-2026-13989 was patched at 2026-07-03
debian: CVE-2026-13989 was patched at 2026-07-05, 2026-07-14
1190.
Spoofing - Chromium (CVE-2026-13996) - Medium [300]
Description: Inappropriate implementation in Permissions in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00219, EPSS Percentile is 0.12466 |
altlinux: CVE-2026-13996 was patched at 2026-07-03
debian: CVE-2026-13996 was patched at 2026-07-05, 2026-07-14
1191.
Spoofing - Chromium (CVE-2026-14002) - Medium [300]
Description: Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00219, EPSS Percentile is 0.12467 |
altlinux: CVE-2026-14002 was patched at 2026-07-03
debian: CVE-2026-14002 was patched at 2026-07-05, 2026-07-14
1192.
Spoofing - Chromium (CVE-2026-14014) - Medium [300]
Description: Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00227, EPSS Percentile is 0.13562 |
altlinux: CVE-2026-14014 was patched at 2026-07-03
debian: CVE-2026-14014 was patched at 2026-07-05, 2026-07-14
1193.
Spoofing - Chromium (CVE-2026-14404) - Medium [300]
Description: Inappropriate implementation in PDFium in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00202, EPSS Percentile is 0.10327 |
altlinux: CVE-2026-14404 was patched at 2026-07-03
debian: CVE-2026-14404 was patched at 2026-07-05, 2026-07-14
1194.
Denial of Service - Erlang/OTP (CVE-2026-55950) - Medium [298]
Description: Time-of-check Time-of-use (TOCTOU) race condition vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | Erlang/OTP is a set of libraries for the Erlang programming language | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00379, EPSS Percentile is 0.30659 |
debian: CVE-2026-55950 was patched at 2026-07-14
1195.
Memory Corruption - Linux Kernel (CVE-2026-53194) - Medium [298]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00148, EPSS Percentile is 0.04517 |
altlinux: CVE-2026-53194 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53194 was patched at 2026-07-14
1196.
Memory Corruption - Linux Kernel (CVE-2026-53352) - Medium [298]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00086, EPSS Percentile is 0.00411 |
altlinux: CVE-2026-53352 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53352 was patched at 2026-07-14
1197.
Path Traversal - Keras (CVE-2026-12479) - Medium [298]
Description: A path traversal vulnerability exists in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.4 | 14 | High-level neural networks API, running on top of TensorFlow, allowing model building and training | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00384, EPSS Percentile is 0.31104 |
debian: CVE-2026-12479 was patched at 2026-07-14
1198.
Cross Site Scripting - Hugo (CVE-2026-58402) - Medium [297]
Description: Hugo is a static site generator. From 0.60.0 until 0.163.3, Hugo's default code-block renderer wrote the Markdown code-fence language or info-string into the code class="language-…" data-lang="…" wrapper without HTML escaping. A fence info-string containing a quote and a script payload breaks out of the attribute and injects a live script element. This issue is fixed in 0.163.3.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Product detected by a:gohugo:hugo (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06881 |
altlinux: CVE-2026-58402 was patched at 2026-07-01
debian: CVE-2026-58402 was patched at 2026-07-14
1199.
Cross Site Scripting - rabbitmq_server (CVE-2026-57214) - Medium [297]
Description: RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the RabbitMQ management UI renders the x-internal-purpose queue or exchange argument into an HTML title attribute without proper escaping on the Queues and Exchanges pages, allowing a user with permission to declare a queue or exchange to execute JavaScript in another user's browser. This issue is fixed in version 4.2.5.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.5 | 14 | Product detected by a:broadcom:rabbitmq_server (does NOT exist in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12582 |
debian: CVE-2026-57214 was patched at 2026-07-14
1200.
Remote Code Execution - Unknown Product (CVE-2026-56208) - Medium [297]
Description: {'nvd_cve_data_all': 'A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer wrap-around guard to be bypassed when g_lag_in_frames is set to 1 or higher. This results in a 232-byte out-of-bounds write on every encoded frame after the second, corrupting adjacent heap objects. An attacker who can influence encoder configuration in a transcoding service or WebRTC session could exploit this to cause a denial of service (process crash) or potentially achieve code execution.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00281, EPSS Percentile is 0.20386 |
debian: CVE-2026-56208 was patched at 2026-06-24
oraclelinux: CVE-2026-56208 was patched at 2026-07-28
redhat: CVE-2026-56208 was patched at 2026-07-28
1201.
Remote Code Execution - Unknown Product (CVE-2026-56211) - Medium [297]
Description: {'nvd_cve_data_all': 'A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic refresh map pointer, brute-force the process base address via a crash oracle, and redirect control flow to achieve arbitrary command execution. Exploitation requires the target service to use libaom with SVC encoding enabled and accept attacker-supplied video frames.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A remote code execution vulnerability was found in libaom, the reference AV1 codec implementation. Insufficient bounds validation in the AV1 encoder's SVC (Scalable Video Coding) layer ID control allows an attacker to supply crafted video frame pixels that overlap with internal encoder layer context structures. In fork-based video processing services, an attacker can use this to hijack the cyclic refresh map pointer, brute-force the process base address via a crash oracle, and redirect control flow to achieve arbitrary command execution. Exploitation requires the target service to use libaom with SVC encoding enabled and accept attacker-supplied video frames.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00414, EPSS Percentile is 0.34065 |
debian: CVE-2026-56211 was patched at 2026-06-24
1202.
Denial of Service - Perl (CVE-2026-13713) - Medium [296]
Description: YAML::Syck versions before 1.47 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03327 |
debian: CVE-2026-13713 was patched at 2026-07-14
1203.
Denial of Service - Wireshark (CVE-2026-15173) - Medium [296]
Description: pcapng file parser crash in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00089, EPSS Percentile is 0.00533 |
altlinux: CVE-2026-15173 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15173 was patched at 2026-07-14
1204.
Denial of Service - Wireshark (CVE-2026-15174) - Medium [296]
Description: Catapult DCT2000 protocol dissector crash in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | Wireshark is a free and open-source packet analyzer. It is used for network troubleshooting, analysis, software and communications protocol development, and education | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00092, EPSS Percentile is 0.00624 |
altlinux: CVE-2026-15174 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15174 was patched at 2026-07-14
1205.
Memory Corruption - ImageMagick (CVE-2026-61863) - Medium [296]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00187, EPSS Percentile is 0.08665 |
altlinux: CVE-2026-61863 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-61863 was patched at 2026-07-14
1206.
Memory Corruption - ImageMagick (CVE-2026-61866) - Medium [296]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00187, EPSS Percentile is 0.08665 |
altlinux: CVE-2026-61866 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-61866 was patched at 2026-07-14
1207.
Denial of Service - dhcpcd (CVE-2026-56113) - Medium [295]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.45 | 14 | dhcpcd is an open-source DHCP and network configuration client used on Linux, BSD, and other Unix-like operating systems to automatically configure network interfaces, IP addresses, routes, and DNS settings. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07293 |
debian: CVE-2026-56113 was patched at 2026-06-24
1208.
Denial of Service - dhcpcd (CVE-2026-56116) - Medium [295]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.45 | 14 | dhcpcd is an open-source DHCP and network configuration client used on Linux, BSD, and other Unix-like operating systems to automatically configure network interfaces, IP addresses, routes, and DNS settings. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00188, EPSS Percentile is 0.08689 |
debian: CVE-2026-56116 was patched at 2026-06-24
1209.
Incorrect Calculation - Chromium (CVE-2026-14391) - Medium [294]
Description: Integer overflow in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00234, EPSS Percentile is 0.14416 |
altlinux: CVE-2026-14391 was patched at 2026-07-03
debian: CVE-2026-14391 was patched at 2026-07-05, 2026-07-14
1210.
Memory Corruption - Chromium (CVE-2026-14063) - Medium [294]
Description: Out of bounds read in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via malicious network traffic. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.6 | 10 | CVSS Base Score is 5.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00141, EPSS Percentile is 0.03886 |
altlinux: CVE-2026-14063 was patched at 2026-07-03
debian: CVE-2026-14063 was patched at 2026-07-05, 2026-07-14
1211.
Command Injection - Unknown Product (CVE-2026-13501) - Medium [292]
Description: {'nvd_cve_data_all': 'A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/src/org/antlr/v4/codegen/target/GoTarget.java of the component gofmt. The manipulation leads to command injection. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/src/org/antlr/v4/codegen/target/GoTarget.java of the component gofmt. The manipulation leads to command injection. The attack can only be performed from a local environment. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00679, EPSS Percentile is 0.48764 |
debian: CVE-2026-13501 was patched at 2026-07-14
1212.
Command Injection - Unknown Product (CVE-2026-47240) - Medium [292]
Description: {'nvd_cve_data_all': 'Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a "raw data" argument that is sent verbatim after validation to prevent command injection. However, if a server does not support non-synchronizing literals, it may still be possible to inject arbitrary IMAP commands inside non-synchronizing literals. A server without support for non-synchronizing literals may interpret the "+}\\r\\n" as the end of a malformed command line and respond with a tagged BAD. In that case, the contents of the literal will be interpreted as one or more new pipelined commands, allowing a CRLF command injection attack to succeed. This affects criteria for #search and #uid_search; search_keys for #sort, #thread, #uid_sort, and #uid_thread; and attr for #fetch and #uid_fetch. This vulnerability is fixed in 0.6.5 and 0.5.15.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a "raw data" argument that is sent verbatim after validation to prevent command injection. However, if a server does not support non-synchronizing literals, it may still be possible to inject arbitrary IMAP commands inside non-synchronizing literals. A server without support for non-synchronizing literals may interpret the "+}\\r\\n" as the end of a malformed command line and respond with a tagged BAD. In that case, the contents of the literal will be interpreted as one or more new pipelined commands, allowing a CRLF command injection attack to succeed. This affects criteria for #search and #uid_search; search_keys for #sort, #thread, #uid_sort, and #uid_thread; and attr for #fetch and #uid_fetch. This vulnerability is fixed in 0.6.5 and 0.5.15.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00491, EPSS Percentile is 0.39493 |
debian: CVE-2026-47240 was patched at 2026-07-14
1213.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53131) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: require Ethernet MAC header before using eth_hdr() `ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and `hash:mac` ipset types, and `nf_log_syslog` access `eth_hdr(skb)` after either assuming that the skb is associated with an Ethernet device or checking only that the `ETH_HLEN` bytes at `skb_mac_header(skb)` lie between `skb->head` and `skb->data`. Make these paths first verify that the skb is associated with an Ethernet device, that the MAC header was set, and that it spans at least a full Ethernet header before accessing `eth_hdr(skb)`.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: require Ethernet MAC header before using eth_hdr()\n\n`ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and\n`hash:mac` ipset types, and `nf_log_syslog` access `eth_hdr(skb)`\nafter either assuming that the skb is associated with an Ethernet\ndevice or checking only that the `ETH_HLEN` bytes at\n`skb_mac_header(skb)` lie between `skb->head` and `skb->data`.\n\nMake these paths first verify that the skb is associated with an\nEthernet device, that the MAC header was set, and that it spans at\nleast a full Ethernet header before accessing `eth_hdr(skb)`.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.4. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00425, EPSS Percentile is 0.34986 |
altlinux: CVE-2026-53131 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53131 was patched at 2026-07-14
1214.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53183) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mptcp: allow subflow rcv wnd to shrink In MPTCP connection, the `window` field in the TCP header refers to the MPTCP-level rcv_nxt and it's right edge should not move backward. Such constraint is enforced at DSS option generation time. At the same time, the TCP stack ensures independently that the TCP-level rcv wnd right's edge does not move backward. That in turn causes artificial inflating of the MPTCP rcv window when the incoming data is acked at the TCP level and is OoO in the MPTCP sequence space (or lands in the backlog). As a consequence, the incoming traffic can exceed the receiver rcvbuf size even when the sender is not misbehaving. Prevent such scenario forcibly allowing the TCP subflow to shrink the TCP-level rcv wnd regardless of the current netns setting.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: allow subflow rcv wnd to shrink\n\nIn MPTCP connection, the `window` field in the TCP header refers to the\nMPTCP-level rcv_nxt and it's right edge should not move backward. Such\nconstraint is enforced at DSS option generation time.\n\nAt the same time, the TCP stack ensures independently that the TCP-level\nrcv wnd right's edge does not move backward. That in turn causes artificial\ninflating of the MPTCP rcv window when the incoming data is acked at the\nTCP level and is OoO in the MPTCP sequence space (or lands in the backlog).\n\nAs a consequence, the incoming traffic can exceed the receiver rcvbuf size\neven when the sender is not misbehaving.\n\nPrevent such scenario forcibly allowing the TCP subflow to shrink the\nTCP-level rcv wnd regardless of the current netns setting.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00479, EPSS Percentile is 0.38777 |
altlinux: CVE-2026-53183 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53183 was patched at 2026-07-14
1215.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53184) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: udp: clear skb->dev before running a sockmap verdict On the UDP receive path skb->dev is repurposed as dev_scratch (the truesize/state cache set by udp_set_dev_scratch()), through the union { struct net_device *dev; unsigned long dev_scratch; } in sk_buff. When a UDP socket is in a sockmap, sk_data_ready is sk_psock_verdict_data_ready(), which calls udp_read_skb() -> recv_actor() (sk_psock_verdict_recv) to run the attached SK_SKB verdict program in softirq. If that program calls a socket-lookup helper (bpf_sk_lookup_tcp/udp, bpf_skc_lookup_tcp), bpf_skc_lookup() does: \tif (skb->dev) \t\tcaller_net = dev_net(skb->dev); skb->dev still holds the dev_scratch value (a non-NULL integer), so dev_net() dereferences it as a struct net_device * and the kernel takes a general protection fault on a non-canonical address in softirq: Oops: general protection fault, probably for non-canonical address 0x1010000800004a0 CPU: 1 UID: 0 PID: 1406 Comm: syz.2.19 Not tainted 7.1.0-rc6 #1 PREEMPT(full) RIP: 0010:bpf_skc_lookup net/core/filter.c:7033 [inline] RIP: 0010:bpf_sk_lookup+0x45/0x160 net/core/filter.c:7047 Call Trace: <IRQ> bpf_prog_4675cb904b7071f8+0x12e/0x14e bpf_prog_run_pin_on_cpu+0xc6/0x1f0 sk_psock_verdict_recv+0x1ba/0x350 udp_read_skb+0x31a/0x370 sk_psock_verdict_data_ready+0x2e3/0x600 __udp_enqueue_schedule_skb+0x4c8/0x650 udpv6_queue_rcv_one_skb+0x3ec/0x740 udp6_unicast_rcv_skb+0x11d/0x140 ip6_protocol_deliver_rcu+0x61e/0x950 ip6_input_finish+0xa9/0x150 NF_HOOK+0x286/0x2f0 ip6_input+0x117/0x220 NF_HOOK+0x286/0x2f0 __netif_receive_skb+0x85/0x200 process_backlog+0x374/0x9a0 __napi_poll+0x4f/0x1c0 net_rx_action+0x3b0/0x770 handle_softirqs+0x15a/0x460 do_softirq+0x57/0x80 </IRQ> The rmem charge that dev_scratch accounted for is released by skb_recv_udp() on dequeue, just above, so the scratch is dead by the time recv_actor() runs. Clear skb->dev so bpf_skc_lookup() falls back to sock_net(skb->sk), which skb_set_owner_sk_safe() set just above.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nudp: clear skb->dev before running a sockmap verdict\n\nOn the UDP receive path skb->dev is repurposed as dev_scratch (the\ntruesize/state cache set by udp_set_dev_scratch()), through the\nunion { struct net_device *dev; unsigned long dev_scratch; } in sk_buff.\n\nWhen a UDP socket is in a sockmap, sk_data_ready is\nsk_psock_verdict_data_ready(), which calls udp_read_skb() -> recv_actor()\n(sk_psock_verdict_recv) to run the attached SK_SKB verdict program in softirq.\nIf that program calls a socket-lookup helper (bpf_sk_lookup_tcp/udp,\nbpf_skc_lookup_tcp), bpf_skc_lookup() does:\n\n\tif (skb->dev)\n\t\tcaller_net = dev_net(skb->dev);\n\nskb->dev still holds the dev_scratch value (a non-NULL integer), so dev_net()\ndereferences it as a struct net_device * and the kernel takes a general\nprotection fault on a non-canonical address in softirq:\n\n Oops: general protection fault, probably for non-canonical address 0x1010000800004a0\n CPU: 1 UID: 0 PID: 1406 Comm: syz.2.19 Not tainted 7.1.0-rc6 #1 PREEMPT(full)\n RIP: 0010:bpf_skc_lookup net/core/filter.c:7033 [inline]\n RIP: 0010:bpf_sk_lookup+0x45/0x160 net/core/filter.c:7047\n Call Trace:\n <IRQ>\n bpf_prog_4675cb904b7071f8+0x12e/0x14e\n bpf_prog_run_pin_on_cpu+0xc6/0x1f0\n sk_psock_verdict_recv+0x1ba/0x350\n udp_read_skb+0x31a/0x370\n sk_psock_verdict_data_ready+0x2e3/0x600\n __udp_enqueue_schedule_skb+0x4c8/0x650\n udpv6_queue_rcv_one_skb+0x3ec/0x740\n udp6_unicast_rcv_skb+0x11d/0x140\n ip6_protocol_deliver_rcu+0x61e/0x950\n ip6_input_finish+0xa9/0x150\n NF_HOOK+0x286/0x2f0\n ip6_input+0x117/0x220\n NF_HOOK+0x286/0x2f0\n __netif_receive_skb+0x85/0x200\n process_backlog+0x374/0x9a0\n __napi_poll+0x4f/0x1c0\n net_rx_action+0x3b0/0x770\n handle_softirqs+0x15a/0x460\n do_softirq+0x57/0x80\n </IRQ>\n\nThe rmem charge that dev_scratch accounted for is released by skb_recv_udp() on\ndequeue, just above, so the scratch is dead by the time recv_actor() runs. Clear\nskb->dev so bpf_skc_lookup() falls back to sock_net(skb->sk), which\nskb_set_owner_sk_safe() set just above.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00479, EPSS Percentile is 0.38779 |
altlinux: CVE-2026-53184 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53184 was patched at 2026-07-14
1216.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53199) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf netvsc_copy_to_send_buf() copies page buffer entries into the VMBus send buffer using phys_to_virt() on the entry PFN. Entries for the RNDIS header and the skb linear data come from kmalloc'd memory and are always in the kernel direct map, but entries for skb fragments reference page cache or user pages, which on 32-bit x86 with CONFIG_HIGHMEM=y can live above the LOWMEM boundary. For such a page phys_to_virt() returns an address outside the direct map and the subsequent memcpy() faults on the transmit softirq path, which is fatal. Map the pages with kmap_local_page() instead, handling two properties of the page buffer entries: - pb[i].pfn is a Hyper-V PFN at HV_HYP_PAGE_SIZE (4K) granularity, not a native PFN. Reconstruct the physical address first and derive the native page from it, so the mapping stays correct where PAGE_SIZE > HV_HYP_PAGE_SIZE (e.g. arm64 with 64K pages). - Since commit 41a6328b2c55 ("hv_netvsc: Preserve contiguous PFN grouping in the page buffer array"), an entry describes a full physically contiguous fragment and pb[i].len can exceed PAGE_SIZE, while kmap_local_page() maps a single page. Copy page by page, splitting at native page boundaries. The copy path only handles packets smaller than the send section size (6144 bytes by default); larger packets take the cp_partial path where only the RNDIS header is copied. So entries here are bounded by the section size and a copy is split at most once on 4K-page systems. On !CONFIG_HIGHMEM configs kmap_local_page() folds to page_address() and no mapping work is added.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhv_netvsc: use kmap_local_page in netvsc_copy_to_send_buf\n\nnetvsc_copy_to_send_buf() copies page buffer entries into the VMBus\nsend buffer using phys_to_virt() on the entry PFN. Entries for the\nRNDIS header and the skb linear data come from kmalloc'd memory and\nare always in the kernel direct map, but entries for skb fragments\nreference page cache or user pages, which on 32-bit x86 with\nCONFIG_HIGHMEM=y can live above the LOWMEM boundary. For such a page\nphys_to_virt() returns an address outside the direct map and the\nsubsequent memcpy() faults on the transmit softirq path, which is\nfatal.\n\nMap the pages with kmap_local_page() instead, handling two properties\nof the page buffer entries:\n\n - pb[i].pfn is a Hyper-V PFN at HV_HYP_PAGE_SIZE (4K) granularity,\n not a native PFN. Reconstruct the physical address first and derive\n the native page from it, so the mapping stays correct where\n PAGE_SIZE > HV_HYP_PAGE_SIZE (e.g. arm64 with 64K pages).\n\n - Since commit 41a6328b2c55 ("hv_netvsc: Preserve contiguous PFN\n grouping in the page buffer array"), an entry describes a full\n physically contiguous fragment and pb[i].len can exceed PAGE_SIZE,\n while kmap_local_page() maps a single page. Copy page by page,\n splitting at native page boundaries.\n\nThe copy path only handles packets smaller than the send section size\n(6144 bytes by default); larger packets take the cp_partial path where\nonly the RNDIS header is copied. So entries here are bounded by the\nsection size and a copy is split at most once on 4K-page systems. On\n!CONFIG_HIGHMEM configs kmap_local_page() folds to page_address() and\nno mapping work is added.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00501, EPSS Percentile is 0.40115 |
altlinux: CVE-2026-53199 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53199 was patched at 2026-07-14
1217.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53217) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: mvpp2: sync RX data at the hardware packet offset mvpp2 programs the RX queue packet offset, so hardware writes received data at dma_addr + MVPP2_SKB_HEADROOM. The current CPU sync starts at dma_addr and only covers rx_bytes + MVPP2_MH_SIZE bytes, which syncs the unused headroom and misses the same number of bytes at the packet tail. On non-coherent DMA systems this can leave the CPU reading stale cache contents for the end of the received frame. Use dma_sync_single_range_for_cpu() with MVPP2_SKB_HEADROOM as the range offset so the sync covers the Marvell header and packet data actually written by hardware.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mvpp2: sync RX data at the hardware packet offset\n\nmvpp2 programs the RX queue packet offset, so hardware writes received\ndata at dma_addr + MVPP2_SKB_HEADROOM. The current CPU sync starts at\ndma_addr and only covers rx_bytes + MVPP2_MH_SIZE bytes, which syncs the\nunused headroom and misses the same number of bytes at the packet tail.\n\nOn non-coherent DMA systems this can leave the CPU reading stale cache\ncontents for the end of the received frame.\n\nUse dma_sync_single_range_for_cpu() with MVPP2_SKB_HEADROOM as the range\noffset so the sync covers the Marvell header and packet data actually\nwritten by hardware.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00384, EPSS Percentile is 0.31188 |
altlinux: CVE-2026-53217 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53217 was patched at 2026-07-14
1218.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53229) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure In the XSK branch of mlx5e_xmit_xdp_buff(), when sq->xmit_xdp_frame() returns false (e.g. XDPSQ is full), the function returns without unmapping the DMA address or freeing the xdp_frame allocated by xdp_convert_zc_to_xdp_frame(). The xdpi_fifo push only happens on success, so the completion path cannot recover these entries. With CONFIG_DMA_API_DEBUG=y, the leak surfaces on driver unbind: DMA-API: pci 0000:08:00.0: device driver has pending DMA allocations while released from device [count=1116] One of leaked entries details: [device address=0x000000010ffd7028] [size=1534 bytes] [mapped with DMA_TO_DEVICE] [mapped as phy] WARNING: kernel/dma/debug.c:881 at dma_debug_device_change+0x127/0x180 ... DMA-API: Mapped at: debug_dma_map_phys+0x4b/0xd0 dma_map_phys+0xfd/0x2d0 mlx5e_xdp_handle+0x5ae/0xac0 [mlx5_core] mlx5e_xsk_skb_from_cqe_mpwrq_linear+0xc4/0x170 [mlx5_core] mlx5e_handle_rx_cqe_mpwrq+0xc1/0x290 [mlx5_core] Add the missing unmap + xdp_return_frame, matching the cleanup already done in mlx5e_xdp_xmit(). has_frags is rejected earlier in this branch, so no per-frag unmap is needed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/mlx5e: xsk: Fix DMA and xdp_frame leak on XDP_TX xmit failure\n\nIn the XSK branch of mlx5e_xmit_xdp_buff(), when sq->xmit_xdp_frame()\nreturns false (e.g. XDPSQ is full), the function returns without\nunmapping the DMA address or freeing the xdp_frame allocated by\nxdp_convert_zc_to_xdp_frame(). The xdpi_fifo push only happens on\nsuccess, so the completion path cannot recover these entries.\n\nWith CONFIG_DMA_API_DEBUG=y, the leak surfaces on driver unbind:\n\n DMA-API: pci 0000:08:00.0: device driver has pending DMA\n allocations while released from device [count=1116]\n One of leaked entries details: [device address=0x000000010ffd7028]\n [size=1534 bytes] [mapped with DMA_TO_DEVICE] [mapped as phy]\n WARNING: kernel/dma/debug.c:881 at dma_debug_device_change+0x127/0x180\n ...\n DMA-API: Mapped at:\n debug_dma_map_phys+0x4b/0xd0\n dma_map_phys+0xfd/0x2d0\n mlx5e_xdp_handle+0x5ae/0xac0 [mlx5_core]\n mlx5e_xsk_skb_from_cqe_mpwrq_linear+0xc4/0x170 [mlx5_core]\n mlx5e_handle_rx_cqe_mpwrq+0xc1/0x290 [mlx5_core]\n\nAdd the missing unmap + xdp_return_frame, matching the cleanup already\ndone in mlx5e_xdp_xmit(). has_frags is rejected earlier in this branch,\nso no per-frag unmap is needed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00441, EPSS Percentile is 0.36196 |
altlinux: CVE-2026-53229 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53229 was patched at 2026-07-14
1219.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53235) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: add pskb_may_pull() to skb_gro_receive_list() skb_gro_receive_list() calls skb_pull(skb, skb_gro_offset(skb)) without first ensuring the data is in the linear area via pskb_may_pull(). When the skb arrives via napi_gro_frags(), skb_headlen can be 0 (all data in page fragments) while skb_gro_offset is non-zero (after IP+TCP header parsing). The skb_pull() then decrements skb->len by skb_gro_offset but skb->data_len stays unchanged, hitting BUG_ON(skb->len < skb->data_len) in __skb_pull(). The UDP fraglist GRO path already contains this guard at udp_offload.c:749. Adding it to skb_gro_receive_list() itself provides centralized protection for all callers (TCP, UDP, and any future protocols), and ensures the precondition of skb_pull() is satisfied before it is called. On pskb_may_pull() failure, set NAPI_GRO_CB(skb)->flush = 1 so the skb is not held as a new GRO head and is instead delivered through the normal receive path, matching the UDP handling.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: add pskb_may_pull() to skb_gro_receive_list()\n\nskb_gro_receive_list() calls skb_pull(skb, skb_gro_offset(skb)) without\nfirst ensuring the data is in the linear area via pskb_may_pull(). When\nthe skb arrives via napi_gro_frags(), skb_headlen can be 0 (all data in\npage fragments) while skb_gro_offset is non-zero (after IP+TCP header\nparsing). The skb_pull() then decrements skb->len by skb_gro_offset\nbut skb->data_len stays unchanged, hitting BUG_ON(skb->len < skb->data_len)\nin __skb_pull().\n\nThe UDP fraglist GRO path already contains this guard at\nudp_offload.c:749. Adding it to skb_gro_receive_list() itself provides\ncentralized protection for all callers (TCP, UDP, and any future\nprotocols), and ensures the precondition of skb_pull() is satisfied\nbefore it is called.\n\nOn pskb_may_pull() failure, set NAPI_GRO_CB(skb)->flush = 1 so the\nskb is not held as a new GRO head and is instead delivered through the\nnormal receive path, matching the UDP handling.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00441, EPSS Percentile is 0.36196 |
altlinux: CVE-2026-53235 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53235 was patched at 2026-07-14
1220.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53363) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags() iptfs_consume_frags() transfers paged fragments from one socket buffer to another but fails to propagate the SKBFL_SHARED_FRAG flag. This is the same class of bug that was fixed in skb_try_coalesce() for CVE-2026-46300: when fragments backed by read-only page-cache pages are merged, the marker indicating their shared nature must be preserved so that ESP can decide correctly whether in-place encryption is safe. Apply the same two-line fix used in skb_try_coalesce() to iptfs_consume_frags().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()\n\niptfs_consume_frags() transfers paged fragments from one socket buffer\nto another but fails to propagate the SKBFL_SHARED_FRAG flag. This is\nthe same class of bug that was fixed in skb_try_coalesce() for\nCVE-2026-46300: when fragments backed by read-only page-cache pages are\nmerged, the marker indicating their shared nature must be preserved so\nthat ESP can decide correctly whether in-place encryption is safe.\n\nApply the same two-line fix used in skb_try_coalesce() to\niptfs_consume_frags().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.21811 |
altlinux: CVE-2026-53363 was patched at 2026-06-19, 2026-06-22, 2026-07-06
1221.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53394) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: avoid leaking pre-allocated openowner on unconfirmed retry race When find_or_alloc_open_stateowner() encounters an unconfirmed owner, it calls release_openowner() and sets oo = NULL. Control then falls through past the `if (oo)` guard -- which would have freed any pre-allocated `new` -- and unconditionally executes `new = alloc_stateowner(...)`. If `new` was already allocated on a prior iteration, the pointer is silently overwritten and the previous allocation (slab object + owner name buffer) is leaked. This requires a race: two NFSv4.0 OPEN threads with the same owner string, where a concurrent thread inserts a new unconfirmed owner into the hash between retry iterations. The window is narrow but repeatable under adversarial conditions. Fix by adding `goto retry` after `oo = NULL` so the already-allocated `new` is reused on the next iteration rather than overwritten.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: avoid leaking pre-allocated openowner on unconfirmed retry race\n\nWhen find_or_alloc_open_stateowner() encounters an unconfirmed owner, it\ncalls release_openowner() and sets oo = NULL. Control then falls through\npast the `if (oo)` guard -- which would have freed any pre-allocated\n`new` -- and unconditionally executes `new = alloc_stateowner(...)`. If\n`new` was already allocated on a prior iteration, the pointer is\nsilently overwritten and the previous allocation (slab object + owner\nname buffer) is leaked.\n\nThis requires a race: two NFSv4.0 OPEN threads with the same owner\nstring, where a concurrent thread inserts a new unconfirmed owner into\nthe hash between retry iterations. The window is narrow but repeatable\nunder adversarial conditions.\n\nFix by adding `goto retry` after `oo = NULL` so the already-allocated\n`new` is reused on the next iteration rather than overwritten.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00446, EPSS Percentile is 0.36632 |
debian: CVE-2026-53394 was patched at 2026-07-14
1222.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53397) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: fix posix_acl leak on SETACL decode failure nfsaclsvc_decode_setaclargs() and nfs3svc_decode_setaclargs() each call nfs_stream_decode_acl() twice, first for NFS_ACL and then for NFS_DFACL. Each successful call transfers ownership of a freshly allocated posix_acl into argp->acl_access or argp->acl_default. If the first call succeeds but the second fails, the decoder returns false and argp->acl_access is left dangling. ACLPROC2_SETACL.pc_release was wired to nfssvc_release_attrstat and ACLPROC3_SETACL.pc_release was wired to nfs3svc_release_fhandle. Both only call fh_put() and have no knowledge of the ACL fields on argp. The posix_acl_release() pairs sat at the out: labels inside nfsacld_proc_setacl() and nfsd3_proc_setacl(), but svc_process() skips pc_func when pc_decode returns false, so that cleanup is unreachable on decode failure: svc_process_common() pc_decode() /* decode_setaclargs: false */ /* pc_func skipped */ pc_release() /* fh_put only -- ACLs leaked */ The orphaned posix_acl is leaked for the lifetime of the server. Fix by adding nfsaclsvc_release_setacl() and nfs3svc_release_setacl(), which release both argp->acl_access and argp->acl_default in addition to fh_put(), and wiring them as pc_release for their respective SETACL procedures. pc_release runs on every path svc_process() takes after decode, including decode failure, so the posix_acl_release() pairs are removed from the proc functions' out: labels to keep ownership in one place. This matches the existing release_getacl() pattern used by the sibling GETACL procedures.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: fix posix_acl leak on SETACL decode failure\n\nnfsaclsvc_decode_setaclargs() and nfs3svc_decode_setaclargs() each\ncall nfs_stream_decode_acl() twice, first for NFS_ACL and then for\nNFS_DFACL. Each successful call transfers ownership of a freshly\nallocated posix_acl into argp->acl_access or argp->acl_default. If\nthe first call succeeds but the second fails, the decoder returns\nfalse and argp->acl_access is left dangling.\n\nACLPROC2_SETACL.pc_release was wired to nfssvc_release_attrstat and\nACLPROC3_SETACL.pc_release was wired to nfs3svc_release_fhandle.\nBoth only call fh_put() and have no knowledge of the ACL fields on\nargp. The posix_acl_release() pairs sat at the out: labels inside\nnfsacld_proc_setacl() and nfsd3_proc_setacl(), but svc_process()\nskips pc_func when pc_decode returns false, so that cleanup is\nunreachable on decode failure:\n\n svc_process_common()\n pc_decode() /* decode_setaclargs: false */\n /* pc_func skipped */\n pc_release() /* fh_put only -- ACLs leaked */\n\nThe orphaned posix_acl is leaked for the lifetime of the server.\n\nFix by adding nfsaclsvc_release_setacl() and nfs3svc_release_setacl(),\nwhich release both argp->acl_access and argp->acl_default in addition\nto fh_put(), and wiring them as pc_release for their respective SETACL\nprocedures. pc_release runs on every path svc_process() takes after\ndecode, including decode failure, so the posix_acl_release() pairs are\nremoved from the proc functions' out: labels to keep ownership in one\nplace. This matches the existing release_getacl() pattern used by\nthe sibling GETACL procedures.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00529, EPSS Percentile is 0.41747 |
debian: CVE-2026-53397 was patched at 2026-07-14, 2026-07-30
1223.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63830) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: skmsg: preserve sg.copy across SG transforms The sk_msg sg.copy bitmap is part of the scatterlist entry ownership state. A set bit tells sk_msg_compute_data_pointers() not to expose the entry through writable BPF ctx->data. This protects entries backed by pages that are not private to the sk_msg, such as splice-backed file page-cache pages. Several sk_msg transform paths move, copy, split, or compact msg->sg.data[] entries without moving the matching sg.copy bit. This can make an externally backed entry arrive at a new slot with a clear copy bit. A later SK_MSG verdict can then expose sg_virt(sge) as writable ctx->data and BPF stores can modify the original page cache. Keep sg.copy synchronized with sg.data[] whenever entries are transferred, shifted, split, or copied into a new sk_msg. Clear the bit when an entry is replaced by a newly allocated private page or freed. This covers the BPF pull/push/pop helpers, sk_msg_shift_left/right(), sk_msg_xfer(), and tls_split_open_record(), including the partial tail entry created during TLS open-record splitting.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: skmsg: preserve sg.copy across SG transforms\n\nThe sk_msg sg.copy bitmap is part of the scatterlist entry ownership\nstate. A set bit tells sk_msg_compute_data_pointers() not to expose the\nentry through writable BPF ctx->data. This protects entries backed by\npages that are not private to the sk_msg, such as splice-backed file\npage-cache pages.\n\nSeveral sk_msg transform paths move, copy, split, or compact\nmsg->sg.data[] entries without moving the matching sg.copy bit. This can\nmake an externally backed entry arrive at a new slot with a clear copy\nbit. A later SK_MSG verdict can then expose sg_virt(sge) as writable\nctx->data and BPF stores can modify the original page cache.\n\nKeep sg.copy synchronized with sg.data[] whenever entries are\ntransferred, shifted, split, or copied into a new sk_msg. Clear the bit\nwhen an entry is replaced by a newly allocated private page or freed.\nThis covers the BPF pull/push/pop helpers, sk_msg_shift_left/right(),\nsk_msg_xfer(), and tls_split_open_record(), including the partial tail\nentry created during TLS open-record splitting.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.4. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00352, EPSS Percentile is 0.27935 |
debian: CVE-2026-63830 was patched at 2026-07-14, 2026-07-30
1224.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63975) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp If dcid is received for an already-assigned destination CID the spec requires that both channels to be discarded, but calling l2cap_chan_del may invalidate the tmp cursor created by list_for_each_entry_safe and in fact it is the wrong procedure as the chan->dcid may be assigned previously it really needs to be disconnected. Calling l2cap_chan_clone directly may still lead to l2cap_chan_del so instead schedule l2cap_chan_timeout with delay 0 to close the channel asynchronously.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: Fix possible crash on l2cap_ecred_conn_rsp\n\nIf dcid is received for an already-assigned destination CID the spec\nrequires that both channels to be discarded, but calling l2cap_chan_del\nmay invalidate the tmp cursor created by list_for_each_entry_safe and\nin fact it is the wrong procedure as the chan->dcid may be assigned\npreviously it really needs to be disconnected.\n\nCalling l2cap_chan_clone directly may still lead to l2cap_chan_del so\ninstead schedule l2cap_chan_timeout with delay 0 to close the channel\nasynchronously.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.27123 |
debian: CVE-2026-63975 was patched at 2026-07-14
ubuntu: CVE-2026-63975 was patched at 2026-07-30
1225.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63980) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/handshake: Use spin_lock_bh for hn_lock nvmet_tcp_state_change(), a socket callback that runs in BH context, can reach handshake_req_cancel() via nvmet_tcp_schedule_release_queue() and tls_handshake_cancel(). handshake_req_cancel() acquires hn->hn_lock with plain spin_lock(). If a process-context thread on the same CPU holds hn->hn_lock when a softirq invokes the cancel path, the lock attempt deadlocks. This is the only caller that invokes tls_handshake_cancel() from BH context; every other consumer calls it from process context. Deferring the cancel to process context in the NVMe target is not straightforward: nvmet_tcp_schedule_release_queue() must call tls_handshake_cancel() atomically with its state transition to DISCONNECTING. If the cancel were deferred, the handshake completion callback could fire in the window before the cancel runs, observe the unexpected state, and return without dropping its kref on the queue. Reworking that interlock is considerably more invasive than hardening the handshake lock. Convert all hn->hn_lock acquisitions from spin_lock/spin_unlock to spin_lock_bh/spin_unlock_bh so the lock is never taken with softirqs enabled.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/handshake: Use spin_lock_bh for hn_lock\n\nnvmet_tcp_state_change(), a socket callback that runs in BH context,\ncan reach handshake_req_cancel() via nvmet_tcp_schedule_release_queue()\nand tls_handshake_cancel(). handshake_req_cancel() acquires\nhn->hn_lock with plain spin_lock(). If a process-context thread on\nthe same CPU holds hn->hn_lock when a softirq invokes the cancel path,\nthe lock attempt deadlocks. This is the only caller that invokes\ntls_handshake_cancel() from BH context; every other consumer calls it\nfrom process context.\n\nDeferring the cancel to process context in the NVMe target is not\nstraightforward: nvmet_tcp_schedule_release_queue() must call\ntls_handshake_cancel() atomically with its state transition to\nDISCONNECTING. If the cancel were deferred, the handshake completion\ncallback could fire in the window before the cancel runs, observe the\nunexpected state, and return without dropping its kref on the queue.\nReworking that interlock is considerably more invasive than hardening\nthe handshake lock. Convert all hn->hn_lock acquisitions from\nspin_lock/spin_unlock to spin_lock_bh/spin_unlock_bh so the lock is\nnever taken with softirqs enabled.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00441, EPSS Percentile is 0.36198 |
debian: CVE-2026-63980 was patched at 2026-07-14
ubuntu: CVE-2026-63980 was patched at 2026-07-30
1226.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64003) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: scsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues While a SCSI host is in a recovery state, scsi_mq_requeue_cmd() will not set the requeue list for a requeued command to be kicked in the future. The expectation is a call to scsi_run_host_queues() will kick all SCSI devices once the recovery state is cleared. However, scsi_run_host_queues() uses shost_for_each_device() which uses scsi_device_get() and so will ignore devices in a partially removed state like SDEV_CANCEL. But these devices may also have requeued requests, leaving their requests stuck from not being kicked and causing the removal process of the device to hang. scsi_run_host_queues() needs to run against more devices than the macro shost_for_each_device() allows. Instead of using the too limiting scsi_device_get() state checks, only ignore devices in SDEV_DEL state or when unable to acquire a reference. Attempt to run the queues for all other devices when scsi_run_host_queues() is called.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: core: Run queues for all non-SDEV_DEL devices from scsi_run_host_queues\n\nWhile a SCSI host is in a recovery state, scsi_mq_requeue_cmd() will not\nset the requeue list for a requeued command to be kicked in the future.\nThe expectation is a call to scsi_run_host_queues() will kick all SCSI\ndevices once the recovery state is cleared.\n\nHowever, scsi_run_host_queues() uses shost_for_each_device() which uses\nscsi_device_get() and so will ignore devices in a partially removed\nstate like SDEV_CANCEL. But these devices may also have requeued\nrequests, leaving their requests stuck from not being kicked and causing\nthe removal process of the device to hang.\n\nscsi_run_host_queues() needs to run against more devices than the macro\nshost_for_each_device() allows. Instead of using the too limiting\nscsi_device_get() state checks, only ignore devices in SDEV_DEL state or\nwhen unable to acquire a reference. Attempt to run the queues for all\nother devices when scsi_run_host_queues() is called.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00441, EPSS Percentile is 0.36197 |
debian: CVE-2026-64003 was patched at 2026-07-14
ubuntu: CVE-2026-64003 was patched at 2026-07-30
1227.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64024) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction Blamed commit moved the TIME_WAIT-derived ISN from the skb control block to a per-CPU variable, assuming the value would always be consumed by tcp_conn_request() for the same packet that wrote it. That assumption is violated by multiple drop paths between the producer (__this_cpu_write(tcp_tw_isn, isn) in tcp_v{4,6}_rcv()) and the consumer (tcp_conn_request()): - min_ttl / min_hopcount check - xfrm policy check - tcp_inbound_hash() MD5/AO mismatch - tcp_filter() eBPF/SO_ATTACH_FILTER drop - th->syn && th->fin discard in tcp_rcv_state_process() TCP_LISTEN - psp_sk_rx_policy_check() in tcp_v{4,6}_do_rcv() - tcp_checksum_complete() in tcp_v{4,6}_do_rcv() - tcp_v{4,6}_cookie_check() returning NULL When a packet is dropped on any of these paths, tcp_tw_isn is left set. The next SYN processed on the same CPU then consumes the non zero value in tcp_conn_request(), receiving a potentially predictable ISN. This patch moves back tcp_tw_isn to skb->cb[], getting rid of the per-cpu variable. Note that tcp_v{4,6}_fill_cb() do not set it. Very litle impact on overall code size/complexity: $ scripts/bloat-o-meter -t vmlinux.old vmlinux.new add/remove: 0/0 grow/shrink: 2/1 up/down: 8/-15 (-7) Function old new delta tcp_v6_rcv 3038 3042 +4 tcp_v4_rcv 3035 3039 +4 tcp_conn_request 2938 2923 -15 Total: Before=24436060, After=24436053, chg -0.00%', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: fix stale per-CPU tcp_tw_isn leak enabling ISN prediction\n\nBlamed commit moved the TIME_WAIT-derived ISN from the skb control\nblock to a per-CPU variable, assuming the value would always be consumed\nby tcp_conn_request() for the same packet that wrote it. That assumption\nis violated by multiple drop paths between the producer\n(__this_cpu_write(tcp_tw_isn, isn) in tcp_v{4,6}_rcv()) and the consumer\n(tcp_conn_request()):\n\n - min_ttl / min_hopcount check\n - xfrm policy check\n - tcp_inbound_hash() MD5/AO mismatch\n - tcp_filter() eBPF/SO_ATTACH_FILTER drop\n - th->syn && th->fin discard in tcp_rcv_state_process() TCP_LISTEN\n - psp_sk_rx_policy_check() in tcp_v{4,6}_do_rcv()\n - tcp_checksum_complete() in tcp_v{4,6}_do_rcv()\n - tcp_v{4,6}_cookie_check() returning NULL\n\nWhen a packet is dropped on any of these paths, tcp_tw_isn is left set.\n\nThe next SYN processed on the same CPU then consumes the non zero value in\ntcp_conn_request(), receiving a potentially predictable ISN.\n\nThis patch moves back tcp_tw_isn to skb->cb[], getting rid of the per-cpu\nvariable.\n\nNote that tcp_v{4,6}_fill_cb() do not set it.\n\nVery litle impact on overall code size/complexity:\n\n$ scripts/bloat-o-meter -t vmlinux.old vmlinux.new\nadd/remove: 0/0 grow/shrink: 2/1 up/down: 8/-15 (-7)\nFunction old new delta\ntcp_v6_rcv 3038 3042 +4\ntcp_v4_rcv 3035 3039 +4\ntcp_conn_request 2938 2923 -15\nTotal: Before=24436060, After=24436053, chg -0.00%', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.4. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00385, EPSS Percentile is 0.31305 |
debian: CVE-2026-64024 was patched at 2026-07-14
ubuntu: CVE-2026-64024 was patched at 2026-07-30
1228.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64048) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot On the SMC-D client, slot 0 of ini->ism_dev[]/ini->ism_chid[] is reserved for an SMC-Dv1 device. smc_find_ism_v2_device_clnt() populates V2 entries starting at index 1, so when no V1 device is selected slot 0 is left in its kzalloc()'ed state with ism_dev[0] == NULL and ism_chid[0] == 0. smc_v2_determine_accepted_chid() then matches the peer's CHID against the array starting from index 0 using the CHID alone. A malicious peer replying to a SMC-Dv2-only proposal with d1.chid == 0 matches the empty slot, ini->ism_selected becomes 0, and the subsequent ism_dev[0]->lgr_lock dereference in smc_conn_create() faults at offsetof(struct smcd_dev, lgr_lock) == 0x68: BUG: KASAN: null-ptr-deref in _raw_spin_lock_bh+0x79/0xe0 Write of size 4 at addr 0000000000000068 by task exploit/144 Call Trace: _raw_spin_lock_bh smc_conn_create (net/smc/smc_core.c:1997) __smc_connect (net/smc/af_smc.c:1447) smc_connect (net/smc/af_smc.c:1720) __sys_connect __x64_sys_connect do_syscall_64 Require ism_dev[i] to be non-NULL before accepting a CHID match.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: reject CHID-0 ACCEPT that matches an empty ism_dev slot\n\nOn the SMC-D client, slot 0 of ini->ism_dev[]/ini->ism_chid[] is\nreserved for an SMC-Dv1 device. smc_find_ism_v2_device_clnt()\npopulates V2 entries starting at index 1, so when no V1 device is\nselected slot 0 is left in its kzalloc()'ed state with ism_dev[0] ==\nNULL and ism_chid[0] == 0.\n\nsmc_v2_determine_accepted_chid() then matches the peer's CHID against\nthe array starting from index 0 using the CHID alone. A malicious\npeer replying to a SMC-Dv2-only proposal with d1.chid == 0 matches\nthe empty slot, ini->ism_selected becomes 0, and the subsequent\nism_dev[0]->lgr_lock dereference in smc_conn_create() faults at\noffsetof(struct smcd_dev, lgr_lock) == 0x68:\n\n BUG: KASAN: null-ptr-deref in _raw_spin_lock_bh+0x79/0xe0\n Write of size 4 at addr 0000000000000068 by task exploit/144\n Call Trace:\n _raw_spin_lock_bh\n smc_conn_create (net/smc/smc_core.c:1997)\n __smc_connect (net/smc/af_smc.c:1447)\n smc_connect (net/smc/af_smc.c:1720)\n __sys_connect\n __x64_sys_connect\n do_syscall_64\n\nRequire ism_dev[i] to be non-NULL before accepting a CHID match.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00479, EPSS Percentile is 0.38779 |
debian: CVE-2026-64048 was patched at 2026-07-14
ubuntu: CVE-2026-64048 was patched at 2026-07-30
1229.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64093) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: directly shut down timer on cleanup batadv_tp_sender_cleanup() was calling timer_delete_sync() followed by timer_delete() to guard against the timer handler re-arming itself between the two calls. This double-deletion hack relied on the sending status being set to 0 to suppress re-arming. Replace both calls with a single timer_shutdown_sync(). This function both waits for any running timer callback to complete (like timer_delete_sync()) and permanently disarms the timer so it cannot be re-armed afterwards, making re-arming prevention unconditional and self-documenting. The re-arming property is also required because otherwise: 1. context 0 (batadv_tp_recv_ack()) checks in batadv_tp_reset_sender_timer() if sending is still 1 -> it is 2. context 1 changes in batadv_tp_sender_shutdown() sending to 0 and in this process forces the kthread to stop timer in batadv_tp_sender_cleanup() 3. context 0 continues in batadv_tp_reset_sender_timer() and rearms the timer -> but the reference for it is already gone', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tp_meter: directly shut down timer on cleanup\n\nbatadv_tp_sender_cleanup() was calling timer_delete_sync() followed by\ntimer_delete() to guard against the timer handler re-arming itself between\nthe two calls. This double-deletion hack relied on the sending status being\nset to 0 to suppress re-arming.\n\nReplace both calls with a single timer_shutdown_sync(). This function both\nwaits for any running timer callback to complete (like timer_delete_sync())\nand permanently disarms the timer so it cannot be re-armed afterwards,\nmaking re-arming prevention unconditional and self-documenting.\n\nThe re-arming property is also required because otherwise:\n\n1. context 0 (batadv_tp_recv_ack()) checks in\n batadv_tp_reset_sender_timer() if sending is still 1 -> it is\n2. context 1 changes in batadv_tp_sender_shutdown() sending to 0 and in\n this process forces the kthread to stop timer in\n batadv_tp_sender_cleanup()\n3. context 0 continues in batadv_tp_reset_sender_timer() and rearms the\n timer -> but the reference for it is already gone', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00337, EPSS Percentile is 0.26273 |
debian: CVE-2026-64093 was patched at 2026-07-14
ubuntu: CVE-2026-64093 was patched at 2026-07-30
1230.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64138) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate SID in parent security descriptor during ACL inheritance Introduce smb_validate_ntsd_sid() helper to safely validate Owner SID and Group SID inside the NT Security Descriptor (smb_ntsd) retrieved from the parent directory.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nksmbd: validate SID in parent security descriptor during ACL inheritance\n\nIntroduce smb_validate_ntsd_sid() helper to safely validate Owner SID\nand Group SID inside the NT Security Descriptor (smb_ntsd) retrieved\nfrom the parent directory.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00415, EPSS Percentile is 0.34143 |
debian: CVE-2026-64138 was patched at 2026-07-14
ubuntu: CVE-2026-64138 was patched at 2026-07-30
1231.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64148) - Medium [292]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: pds_core: fix error handling in pdsc_devcmd_wait Fix two cases where pdsc_devcmd_wait() returns stale success from the completion register instead of an error: 1. FW crash: If firmware stops running, the wait loop breaks early with running=false. The condition "if ((!done || timeout) && running)" is false, so error handling is bypassed and stale status is returned. Check !running first and return -ENXIO. 2. Timeout: If a command times out, err is set to -ETIMEDOUT but then overwritten by pdsc_err_to_errno(status) which reads stale status. Return -ETIMEDOUT immediately after cleaning up. Both errors now propagate to pdsc_devcmd_locked() which queues health_work for recovery.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\npds_core: fix error handling in pdsc_devcmd_wait\n\nFix two cases where pdsc_devcmd_wait() returns stale success from\nthe completion register instead of an error:\n\n1. FW crash: If firmware stops running, the wait loop breaks early with\n running=false. The condition "if ((!done || timeout) && running)" is\n false, so error handling is bypassed and stale status is returned.\n Check !running first and return -ENXIO.\n\n2. Timeout: If a command times out, err is set to -ETIMEDOUT but then\n overwritten by pdsc_err_to_errno(status) which reads stale status.\n Return -ETIMEDOUT immediately after cleaning up.\n\nBoth errors now propagate to pdsc_devcmd_locked() which queues\nhealth_work for recovery.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00475, EPSS Percentile is 0.38532 |
debian: CVE-2026-64148 was patched at 2026-07-14
ubuntu: CVE-2026-64148 was patched at 2026-07-30
1232.
Denial of Service - 389 Directory Server (CVE-2026-14940) - Medium [291]
Description: A heap-buffer-overflow flaw was found in 389 Directory Server (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | 389 Directory Server is a highly usable, fully featured, reliable and secure LDAP server implementation | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00294, EPSS Percentile is 0.21681 |
debian: CVE-2026-14940 was patched at 2026-07-14
1233.
Denial of Service - Pypdf (CVE-2026-59938) - Medium [291]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22662 |
debian: CVE-2026-59938 was patched at 2026-07-14
1234.
Denial of Service - TLS (CVE-2026-12932) - Medium [291]
Description: A memory leak in the
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | TLS | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-12932 was patched at 2026-07-03, 2026-07-14
ubuntu: CVE-2026-12932 was patched at 2026-07-30
1235.
Denial of Service - Xrdp (CVE-2026-55238) - Medium [291]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | xrdp is an open source remote desktop protocol server | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00305, EPSS Percentile is 0.22882 |
altlinux: CVE-2026-55238 was patched at 2026-07-08
debian: CVE-2026-55238 was patched at 2026-07-14
1236.
Denial of Service - openvpn (CVE-2026-13122) - Medium [291]
Description: OpenVPN version 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote attackers to cause a denial of service via a malformed authentication token that triggers a reachable assertion when external-auth is enabled
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:openvpn:openvpn (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00294, EPSS Percentile is 0.2166 |
debian: CVE-2026-13122 was patched at 2026-07-03, 2026-07-14
ubuntu: CVE-2026-13122 was patched at 2026-07-30
1237.
Incorrect Calculation - Gawk (CVE-2026-40468) - Medium [291]
Description: Integer overflow vulnerability has been found in "builtin.c" program file of gawk. This issue may lead to memory exhaustion on the hosting operating system and could be used to overwrite gawk heap metadata and objects with attacker-controlled bytes. It affects gawk in versions 5.4.0 and below.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:fossies:gawk (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00201, EPSS Percentile is 0.10205 |
debian: CVE-2026-40468 was patched at 2026-07-14
ubuntu: CVE-2026-40468 was patched at 2026-07-30
1238.
Incorrect Calculation - nats-server (CVE-2026-58207) - Medium [291]
Description: NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client able to send account-scoped connection monitoring requests could crash the server by supplying Connz pagination Offset and Limit values that overflowed internal arithmetic before the response window was safely bounded. This issue is fixed in versions 2.14.3 and 2.12.12.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:linuxfoundation:nats-server (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00397, EPSS Percentile is 0.32491 |
altlinux: CVE-2026-58207 was patched at 2026-07-10, 2026-07-13, 2026-07-14
debian: CVE-2026-58207 was patched at 2026-07-14
1239.
Memory Corruption - DCMTK (CVE-2026-12805) - Medium [291]
Description: A flaw has been found in OFFIS
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | DCMTK (DICOM Toolkit) is an open-source collection of libraries and applications implementing large parts of the DICOM standard, including image processing, storage, and network services for medical imaging. | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00468, EPSS Percentile is 0.38043 |
debian: CVE-2026-12805 was patched at 2026-06-24
1240.
Memory Corruption - X Server (CVE-2026-55999) - Medium [291]
Description: Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a heap
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:x.org:x_server (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00269, EPSS Percentile is 0.18935 |
almalinux: CVE-2026-55999 was patched at 2026-07-13
altlinux: CVE-2026-55999 was patched at 2026-07-08, 2026-07-14
debian: CVE-2026-55999 was patched at 2026-07-14
oraclelinux: CVE-2026-55999 was patched at 2026-07-13
redhat: CVE-2026-55999 was patched at 2026-07-13
1241.
Memory Corruption - dos (CVE-2026-48142) - Medium [291]
Description: NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_charset_module module. When content is served or proxied through a location block with both source_charset utf-8; and a charset directive (for example, charset koi8-r;) configured, remote, unauthenticated attackers can send requests (in conjunction with conditions beyond their control) to cause a heap buffer over-read in the NGINX worker process, leading to limited disclosure of memory or a restart. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:f5:dos (does NOT exist in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.00684, EPSS Percentile is 0.48973 |
altlinux: CVE-2026-48142 was patched at 2026-06-23, 2026-06-25, 2026-06-26
debian: CVE-2026-48142 was patched at 2026-06-24, 2026-06-30
redos: CVE-2026-48142 was patched at 2026-07-14
ubuntu: CVE-2026-48142 was patched at 2026-07-30
1242.
Memory Corruption - nsd (CVE-2026-12245) - Medium [291]
Description: NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT connection, and closing the connection without reading the response.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:nlnetlabs:nsd (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00319, EPSS Percentile is 0.24371 |
altlinux: CVE-2026-12245 was patched at 2026-06-26, 2026-06-29
ubuntu: CVE-2026-12245 was patched at 2026-07-30
1243.
Path Traversal - Cacti (CVE-2026-39899) - Medium [291]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00283, EPSS Percentile is 0.20568 |
altlinux: CVE-2026-39899 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-39899 was patched at 2026-07-14
1244.
Security Feature Bypass - wolfssl (CVE-2026-6412) - Medium [291]
Description: Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate processing.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.5 | 14 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00074, EPSS Percentile is 0.00087 |
debian: CVE-2026-6412 was patched at 2026-07-14
debian: CVE-2026-64121 was patched at 2026-07-14
debian: CVE-2026-64123 was patched at 2026-07-14
debian: CVE-2026-64125 was patched at 2026-07-14
debian: CVE-2026-64126 was patched at 2026-07-14
debian: CVE-2026-64127 was patched at 2026-07-14
debian: CVE-2026-64128 was patched at 2026-07-14
ubuntu: CVE-2026-64121 was patched at 2026-07-30
ubuntu: CVE-2026-64123 was patched at 2026-07-30
ubuntu: CVE-2026-64125 was patched at 2026-07-30
ubuntu: CVE-2026-64126 was patched at 2026-07-30
ubuntu: CVE-2026-64127 was patched at 2026-07-30
ubuntu: CVE-2026-64128 was patched at 2026-07-30
1245.
Cross Site Scripting - Gogs (CVE-2026-26276) - Medium [289]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.08245 |
altlinux: CVE-2026-26276 was patched at 2026-06-25
1246.
Memory Corruption - Open Asset Import Library Assimp (CVE-2026-14604) - Medium [289]
Description: A vulnerability was determined in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | Open Asset Import Library is a library that loads various 3D file formats into a shared, in-memory format | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00233, EPSS Percentile is 0.14372 |
debian: CVE-2026-14604 was patched at 2026-07-14
1247.
Memory Corruption - QEMU (CVE-2026-9539) - Medium [289]
Description: An out-of-bounds heap read and integer underflow in the TCP urgent data handling (sosendoob) in freedesktop.org libslirp version before v4.9.2 on hypervisor host environments (e.g.,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | QEMU is a generic and open source machine & userspace emulator and virtualizer | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00106, EPSS Percentile is 0.01274 |
debian: CVE-2026-9539 was patched at 2026-07-14
ubuntu: CVE-2026-9539 was patched at 2026-07-30
1248.
Path Traversal - Babel (CVE-2026-49356) - Medium [289]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.7 | 14 | Babel is a free and open-source JavaScript transcompiler that is mainly used to convert ECMAScript 2015+ code into backwards-compatible JavaScript code that can be run by older JavaScript engines | |
| 0.4 | 10 | CVSS Base Score is 3.6. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.0267 |
debian: CVE-2026-49356 was patched at 2026-07-14
1249.
Information Disclosure - Keras (CVE-2026-12480) - Medium [286]
Description: Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides in the `H5IOStore._verify_dataset()` and `file_editor.py` methods, which fail to check the `dataset.is_virtual` property of HDF5 datasets. This allows an attacker to craft a malicious `.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.4 | 14 | High-level neural networks API, running on top of TensorFlow, allowing model building and training | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.0278 |
debian: CVE-2026-12480 was patched at 2026-07-14
1250.
Server-Side Request Forgery - Unknown Product (CVE-2026-50151) - Medium [286]
Description: {'nvd_cve_data_all': 'oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, registry/remote/repository.go in blobStore.completePushAfterInitialPost follows a registry-controlled Location header during monolithic blob upload and reuses the Authorization header from the initial POST request for the subsequent PUT request, allowing a malicious registry to return a cross-host Location and receive the caller's credentials at an attacker-controlled endpoint. This issue is fixed in version 2.6.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00364, EPSS Percentile is 0.29164 |
debian: CVE-2026-50151 was patched at 2026-07-14
1251.
Server-Side Request Forgery - Unknown Product (CVE-2026-53727) - Medium [286]
Description: {'nvd_cve_data_all': 'css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb, and therefore load_uri! and the @import-following branch of add_block!, issued HTTP and HTTPS requests against any host, port, and URI without a scheme allowlist, host or IP filtering, or protection against link-local, loopback, or RFC-1918 addresses. Location: redirects were followed recursively back into the same function, which also serviced file:// URIs, so a single attacker-controlled HTTP redirect could upgrade the bug from SSRF to arbitrary local file disclosure. Any consumer of css_parser that hands it attacker-influenced CSS together with a base_uri: option is exposed. This issue is fixed in version 3.0.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'css_parser is a Ruby CSS parser. From 2.2.0 until 3.0.0, CssParser::Parser#read_remote_file in lib/css_parser/parser.rb, and therefore load_uri! and the @import-following branch of add_block!, issued HTTP and HTTPS requests against any host, port, and URI without a scheme allowlist, host or IP filtering, or protection against link-local, loopback, or RFC-1918 addresses. Location: redirects were followed recursively back into the same function, which also serviced file:// URIs, so a single attacker-controlled HTTP redirect could upgrade the bug from SSRF to arbitrary local file disclosure. Any consumer of css_parser that hands it attacker-influenced CSS together with a base_uri: option is exposed. This issue is fixed in version 3.0.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.9. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00302, EPSS Percentile is 0.2256 |
debian: CVE-2026-53727 was patched at 2026-07-14
1252.
Remote Code Execution - Unknown Product (CVE-2026-12505) - Medium [285]
Description: {'nvd_cve_data_all': 'A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the cifs-utils package where the cifs.upcall helper fails to securely drop its root privileges before looking up user information inside a user-controlled environment. A local, low privileged attacker can exploit this by using a crafted request_key payload to trick the root-owned helper into entering a custom environment (namespace) containing a malicious NSS module. This forces the system to load the attacker's controlled NSS Module and configuration, allowing them to execute arbitrary commands as the root user, elevating their privileges and fully compromising the system.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.0531 |
almalinux: CVE-2026-12505 was patched at 2026-07-15
altlinux: CVE-2026-12505 was patched at 2026-07-29
debian: CVE-2026-12505 was patched at 2026-06-24
oraclelinux: CVE-2026-12505 was patched at 2026-07-15, 2026-07-21
redhat: CVE-2026-12505 was patched at 2026-07-15
ubuntu: CVE-2026-12505 was patched at 2026-07-30
1253.
Security Feature Bypass - Wasmtime (CVE-2026-58494) - Medium [285]
Description: Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0.3, and 46.0.1,
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.25 | 14 | Standalone WebAssembly runtime written in Rust | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02111 |
debian: CVE-2026-58494 was patched at 2026-07-14
1254.
Denial of Service - ImageMagick (CVE-2026-55595) - Medium [284]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0009, EPSS Percentile is 0.00565 |
altlinux: CVE-2026-55595 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-55595 was patched at 2026-07-07, 2026-07-14
1255.
Denial of Service - ImageMagick (CVE-2026-61860) - Medium [284]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00222, EPSS Percentile is 0.12859 |
debian: CVE-2026-61860 was patched at 2026-07-14
1256.
Denial of Service - ImageMagick (CVE-2026-61868) - Medium [284]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00222, EPSS Percentile is 0.12859 |
debian: CVE-2026-61868 was patched at 2026-07-14
1257.
Denial of Service - ImageMagick (CVE-2026-61871) - Medium [284]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00232, EPSS Percentile is 0.14152 |
debian: CVE-2026-61871 was patched at 2026-07-14
1258.
Incorrect Calculation - ImageMagick (CVE-2026-53466) - Medium [284]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12712 |
altlinux: CVE-2026-53466 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-53466 was patched at 2026-07-07, 2026-07-14
1259.
Memory Corruption - Perl (CVE-2026-13593) - Medium [284]
Description: CSS::Minifier::XS versions before 0.14 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00229, EPSS Percentile is 0.13879 |
debian: CVE-2026-13593 was patched at 2026-07-14
1260.
Memory Corruption - Perl (CVE-2026-57076) - Medium [284]
Description: YAML::Syck versions before 1.47 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02575 |
debian: CVE-2026-57076 was patched at 2026-07-14
1261.
Memory Corruption - Perl (CVE-2026-57077) - Medium [284]
Description: YAML::Syck versions before 1.47 for
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00141, EPSS Percentile is 0.03924 |
debian: CVE-2026-57077 was patched at 2026-07-14
1262.
Information Disclosure - ImageMagick (CVE-2026-61862) - Medium [283]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.3 | 10 | CVSS Base Score is 2.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00105, EPSS Percentile is 0.01237 |
debian: CVE-2026-61862 was patched at 2026-07-14
1263.
Code Injection - Unknown Product (CVE-2026-13500) - Medium [280]
Description: {'nvd_cve_data_all': 'A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the component Grammar Action Block Handler. Executing a manipulation can lead to code injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the component Grammar Action Block Handler. Executing a manipulation can lead to code injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Code Injection | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00311, EPSS Percentile is 0.23509 |
debian: CVE-2026-13500 was patched at 2026-07-14
1264.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53180) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: timers/migration: Fix livelock in tmigr_handle_remote_up() tmigr_handle_remote_cpu() skips timer_expire_remote() when cpu == smp_processor_id(), assuming the local softirq path already handled this CPU's timers. This assumption is wrong because jiffies can advance after the handling of the CPU's global timers in run_timer_base(BASE_GLOBAL) and before tmigr_handle_remote() evaluates the expiry times. As a consequence a timer which expires after the CPU local timer wheel advanced and becomes expired in the remote handling is ignored and the callback is never invoked and removed from the timer wheel. What's worse is that fetch_next_timer_interrupt_remote() keeps reporting it as expired, and the event is re-queued with expires == now on each iteration. The goto-again loop spins indefinitely. Fix this by calling timer_expire_remote() unconditionally. That's minimal overhead for the common case as __run_timer_base() returns immediately if there is nothing to expire in the local wheel. [ tglx: Amend change log and add a comment ]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntimers/migration: Fix livelock in tmigr_handle_remote_up()\n\ntmigr_handle_remote_cpu() skips timer_expire_remote() when cpu ==\nsmp_processor_id(), assuming the local softirq path already handled this\nCPU's timers.\n\nThis assumption is wrong because jiffies can advance after the handling of\nthe CPU's global timers in run_timer_base(BASE_GLOBAL) and before\ntmigr_handle_remote() evaluates the expiry times.\n\nAs a consequence a timer which expires after the CPU local timer wheel\nadvanced and becomes expired in the remote handling is ignored and the\ncallback is never invoked and removed from the timer wheel.\n\nWhat's worse is that fetch_next_timer_interrupt_remote() keeps reporting it\nas expired, and the event is re-queued with expires == now on each\niteration. The goto-again loop spins indefinitely.\n\nFix this by calling timer_expire_remote() unconditionally. That's minimal\noverhead for the common case as __run_timer_base() returns immediately if\nthere is nothing to expire in the local wheel.\n\n[ tglx: Amend change log and add a comment ]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0034, EPSS Percentile is 0.26648 |
altlinux: CVE-2026-53180 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53180 was patched at 2026-07-14
1265.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53232) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: phy: clean the sfp upstream if phy probing fails Sashiko reported that we don't call sfp_bus_del_upstream() in the probe failure path, so let's add it, otherwise the sfp-bus is left with a dangling 'upstream' field, that may be used later on during SFP events. This issue existed before the generic phylib sfp support, back when drivers were calling phy_sfp_probe themselves.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: clean the sfp upstream if phy probing fails\n\nSashiko reported that we don't call sfp_bus_del_upstream() in the probe\nfailure path, so let's add it, otherwise the sfp-bus is left with a\ndangling 'upstream' field, that may be used later on during SFP events.\n\nThis issue existed before the generic phylib sfp support, back when\ndrivers were calling phy_sfp_probe themselves.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.16913 |
debian: CVE-2026-53232 was patched at 2026-07-14
1266.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53244) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: VFS: fix possible failure to unlock in nfsd4_create_file() atomic_create() in fs/namei.c drops the reference to the dentry when it returns an error. This behaviour was imported into dentry_create() so that it will drop the reference if an error is returned from atomic_create(), though not if vfs_create() returns an error (in the case where ->atomic_create is not supported). The caller - nfsd4_create_file() - is made aware of this by checking path->dentry, which will either be a counted reference to a dentry, or an error pointer. However the change to use start_creating()/end_creating() (which landed shortly before the dentry_create() change landed, though was likely developed around the same time) means that nfsd4_create_file() *needs* a valid dentry so that it can unlock the parent. The net result is that if NFSD exports a filesystem which uses ->atomic_create, and if a call to ->atomic_create returns an error, then nfsd4_create_file() will pass an error pointer to end_creating() and the parent will not be unlocked. Fix this by changing dentry_create() to make sure path->dentry is always a valid dentry, never an error-pointer. The actual error is already returned a different way. Note that if ->atomic_create() returns a different dentry (which may not be possible in practice) we are guaranteed (because it is only ever provided by d_spliace_alias()) that it will have the same d_parent and so it will have the same effect when passed to end_creating().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nVFS: fix possible failure to unlock in nfsd4_create_file()\n\natomic_create() in fs/namei.c drops the reference to the dentry\nwhen it returns an error.\nThis behaviour was imported into dentry_create() so that it\nwill drop the reference if an error is returned from atomic_create(),\nthough not if vfs_create() returns an error (in the case where\n->atomic_create is not supported).\n\nThe caller - nfsd4_create_file() - is made aware of this by checking\npath->dentry, which will either be a counted reference to a dentry, or\nan error pointer.\n\nHowever the change to use start_creating()/end_creating() (which landed\nshortly before the dentry_create() change landed, though was likely\ndeveloped around the same time) means that nfsd4_create_file() *needs* a\nvalid dentry so that it can unlock the parent.\n\nThe net result is that if NFSD exports a filesystem which uses\n->atomic_create, and if a call to ->atomic_create returns an error, then\nnfsd4_create_file() will pass an error pointer to end_creating()\nand the parent will not be unlocked.\n\nFix this by changing dentry_create() to make sure path->dentry is always\na valid dentry, never an error-pointer. The actual error is already\nreturned a different way.\n\nNote that if ->atomic_create() returns a different dentry (which may not\nbe possible in practice) we are guaranteed (because it is only ever\nprovided by d_spliace_alias()) that it will have the same d_parent and\nso it will have the same effect when passed to end_creating().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00344, EPSS Percentile is 0.27012 |
altlinux: CVE-2026-53244 was patched at 2026-06-19
1267.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63893) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject u32 wrap in tb_property_entry_valid() entry->value is u32 and entry->length is u16; the sum is performed in u32 and wraps. A malicious XDomain peer can pick value = 0xffffff00, length = 0x100 so the sum 0x100000000 wraps to 0 and passes the > block_len check. tb_property_parse() then passes entry->value to parse_dwdata() as a dword offset into the property block, reading attacker-directed memory far past the allocation. For TEXT-typed entries with the "deviceid" or "vendorid" keys this lands in xd->device_name / xd->vendor_name and is readable back via the per-XDomain device_name / vendor_name sysfs attributes; the leak is NUL-bounded (kstrdup() stops at the first zero byte) and untargeted (the attacker picks a delta, not an absolute address). DATA-typed entries are parsed into property->value.data but not generically surfaced to userspace. Use check_add_overflow() so a wrapped sum is rejected.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: property: Reject u32 wrap in tb_property_entry_valid()\n\nentry->value is u32 and entry->length is u16; the sum is performed in\nu32 and wraps. A malicious XDomain peer can pick\nvalue = 0xffffff00, length = 0x100 so the sum 0x100000000 wraps to 0\nand passes the > block_len check. tb_property_parse() then passes\nentry->value to parse_dwdata() as a dword offset into the property\nblock, reading attacker-directed memory far past the allocation.\n\nFor TEXT-typed entries with the "deviceid" or "vendorid" keys this\nlands in xd->device_name / xd->vendor_name and is readable back via\nthe per-XDomain device_name / vendor_name sysfs attributes; the leak\nis NUL-bounded (kstrdup() stops at the first zero byte) and\nuntargeted (the attacker picks a delta, not an absolute address).\nDATA-typed entries are parsed into property->value.data but not\ngenerically surfaced to userspace.\n\nUse check_add_overflow() so a wrapped sum is rejected.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0036, EPSS Percentile is 0.28695 |
debian: CVE-2026-63893 was patched at 2026-07-14
ubuntu: CVE-2026-63893 was patched at 2026-07-30
1268.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63925) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: macsec: fix replay protection at XPN lower-PN wrap In macsec_post_decrypt(), when pn is U32_MAX, pn + 1 overflows u32 to 0 and the first branch never fires. If next_pn_halves.lower is also in the upper half, pn_same_half(pn, lower) is true and the XPN else-if does not fire either, leaving next_pn_halves unchanged. An attacker that captures the legitimate frame carrying pn == 0xFFFFFFFF on an XPN association can then replay it indefinitely, since lowest_pn never rises above the captured pn and macsec_decrypt() reconstructs the same IV. Extend the XPN else-if to also fire when pn + 1 wraps to 0, so receipt of pn == U32_MAX advances next_pn_halves to (upper + 1, 0).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmacsec: fix replay protection at XPN lower-PN wrap\n\nIn macsec_post_decrypt(), when pn is U32_MAX, pn + 1 overflows u32 to 0\nand the first branch never fires. If next_pn_halves.lower is also in the\nupper half, pn_same_half(pn, lower) is true and the XPN else-if does not\nfire either, leaving next_pn_halves unchanged. An attacker that captures\nthe legitimate frame carrying pn == 0xFFFFFFFF on an XPN association\ncan then replay it indefinitely, since lowest_pn never rises above\nthe captured pn and macsec_decrypt() reconstructs the same IV.\n\nExtend the XPN else-if to also fire when pn + 1 wraps to 0, so receipt\nof pn == U32_MAX advances next_pn_halves to (upper + 1, 0).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00341, EPSS Percentile is 0.2669 |
debian: CVE-2026-63925 was patched at 2026-07-14
ubuntu: CVE-2026-63925 was patched at 2026-07-30
1269.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63974) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close Since hci_dev_close_sync() can now be called during the reset path, we should also set HCI_CMD_DRAIN_WORKQUEUE. This avoids queuing timeouts while the hdev workqueue is being drained.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: hci_sync: Set HCI_CMD_DRAIN_WORKQUEUE during device close\n\nSince hci_dev_close_sync() can now be called during the reset path, we\nshould also set HCI_CMD_DRAIN_WORKQUEUE. This avoids queuing timeouts\nwhile the hdev workqueue is being drained.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00317, EPSS Percentile is 0.24164 |
debian: CVE-2026-63974 was patched at 2026-07-14
ubuntu: CVE-2026-63974 was patched at 2026-07-30
1270.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64088) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative tt_buff_len batadv_orig_node::tt_buff_len was declared as s16, but the field is never intended to hold a negative value. When a value greater than 32767 is assigned, it wraps to a negative signed integer. In batadv_send_other_tt_response(), tt_buff_len is temporarily widened to s32. The incorrectly negative s16 value propagates into the s32, causing batadv_tt_prepare_tvlv_global_data() to allocate a full sized buffer but populates only a small portion of it with the collected changeset. All remaining bits are kept uninitialized. Using an u16 avoids this type confusion and ensures that no (negative) sign extension is performed in batadv_send_other_tt_response().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tt: fix negative tt_buff_len\n\nbatadv_orig_node::tt_buff_len was declared as s16, but the field is never\nintended to hold a negative value. When a value greater than 32767 is\nassigned, it wraps to a negative signed integer.\n\nIn batadv_send_other_tt_response(), tt_buff_len is temporarily widened to\ns32. The incorrectly negative s16 value propagates into the s32, causing\nbatadv_tt_prepare_tvlv_global_data() to allocate a full sized buffer but\npopulates only a small portion of it with the collected changeset. All\nremaining bits are kept uninitialized.\n\nUsing an u16 avoids this type confusion and ensures that no (negative) sign\nextension is performed in batadv_send_other_tt_response().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00281, EPSS Percentile is 0.20418 |
debian: CVE-2026-64088 was patched at 2026-07-14
ubuntu: CVE-2026-64088 was patched at 2026-07-30
1271.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64178) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: Fix UAF read of dev->name bnep_add_connection() needs to keep holding the bnep_session_sem while reading dev->name (just like bnep_get_connlist() does); otherwise the bnep_session() thread can concurrently free the net_device, which can for example be triggered by a concurrent bnep_del_connection(). (This UAF is fairly uninteresting from a security perspective; calling bnep_add_connection() requires passing a capable(CAP_NET_ADMIN) check. It also requires completely tearing down a netdev during a fairly tight race window.)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: bnep: Fix UAF read of dev->name\n\nbnep_add_connection() needs to keep holding the bnep_session_sem while\nreading dev->name (just like bnep_get_connlist() does); otherwise the\nbnep_session() thread can concurrently free the net_device, which can for\nexample be triggered by a concurrent bnep_del_connection().\n\n(This UAF is fairly uninteresting from a security perspective;\ncalling bnep_add_connection() requires passing a capable(CAP_NET_ADMIN)\ncheck. It also requires completely tearing down a netdev during a fairly\ntight race window.)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00249, EPSS Percentile is 0.16367 |
debian: CVE-2026-64178 was patched at 2026-07-14
ubuntu: CVE-2026-64178 was patched at 2026-07-30
1272.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64206) - Medium [280]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock l2cap_conn_del() takes conn->lock and then calls cancel_work_sync() for pending_rx_work. process_pending_rx() takes the same mutex, so teardown can deadlock against the worker it is flushing. This issue was found by our static analysis tool and then manually reviewed against the current tree. The grounded PoC kept the l2cap_conn_ready() -> queue_work(..., &conn->pending_rx_work) submit path, the l2cap_conn_del() -> cancel_work_sync(&conn->pending_rx_work) teardown path, and the process_pending_rx() -> mutex_lock(&conn->lock) worker edge. Lockdep WARNING: possible circular locking dependency detected process_pending_rx+0x21/0x2a [vuln_msv] l2cap_conn_del.constprop.0+0x3f/0x4e [vuln_msv] *** DEADLOCK *** Cancel pending_rx_work before taking conn->lock, matching the existing lock-before-drain ordering used for the two delayed works in the same teardown path. The pending_rx queue is still purged after the work has been cancelled and conn->lock has been acquired.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: cancel pending_rx_work before taking conn->lock\n\nl2cap_conn_del() takes conn->lock and then calls cancel_work_sync() for\npending_rx_work. process_pending_rx() takes the same mutex, so teardown\ncan deadlock against the worker it is flushing.\n\nThis issue was found by our static analysis tool and then manually\nreviewed against the current tree.\n\nThe grounded PoC kept the l2cap_conn_ready() -> queue_work(...,\n&conn->pending_rx_work) submit path, the l2cap_conn_del() ->\ncancel_work_sync(&conn->pending_rx_work) teardown path, and the\nprocess_pending_rx() -> mutex_lock(&conn->lock) worker edge. Lockdep\n\n WARNING: possible circular locking dependency detected\n process_pending_rx+0x21/0x2a [vuln_msv]\n l2cap_conn_del.constprop.0+0x3f/0x4e [vuln_msv]\n *** DEADLOCK ***\n\nCancel pending_rx_work before taking conn->lock, matching the existing\nlock-before-drain ordering used for the two delayed works in the same\nteardown path. The pending_rx queue is still purged after the work has\nbeen cancelled and conn->lock has been acquired.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00262, EPSS Percentile is 0.1795 |
debian: CVE-2026-64206 was patched at 2026-07-14
1273.
Denial of Service - Libheif (CVE-2026-47714) - Medium [279]
Description: libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, the inline mask parsing code in `libheif/region.cc` contains an integer overflow. Both `width` and `height` are `unsigned int` (32-bit) values parsed from the HEIF file. Their product can exceed `UINT32_MAX`, wrapping to a small value before the division by 8. This causes an undersized buffer allocation, leading to
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:struktur:libheif (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00107, EPSS Percentile is 0.01315 |
debian: CVE-2026-47714 was patched at 2026-07-14
ubuntu: CVE-2026-47714 was patched at 2026-07-30
1274.
Denial of Service - Patch (CVE-2026-56288) - Medium [279]
Description: GNU patch is vulnerable to a NULL pointer dereference when processing a specially crafted unified-diff patch file. Improper handling of consecutive end-of-file newline markers can corrupt internal hunk (single block of changes in diff) data structures, causing the application to pass a NULL pointer to fwrite() during patch processing. An attacker can trigger this condition with a malicious patch file, causing the utility
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:gnu:patch (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00115, EPSS Percentile is 0.01804 |
debian: CVE-2026-56288 was patched at 2026-07-14
1275.
Denial of Service - Patch (CVE-2026-56289) - Medium [279]
Description: GNU patch is vulnerable to a denial of service (DoS) due to improper validation of hunk (single block of changes in diff) line offsets in unified-diff input. A specially crafted patch can specify an extremely large line number, causing the application to enter an effectively infinite processing loop while attempting to locate the requested position. This results in excessive CPU consumption and prevents the process from completing. An attacker can trigger this behavior by supplying a malicious patch file, causing the utility to become unresponsive and require manual termination. This issue has been fixed in the commit faba04ef4f2b410257f76c1b9dc85e350929c4b9
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:gnu:patch (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00115, EPSS Percentile is 0.01804 |
debian: CVE-2026-56289 was patched at 2026-07-14
1276.
Denial of Service - Pypdf (CVE-2026-49461) - Medium [279]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02265 |
debian: CVE-2026-49461 was patched at 2026-06-24
redos: CVE-2026-49461 was patched at 2026-07-29
1277.
Denial of Service - Pypdf (CVE-2026-54530) - Medium [279]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02266 |
debian: CVE-2026-54530 was patched at 2026-06-24
redos: CVE-2026-54530 was patched at 2026-07-29
1278.
Denial of Service - Pypdf (CVE-2026-54531) - Medium [279]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02266 |
debian: CVE-2026-54531 was patched at 2026-06-24
redos: CVE-2026-54531 was patched at 2026-07-29
1279.
Denial of Service - Pypdf (CVE-2026-54651) - Medium [279]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0011, EPSS Percentile is 0.01493 |
debian: CVE-2026-54651 was patched at 2026-06-24
1280.
Denial of Service - TLS (CVE-2026-12996) - Medium [279]
Description: A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | TLS | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-12996 was patched at 2026-07-03, 2026-07-14
ubuntu: CVE-2026-12996 was patched at 2026-07-30
1281.
Denial of Service - Thunderbird (CVE-2026-57962) - Medium [279]
Description: A malicious LDAP server, which a Thunderbird user is configured to query for address-book autocomplete, can stash arbitrarily large amounts of attacker-supplied data into the Thunderbird LDAP client until it crashes due to memory exhaustion. This vulnerability was fixed in Thunderbird 152.0.1 and Thunderbird 140.12.1.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:mozilla:thunderbird (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12627 |
altlinux: CVE-2026-57962 was patched at 2026-07-02
debian: CVE-2026-57962 was patched at 2026-07-14
1282.
Incorrect Calculation - ProFTPD (CVE-2026-63091) - Medium [279]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | ProFTPD is a highly configurable and modular open-source FTP server designed for Unix-like systems, offering advanced features such as virtual hosting, authentication modules, and flexible configuration similar to Apache. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.21775 |
debian: CVE-2026-63091 was patched at 2026-07-14
1283.
Memory Corruption - Gawk (CVE-2026-40467) - Medium [279]
Description: Use After Free vulnerability has been found in "io.c" program file of gawk (do_getline_redir() routine). This issue may lead to a crash. It affects gawk in versions 5.4.0 and below.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:fossies:gawk (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00213, EPSS Percentile is 0.11803 |
debian: CVE-2026-40467 was patched at 2026-07-14
ubuntu: CVE-2026-40467 was patched at 2026-07-30
1284.
Memory Corruption - X Server (CVE-2026-56000) - Medium [279]
Description: Local attackers with a X connection able to provide GLX commit to the X server xorg-server before 21.2.24 and xwayland before 24.1.13 could cause a Heap Use After Free, due to CommonMakeCurrent() pointing into potentially reallocated memory.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:x.org:x_server (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00222, EPSS Percentile is 0.12882 |
altlinux: CVE-2026-56000 was patched at 2026-07-08, 2026-07-14
debian: CVE-2026-56000 was patched at 2026-07-14
redhat: CVE-2026-56000 was patched at 2026-07-13
1285.
Memory Corruption - perl (CVE-2026-57432) - Medium [279]
Description: Perl versions through 5.43.10 have an integer overflow in S_measure_struct leading to an out-of-bounds heap read in pack and unpack. S_measure_struct adds each item's size times its repeat count to a running total with no overflow check, so a large repeat count in a pack or unpack template wraps the signed SSize_t total negative. The @, X, and x position codes then guard their moves with a signed length comparison that passes when the length is negative, advancing the buffer pointer out of bounds. A template derived from untrusted input can read heap memory past the buffer and return it to the caller.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:perl:perl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11461 |
debian: CVE-2026-57432 was patched at 2026-07-14
1286.
Memory Corruption - wolfssl (CVE-2026-6325) - Medium [279]
Description: Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversized signature algorithms list, allowing a write past the bounds of the destination buffer.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07285 |
debian: CVE-2026-6325 was patched at 2026-07-14
1287.
Path Traversal - Unknown Product (CVE-2026-11940) - Medium [279]
Description: {'nvd_cve_data_all': 'tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a deeper name than the hardlink itself. The extraction fallback validated the symlink at it's archived location but recreated it at the hardlink's shallower path, letting a relative target the filter judged contained escape the destination directory. This allowed a malicious tar archive to create a symlink pointing outside the destination, enabling out-of-destination file reads or writes. This was an incomplete fix of CVE-2025-4330.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'tarfile.extractall() with the 'data' or 'tar'\n filter could be bypassed by a crafted archive where a hardlink \nreferences a symlink stored at a deeper name than the hardlink itself.\xa0 \nThe extraction fallback validated the symlink at it's archived location \nbut recreated it at the hardlink's shallower\npath, letting a relative\n target the filter judged contained escape the destination directory.\xa0 \nThis allowed a malicious tar archive to create a symlink pointing \noutside the destination, enabling out-of-destination file reads or \nwrites. This was an incomplete fix of CVE-2025-4330.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to Vulners data source | |
| 0.5 | 10 | EPSS Probability is 0.00633, EPSS Percentile is 0.46814 |
debian: CVE-2026-11940 was patched at 2026-06-24
1288.
Path Traversal - grafana (CVE-2026-10601) - Medium [279]
Description: A user with Viewer permissions can use specially crafted requests to the Tempo and Loki data source plugins to reach unintended backend endpoints. Depending on the backend configuration this can expose data source credentials, leak internal responses, or trigger administrative actions on the configured backend.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:grafana:grafana (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00258, EPSS Percentile is 0.17499 |
redos: CVE-2026-10601 was patched at 2026-07-14
1289.
Security Feature Bypass - Unknown Product (CVE-2026-54423) - Medium [279]
Description: {'nvd_cve_data_all': 'In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In OpenStack Ironic before 37.0.1, an Ironic user with the ability to deploy nodes using the IPMI management interface can maliciously use the send_raw step to send arbitrary IPMI commands to a node, bypassing Ironic's access control.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00302, EPSS Percentile is 0.2259 |
debian: CVE-2026-54423 was patched at 2026-07-14
1290.
Spoofing - Chromium (CVE-2026-14153) - Medium [276]
Description: Inappropriate implementation in Glic in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00181, EPSS Percentile is 0.07953 |
altlinux: CVE-2026-14153 was patched at 2026-07-03
debian: CVE-2026-14153 was patched at 2026-07-05, 2026-07-14
1291.
Denial of Service - Erlang/OTP (CVE-2026-54886) - Medium [275]
Description: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to render an SFTP channel permanently unresponsive. The handle_data/4 function in ssh_sftpd contains a catch-all clause that accepts channel data of any type. When channel data with a non-zero type code (SSH_MSG_CHANNEL_EXTENDED_DATA) arrives with an empty pending buffer and a payload at or below the SFTP packet size limit, the clause tail-calls itself with identical arguments, creating an infinite loop. The SFTP protocol operates exclusively on normal channel data (type 0). Extended data (non-zero type) is meaningless for SFTP and is never sent by conforming clients. However, the SSH protocol permits any channel participant to send extended data on an open channel, so an authenticated SFTP client can trigger the loop by sending SSH_MSG_CHANNEL_EXTENDED_DATA with any data_type_code and any non-empty payload at or below the size limit. The targeted ssh_sftpd process enters an infinite tail-recursive loop. It never processes another message, its message queue grows without bound, and it can only be stopped by killing the process. BEAM's reduction-based scheduler preemption continues to function, so other processes on the node are not starved, but each stuck channel process consumes its full CPU time share continuously and accumulates unbounded message queue memory. Opening many channels amplifies the CPU and memory impact.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | Erlang/OTP is a set of libraries for the Erlang programming language | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00331, EPSS Percentile is 0.25635 |
debian: CVE-2026-54886 was patched at 2026-07-14
1292.
Denial of Service - Erlang/OTP (CVE-2026-54887) - Medium [275]
Description: Use of Default Cryptographic Key vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | Erlang/OTP is a set of libraries for the Erlang programming language | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00243, EPSS Percentile is 0.15652 |
debian: CVE-2026-54887 was patched at 2026-07-14
1293.
Security Feature Bypass - Erlang/OTP (CVE-2026-54891) - Medium [275]
Description: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0.4 | 14 | Erlang/OTP is a set of libraries for the Erlang programming language | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00135, EPSS Percentile is 0.03423 |
debian: CVE-2026-54891 was patched at 2026-07-14
1294.
Cross Site Scripting - Unknown Product (CVE-2026-11998) - Medium [273]
Description: {'nvd_cve_data_all': 'A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session. SCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '<iframe>' documents, route templates, etc. A flaw in the logic that tries to match entire URLs against regular expression matchers can result in partial matches for certain types of regular expressions, effectively bypassing the policies and allowing the use of unsafe values as resource URLs. This issue affects AngularJS versions greater than or equal to 1.2.0-rc.3. Note: The AngularJS project was already End-of-Life when this CVE was published and will not receive any updates to address this issue. For more information see the End-of-Life announcement https://docs.angularjs.org/misc/version-support-status .', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows bypassing certain SCE policies for resource URLs and can lead to arbitrary JavaScript execution within the context of the victim's browser session.\n\n\nSCE's purpose is to ensure that only trusted or safe values are used in certain security-sensitive contexts, such as resource URLs, including URLs that define executable JavaScript scripts, '<iframe>' documents, route templates, etc. A flaw in the logic that tries to match entire URLs against regular expression matchers can result in partial matches for certain types of regular expressions, effectively bypassing the policies and allowing the use of unsafe values as resource URLs.\n\n\nThis issue affects AngularJS versions greater than or equal to 1.2.0-rc.3.\n\n\nNote:\nThe AngularJS project was already End-of-Life when this CVE was published and will not receive any updates to address this issue. For more information see the\xa0 End-of-Life announcement https://docs.angularjs.org/misc/version-support-status .', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00333, EPSS Percentile is 0.25899 |
debian: CVE-2026-11998 was patched at 2026-07-14
1295.
Remote Code Execution - Unknown Product (CVE-2026-46606) - Medium [273]
Description: {'nvd_cve_data_all': 'Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances KVM/QEMU monitoring engine (glances/plugins/vms/engines/virsh.py) passes VM domain names, read directly from virsh list --all output, into f-string command templates that are processed by secure_popen(). secure_popen() is explicitly designed to interpret &&, |, and > as shell operators. Because domain names are never sanitised before interpolation, any user with the ability to create or rename a KVM/QEMU virtual machine can execute arbitrary commands as the OS user running Glances — commonly root on hypervisor hosts. This vulnerability is fixed in 4.5.5.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances KVM/QEMU monitoring engine (glances/plugins/vms/engines/virsh.py) passes VM domain names, read directly from virsh list --all output, into f-string command templates that are processed by secure_popen(). secure_popen() is explicitly designed to interpret &&, |, and > as shell operators. Because domain names are never sanitised before interpolation, any user with the ability to create or rename a KVM/QEMU virtual machine can execute arbitrary commands as the OS user running Glances — commonly root on hypervisor hosts. This vulnerability is fixed in 4.5.5.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.04015 |
debian: CVE-2026-46606 was patched at 2026-07-14
1296.
Remote Code Execution - Unknown Product (CVE-2026-46607) - Medium [273]
Description: {'nvd_cve_data_all': 'Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDG_CACHE_HOME/glances/glances-version.db). No integrity check, signature verification, or format validation is performed before deserialization. An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default). This vulnerability is fixed in 4.5.5.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDG_CACHE_HOME/glances/glances-version.db). No integrity check, signature verification, or format validation is performed before deserialization. An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default). This vulnerability is fixed in 4.5.5.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02995 |
debian: CVE-2026-46607 was patched at 2026-07-14
1297.
Memory Corruption - ImageMagick (CVE-2026-55577) - Medium [272]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.13462 |
altlinux: CVE-2026-55577 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-55577 was patched at 2026-07-07, 2026-07-14
1298.
Unknown Vulnerability Type - Apache Tomcat (CVE-2026-53434) - Medium [271]
Description: {'nvd_cve_data_all': 'Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00525, EPSS Percentile is 0.41526 |
altlinux: CVE-2026-53434 was patched at 2026-06-24, 2026-07-10, 2026-07-20
debian: CVE-2026-53434 was patched at 2026-07-14
1299.
Unknown Vulnerability Type - Apache Tomcat (CVE-2026-55276) - Medium [271]
Description: {'nvd_cve_data_all': 'Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100.\xa0Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00543, EPSS Percentile is 0.42525 |
altlinux: CVE-2026-55276 was patched at 2026-06-24, 2026-07-10, 2026-07-20
debian: CVE-2026-55276 was patched at 2026-07-14
ubuntu: CVE-2026-55276 was patched at 2026-07-30
1300.
Unknown Vulnerability Type - Apache Tomcat (CVE-2026-59084) - Medium [271]
Description: {'nvd_cve_data_all': 'Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.\xa0Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.24, 10.1.57 or 9.0.120 which fix the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00506, EPSS Percentile is 0.40445 |
altlinux: CVE-2026-59084 was patched at 2026-07-13, 2026-07-17, 2026-07-20
debian: CVE-2026-59084 was patched at 2026-07-14
1301.
Incorrect Calculation - Chromium (CVE-2026-15108) - Medium [270]
Description: Integer overflow in Extensions API in Google Chrome prior to 150.0.7871.115 allowed an attacker who convinced a user to install a malicious extension to perform an out of bounds memory read via a crafted Chrome Extension. (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.0258 |
altlinux: CVE-2026-15108 was patched at 2026-07-09
debian: CVE-2026-15108 was patched at 2026-07-11, 2026-07-14
1302.
Unknown Vulnerability Type - Apache Log4j (CVE-2026-49844) - Medium [269]
Description: {'nvd_cve_data_all': 'Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0. The fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document. The defect is reachable only when both of the following conditions hold: * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}). * The application logs a MapMessage that contains an attacker-controlled floating-point value. An attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing. Users are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Improper encoding of non-finite floating-point values during MapMessage JSON serialization in Apache Log4j API produces output that is not valid JSON. This issue affects Apache Log4j API versions 2.13.1 through 2.25.4 and version 2.26.0.\n\nThe fix for CVE-2026-34481 did not cover all code paths: when a MapMessage contains a non-finite IEEE 754 value (NaN, Infinity, or -Infinity), MapMessage.asJson() emits the corresponding bare token. RFC 8259 does not permit these tokens, so a conformant parser rejects the resulting document.\n\nThe defect is reachable only when both of the following conditions hold:\n\n * The application uses the message resolver https://logging.apache.org/log4j/2.x/manual/json-template-layout.html#event-template-resolver-message of JsonTemplateLayout or any other layout that relies on MapMessage.asJson() or MapMessage.getFormattedMessage(new String[]{"JSON"}).\n * The application logs a MapMessage that contains an attacker-controlled floating-point value.\n\n\nAn attacker who can supply a non-finite value can cause the affected layout to emit malformed JSON, which may corrupt the enclosing log record or disrupt downstream log ingestion and parsing.\n\nUsers are advised to upgrade to Apache Log4j API 2.25.5 or 2.26.1, both of which emit RFC 8259-compliant JSON for non-finite values.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | Apache Log4j is a Java-based logging utility | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00574, EPSS Percentile is 0.44098 |
debian: CVE-2026-49844 was patched at 2026-07-14
1303.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63832) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: mt76: add wcid publish check in mt76_sta_add Since mt7925_mac_sta_add publishes wcid, add publish check in mt76_sta_add to avoid reinitializing the wcid->poll_list. Found dev->sta_poll_list corruption when using mt7925 and 7.1-rc4. According to the corruption information, prev->next was changed to itself. wlan0: disconnect from AP 90:fb:5d:94:8b:e3 for new auth to 90:fb:5d:94:8b:e2 wlan0: authenticate with 90:fb:5d:94:8b:e2 (local address=84:9e:56:9c:7e:6b) wlan0: send auth to 90:fb:5d:94:8b:e2 (try 1/3) slab kmalloc-8k start ffff8c80958a6000 pointer offset 4160 size 8192 list_add corruption. prev->next should be next (ffff8c808a7488f8), but was ffff8c80958a7040. (prev=ffff8c80958a7040). mt76_wcid_add_poll+0x95/0xd0 [mt76] mt7925_mac_add_txs.part.0+0xa5/0xe0 [mt7925_common] mt7925_rx_check+0xa7/0xc0 [mt7925_common] mt76_dma_rx_poll+0x50d/0x790 [mt76] mt792x_poll_rx+0x52/0xe0 [mt792x_lib]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mt76: add wcid publish check in mt76_sta_add\n\nSince mt7925_mac_sta_add publishes wcid, add publish check in mt76_sta_add\nto avoid reinitializing the wcid->poll_list.\n\nFound dev->sta_poll_list corruption when using mt7925 and 7.1-rc4.\nAccording to the corruption information, prev->next was changed to itself.\n\nwlan0: disconnect from AP 90:fb:5d:94:8b:e3 for new auth to 90:fb:5d:94:8b:e2\nwlan0: authenticate with 90:fb:5d:94:8b:e2 (local address=84:9e:56:9c:7e:6b)\nwlan0: send auth to 90:fb:5d:94:8b:e2 (try 1/3)\n slab kmalloc-8k start ffff8c80958a6000 pointer offset 4160 size 8192\nlist_add corruption. prev->next should be next (ffff8c808a7488f8), but was ffff8c80958a7040. (prev=ffff8c80958a7040).\n\n mt76_wcid_add_poll+0x95/0xd0 [mt76]\n mt7925_mac_add_txs.part.0+0xa5/0xe0 [mt7925_common]\n mt7925_rx_check+0xa7/0xc0 [mt7925_common]\n mt76_dma_rx_poll+0x50d/0x790 [mt76]\n mt792x_poll_rx+0x52/0xe0 [mt792x_lib]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00223, EPSS Percentile is 0.13082 |
debian: CVE-2026-63832 was patched at 2026-07-14
1304.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63867) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mptcp: close TOCTOU race while computing rcv_wnd The MPTCP output path access locklessly the MPTCP-level ack_seq in multiple times, using possibly different values for the data_ack in the DSS option and to compute the announced rcv wnd for the same packet. Refactor the cote to avoid inconsistencies which may confuse the peer. Also ensure that the MPTCP level rcv wnd is updated only when the egress packet actually contains a DSS ack.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmptcp: close TOCTOU race while computing rcv_wnd\n\nThe MPTCP output path access locklessly the MPTCP-level ack_seq\nin multiple times, using possibly different values for the data_ack\nin the DSS option and to compute the announced rcv wnd for the same\npacket.\n\nRefactor the cote to avoid inconsistencies which may confuse the\npeer. Also ensure that the MPTCP level rcv wnd is updated only when\nthe egress packet actually contains a DSS ack.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00321, EPSS Percentile is 0.24605 |
debian: CVE-2026-63867 was patched at 2026-07-14
1305.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63872) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: esp: fix page frag reference leak on skb_to_sgvec failure In esp_output_tail(), when esp->inplace is false, the old skb page frags are replaced with a new page from the xfrm page_frag cache. The source scatterlist (sg) is built from the old frags before the replacement, and esp_ssg_unref() is responsible for releasing the old page references after the crypto operation completes. However, if the second skb_to_sgvec() call (which builds the destination scatterlist from the new page) fails, the code jumps to error_free which only calls kfree(tmp). The old page frag references captured in the source scatterlist are never released: 1. sg[] is built from old frags via skb_to_sgvec() (no extra get_page) 2. nr_frags is set to 1 and frag[0] is replaced with the new page 3. Second skb_to_sgvec() fails -> goto error_free 4. kfree(tmp) frees the sg[] memory but old frags are not unref'd 5. kfree_skb() only releases frag[0] (the new page), not the old ones Fix this by adding a bool parameter to esp_ssg_unref() that, when true, unconditionally unrefs the source scatterlist frags without checking req->src and req->dst, since those fields are not yet initialized by aead_request_set_crypt() at the point of the error. Existing callers pass false to preserve the original behavior. The same issue exists in both esp4 and esp6 as the code is identical.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nesp: fix page frag reference leak on skb_to_sgvec failure\n\nIn esp_output_tail(), when esp->inplace is false, the old skb page frags\nare replaced with a new page from the xfrm page_frag cache. The source\nscatterlist (sg) is built from the old frags before the replacement, and\nesp_ssg_unref() is responsible for releasing the old page references\nafter the crypto operation completes.\n\nHowever, if the second skb_to_sgvec() call (which builds the destination\nscatterlist from the new page) fails, the code jumps to error_free which\nonly calls kfree(tmp). The old page frag references captured in the\nsource scatterlist are never released:\n\n 1. sg[] is built from old frags via skb_to_sgvec() (no extra get_page)\n 2. nr_frags is set to 1 and frag[0] is replaced with the new page\n 3. Second skb_to_sgvec() fails -> goto error_free\n 4. kfree(tmp) frees the sg[] memory but old frags are not unref'd\n 5. kfree_skb() only releases frag[0] (the new page), not the old ones\n\nFix this by adding a bool parameter to esp_ssg_unref() that, when true,\nunconditionally unrefs the source scatterlist frags without checking\nreq->src and req->dst, since those fields are not yet initialized by\naead_request_set_crypt() at the point of the error. Existing callers\npass false to preserve the original behavior.\n\nThe same issue exists in both esp4 and esp6 as the code is identical.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00279, EPSS Percentile is 0.20147 |
debian: CVE-2026-63872 was patched at 2026-07-14
1306.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63917) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_changelink(). ip netns add ns1 ip netns add ns2 ip -n ns1 link add vti6_test type vti6 remote ::1 local ::2 key 7 ip -n ns1 link set vti6_test netns ns2 ip -n ns2 link set vti6_test type vti6 remote ::3 local ::4 key 9 ip netns del ns2 ip netns del ns1 [ 132.495484] ------------[ cut here ]------------ [ 132.497609] kernel BUG at net/core/dev.c:12376! Commit 61220ab34948 ("vti6: Enable namespace changing") dropped NETIF_F_NETNS_LOCAL from vti6 devices. A vti6 tunnel can then move through IFLA_NET_NS_FD. After the move dev_net(dev) points at the new netns while t->net stays at the creation netns. vti6_changelink() and vti6_update() still use dev_net(dev) and dev_net(t->dev). They unlink from one per netns hash and relink into another. The creation netns is left with a stale entry. cleanup_net() of that netns later walks freed memory. Reachable from an unprivileged user namespace (unshare --user --map-root-user --net). Cross tenant scope on container hosts.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nip6: vti: Use ip6_tnl.net in vti6_changelink().\n\nip netns add ns1\nip netns add ns2\nip -n ns1 link add vti6_test type vti6 remote ::1 local ::2 key 7\nip -n ns1 link set vti6_test netns ns2\nip -n ns2 link set vti6_test type vti6 remote ::3 local ::4 key 9\nip netns del ns2\nip netns del ns1\n[ 132.495484] ------------[ cut here ]------------\n[ 132.497609] kernel BUG at net/core/dev.c:12376!\n\nCommit 61220ab34948 ("vti6: Enable namespace changing") dropped\nNETIF_F_NETNS_LOCAL from vti6 devices. A vti6 tunnel can then\nmove through IFLA_NET_NS_FD. After the move dev_net(dev) points\nat the new netns while t->net stays at the creation netns.\n\nvti6_changelink() and vti6_update() still use dev_net(dev) and\ndev_net(t->dev). They unlink from one per netns hash and relink\ninto another. The creation netns is left with a stale entry.\ncleanup_net() of that netns later walks freed memory.\n\nReachable from an unprivileged user namespace (unshare --user\n--map-root-user --net). Cross tenant scope on container hosts.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06045 |
debian: CVE-2026-63917 was patched at 2026-07-14
ubuntu: CVE-2026-63917 was patched at 2026-07-30
1307.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63921) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate(). After patch 1/2 in this series, vti6_update() unlinks and relinks the tunnel through t->net. vti6_siocdevprivate() still uses dev_net(dev) for the collision lookup. For a tunnel moved through IFLA_NET_NS_FD, dev_net(dev) is the new netns, not t->net. SIOCCHGTUNNEL on a migrated tunnel then runs: net = dev_net(dev) /* migrated netns */ t = vti6_locate(net, &p1, false) /* misses target in t->net */ ... t = netdev_priv(dev) vti6_update(t, &p1, false) /* mutates t->net's hash */ A caller in the migrated netns picks params that match a tunnel in the creation netns. The lookup in dev_net(dev) finds nothing. vti6_update() prepends the migrated tunnel at the head of the creation netns hash bucket for those params. Later lookups in the creation netns resolve to the migrated device. xfrm receive delivers the matched packets through a device the caller controls. Reachable from an unprivileged user namespace (unshare --user --map-root-user --net). Cross tenant scope on container hosts. Switch the SIOCCHGTUNNEL path on a non fallback device to use t->net for the lookup. The lookup now matches the netns vti6_update() operates on. Also add ns_capable(self->net->user_ns, CAP_NET_ADMIN) before the lookup. The check at the top of the case is against dev_net(dev)->user_ns, which after migration is the attacker's netns. A caller there can pick params absent from self->net, the lookup returns NULL, t becomes self, and vti6_update() inserts the device into the creation netns hash. The new check requires CAP_NET_ADMIN in the creation netns user_ns too. SIOCADDTUNNEL and SIOCCHGTUNNEL on the fallback device keep dev_net(dev), which equals init_net there.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().\n\nAfter patch 1/2 in this series, vti6_update() unlinks and relinks\nthe tunnel through t->net. vti6_siocdevprivate() still uses\ndev_net(dev) for the collision lookup. For a tunnel moved through\nIFLA_NET_NS_FD, dev_net(dev) is the new netns, not t->net.\n\nSIOCCHGTUNNEL on a migrated tunnel then runs:\n\n net = dev_net(dev) /* migrated netns */\n t = vti6_locate(net, &p1, false) /* misses target in t->net */\n ...\n t = netdev_priv(dev)\n vti6_update(t, &p1, false) /* mutates t->net's hash */\n\nA caller in the migrated netns picks params that match a tunnel\nin the creation netns. The lookup in dev_net(dev) finds nothing.\nvti6_update() prepends the migrated tunnel at the head of the\ncreation netns hash bucket for those params. Later lookups in\nthe creation netns resolve to the migrated device. xfrm receive\ndelivers the matched packets through a device the caller controls.\n\nReachable from an unprivileged user namespace (unshare --user\n--map-root-user --net). Cross tenant scope on container hosts.\n\nSwitch the SIOCCHGTUNNEL path on a non fallback device to use\nt->net for the lookup. The lookup now matches the netns\nvti6_update() operates on.\n\nAlso add ns_capable(self->net->user_ns, CAP_NET_ADMIN) before\nthe lookup. The check at the top of the case is against\ndev_net(dev)->user_ns, which after migration is the attacker's\nnetns. A caller there can pick params absent from self->net,\nthe lookup returns NULL, t becomes self, and vti6_update()\ninserts the device into the creation netns hash. The new check\nrequires CAP_NET_ADMIN in the creation netns user_ns too.\n\nSIOCADDTUNNEL and SIOCCHGTUNNEL on the fallback device keep\ndev_net(dev), which equals init_net there.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00176, EPSS Percentile is 0.0738 |
debian: CVE-2026-63921 was patched at 2026-07-14
ubuntu: CVE-2026-63921 was patched at 2026-07-30
1308.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63937) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer Use READ_ONCE() when reading entries/indices from the guest-accessible Page State Change buffer to defend against TOCTOU bugs. Don't bother with READ_ONCE()/WRITE_ONCE() for cases where KVM is writing (and not consuming the result!), as the guest isn't supposed to touch the buffer while it's being processed. I.e. using READ_ONCE() is all about protecting against misbehaving guests.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Use READ_ONCE() when reading entries/indices from PSC buffer\n\nUse READ_ONCE() when reading entries/indices from the guest-accessible\nPage State Change buffer to defend against TOCTOU bugs.\n\nDon't bother with READ_ONCE()/WRITE_ONCE() for cases where KVM is writing\n(and not consuming the result!), as the guest isn't supposed to touch the\nbuffer while it's being processed. I.e. using READ_ONCE() is all about\nprotecting against misbehaving guests.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.05982 |
debian: CVE-2026-63937 was patched at 2026-07-14
ubuntu: CVE-2026-63937 was patched at 2026-07-30
1309.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63938) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Check PSC request indices against the actual size of the buffer When processing Page State Change (PSC) requests, validate the PSC buffer against the effective size of the scratch area, which could be less than the maximum size if the guest provided a pointer that isn't exactly at the start of the GHCB shared buffer.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Check PSC request indices against the actual size of the buffer\n\nWhen processing Page State Change (PSC) requests, validate the PSC buffer\nagainst the effective size of the scratch area, which could be less than\nthe maximum size if the guest provided a pointer that isn't exactly at the\nstart of the GHCB shared buffer.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07858 |
debian: CVE-2026-63938 was patched at 2026-07-14
ubuntu: CVE-2026-63938 was patched at 2026-07-30
1310.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63939) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Compute the correct max length of the in-GHCB scratch area When setting the length of the GHCB scratch area, and the area is in the GHCB shared buffer, set the effective length of the scratch area to the max possible size given the start of the guest-provided pointer, and the end of the shared buffer. The code was "fine" when first introduced, as KVM doesn't consult the length of the buffer when emulating MMIO, because the passed in @len always specifies the *max* size required. But for PSC requests, the incoming @len is just the minimum length (to process the header), and KVM needs to know the full size of the scratch area to avoid buffer overflows (spoiler alert). Opportunistically rename @len => @min_len to better reflect its role.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Compute the correct max length of the in-GHCB scratch area\n\nWhen setting the length of the GHCB scratch area, and the area is in the\nGHCB shared buffer, set the effective length of the scratch area to the max\npossible size given the start of the guest-provided pointer, and the end of\nthe shared buffer.\n\nThe code was "fine" when first introduced, as KVM doesn't consult the\nlength of the buffer when emulating MMIO, because the passed in @len always\nspecifies the *max* size required. But for PSC requests, the incoming @len\nis just the minimum length (to process the header), and KVM needs to know\nthe full size of the scratch area to avoid buffer overflows (spoiler alert).\n\nOpportunistically rename @len => @min_len to better reflect its role.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00197, EPSS Percentile is 0.09762 |
debian: CVE-2026-63939 was patched at 2026-07-14
ubuntu: CVE-2026-63939 was patched at 2026-07-30
1311.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63940) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: KVM: SEV: Ignore Port I/O requests of length '0' Explicitly ignore Port I/O requests of length '0' (or count '0'), so that setting up the software scratch area (and other code) doesn't have to worry about underflowing the length, and to allow for WARNing on trying to configure the scratch area with len==0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: SEV: Ignore Port I/O requests of length '0'\n\nExplicitly ignore Port I/O requests of length '0' (or count '0'), so that\nsetting up the software scratch area (and other code) doesn't have to\nworry about underflowing the length, and to allow for WARNing on trying\nto configure the scratch area with len==0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07858 |
debian: CVE-2026-63940 was patched at 2026-07-14
ubuntu: CVE-2026-63940 was patched at 2026-07-30
1312.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63941) - Medium [269]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor ZCR_EL2 can be updated by a VHE guest hypervisor either using ZCR_EL2 (which traps) or ZCR_EL1 (which does not trap). KVM handles both in different way: - on ZCR_EL2 trap, ZCR_EL2.LEN is immediately capped at the VM's own VL limit. This has the potential to break existing SW that relies on the full LEN field to be stateful. - on ZCR_EL1 access, we do absolutely nothing. On restoring the SVE context for an L2 guest, we directly restore the guest hypervisor's view of ZCR_EL2 into the physical ZCR_EL2. If the guest's view of the register was updated using the ZCR_EL2 accessor, the value has already been sanitised (with the caveat mentioned above). But if the guest used ZCR_EL1, the raw value is written into the HW, and the L2 guest can now access VLs that it shouldn't. Fix all the above by moving the VL capping to the restore points, ensuring that: - the HW is always programmed with a capped value, irrespective of the accessor being used, - the ZCR_EL2.LEN field is always completely stateful, irrespective of the accessor being used. Additionally, move ZCR_EL2 to be a sanitised register, ensuring that only the LEN field is actually stateful. This requires some creative construction of the RES0 mask, as the sysreg generation script does not yet generate RAZ/WI fields. [maz: rewrote commit message, tidy up access_zcr_el2()]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: Correctly cap ZCR_EL2 provided by a guest hypervisor\n\nZCR_EL2 can be updated by a VHE guest hypervisor either using ZCR_EL2\n(which traps) or ZCR_EL1 (which does not trap). KVM handles both in\ndifferent way:\n\n- on ZCR_EL2 trap, ZCR_EL2.LEN is immediately capped at the VM's own\n VL limit. This has the potential to break existing SW that relies\n on the full LEN field to be stateful.\n\n- on ZCR_EL1 access, we do absolutely nothing.\n\nOn restoring the SVE context for an L2 guest, we directly restore the\nguest hypervisor's view of ZCR_EL2 into the physical ZCR_EL2. If the\nguest's view of the register was updated using the ZCR_EL2 accessor,\nthe value has already been sanitised (with the caveat mentioned above).\n\nBut if the guest used ZCR_EL1, the raw value is written into the HW,\nand the L2 guest can now access VLs that it shouldn't.\n\nFix all the above by moving the VL capping to the restore points,\nensuring that:\n\n- the HW is always programmed with a capped value, irrespective of\n the accessor being used,\n\n- the ZCR_EL2.LEN field is always completely stateful, irrespective\n of the accessor being used.\n\nAdditionally, move ZCR_EL2 to be a sanitised register, ensuring that\nonly the LEN field is actually stateful. This requires some creative\nconstruction of the RES0 mask, as the sysreg generation script does\nnot yet generate RAZ/WI fields.\n\n[maz: rewrote commit message, tidy up access_zcr_el2()]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00154, EPSS Percentile is 0.05076 |
debian: CVE-2026-63941 was patched at 2026-07-14
ubuntu: CVE-2026-63941 was patched at 2026-07-30
1313.
Denial of Service - Spice-vdagent (CVE-2026-57965) - Medium [267]
Description: A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability can lead to a heap buffer overflow, causing the spice-vdagent daemon
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:spice-space:spice-vdagent (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00113, EPSS Percentile is 0.01684 |
debian: CVE-2026-57965 was patched at 2026-07-14, 2026-07-24
1314.
Denial of Service - Unknown Product (CVE-2026-13149) - Medium [267]
Description: {'nvd_cve_data_all': 'brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'brace-expansion through 5.0.6 is vulnerable to denial of service. The expand() function exhibits exponential-time complexity in the number of consecutive non-expanding '{}' brace groups. An attacker who passes a crafted string to expand(), directly or transitively, can cause significant CPU consumption and event-loop blocking. The max option does not mitigate this, as it bounds the output size rather than the recursion work.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00348, EPSS Percentile is 0.27478 |
debian: CVE-2026-13149 was patched at 2026-07-14
redhat: CVE-2026-13149 was patched at 2026-07-28
1315.
Denial of Service - Unknown Product (CVE-2026-38076) - Medium [267]
Description: {'nvd_cve_data_all': 'An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An integer overflow in the jbig2_arith_iaid_ctx_new() function of Artifex commit cc37d0 allows attackers to cause a Denial of Service (DoS) via a crafted input.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00432, EPSS Percentile is 0.35488 |
debian: CVE-2026-38076 was patched at 2026-07-14
ubuntu: CVE-2026-38076 was patched at 2026-07-30
1316.
Denial of Service - Unknown Product (CVE-2026-44628) - Medium [267]
Description: {'nvd_cve_data_all': 'An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directory, the expected lockfile, and at least one matching worklist record.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00434, EPSS Percentile is 0.35648 |
debian: CVE-2026-44628 was patched at 2026-07-14
1317.
Denial of Service - Unknown Product (CVE-2026-56740) - Medium [267]
Description: {'nvd_cve_data_all': 'JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and TelnetIO.readNEVariables() in TelnetIO.java:1127-1180 stores each variable pair in a HashMap held by ConnectionData, allowing an unauthenticated attacker to flood unique variable pairs before the terminating IAC SE byte and exhaust JVM heap memory with an OutOfMemoryError. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not limit the number of environment variables a client may inject via the Telnet NEW-ENVIRON option, and TelnetIO.readNEVariables() in TelnetIO.java:1127-1180 stores each variable pair in a HashMap held by ConnectionData, allowing an unauthenticated attacker to flood unique variable pairs before the terminating IAC SE byte and exhaust JVM heap memory with an OutOfMemoryError. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00504, EPSS Percentile is 0.40336 |
debian: CVE-2026-56740 was patched at 2026-07-14
1318.
Denial of Service - Unknown Product (CVE-2026-56741) - Medium [267]
Description: {'nvd_cve_data_all': 'JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'JLine is a Java library for handling console input. Prior to 3.30.14, 4.0.16, and 4.2.1, the JLine3 Telnet server remote-telnet module does not apply an upper bound to terminal dimensions received via the Telnet NAWS option, and TelnetIO.handleNAWS() in TelnetIO.java:856-879 reads client-supplied width and height as 16-bit unsigned integers and passes values such as 65535x65535 to setTerminalGeometry(), allowing an unauthenticated remote attacker to repeatedly alternate values and trigger continuous expensive rendering work that causes CPU exhaustion and denial of service. This issue is fixed in versions 3.30.14, 4.0.16, and 4.2.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00515, EPSS Percentile is 0.40944 |
debian: CVE-2026-56741 was patched at 2026-07-14
1319.
Incorrect Calculation - Wget (CVE-2026-58472) - Medium [267]
Description: GNU Wget through 1.25.0, fixed in commit dd692d9, contains a heap buffer overflow vulnerability in the html_quote_string() function in src/convert.c that allows a remote attacker to trigger memory corruption by supplying a crafted HTML attribute with a large number of characters requiring entity encoding. A server-supplied HTML attribute causes a signed integer counter to overflow during output size accumulation, resulting in an undersized heap allocation and subsequent heap buffer overflow during the copy phase.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:gnu:wget (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12786 |
debian: CVE-2026-58472 was patched at 2026-07-14
ubuntu: CVE-2026-58472 was patched at 2026-07-30
1320.
Memory Corruption - Wget (CVE-2026-58471) - Medium [267]
Description: GNU Wget through 1.25.0, fixed in commit c2640fe, contains a heap buffer overflow vulnerability in the convert_fname() function within src/url.c that allows remote attackers to trigger
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:gnu:wget (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12786 |
debian: CVE-2026-58471 was patched at 2026-07-14
ubuntu: CVE-2026-58471 was patched at 2026-07-30
1321.
Path Traversal - Unknown Product (CVE-2026-55677) - Medium [267]
Description: {'nvd_cve_data_all': 'Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is), while StaticDirectoryHandler unescapes %2F to / before resolving filesystem paths. This allows an attacker to bypass route-level access controls and read static files without authorization. This vulnerability is fixed in 4.15.3 and 5.2.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00431, EPSS Percentile is 0.35414 |
debian: CVE-2026-55677 was patched at 2026-07-14
1322.
Security Feature Bypass - Unknown Product (CVE-2026-42387) - Medium [267]
Description: {'nvd_cve_data_all': 'A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to a crash of the Recursor due to insuffcient input validation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00386, EPSS Percentile is 0.31318 |
debian: CVE-2026-42387 was patched at 2026-06-25, 2026-07-14
1323.
Security Feature Bypass - Unknown Product (CVE-2026-42388) - Medium [267]
Description: {'nvd_cve_data_all': 'Incomplete validation of the SOA record present in a catalog zone might lead to a crash.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Incomplete validation of the SOA record present in a catalog zone might lead to a crash.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00386, EPSS Percentile is 0.31318 |
debian: CVE-2026-42388 was patched at 2026-06-25, 2026-07-14
1324.
Unknown Vulnerability Type - Apache ActiveMQ (CVE-2026-54475) - Medium [266]
Description: {'nvd_cve_data_all': 'Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ. Apache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be broken as this is only checked in the client, allowing a different connection to consume from another connection's temporary destination. This issue affects Apache ActiveMQ Broker: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7. Users are recommended to upgrade to version 6.2.7, which fixes the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Missing Authorization vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.\n\nApache ActiveMQ Classic temporary destinations are expected to be isolated to the connection that created them. The isolation can be broken as this is only checked in the client, allowing a\xa0different connection to consume from another connection's temporary\ndestination.\nThis issue affects Apache ActiveMQ Broker: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ All: before 5.19.8, from 6.0.0 before 6.2.7; Apache ActiveMQ: before 5.19.8, from 6.0.0 before 6.2.7.\n\nUsers are recommended to upgrade to version 6.2.7, which fixes the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Apache ActiveMQ is an open source message broker written in Java together with a full Java Message Service (JMS) client | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.6 | 10 | EPSS Probability is 0.00902, EPSS Percentile is 0.56199 |
debian: CVE-2026-54475 was patched at 2026-07-14
1325.
Memory Corruption - Open Asset Import Library Assimp (CVE-2025-15666) - Medium [265]
Description: A security vulnerability has been detected in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | Open Asset Import Library is a library that loads various 3D file formats into a shared, in-memory format | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02494 |
debian: CVE-2025-15666 was patched at 2026-07-14
1326.
Memory Corruption - Open Asset Import Library Assimp (CVE-2026-14610) - Medium [265]
Description: A flaw has been found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.7 | 14 | Open Asset Import Library is a library that loads various 3D file formats into a shared, in-memory format | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02821 |
debian: CVE-2026-14610 was patched at 2026-07-14
1327.
Server-Side Request Forgery - JOSE (CVE-2026-54430) - Medium [264]
Description: liboauth2 is vulnerable to Server-Side Request Forgery in oauth2_
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0.3 | 14 | JavaScript module for JSON Object Signing and Encryption (JOSE) | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02265 |
debian: CVE-2026-54430 was patched at 2026-07-14
1328.
Spoofing - Chromium (CVE-2026-13837) - Medium [264]
Description: Inappropriate implementation in CSS in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14866 |
altlinux: CVE-2026-13837 was patched at 2026-07-03
debian: CVE-2026-13837 was patched at 2026-07-05, 2026-07-14
1329.
Spoofing - Chromium (CVE-2026-13842) - Medium [264]
Description: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00227, EPSS Percentile is 0.13556 |
altlinux: CVE-2026-13842 was patched at 2026-07-03
debian: CVE-2026-13842 was patched at 2026-07-05, 2026-07-14
1330.
Spoofing - Chromium (CVE-2026-13857) - Medium [264]
Description: Inappropriate implementation in Geometry in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11539 |
altlinux: CVE-2026-13857 was patched at 2026-07-03
debian: CVE-2026-13857 was patched at 2026-07-05, 2026-07-14
1331.
Spoofing - Chromium (CVE-2026-13860) - Medium [264]
Description: Incorrect security UI in Autofill in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11538 |
altlinux: CVE-2026-13860 was patched at 2026-07-03
debian: CVE-2026-13860 was patched at 2026-07-05, 2026-07-14
1332.
Spoofing - Chromium (CVE-2026-13867) - Medium [264]
Description: Inappropriate implementation in Geolocation in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14866 |
altlinux: CVE-2026-13867 was patched at 2026-07-03
debian: CVE-2026-13867 was patched at 2026-07-05, 2026-07-14
1333.
Spoofing - Chromium (CVE-2026-13895) - Medium [264]
Description: Inappropriate implementation in Autofill in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00218, EPSS Percentile is 0.12438 |
altlinux: CVE-2026-13895 was patched at 2026-07-03
debian: CVE-2026-13895 was patched at 2026-07-05, 2026-07-14
1334.
Spoofing - Chromium (CVE-2026-13902) - Medium [264]
Description: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14865 |
altlinux: CVE-2026-13902 was patched at 2026-07-03
debian: CVE-2026-13902 was patched at 2026-07-05, 2026-07-14
1335.
Spoofing - Chromium (CVE-2026-13907) - Medium [264]
Description: Inappropriate implementation in iOSWeb in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00218, EPSS Percentile is 0.12438 |
altlinux: CVE-2026-13907 was patched at 2026-07-03
debian: CVE-2026-13907 was patched at 2026-07-05, 2026-07-14
1336.
Spoofing - Chromium (CVE-2026-13912) - Medium [264]
Description: Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14866 |
altlinux: CVE-2026-13912 was patched at 2026-07-03
debian: CVE-2026-13912 was patched at 2026-07-05, 2026-07-14
1337.
Spoofing - Chromium (CVE-2026-13916) - Medium [264]
Description: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14867 |
altlinux: CVE-2026-13916 was patched at 2026-07-03
debian: CVE-2026-13916 was patched at 2026-07-05, 2026-07-14
1338.
Spoofing - Chromium (CVE-2026-13941) - Medium [264]
Description: Inappropriate implementation in SiteSettings in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14865 |
altlinux: CVE-2026-13941 was patched at 2026-07-03
debian: CVE-2026-13941 was patched at 2026-07-05, 2026-07-14
1339.
Spoofing - Chromium (CVE-2026-13956) - Medium [264]
Description: Incorrect security UI in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11538 |
altlinux: CVE-2026-13956 was patched at 2026-07-03
debian: CVE-2026-13956 was patched at 2026-07-05, 2026-07-14
1340.
Spoofing - Chromium (CVE-2026-13960) - Medium [264]
Description: Inappropriate implementation in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14865 |
altlinux: CVE-2026-13960 was patched at 2026-07-03
debian: CVE-2026-13960 was patched at 2026-07-05, 2026-07-14
1341.
Spoofing - Chromium (CVE-2026-13966) - Medium [264]
Description: Inappropriate implementation in History in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00237, EPSS Percentile is 0.14867 |
altlinux: CVE-2026-13966 was patched at 2026-07-03
debian: CVE-2026-13966 was patched at 2026-07-05, 2026-07-14
1342.
Spoofing - Chromium (CVE-2026-13972) - Medium [264]
Description: Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00222, EPSS Percentile is 0.12839 |
altlinux: CVE-2026-13972 was patched at 2026-07-03
debian: CVE-2026-13972 was patched at 2026-07-05, 2026-07-14
1343.
Spoofing - Chromium (CVE-2026-13973) - Medium [264]
Description: Inappropriate implementation in UI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00192, EPSS Percentile is 0.09113 |
altlinux: CVE-2026-13973 was patched at 2026-07-03
debian: CVE-2026-13973 was patched at 2026-07-05, 2026-07-14
1344.
Spoofing - Chromium (CVE-2026-13979) - Medium [264]
Description: Inappropriate implementation in Paint in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00231, EPSS Percentile is 0.14055 |
altlinux: CVE-2026-13979 was patched at 2026-07-03
debian: CVE-2026-13979 was patched at 2026-07-05, 2026-07-14
1345.
Spoofing - Chromium (CVE-2026-13980) - Medium [264]
Description: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.1402 |
altlinux: CVE-2026-13980 was patched at 2026-07-03
debian: CVE-2026-13980 was patched at 2026-07-05, 2026-07-14
1346.
Spoofing - Chromium (CVE-2026-13981) - Medium [264]
Description: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.14021 |
altlinux: CVE-2026-13981 was patched at 2026-07-03
debian: CVE-2026-13981 was patched at 2026-07-05, 2026-07-14
1347.
Spoofing - Chromium (CVE-2026-13983) - Medium [264]
Description: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00158, EPSS Percentile is 0.05438 |
altlinux: CVE-2026-13983 was patched at 2026-07-03
debian: CVE-2026-13983 was patched at 2026-07-05, 2026-07-14
1348.
Spoofing - Chromium (CVE-2026-13986) - Medium [264]
Description: Inappropriate implementation in Media UI in Google Chrome on ChromeOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10717 |
altlinux: CVE-2026-13986 was patched at 2026-07-03
debian: CVE-2026-13986 was patched at 2026-07-05, 2026-07-14
1349.
Spoofing - Chromium (CVE-2026-13987) - Medium [264]
Description: Incorrect security UI in Mobile in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00183, EPSS Percentile is 0.08162 |
altlinux: CVE-2026-13987 was patched at 2026-07-03
debian: CVE-2026-13987 was patched at 2026-07-05, 2026-07-14
1350.
Spoofing - Chromium (CVE-2026-13992) - Medium [264]
Description: Inappropriate implementation in UI in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00191, EPSS Percentile is 0.09091 |
altlinux: CVE-2026-13992 was patched at 2026-07-03
debian: CVE-2026-13992 was patched at 2026-07-05, 2026-07-14
1351.
Spoofing - Chromium (CVE-2026-13993) - Medium [264]
Description: Incorrect security UI in WebAppInstalls in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform domain
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00154, EPSS Percentile is 0.05058 |
altlinux: CVE-2026-13993 was patched at 2026-07-03
debian: CVE-2026-13993 was patched at 2026-07-05, 2026-07-14
1352.
Spoofing - Chromium (CVE-2026-13994) - Medium [264]
Description: Inappropriate implementation in Credential Management in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00183, EPSS Percentile is 0.08161 |
altlinux: CVE-2026-13994 was patched at 2026-07-03
debian: CVE-2026-13994 was patched at 2026-07-05, 2026-07-14
1353.
Spoofing - Chromium (CVE-2026-13997) - Medium [264]
Description: Incorrect security UI in Extensions in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00154, EPSS Percentile is 0.05058 |
altlinux: CVE-2026-13997 was patched at 2026-07-03
debian: CVE-2026-13997 was patched at 2026-07-05, 2026-07-14
1354.
Spoofing - Chromium (CVE-2026-13998) - Medium [264]
Description: Incorrect security UI in File Input in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00154, EPSS Percentile is 0.0504 |
altlinux: CVE-2026-13998 was patched at 2026-07-03
debian: CVE-2026-13998 was patched at 2026-07-05, 2026-07-14
1355.
Spoofing - Chromium (CVE-2026-14013) - Medium [264]
Description: Inappropriate implementation in SVG in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00191, EPSS Percentile is 0.09019 |
altlinux: CVE-2026-14013 was patched at 2026-07-03
debian: CVE-2026-14013 was patched at 2026-07-05, 2026-07-14
1356.
Spoofing - Chromium (CVE-2026-14026) - Medium [264]
Description: Incorrect security UI in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.056 |
altlinux: CVE-2026-14026 was patched at 2026-07-03
debian: CVE-2026-14026 was patched at 2026-07-05, 2026-07-14
1357.
Spoofing - Chromium (CVE-2026-14028) - Medium [264]
Description: Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.05976 |
altlinux: CVE-2026-14028 was patched at 2026-07-03
debian: CVE-2026-14028 was patched at 2026-07-05, 2026-07-14
1358.
Spoofing - Chromium (CVE-2026-14030) - Medium [264]
Description: Inappropriate implementation in SplitView in Google Chrome on Linux prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.05599 |
altlinux: CVE-2026-14030 was patched at 2026-07-03
debian: CVE-2026-14030 was patched at 2026-07-05, 2026-07-14
1359.
Spoofing - Chromium (CVE-2026-14031) - Medium [264]
Description: Inappropriate implementation in File Input in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07306 |
altlinux: CVE-2026-14031 was patched at 2026-07-03
debian: CVE-2026-14031 was patched at 2026-07-05, 2026-07-14
1360.
Spoofing - Chromium (CVE-2026-14042) - Medium [264]
Description: Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00198, EPSS Percentile is 0.09849 |
altlinux: CVE-2026-14042 was patched at 2026-07-03
debian: CVE-2026-14042 was patched at 2026-07-05, 2026-07-14
1361.
Spoofing - Chromium (CVE-2026-14072) - Medium [264]
Description: Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00198, EPSS Percentile is 0.09849 |
altlinux: CVE-2026-14072 was patched at 2026-07-03
debian: CVE-2026-14072 was patched at 2026-07-05, 2026-07-14
1362.
Spoofing - Chromium (CVE-2026-14077) - Medium [264]
Description: Inappropriate implementation in Select in Google Chrome on Mac prior to 150.0.7871.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07307 |
altlinux: CVE-2026-14077 was patched at 2026-07-03
debian: CVE-2026-14077 was patched at 2026-07-05, 2026-07-14
1363.
Spoofing - Chromium (CVE-2026-14123) - Medium [264]
Description: Incorrect security UI in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07761 |
altlinux: CVE-2026-14123 was patched at 2026-07-03
debian: CVE-2026-14123 was patched at 2026-07-05, 2026-07-14
1364.
Spoofing - Chromium (CVE-2026-14126) - Medium [264]
Description: Incorrect security UI in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform domain
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00183, EPSS Percentile is 0.08161 |
altlinux: CVE-2026-14126 was patched at 2026-07-03
debian: CVE-2026-14126 was patched at 2026-07-05, 2026-07-14
1365.
Spoofing - Chromium (CVE-2026-14128) - Medium [264]
Description: Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07761 |
altlinux: CVE-2026-14128 was patched at 2026-07-03
debian: CVE-2026-14128 was patched at 2026-07-05, 2026-07-14
1366.
Spoofing - Chromium (CVE-2026-14129) - Medium [264]
Description: Inappropriate implementation in PreviewTab in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00154, EPSS Percentile is 0.05058 |
altlinux: CVE-2026-14129 was patched at 2026-07-03
debian: CVE-2026-14129 was patched at 2026-07-05, 2026-07-14
1367.
Spoofing - Chromium (CVE-2026-14132) - Medium [264]
Description: Inappropriate implementation in WebXR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07797 |
altlinux: CVE-2026-14132 was patched at 2026-07-03
debian: CVE-2026-14132 was patched at 2026-07-05, 2026-07-14
1368.
Spoofing - Chromium (CVE-2026-14134) - Medium [264]
Description: Inappropriate implementation in Autofill in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00183, EPSS Percentile is 0.08161 |
altlinux: CVE-2026-14134 was patched at 2026-07-03
debian: CVE-2026-14134 was patched at 2026-07-05, 2026-07-14
1369.
Spoofing - Chromium (CVE-2026-14138) - Medium [264]
Description: Inappropriate implementation in WebAppInstalls in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.05976 |
altlinux: CVE-2026-14138 was patched at 2026-07-03
debian: CVE-2026-14138 was patched at 2026-07-05, 2026-07-14
1370.
Spoofing - Chromium (CVE-2026-14139) - Medium [264]
Description: Inappropriate implementation in TabStrip in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.05976 |
altlinux: CVE-2026-14139 was patched at 2026-07-03
debian: CVE-2026-14139 was patched at 2026-07-05, 2026-07-14
1371.
Spoofing - Chromium (CVE-2026-14141) - Medium [264]
Description: Incorrect security UI in Document Picture-in-Picture in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to perform domain
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00202, EPSS Percentile is 0.10378 |
altlinux: CVE-2026-14141 was patched at 2026-07-03
debian: CVE-2026-14141 was patched at 2026-07-05, 2026-07-14
1372.
Spoofing - Chromium (CVE-2026-14143) - Medium [264]
Description: Incorrect security UI in Passwords in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07762 |
altlinux: CVE-2026-14143 was patched at 2026-07-03
debian: CVE-2026-14143 was patched at 2026-07-05, 2026-07-14
1373.
Spoofing - Chromium (CVE-2026-14154) - Medium [264]
Description: Inappropriate implementation in DevTools in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0013, EPSS Percentile is 0.03011 |
altlinux: CVE-2026-14154 was patched at 2026-07-03
debian: CVE-2026-14154 was patched at 2026-07-05, 2026-07-14
1374.
Spoofing - Chromium (CVE-2026-14410) - Medium [264]
Description: Inappropriate implementation in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker who had compromised the renderer process to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00191, EPSS Percentile is 0.09019 |
altlinux: CVE-2026-14410 was patched at 2026-07-03
debian: CVE-2026-14410 was patched at 2026-07-05, 2026-07-14
1375.
Unknown Vulnerability Type - Safari (CVE-2026-43721) - Medium [264]
Description: {'nvd_cve_data_all': 'This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to silently hijack clipboard data.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2, tvOS 26.6, visionOS 26.6, watchOS 26.6. A malicious website may be able to silently hijack clipboard data.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Safari is a web browser developed by Apple. It is built into Apple's operating systems, including macOS, iOS, iPadOS and their upcoming VisionOS, and uses Apple's open-source browser engine WebKit, which was derived from KHTML. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00437, EPSS Percentile is 0.35938 |
almalinux: CVE-2026-43721 was patched at 2026-07-20
debian: CVE-2026-43721 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43721 was patched at 2026-07-20
redhat: CVE-2026-43721 was patched at 2026-07-20
1376.
Denial of Service - GPAC (CVE-2026-50810) - Medium [263]
Description: A NULL pointer dereference in smooth_parse_stream_index() in src/media_tools/mpd.c in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02247 |
debian: CVE-2026-50810 was patched at 2026-07-14
1377.
Server-Side Request Forgery - Unknown Product (CVE-2026-16221) - Medium [262]
Description: {'nvd_cve_data_all': 'Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use fast-uri to enforce host-based policy such as allowlists, denylists, loopback or SSRF filtering, redirect validation, or outbound proxy routing before passing the same URL into Node's URL or fetch consumers can be steered to an unintended destination, including cloud metadata endpoints, loopback, or internal hosts. Patches: upgrade to fast-uri 4.1.1, 3.1.4, or 2.4.3. Workarounds: none.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Impact: fast-uri versions from 2.3.1 through 4.1.0 (including the 3.x line up to 3.1.3 and the 2.x line up to 2.4.2) do not treat a literal backslash character (U+005C) as an authority delimiter. Node's native WHATWG URL parser, used by fetch, undici, and Node's http and https clients, normalizes the backslash to a forward slash for special schemes such as http, https, ws, wss, ftp, and file. As a result, the two parsers extract different hosts from the same input string. Applications that use fast-uri to enforce host-based policy such as allowlists, denylists, loopback or SSRF filtering, redirect validation, or outbound proxy routing before passing the same URL into Node's URL or fetch consumers can be steered to an unintended destination, including cloud metadata endpoints, loopback, or internal hosts. \n\nPatches: upgrade to fast-uri 4.1.1, 3.1.4, or 2.4.3.\n\nWorkarounds: none.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00221, EPSS Percentile is 0.12835 |
debian: CVE-2026-16221 was patched at 2026-07-14
1378.
Remote Code Execution - Unknown Product (CVE-2026-13006) - Medium [261]
Description: {'nvd_cve_data_all': 'ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.36 in Java applications, allows an attacker to execute arbitrary code circumventing existing protections against CVE-2025-11226 by compromising an existing logback configuration file or by injecting an environment variable before program execution. A successful attack requires the presence of Janino library to be present on the user's class path. In addition, the attacker must have write access to a configuration file. Alternatively, the attacker could inject a malicious environment variable pointing to a malicious configuration file. In both cases, the attack requires existing privilege. Please note that in logack version 1.5.37 conditional processing using Janino was removed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ACE vulnerability in conditional configuration file processing by QOS.CH logback-core up to and including version 1.5.36 in Java applications, allows an attacker to execute arbitrary code circumventing existing protections against CVE-2025-11226 by\xa0compromising an existing logback configuration file or by injecting an environment variable before program execution.\n\n\n\nA successful attack requires the presence of Janino library to be present on the user's class path. In addition, the attacker must\xa0 have write access to a \nconfiguration file. Alternatively, the attacker could inject a malicious \nenvironment variable pointing to a malicious configuration file. In both \ncases, the attack requires existing privilege.\n\nPlease note that in logack version 1.5.37 conditional processing using Janino was removed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 1.0 | 15 | Remote Code Execution | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02382 |
debian: CVE-2026-13006 was patched at 2026-07-14
1379.
Denial of Service - ImageMagick (CVE-2026-56375) - Medium [260]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00111, EPSS Percentile is 0.01533 |
debian: CVE-2026-56375 was patched at 2026-07-14
redos: CVE-2026-56375 was patched at 2026-07-28
1380.
Denial of Service - ImageMagick (CVE-2026-61867) - Medium [260]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.3 | 10 | CVSS Base Score is 2.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00102, EPSS Percentile is 0.01106 |
debian: CVE-2026-61867 was patched at 2026-07-14
1381.
Denial of Service - ImageMagick (CVE-2026-61869) - Medium [260]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.3 | 10 | CVSS Base Score is 2.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00102, EPSS Percentile is 0.01107 |
debian: CVE-2026-61869 was patched at 2026-07-14
1382.
Incorrect Calculation - ImageMagick (CVE-2026-55597) - Medium [260]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00103, EPSS Percentile is 0.01163 |
altlinux: CVE-2026-55597 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-55597 was patched at 2026-07-07, 2026-07-14
1383.
Memory Corruption - ImageMagick (CVE-2026-55510) - Medium [260]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00103, EPSS Percentile is 0.01157 |
altlinux: CVE-2026-55510 was patched at 2026-07-11, 2026-07-15, 2026-07-16
1384.
Memory Corruption - dhcpcd (CVE-2026-56114) - Medium [259]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.45 | 14 | dhcpcd is an open-source DHCP and network configuration client used on Linux, BSD, and other Unix-like operating systems to automatically configure network interfaces, IP addresses, routes, and DNS settings. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07293 |
debian: CVE-2026-56114 was patched at 2026-06-24, 2026-07-14
1385.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53146) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Limit XDomain response copy to actual frame size tb_xdomain_copy() copies req->response_size bytes from the received packet buffer regardless of the actual frame size. When a short response arrives, this reads past the valid frame data in the DMA pool buffer into stale contents from previous transactions. Use the minimum of frame size and expected response size for the copy length.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: Limit XDomain response copy to actual frame size\n\ntb_xdomain_copy() copies req->response_size bytes from the received\npacket buffer regardless of the actual frame size. When a short\nresponse arrives, this reads past the valid frame data in the DMA\npool buffer into stale contents from previous transactions.\n\nUse the minimum of frame size and expected response size for the\ncopy length.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00242, EPSS Percentile is 0.15519 |
altlinux: CVE-2026-53146 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53146 was patched at 2026-07-14
1386.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53170) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: reject DMA commands with uninitialized length cmd_state_init() initializes the command state with memset(0xff), leaving dma->len at U64_MAX to signal missing setup. The only setter is NPU_SET_DMA0_LEN; if userspace omits this command and issues NPU_OP_DMA_START, dma->len remains U64_MAX. In dma_length(), a positive stride added to U64_MAX wraps to a small value. With size0 == 1, check_mul_overflow() does not trigger and dma_length() returns 0 instead of U64_MAX. The caller's U64_MAX check then passes, region_size[] stays 0, and the bounds check in ethosu_job.c is bypassed, allowing hardware to execute DMA with stale physical addresses. Fix by checking for U64_MAX at the start of dma_length() before any arithmetic, consistent with the sentinel value used throughout the driver to detect uninitialized fields.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\naccel/ethosu: reject DMA commands with uninitialized length\n\ncmd_state_init() initializes the command state with memset(0xff),\nleaving dma->len at U64_MAX to signal missing setup. The only setter\nis NPU_SET_DMA0_LEN; if userspace omits this command and issues\nNPU_OP_DMA_START, dma->len remains U64_MAX.\n\nIn dma_length(), a positive stride added to U64_MAX wraps to a small\nvalue. With size0 == 1, check_mul_overflow() does not trigger and\ndma_length() returns 0 instead of U64_MAX. The caller's U64_MAX check\nthen passes, region_size[] stays 0, and the bounds check in\nethosu_job.c is bypassed, allowing hardware to execute DMA with stale\nphysical addresses.\n\nFix by checking for U64_MAX at the start of dma_length() before any\narithmetic, consistent with the sentinel value used throughout the\ndriver to detect uninitialized fields.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02831 |
altlinux: CVE-2026-53170 was patched at 2026-06-19
1387.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53171) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: accel/ethosu: fix arithmetic issues in dma_length() dma_length() derives DMA region usage from command stream values and updates region_size[]: len = ((len + stride[0]) * size0 + stride[1]) * size1 region_size[region] = max(..., len + dma->offset) Several arithmetic issues can corrupt the derived region size: - signed stride values may underflow when added to len - intermediate multiplications may overflow - len + dma->offset may overflow during region_size updates - dma_length() error returns were not validated by the caller region_size[] is later used by ethosu_job.c to validate command stream accesses against GEM buffer sizes. Arithmetic wraparound can therefore under-report region usage and bypass the bounds validation. Fix by validating signed additions, using overflow helpers for multiplications and offset updates, and propagating dma_length() failures to the caller.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\naccel/ethosu: fix arithmetic issues in dma_length()\n\ndma_length() derives DMA region usage from command stream values and\nupdates region_size[]:\n\n len = ((len + stride[0]) * size0 + stride[1]) * size1\n region_size[region] = max(..., len + dma->offset)\n\nSeveral arithmetic issues can corrupt the derived region size:\n\n- signed stride values may underflow when added to len\n- intermediate multiplications may overflow\n- len + dma->offset may overflow during region_size updates\n- dma_length() error returns were not validated by the caller\n\nregion_size[] is later used by ethosu_job.c to validate command stream\naccesses against GEM buffer sizes. Arithmetic wraparound can therefore\nunder-report region usage and bypass the bounds validation.\n\nFix by validating signed additions, using overflow helpers for\nmultiplications and offset updates, and propagating dma_length()\nfailures to the caller.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02831 |
altlinux: CVE-2026-53171 was patched at 2026-06-19
1388.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53188) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Validate the passed in fops for ib_get_ucaps() Sashiko pointed out it is not safe to rely only on the devt because char/block alias so if the user finds a block device with the same dev_t it can masquerade as a ucap cdev fd. Test the f_ops to only accept authentic cdevs.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: Validate the passed in fops for ib_get_ucaps()\n\nSashiko pointed out it is not safe to rely only on the devt because\nchar/block alias so if the user finds a block device with the same dev_t\nit can masquerade as a ucap cdev fd.\n\nTest the f_ops to only accept authentic cdevs.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02772 |
altlinux: CVE-2026-53188 was patched at 2026-06-19, 2026-06-22, 2026-07-06
1389.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53200) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: nv: Fix handling of XN[0] when !FEAT_XNX XN has already been extracted from its bitfield position so using FIELD_PREP() on the mask that clears XN[0] is completely broken, having the effect of unconditionally granting execute permissions... Fix the obvious mistake by manipulating the right bit.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: nv: Fix handling of XN[0] when !FEAT_XNX\n\nXN has already been extracted from its bitfield position so using\nFIELD_PREP() on the mask that clears XN[0] is completely broken, having\nthe effect of unconditionally granting execute permissions...\n\nFix the obvious mistake by manipulating the right bit.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02192 |
altlinux: CVE-2026-53200 was patched at 2026-06-19
1390.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53266) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: make ebt_snat ARP rewrite writable The ebtables SNAT target keeps the Ethernet source address rewrite behind skb_ensure_writable(skb, 0). This is intentional: at the bridge ebtables hooks the Ethernet header is addressed through skb_mac_header()/eth_hdr(), while skb->data points at the Ethernet payload. Asking skb_ensure_writable() for ETH_HLEN bytes would check the payload, not the Ethernet header, and would reintroduce the small packet regression fixed by commit 63137bc5882a. However, the optional ARP sender hardware address rewrite is different. It writes through skb_store_bits() at an offset relative to skb->data: skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN) skb_header_pointer() only safely reads the ARP header; it does not make the later sender hardware address range writable. If that range is still held in a nonlinear skb fragment backed by a splice-imported file page, skb_store_bits() maps the frag page and copies the new MAC address directly into it. Ensure the ARP SHA range is writable before reading the ARP header and before calling skb_store_bits().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: make ebt_snat ARP rewrite writable\n\nThe ebtables SNAT target keeps the Ethernet source address rewrite\nbehind skb_ensure_writable(skb, 0). This is intentional: at the bridge\nebtables hooks the Ethernet header is addressed through\nskb_mac_header()/eth_hdr(), while skb->data points at the Ethernet\npayload. Asking skb_ensure_writable() for ETH_HLEN bytes would check\nthe payload, not the Ethernet header, and would reintroduce the small\npacket regression fixed by commit 63137bc5882a.\n\nHowever, the optional ARP sender hardware address rewrite is different.\nIt writes through skb_store_bits() at an offset relative to skb->data:\n\n skb_store_bits(skb, sizeof(struct arphdr), info->mac, ETH_ALEN)\n\nskb_header_pointer() only safely reads the ARP header; it does not make\nthe later sender hardware address range writable. If that range is\nstill held in a nonlinear skb fragment backed by a splice-imported file\npage, skb_store_bits() maps the frag page and copies the new MAC address\ndirectly into it.\n\nEnsure the ARP SHA range is writable before reading the ARP header and\nbefore calling skb_store_bits().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02245 |
almalinux: CVE-2026-53266 was patched at 2026-07-08, 2026-07-14
altlinux: CVE-2026-53266 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53266 was patched at 2026-07-14
oraclelinux: CVE-2026-53266 was patched at 2026-07-14
redhat: CVE-2026-53266 was patched at 2026-07-08, 2026-07-14
1391.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53354) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: arm64: errata: Mitigate TLBI errata on various Arm CPUs A number of CPUs developed by Arm suffer from errata whereby a broadcast TLBI;DSB sequence may complete before the global observation of writes which are translated by an affected TLB entry. These errata ONLY affect the completion of memory accesses which have been translated by an invalidated TLB entry, and these errata DO NOT affect the actual invalidation of TLB entries. TLB entries are removed correctly. This issue has been assigned CVE ID CVE-2025-10263. To mitigate this issue, Arm recommends that software follows any affected TLBI;DSB sequence with an additional TLBI;DSB, which will ensure that all memory write effects affected by the first TLBI have been globally observed. The additional TLBI can use any operation that is broadcast to affected CPUs, and the additional DSB can use any option that is sufficient to complete the additional TLBI. The ARM64_WORKAROUND_REPEAT_TLBI workaround is sufficient to mitigate the issue. Enable this workaround for affected CPUs, and update the silicon errata documentation accordingly. Note that due to the manner in which Arm develops IP and tracks errata, some CPUs share a common erratum number.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\narm64: errata: Mitigate TLBI errata on various Arm CPUs\n\nA number of CPUs developed by Arm suffer from errata whereby a broadcast\nTLBI;DSB sequence may complete before the global observation of writes\nwhich are translated by an affected TLB entry.\n\nThese errata ONLY affect the completion of memory accesses which have\nbeen translated by an invalidated TLB entry, and these errata DO NOT\naffect the actual invalidation of TLB entries. TLB entries are removed\ncorrectly.\n\nThis issue has been assigned CVE ID CVE-2025-10263.\n\nTo mitigate this issue, Arm recommends that software follows any\naffected TLBI;DSB sequence with an additional TLBI;DSB, which will\nensure that all memory write effects affected by the first TLBI have\nbeen globally observed. The additional TLBI can use any operation that\nis broadcast to affected CPUs, and the additional DSB can use any option\nthat is sufficient to complete the additional TLBI.\n\nThe ARM64_WORKAROUND_REPEAT_TLBI workaround is sufficient to mitigate\nthe issue. Enable this workaround for affected CPUs, and update the\nsilicon errata documentation accordingly.\n\nNote that due to the manner in which Arm develops IP and tracks errata,\nsome CPUs share a common erratum number.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02389 |
altlinux: CVE-2026-53354 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-07, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53354 was patched at 2026-07-14
ubuntu: CVE-2026-53354 was patched at 2026-07-30
1392.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53366) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv4: account for fraggap on the paged allocation path In __ip_append_data(), when the paged-allocation branch is taken, alloclen and pagedlen are computed as \talloclen = fragheaderlen + transhdrlen; \tpagedlen = datalen - transhdrlen; datalen already includes fraggap, but the fraggap bytes carried over from the previous skb are copied into the new skb's linear area at offset transhdrlen by the subsequent skb_copy_and_csum_bits(). The linear area is therefore undersized by fraggap bytes while pagedlen is overstated by the same amount. The non-paged branch sets alloclen to fraglen, which already accounts for fraggap because datalen does. Bring the paged branch in line by adding fraggap to alloclen and subtracting it from pagedlen. After this adjustment, copy no longer collapses to -fraggap on the paged path, so remove the stale comment describing that old arithmetic.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: account for fraggap on the paged allocation path\n\nIn __ip_append_data(), when the paged-allocation branch is taken,\nalloclen and pagedlen are computed as\n\n\talloclen = fragheaderlen + transhdrlen;\n\tpagedlen = datalen - transhdrlen;\n\ndatalen already includes fraggap, but the fraggap bytes carried over\nfrom the previous skb are copied into the new skb's linear area at\noffset transhdrlen by the subsequent skb_copy_and_csum_bits(). The\nlinear area is therefore undersized by fraggap bytes while pagedlen is\noverstated by the same amount.\n\nThe non-paged branch sets alloclen to fraglen, which already accounts\nfor fraggap because datalen does. Bring the paged branch in line by\nadding fraggap to alloclen and subtracting it from pagedlen.\n\nAfter this adjustment, copy no longer collapses to -fraggap on the\npaged path, so remove the stale comment describing that old arithmetic.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00171, EPSS Percentile is 0.06759 |
almalinux: CVE-2026-53366 was patched at 2026-07-02
altlinux: CVE-2026-53366 was patched at 2026-07-04, 2026-07-06, 2026-07-07, 2026-07-24, 2026-07-25
debian: CVE-2026-53366 was patched at 2026-07-14, 2026-07-30
1393.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53374) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allocation GART TLB is flushed after unmapping but not after mapping. Since amdgpu_bo_create_kernel() does not zero-initialize the buffer, when a single PTE is written the TLB may speculatively load other uninitialized entries from the same cacheline. Those garbage entries can appear valid, and a subsequent write to another PTE in the same cacheline may cause the GPU to use a stale garbage PTE from the TLB. Fix this by calling memset_io() to zero-initialize the GART table with gart_pte_flags immediately after allocation. Using AMDGPU_GEM_CREATE_VRAM_CLEARED, SDMA-based clear will not work since SDMA needs GART to be initialized to work. (cherry picked from commit d9af8263b82b6eaa60c5718e0c6631c5037e4b24)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: zero-initialize GART table on allocation\n\nGART TLB is flushed after unmapping but not after mapping. Since\namdgpu_bo_create_kernel() does not zero-initialize the buffer, when a\nsingle PTE is written the TLB may speculatively load other uninitialized\nentries from the same cacheline. Those garbage entries can appear valid,\nand a subsequent write to another PTE in the same cacheline may cause the\nGPU to use a stale garbage PTE from the TLB.\n\nFix this by calling memset_io() to zero-initialize the GART table with\ngart_pte_flags immediately after allocation.\n\nUsing AMDGPU_GEM_CREATE_VRAM_CLEARED, SDMA-based clear will not work\nsince SDMA needs GART to be initialized to work.\n\n(cherry picked from commit d9af8263b82b6eaa60c5718e0c6631c5037e4b24)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02178 |
debian: CVE-2026-53374 was patched at 2026-07-14
ubuntu: CVE-2026-53374 was patched at 2026-07-30
1394.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53375) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vce: Prevent partial address patches In the case that only one of lo/hi is valid, the patching could result in a bad address written to in FW.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vce: Prevent partial address patches\n\nIn the case that only one of lo/hi is valid, the patching could result\nin a bad address written to in FW.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02177 |
debian: CVE-2026-53375 was patched at 2026-07-14
ubuntu: CVE-2026-53375 was patched at 2026-07-30
1395.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63809) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: bpf: use kvfree() for replaced sysctl write buffer proc_sys_call_handler() allocates its temporary sysctl buffer with kvzalloc() and passes it to __cgroup_bpf_run_filter_sysctl(). Since kvzalloc() may fall back to vmalloc() for large allocations, freeing that buffer with kfree() is wrong and can corrupt memory. Use kvfree() to safely handle both kmalloc and kvzalloc()/vmalloc allocations. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1-rc5. Reproduced the bug based on v7.1-rc4 in a QEMU x86_64 guest booted with KASAN and CONFIG_FAILSLAB enabled. To exercise the replacement path, the test tree also included the accompanying fix for the stale ret == 1 check in __cgroup_bpf_run_filter_sysctl(). The reproducer confines failslab injections to the proc_sys_call_handler() range, uses stacktrace-depth=32, and injects fail-nth=1 while writing 8191 bytes to /proc/sys/kernel/domainname from a task in the target cgroup. Under that setup, fail-nth=1 triggered the fault: BUG: unable to handle page fault for address: ffffeb0200024d48 #PF: supervisor read access in kernel mode #PF: error_code(0x0000) - not-present page PGD 0 P4D 0 Oops: Oops: 0000 SMP KASAN NOPTI CPU: 2 UID: 0 PID: 209 Comm: repro_proc_sys_ Not tainted 7.1.0-rc4-00686-g97625979a5d4 PREEMPT(lazy) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014 RIP: 0010:kfree+0x6e/0x510 ... Call Trace: <TASK> ? __cgroup_bpf_run_filter_sysctl+0x626/0xc30 __cgroup_bpf_run_filter_sysctl+0x74d/0xc30 ? __pfx___cgroup_bpf_run_filter_sysctl+0x10/0x10 ? srso_return_thunk+0x5/0x5f ? __kvmalloc_node_noprof+0x345/0x870 ? proc_sys_call_handler+0x250/0x480 ? srso_return_thunk+0x5/0x5f proc_sys_call_handler+0x3a2/0x480 ? __pfx_proc_sys_call_handler+0x10/0x10 ? srso_return_thunk+0x5/0x5f ? selinux_file_permission+0x39f/0x500 ? srso_return_thunk+0x5/0x5f ? lock_is_held_type+0x9e/0x120 vfs_write+0x98e/0x1000 ... </TASK> With this fix applied on top of the same test setup, rerunning the reproducer with fail-nth=1 yields no corresponding Oops reports.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: use kvfree() for replaced sysctl write buffer\n\nproc_sys_call_handler() allocates its temporary sysctl buffer with\nkvzalloc() and passes it to __cgroup_bpf_run_filter_sysctl(). Since\nkvzalloc() may fall back to vmalloc() for large allocations, freeing\nthat buffer with kfree() is wrong and can corrupt memory.\n\nUse kvfree() to safely handle both kmalloc and kvzalloc()/vmalloc\nallocations.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1-rc5.\n\nReproduced the bug based on v7.1-rc4 in a QEMU x86_64 guest booted with\nKASAN and CONFIG_FAILSLAB enabled. To exercise the replacement path, the\ntest tree also included the accompanying fix for the stale ret == 1\ncheck in __cgroup_bpf_run_filter_sysctl(). The reproducer confines\nfailslab injections to the proc_sys_call_handler() range, uses\nstacktrace-depth=32, and injects fail-nth=1 while writing 8191 bytes to\n/proc/sys/kernel/domainname from a task in the target cgroup. Under\nthat setup, fail-nth=1 triggered the fault:\n\n BUG: unable to handle page fault for address: ffffeb0200024d48\n #PF: supervisor read access in kernel mode\n #PF: error_code(0x0000) - not-present page\n PGD 0 P4D 0\n Oops: Oops: 0000 SMP KASAN NOPTI\n CPU: 2 UID: 0 PID: 209 Comm: repro_proc_sys_ Not tainted 7.1.0-rc4-00686-g97625979a5d4 PREEMPT(lazy)\n Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.15.0-1 04/01/2014\n RIP: 0010:kfree+0x6e/0x510\n ...\n Call Trace:\n <TASK>\n ? __cgroup_bpf_run_filter_sysctl+0x626/0xc30\n __cgroup_bpf_run_filter_sysctl+0x74d/0xc30\n ? __pfx___cgroup_bpf_run_filter_sysctl+0x10/0x10\n ? srso_return_thunk+0x5/0x5f\n ? __kvmalloc_node_noprof+0x345/0x870\n ? proc_sys_call_handler+0x250/0x480\n ? srso_return_thunk+0x5/0x5f\n proc_sys_call_handler+0x3a2/0x480\n ? __pfx_proc_sys_call_handler+0x10/0x10\n ? srso_return_thunk+0x5/0x5f\n ? selinux_file_permission+0x39f/0x500\n ? srso_return_thunk+0x5/0x5f\n ? lock_is_held_type+0x9e/0x120\n vfs_write+0x98e/0x1000\n ...\n </TASK>\n\nWith this fix applied on top of the same test setup, rerunning the\nreproducer with fail-nth=1 yields no corresponding Oops reports.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00154, EPSS Percentile is 0.05072 |
debian: CVE-2026-63809 was patched at 2026-07-14, 2026-07-30
1396.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63829) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: ip_gre: require CAP_NET_ADMIN in the device netns for changelink A tunnel changelink() operates on at most two netns, dev_net(dev) and the tunnel link netns t->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in t->net can rewrite a tunnel that lives in t->net. Add rtnl_dev_link_net_capable() next to rtnl_get_net_ns_capable() in net/core/rtnetlink.c. It requires CAP_NET_ADMIN in the link netns and is skipped when the link netns is dev_net(dev), where the rtnl path already checked it. The other patches in this series use the same helper. Gate ipgre_changelink() and erspan_changelink() with it, at the top of the op before any attribute is parsed, because the parsers update live tunnel fields first. ipgre_netlink_parms() sets t->collect_md before ip_tunnel_changelink() runs. Commit 8b484efd5cb4 ("ip6: vti: Use ip6_tnl.net in vti6_siocdevprivate().") added the same check on the ioctl path. This adds it on RTM_NEWLINK.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ip_gre: require CAP_NET_ADMIN in the device netns for changelink\n\nA tunnel changelink() operates on at most two netns, dev_net(dev) and\nthe tunnel link netns t->net. They differ once the device is created in\nor moved to a netns other than the one the request runs in. The rtnl\nchangelink path checks CAP_NET_ADMIN only against dev_net(dev), so a\ncaller privileged there but not in t->net can rewrite a tunnel that\nlives in t->net.\n\nAdd rtnl_dev_link_net_capable() next to rtnl_get_net_ns_capable() in\nnet/core/rtnetlink.c. It requires CAP_NET_ADMIN in the link netns and is\nskipped when the link netns is dev_net(dev), where the rtnl path already\nchecked it. The other patches in this series use the same helper.\n\nGate ipgre_changelink() and erspan_changelink() with it, at the top of\nthe op before any attribute is parsed, because the parsers update live\ntunnel fields first. ipgre_netlink_parms() sets t->collect_md before\nip_tunnel_changelink() runs.\n\nCommit 8b484efd5cb4 ("ip6: vti: Use ip6_tnl.net in\nvti6_siocdevprivate().") added the same check on the ioctl path. This\nadds it on RTM_NEWLINK.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02491 |
debian: CVE-2026-63829 was patched at 2026-07-14
1397.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63865) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: bpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks bpf_lsm_task_to_inode() is called under rcu_read_lock() and bpf_lsm_inet_conn_established() is called from softirq context, so neither hook can be used by sleepable LSM programs.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Drop task_to_inode and inet_conn_established from lsm sleepable hooks\n\nbpf_lsm_task_to_inode() is called under rcu_read_lock() and\nbpf_lsm_inet_conn_established() is called from softirq context, so\nneither hook can be used by sleepable LSM programs.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02246 |
debian: CVE-2026-63865 was patched at 2026-07-14
ubuntu: CVE-2026-63865 was patched at 2026-07-30
1398.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63869) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap When parsing the radiotap header of an injected frame, ieee80211_parse_tx_radiotap() uses the IEEE80211_RADIOTAP_ANTENNA value directly as a shift count: \tinfo->control.antennas |= BIT(*iterator.this_arg); *iterator.this_arg is an 8-bit value taken straight from the frame supplied by userspace, so BIT() can be asked to shift by up to 255. That is undefined behaviour on the unsigned long and is reported by UBSAN: UBSAN: shift-out-of-bounds in net/mac80211/tx.c:2174:30 shift exponent 235 is too large for 64-bit type 'unsigned long' Call Trace: ieee80211_parse_tx_radiotap+0xadb/0x1950 net/mac80211/tx.c:2174 ieee80211_monitor_start_xmit+0xb1f/0x1250 net/mac80211/tx.c:2451 ... packet_sendmsg+0x3eb6/0x50f0 net/packet/af_packet.c:3109 info->control.antennas is a 2-bit bitmap (u8 antennas:2), so only antenna indices 0 and 1 can ever be represented. Ignore any larger value instead of shifting out of bounds.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: mac80211: limit injected antenna index in ieee80211_parse_tx_radiotap\n\nWhen parsing the radiotap header of an injected frame,\nieee80211_parse_tx_radiotap() uses the IEEE80211_RADIOTAP_ANTENNA value\ndirectly as a shift count:\n\n\tinfo->control.antennas |= BIT(*iterator.this_arg);\n\n*iterator.this_arg is an 8-bit value taken straight from the frame\nsupplied by userspace, so BIT() can be asked to shift by up to 255. That\nis undefined behaviour on the unsigned long and is reported by UBSAN:\n\n UBSAN: shift-out-of-bounds in net/mac80211/tx.c:2174:30\n shift exponent 235 is too large for 64-bit type 'unsigned long'\n Call Trace:\n ieee80211_parse_tx_radiotap+0xadb/0x1950 net/mac80211/tx.c:2174\n ieee80211_monitor_start_xmit+0xb1f/0x1250 net/mac80211/tx.c:2451\n ...\n packet_sendmsg+0x3eb6/0x50f0 net/packet/af_packet.c:3109\n\ninfo->control.antennas is a 2-bit bitmap (u8 antennas:2), so only antenna\nindices 0 and 1 can ever be represented. Ignore any larger value instead\nof shifting out of bounds.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.6. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11509 |
debian: CVE-2026-63869 was patched at 2026-07-14
1399.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63875) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: arm64: tlb: Flush walk cache when unsharing PMD tables When huge_pmd_unshare() is called to unshare a PMD table, the tlb_unshare_pmd_ptdesc() function sets tlb->unshared_tables=true but the aarch64 tlb_flush() only checked tlb->freed_tables to determine whether to use TLBF_NONE (vae1is, invalidates walk cache) or TLBF_NOWALKCACHE (vale1is, leaf-only). This caused the stale PMD page table entry to remain in the walk cache after unshare, potentially leading to incorrect page table walks. Fix by including unshared_tables in the check, so that when unsharing tables, TLBF_NONE is used and the walk cache is properly invalidated. Here is the detailed distinction between vae1is and vale1is: | Instruction Combination | Actual Invalidation Scope | | ------------------------ | --------------------------------------------------| | `VAE1IS` + TTL=`0` | All entries at all levels (full invalidation) | | `VAE1IS` + TTL=`2` (L2) | Non-leaf at Level 0/1 + leaf at Level 2 | | `VALE1IS` + TTL=`0` | Leaf entries at all levels (non-leaf not cleared) | | `VALE1IS` + TTL=`2` (L2) | Leaf entry at Level 2 only |', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\narm64: tlb: Flush walk cache when unsharing PMD tables\n\nWhen huge_pmd_unshare() is called to unshare a PMD table, the\ntlb_unshare_pmd_ptdesc() function sets tlb->unshared_tables=true\nbut the aarch64 tlb_flush() only checked tlb->freed_tables to\ndetermine whether to use TLBF_NONE (vae1is, invalidates walk\ncache) or TLBF_NOWALKCACHE (vale1is, leaf-only).\n\nThis caused the stale PMD page table entry to remain in the walk cache\nafter unshare, potentially leading to incorrect page table walks.\n\nFix by including unshared_tables in the check, so that when\nunsharing tables, TLBF_NONE is used and the walk cache is properly\ninvalidated.\n\nHere is the detailed distinction between vae1is and vale1is:\n\n| Instruction Combination | Actual Invalidation Scope |\n| ------------------------ | --------------------------------------------------|\n| `VAE1IS` + TTL=`0` | All entries at all levels (full invalidation) |\n| `VAE1IS` + TTL=`2` (L2) | Non-leaf at Level 0/1 + leaf at Level 2 |\n| `VALE1IS` + TTL=`0` | Leaf entries at all levels (non-leaf not cleared) |\n| `VALE1IS` + TTL=`2` (L2) | Leaf entry at Level 2 only |', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06047 |
debian: CVE-2026-63875 was patched at 2026-07-14
ubuntu: CVE-2026-63875 was patched at 2026-07-30
1400.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63879) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix amdgpu_hmm_range_get_pages The notifier sequence must only be read once or otherwise we could work with invalid pages. While at it also fix the coding style, e.g. drop the pre-initialized return value and use the common define for 2G range. (cherry picked from commit c08972f555945cda57b0adb72272a37910153390)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu: fix amdgpu_hmm_range_get_pages\n\nThe notifier sequence must only be read once or otherwise we could work\nwith invalid pages.\n\nWhile at it also fix the coding style, e.g. drop the pre-initialized\nreturn value and use the common define for 2G range.\n\n(cherry picked from commit c08972f555945cda57b0adb72272a37910153390)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06169 |
debian: CVE-2026-63879 was patched at 2026-07-14
ubuntu: CVE-2026-63879 was patched at 2026-07-30
1401.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63884) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/i915: Fix potential UAF in TTM object purge TLDR: The bo->ttm object might be changed by calling ttm_bo_validate(), move casting it to an i915_tt object later to actually get the right pointer. A user reported hitting the following bug under heavy use on DG2: [26620.095550] Oops: general protection fault, probably for non-canonical address 0xa56b6b6b6b6b6b8b: 0000 1 SMP NOPTI [26620.095556] CPU: 2 UID: 0 PID: 631 Comm: Xorg Not tainted 6.18.8 #1 PREEMPT(lazy) [26620.095558] Hardware name: ASRock B850M Steel Legend WiFi/B850M Steel Legend WiFi, BIOS 3.50 09/18/2025 [26620.095559] RIP: 0010:i915_ttm_purge+0x84/0x100 [i915] [26620.095604] Code: 00 00 00 48 8d 54 24 10 48 89 e6 48 89 fb e8 83 aa ae ff 85 c0 75 6f 48 83 bb a8 01 00 00 00 74 2c 48 8b 45 78 48 85 c0 74 23 <48> 8b 78 20 48 c7 c2 ff ff ff ff 31 f6 e8 7a 73 e3 e0 48 8b 7d 78 [26620.095605] RSP: 0018:ffffc90005fd7430 EFLAGS: 00010282 [26620.095607] RAX: a56b6b6b6b6b6b6b RBX: ffff8881f46c3dc0 RCX: 0000000000000000 [26620.095608] RDX: 0000000000000000 RSI: 0000000000000246 RDI: 00000000ffffffff [26620.095609] RBP: ffff888289610f00 R08: 0000000000000001 R09: ffff88823b022000 [26620.095609] R10: ffff888103029b28 R11: ffff8881fc7f3800 R12: ffff88810b6150d0 [26620.095609] R13: ffff888289610f00 R14: 0000000000000000 R15: ffff8881f46c3dc0 [26620.095610] FS: 00007f1004d86900(0000) GS:ffff88901c858000(0000) knlGS:0000000000000000 [26620.095611] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [26620.095611] CR2: 00007f0fdf489000 CR3: 000000035b0c1000 CR4: 0000000000750ef0 [26620.095612] PKRU: 55555554 [26620.095612] Call Trace: [26620.095615] <TASK> [26620.095615] i915_ttm_move+0x2b9/0x420 [i915] [26620.095642] ? ttm_tt_init+0x65/0x80 [ttm] [26620.095644] ? i915_ttm_tt_create+0xc6/0x150 [i915] [26620.095667] ttm_bo_handle_move_mem+0xb6/0x160 [ttm] [26620.095669] ttm_bo_evict+0x100/0x150 [ttm] [26620.095671] ? preempt_count_add+0x64/0xa0 [26620.095673] ? _raw_spin_lock+0xe/0x30 [26620.095675] ? _raw_spin_unlock+0xd/0x30 [26620.095675] ? i915_gem_object_evictable+0xb7/0xd0 [i915] [26620.095704] ttm_bo_evict_cb+0x6e/0xd0 [ttm] [26620.095705] ttm_lru_walk_for_evict+0xa6/0x200 [ttm] [26620.095708] ttm_bo_alloc_resource+0x185/0x4f0 [ttm] [26620.095709] ? init_object+0x62/0xd0 [26620.095712] ttm_bo_validate+0x7a/0x180 [ttm] [26620.095713] ? _raw_spin_unlock_irqrestore+0x16/0x30 [26620.095714] __i915_ttm_get_pages+0xb0/0x170 [i915] [26620.095737] i915_ttm_get_pages+0x9f/0x150 [i915] [26620.095759] ? i915_gem_do_execbuffer+0xedc/0x2b40 [i915] [26620.095786] ? alloc_debug_processing+0xd0/0x100 [26620.095787] ? _raw_spin_unlock_irqrestore+0x16/0x30 [26620.095788] ? i915_vma_instance+0xa0/0x4e0 [i915] [26620.095822] __i915_gem_object_get_pages+0x2f/0x40 [i915] [26620.095848] i915_vma_pin_ww+0x706/0x980 [i915] [26620.095875] ? i915_gem_do_execbuffer+0xedc/0x2b40 [i915] [26620.095904] eb_validate_vmas+0x170/0xa00 [i915] [26620.095930] i915_gem_do_execbuffer+0x1201/0x2b40 [i915] [26620.095953] ? alloc_debug_processing+0xd0/0x100 [26620.095954] ? _raw_spin_unlock_irqrestore+0x16/0x30 [26620.095955] ? i915_gem_execbuffer2_ioctl+0xc9/0x240 [i915] [26620.095977] ? __wake_up_sync_key+0x32/0x50 [26620.095979] ? i915_gem_execbuffer2_ioctl+0xc9/0x240 [i915] [26620.096001] ? __slab_alloc.isra.0+0x67/0xc0 [26620.096003] i915_gem_execbuffer2_ioctl+0x11a/0x240 [i915] Results from decode_stacktrace.sh pointed to dereference of a file pointer field of a i915 TTM page vector container associated with an object being purged on eviction. That path is taken when the object is marked as no longer needed. Code analysis revealed a possibility of the i915 TTM page vector container being replaced with a new instance inside a function that purges content of the object, should it be still busy. That function is called, indirectly via a more general function that changes the object's placement and caching policy, ---truncated---', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915: Fix potential UAF in TTM object purge\n\nTLDR: The bo->ttm object might be changed by calling ttm_bo_validate(),\n move casting it to an i915_tt object later to actually get the right\n pointer.\n\nA user reported hitting the following bug under heavy use on DG2:\n\n[26620.095550] Oops: general protection fault, probably for non-canonical address 0xa56b6b6b6b6b6b8b: 0000 1 SMP NOPTI\n[26620.095556] CPU: 2 UID: 0 PID: 631 Comm: Xorg Not tainted 6.18.8 #1 PREEMPT(lazy)\n[26620.095558] Hardware name: ASRock B850M Steel Legend WiFi/B850M Steel Legend WiFi, BIOS 3.50 09/18/2025\n[26620.095559] RIP: 0010:i915_ttm_purge+0x84/0x100 [i915]\n[26620.095604] Code: 00 00 00 48 8d 54 24 10 48 89 e6 48 89 fb e8 83 aa ae ff 85 c0 75 6f 48 83 bb a8 01 00 00 00 74 2c 48 8b 45 78 48 85 c0 74 23 <48> 8b 78 20 48 c7 c2 ff ff ff ff 31 f6 e8 7a 73 e3 e0 48 8b 7d 78\n[26620.095605] RSP: 0018:ffffc90005fd7430 EFLAGS: 00010282\n[26620.095607] RAX: a56b6b6b6b6b6b6b RBX: ffff8881f46c3dc0 RCX: 0000000000000000\n[26620.095608] RDX: 0000000000000000 RSI: 0000000000000246 RDI: 00000000ffffffff\n[26620.095609] RBP: ffff888289610f00 R08: 0000000000000001 R09: ffff88823b022000\n[26620.095609] R10: ffff888103029b28 R11: ffff8881fc7f3800 R12: ffff88810b6150d0\n[26620.095609] R13: ffff888289610f00 R14: 0000000000000000 R15: ffff8881f46c3dc0\n[26620.095610] FS: 00007f1004d86900(0000) GS:ffff88901c858000(0000) knlGS:0000000000000000\n[26620.095611] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[26620.095611] CR2: 00007f0fdf489000 CR3: 000000035b0c1000 CR4: 0000000000750ef0\n[26620.095612] PKRU: 55555554\n[26620.095612] Call Trace:\n[26620.095615] <TASK>\n[26620.095615] i915_ttm_move+0x2b9/0x420 [i915]\n[26620.095642] ? ttm_tt_init+0x65/0x80 [ttm]\n[26620.095644] ? i915_ttm_tt_create+0xc6/0x150 [i915]\n[26620.095667] ttm_bo_handle_move_mem+0xb6/0x160 [ttm]\n[26620.095669] ttm_bo_evict+0x100/0x150 [ttm]\n[26620.095671] ? preempt_count_add+0x64/0xa0\n[26620.095673] ? _raw_spin_lock+0xe/0x30\n[26620.095675] ? _raw_spin_unlock+0xd/0x30\n[26620.095675] ? i915_gem_object_evictable+0xb7/0xd0 [i915]\n[26620.095704] ttm_bo_evict_cb+0x6e/0xd0 [ttm]\n[26620.095705] ttm_lru_walk_for_evict+0xa6/0x200 [ttm]\n[26620.095708] ttm_bo_alloc_resource+0x185/0x4f0 [ttm]\n[26620.095709] ? init_object+0x62/0xd0\n[26620.095712] ttm_bo_validate+0x7a/0x180 [ttm]\n[26620.095713] ? _raw_spin_unlock_irqrestore+0x16/0x30\n[26620.095714] __i915_ttm_get_pages+0xb0/0x170 [i915]\n[26620.095737] i915_ttm_get_pages+0x9f/0x150 [i915]\n[26620.095759] ? i915_gem_do_execbuffer+0xedc/0x2b40 [i915]\n[26620.095786] ? alloc_debug_processing+0xd0/0x100\n[26620.095787] ? _raw_spin_unlock_irqrestore+0x16/0x30\n[26620.095788] ? i915_vma_instance+0xa0/0x4e0 [i915]\n[26620.095822] __i915_gem_object_get_pages+0x2f/0x40 [i915]\n[26620.095848] i915_vma_pin_ww+0x706/0x980 [i915]\n[26620.095875] ? i915_gem_do_execbuffer+0xedc/0x2b40 [i915]\n[26620.095904] eb_validate_vmas+0x170/0xa00 [i915]\n[26620.095930] i915_gem_do_execbuffer+0x1201/0x2b40 [i915]\n[26620.095953] ? alloc_debug_processing+0xd0/0x100\n[26620.095954] ? _raw_spin_unlock_irqrestore+0x16/0x30\n[26620.095955] ? i915_gem_execbuffer2_ioctl+0xc9/0x240 [i915]\n[26620.095977] ? __wake_up_sync_key+0x32/0x50\n[26620.095979] ? i915_gem_execbuffer2_ioctl+0xc9/0x240 [i915]\n[26620.096001] ? __slab_alloc.isra.0+0x67/0xc0\n[26620.096003] i915_gem_execbuffer2_ioctl+0x11a/0x240 [i915]\n\nResults from decode_stacktrace.sh pointed to dereference of a file pointer\nfield of a i915 TTM page vector container associated with an object being\npurged on eviction. That path is taken when the object is marked as no\nlonger needed.\n\nCode analysis revealed a possibility of the i915 TTM page vector container\nbeing replaced with a new instance inside a function that purges content\nof the object, should it be still busy. That function is called,\nindirectly via a more general function that changes the object's placement\nand caching policy,\n---truncated---', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06046 |
debian: CVE-2026-63884 was patched at 2026-07-14
ubuntu: CVE-2026-63884 was patched at 2026-07-30
1402.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63926) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: bpf: sockmap: fix tail fragment offset in bpf_msg_push_data When bpf_msg_push_data() inserts data in the middle of a scatterlist entry, it splits the original entry into a left fragment and a right fragment. The right fragment offset is page-local, but the code advances it with `start`, which is the message-global insertion point. For inserts into a non-first SG entry, this over-advances the offset and leaves the split layout inconsistent. Advance the right fragment offset by the fragment-local delta, `start - offset`, which matches the length removed from the front of the original entry.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: sockmap: fix tail fragment offset in bpf_msg_push_data\n\nWhen bpf_msg_push_data() inserts data in the middle of a scatterlist\nentry, it splits the original entry into a left fragment and a right\nfragment.\n\nThe right fragment offset is page-local, but the code advances it with\n`start`, which is the message-global insertion point. For inserts into a\nnon-first SG entry, this over-advances the offset and leaves the split\nlayout inconsistent.\n\nAdvance the right fragment offset by the fragment-local delta,\n`start - offset`, which matches the length removed from the front of the\noriginal entry.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07858 |
debian: CVE-2026-63926 was patched at 2026-07-14
ubuntu: CVE-2026-63926 was patched at 2026-07-30
1403.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63927) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: dwc2: Fix use after free in debug code We're not allowed to dereference "urb" after calling usb_hcd_giveback_urb() so save the urb->status ahead of time.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: dwc2: Fix use after free in debug code\n\nWe're not allowed to dereference "urb" after calling\nusb_hcd_giveback_urb() so save the urb->status ahead of time.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.05586 |
debian: CVE-2026-63927 was patched at 2026-07-14
ubuntu: CVE-2026-63927 was patched at 2026-07-30
1404.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63952) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: memfd: deny writeable mappings when implying SEAL_WRITE When SEAL_EXEC is added, SEAL_WRITE is implied to make W^X. But the implied seal is set after the check that makes sure the memfd can not have any writable mappings. This means one can use SEAL_EXEC to apply SEAL_WRITE while having writeable mappings. This breaks the contract that SEAL_WRITE provides and can be used by an attacker to pass a memfd that appears to be write sealed but can still be modified arbitrarily. Fix this by adding the implied seals before the call for mapping_deny_writable() is done.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmemfd: deny writeable mappings when implying SEAL_WRITE\n\nWhen SEAL_EXEC is added, SEAL_WRITE is implied to make W^X. But the\nimplied seal is set after the check that makes sure the memfd can not have\nany writable mappings. This means one can use SEAL_EXEC to apply\nSEAL_WRITE while having writeable mappings.\n\nThis breaks the contract that SEAL_WRITE provides and can be used by an\nattacker to pass a memfd that appears to be write sealed but can still be\nmodified arbitrarily.\n\nFix this by adding the implied seals before the call for\nmapping_deny_writable() is done.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.05645 |
debian: CVE-2026-63952 was patched at 2026-07-14
ubuntu: CVE-2026-63952 was patched at 2026-07-30
1405.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63954) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hpfs: fix a crash if hpfs_map_dnode_bitmap fails If hpfs_map_dnode_bitmap fails, the code would call hpfs_brelse4 on uninitialized quad buffer head, causing a crash.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhpfs: fix a crash if hpfs_map_dnode_bitmap fails\n\nIf hpfs_map_dnode_bitmap fails, the code would call hpfs_brelse4 on\nuninitialized quad buffer head, causing a crash.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06047 |
debian: CVE-2026-63954 was patched at 2026-07-14
ubuntu: CVE-2026-63954 was patched at 2026-07-30
1406.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63970) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: bind uarg before filling zerocopy skb virtio_transport_send_pkt_info() allocates or reuses the zerocopy uarg before entering the send loop, but virtio_transport_alloc_skb() still fills the skb before it inherits that uarg. When fixed-buffer vectored zerocopy hits MAX_SKB_FRAGS, io_sg_from_iter() may partially attach managed frags and return -EMSGSIZE. The rollback path call kfree_skb() to free an skb that carries SKBFL_MANAGED_FRAG_REFS but no uarg, so skb_release_data() falls through to ordinary frag unref. Pass the uarg into virtio_transport_alloc_skb() and bind it immediately before virtio_transport_fill_skb(). This keeps control or no-payload skbs untouched while ensuring success and rollback share one lifetime rule.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: bind uarg before filling zerocopy skb\n\nvirtio_transport_send_pkt_info() allocates or reuses the zerocopy uarg\nbefore entering the send loop, but virtio_transport_alloc_skb() still\nfills the skb before it inherits that uarg. When fixed-buffer vectored\nzerocopy hits MAX_SKB_FRAGS, io_sg_from_iter() may partially attach\nmanaged frags and return -EMSGSIZE. The rollback path call kfree_skb()\nto free an skb that carries SKBFL_MANAGED_FRAG_REFS but no uarg, so\nskb_release_data() falls through to ordinary frag unref.\n\nPass the uarg into virtio_transport_alloc_skb() and bind it immediately\nbefore virtio_transport_fill_skb(). This keeps control or no-payload skbs\nuntouched while ensuring success and rollback share one lifetime rule.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.05982 |
debian: CVE-2026-63970 was patched at 2026-07-14
ubuntu: CVE-2026-63970 was patched at 2026-07-30
1407.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63971) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: sctp: fix race between sctp_wait_for_connect and peeloff sctp_wait_for_connect() drops and re-acquires the socket lock while waiting for the association to reach ESTABLISHED state. During this window, another thread can peeloff the association to a new socket via getsockopt(SCTP_SOCKOPT_PEELOFF), changing asoc->base.sk. After re-acquiring the old socket lock, sctp_wait_for_connect() returns success without noticing the migration — the caller then accesses the association under the wrong lock in sctp_datamsg_from_user(). Add the same sk != asoc->base.sk check that sctp_wait_for_sndbuf() already has, returning an error if the association was migrated while we slept.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsctp: fix race between sctp_wait_for_connect and peeloff\n\nsctp_wait_for_connect() drops and re-acquires the socket lock while\nwaiting for the association to reach ESTABLISHED state. During this\nwindow, another thread can peeloff the association to a new socket via\ngetsockopt(SCTP_SOCKOPT_PEELOFF), changing asoc->base.sk. After\nre-acquiring the old socket lock, sctp_wait_for_connect() returns\nsuccess without noticing the migration — the caller then accesses\nthe association under the wrong lock in sctp_datamsg_from_user().\n\nAdd the same sk != asoc->base.sk check that sctp_wait_for_sndbuf()\nalready has, returning an error if the association was migrated while\nwe slept.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06046 |
debian: CVE-2026-63971 was patched at 2026-07-14
ubuntu: CVE-2026-63971 was patched at 2026-07-30
1408.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64018) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: mana: validate rx_req_idx to prevent out-of-bounds array access In mana_hwc_rx_event_handler(), rx_req_idx is derived from sge->address in DMA-coherent memory. In Confidential VMs (SEV-SNP/TDX), this memory is shared unencrypted and HW can modify WQE contents at any time. No bounds check exists on rx_req_idx, which can lead to an out-of-bounds access into reqs[]. Add bounds check on rx_req_idx in mana_hwc_rx_event_handler() before using it to index the reqs[] array.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: validate rx_req_idx to prevent out-of-bounds array access\n\nIn mana_hwc_rx_event_handler(), rx_req_idx is derived from\nsge->address in DMA-coherent memory. In Confidential VMs\n(SEV-SNP/TDX), this memory is shared unencrypted and HW can modify\nWQE contents at any time. No bounds check exists on rx_req_idx,\nwhich can lead to an out-of-bounds access into reqs[].\n\nAdd bounds check on rx_req_idx in mana_hwc_rx_event_handler() before\nusing it to index the reqs[] array.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.03955 |
debian: CVE-2026-64018 was patched at 2026-07-14
ubuntu: CVE-2026-64018 was patched at 2026-07-30
1409.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64034) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer In mana_hwc_rx_event_handler(), resp->response.hwc_msg_id is read from DMA-coherent memory and bounds-checked, then mana_hwc_handle_resp() re-reads the same field from the same DMA buffer for test_bit() and pointer arithmetic. DMA-coherent memory is mapped uncacheable on x86 and is shared, unencrypted, in Confidential VMs (SEV-SNP/TDX), so each load goes directly to host-visible memory. A H/W can modify the value between the check and the use, bypassing the bounds validation. Fix this by reading hwc_msg_id exactly once using READ_ONCE() into a stack-local variable in mana_hwc_rx_event_handler(), and passing the validated value as a parameter to mana_hwc_handle_resp().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: mana: Fix TOCTOU double-fetch of hwc_msg_id from DMA buffer\n\nIn mana_hwc_rx_event_handler(), resp->response.hwc_msg_id is read from\nDMA-coherent memory and bounds-checked, then mana_hwc_handle_resp()\nre-reads the same field from the same DMA buffer for test_bit() and\npointer arithmetic.\n\nDMA-coherent memory is mapped uncacheable on x86 and is shared,\nunencrypted, in Confidential VMs (SEV-SNP/TDX), so each load goes\ndirectly to host-visible memory. A H/W can modify the value\nbetween the check and the use, bypassing the bounds validation.\n\nFix this by reading hwc_msg_id exactly once using READ_ONCE() into a\nstack-local variable in mana_hwc_rx_event_handler(), and passing the\nvalidated value as a parameter to mana_hwc_handle_resp().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00151, EPSS Percentile is 0.04769 |
debian: CVE-2026-64034 was patched at 2026-07-14
ubuntu: CVE-2026-64034 was patched at 2026-07-30
1410.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64039) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/msm/snapshot: fix dumping of the unaligned regions The snapshotting code internally aligns data segment to 16 bytes. This works fine for DPU code (where most of the regions are aligned), but fails for snapshotting of the DSI data (because DSI data region is shifted by 4 bytes). Fix the code by removing length alignment and by accurately printing last registers in the region. While reworking the code also fix the 16x memory overallocation in msm_disp_state_dump_regs(). Patchwork: https://patchwork.freedesktop.org/patch/725449/', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/snapshot: fix dumping of the unaligned regions\n\nThe snapshotting code internally aligns data segment to 16 bytes. This\nworks fine for DPU code (where most of the regions are aligned), but\nfails for snapshotting of the DSI data (because DSI data region is\nshifted by 4 bytes). Fix the code by removing length alignment and by\naccurately printing last registers in the region. While reworking the\ncode also fix the 16x memory overallocation in\nmsm_disp_state_dump_regs().\n\nPatchwork: https://patchwork.freedesktop.org/patch/725449/', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07859 |
debian: CVE-2026-64039 was patched at 2026-07-14
ubuntu: CVE-2026-64039 was patched at 2026-07-30
1411.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64095) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: avoid double decrement of bla.num_requests The bla.num_requests is increased when no request_sent was in progress. And it is decremented in various places (announcement was received, backbone is purged, periodic work). But the check if the request_sent is actually set to a specific state and the atomic_dec/_inc are not safe because they are not atomic (TOCTOU) and multiple such code portions can run concurrently. At the same time, it is necessary to modify request_sent (state) and bla.num_requests atomically. Otherwise batadv_bla_send_request() might set request_sent to 1 and is interrupted. batadv_handle_announce() can then set request_sent back to 0 and decrement num_requests before batadv_bla_send_request() incremented it. The two operations must therefore be locked. And since state (request_sent) and wait_periods are only accessed inside this lock, they can be converted to simpler datatypes. And to avoid that the bla.num_requests is touched by a parallel running context with a valid backbone_gw reference after batadv_bla_purge_backbone_gw() ran, a third state "stopped" is required to correctly signal that a backbone_gw is in the state of being cleaned up.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: bla: avoid double decrement of bla.num_requests\n\nThe bla.num_requests is increased when no request_sent was in progress. And\nit is decremented in various places (announcement was received, backbone is\npurged, periodic work). But the check if the request_sent is actually set\nto a specific state and the atomic_dec/_inc are not safe because they are\nnot atomic (TOCTOU) and multiple such code portions can run concurrently.\n\nAt the same time, it is necessary to modify request_sent (state) and\nbla.num_requests atomically. Otherwise batadv_bla_send_request() might set\nrequest_sent to 1 and is interrupted. batadv_handle_announce() can then\nset request_sent back to 0 and decrement num_requests before\nbatadv_bla_send_request() incremented it.\n\nThe two operations must therefore be locked. And since state (request_sent)\nand wait_periods are only accessed inside this lock, they can be converted\nto simpler datatypes. And to avoid that the bla.num_requests is touched by\na parallel running context with a valid backbone_gw reference after\nbatadv_bla_purge_backbone_gw() ran, a third state "stopped" is required to\ncorrectly signal that a backbone_gw is in the state of being cleaned up.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00267, EPSS Percentile is 0.18728 |
debian: CVE-2026-64095 was patched at 2026-07-14
ubuntu: CVE-2026-64095 was patched at 2026-07-30
1412.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64106) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits Userspace can restore an ITS Device Table Entry whose Size field encodes more EventID bits than the virtual ITS supports. The live MAPD path rejects that state, but vgic_its_restore_dte() accepts it and stores the out-of-range value in dev->num_eventid_bits. Reject restored DTEs with num_eventid_bits > VITS_TYPER_IDBITS before allocating the device. This mirrors the MAPD check and prevents the restored state from reaching vgic_its_restore_itt(), where the unchecked value can be converted into an oversized scan_its_table() range.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic-its: Reject restored DTE with out-of-range num_eventid_bits\n\nUserspace can restore an ITS Device Table Entry whose Size field encodes\nmore EventID bits than the virtual ITS supports. The live MAPD path\nrejects that state, but vgic_its_restore_dte() accepts it and stores the\nout-of-range value in dev->num_eventid_bits.\n\nReject restored DTEs with num_eventid_bits > VITS_TYPER_IDBITS before\nallocating the device. This mirrors the MAPD check and prevents the\nrestored state from reaching vgic_its_restore_itt(), where the unchecked\nvalue can be converted into an oversized scan_its_table() range.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 9.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00148, EPSS Percentile is 0.04519 |
debian: CVE-2026-64106 was patched at 2026-07-14
ubuntu: CVE-2026-64106 was patched at 2026-07-30
1413.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64109) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix UAF read of tail->len in unix_stream_data_wait() unix_stream_data_wait() does skb_peek_tail(&sk->sk_receive_queue) without holding any lock that prevents SKBs on that queue from being dequeued and freed. This has been the case since commit 79f632c71bea ("unix/stream: fix peeking with an offset larger than data in queue"). The first consequence of this is that the pointer comparison `tail != last` can be false even if `last` semantically refers to an already-freed SKB while `tail` is a new SKB allocated at the same address; which can cause unix_stream_data_wait() to wrongly keep blocking after new data has arrived, but only in a weird scenario where a peeking recv() and a normal recv() on the same socket are racing, which is probably not a real problem. But since commit 2b514574f7e8 ("net: af_unix: implement splice for stream af_unix sockets"), `tail` is actually dereferenced, which can cause UAF in the following race scenario (where test_setup() runs single-threaded, and afterwards, test_thread1() and test_thread2() run concurrently in two threads: ``` static int socks[2]; void test_setup(void) { socketpair(AF_UNIX, SOCK_STREAM, 0, socks); send(socks[1], "A", 1, 0); int peekoff = 1; setsockopt(socks[0], SOL_SOCKET, SO_PEEK_OFF, &peekoff, sizeof(peekoff)); } void test_thread1(void) { char dummy; recv(socks[0], &dummy, 1, MSG_PEEK); } void test_thread2(void) { char dummy; recv(socks[0], &dummy, 1, 0); shutdown(socks[1], SHUT_WR); } ``` when racing like this: ``` thread1 thread2 unix_stream_read_generic mutex_lock(&u->iolock) skb_peek(&sk->sk_receive_queue) skb_peek_next(skb, &sk->sk_receive_queue) mutex_unlock(&u->iolock) unix_stream_read_generic unix_state_lock(sk) skb_peek(&sk->sk_receive_queue) unix_state_unlock(sk) unix_stream_data_wait unix_state_lock(sk) tail = skb_peek_tail(&sk->sk_receive_queue) spin_lock(&sk->sk_receive_queue.lock) __skb_unlink(skb, &sk->sk_receive_queue) spin_unlock(&sk->sk_receive_queue.lock) consume_skb(skb) [frees the SKB] `tail != last`: false `tail`: true `tail->len != last_len` ***UAF*** ``` Fix the UAF by removing the read of tail->len; checking tail->len would only make sense if SKBs in the receive queue of a UNIX socket could grow, which can no longer happen. Kuniyuki explained: > When commit 869e7c62486e ("net: af_unix: implement stream sendpage > support") added sendpage() support, data could be appended to the last > skb in the receiver's queue. > > That's why we needed to check if the length of the last skb was changed > while waiting for new data in unix_stream_data_wait(). > > However, commit a0dbf5f818f9 ("af_unix: Support MSG_SPLICE_PAGES") and > commit 57d44a354a43 ("unix: Convert unix_stream_sendpage() to use > MSG_SPLICE_PAGES") refactored sendmsg(), and now data is always added > to a new skb. That means this fix is not suitable for kernels before 6.5.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Fix UAF read of tail->len in unix_stream_data_wait()\n\nunix_stream_data_wait() does skb_peek_tail(&sk->sk_receive_queue) without\nholding any lock that prevents SKBs on that queue from being dequeued and\nfreed.\nThis has been the case since commit 79f632c71bea ("unix/stream: fix\npeeking with an offset larger than data in queue").\nThe first consequence of this is that the pointer comparison\n`tail != last` can be false even if `last` semantically refers to an\nalready-freed SKB while `tail` is a new SKB allocated at the same address;\nwhich can cause unix_stream_data_wait() to wrongly keep blocking after new\ndata has arrived, but only in a weird scenario where a peeking recv() and\na normal recv() on the same socket are racing, which is probably not a\nreal problem.\n\nBut since commit 2b514574f7e8 ("net: af_unix: implement splice for stream\naf_unix sockets"), `tail` is actually dereferenced, which can cause UAF in\nthe following race scenario (where test_setup() runs single-threaded,\nand afterwards, test_thread1() and test_thread2() run concurrently in\ntwo threads:\n```\nstatic int socks[2];\nvoid test_setup(void) {\n socketpair(AF_UNIX, SOCK_STREAM, 0, socks);\n send(socks[1], "A", 1, 0);\n int peekoff = 1;\n setsockopt(socks[0], SOL_SOCKET, SO_PEEK_OFF, &peekoff, sizeof(peekoff));\n}\nvoid test_thread1(void) {\n char dummy;\n recv(socks[0], &dummy, 1, MSG_PEEK);\n}\nvoid test_thread2(void) {\n char dummy;\n recv(socks[0], &dummy, 1, 0);\n shutdown(socks[1], SHUT_WR);\n}\n```\n\nwhen racing like this:\n```\nthread1 thread2\nunix_stream_read_generic\n mutex_lock(&u->iolock)\n skb_peek(&sk->sk_receive_queue)\n skb_peek_next(skb, &sk->sk_receive_queue)\n mutex_unlock(&u->iolock)\n unix_stream_read_generic\n unix_state_lock(sk)\n skb_peek(&sk->sk_receive_queue)\n unix_state_unlock(sk)\n unix_stream_data_wait\n unix_state_lock(sk)\n tail = skb_peek_tail(&sk->sk_receive_queue)\n spin_lock(&sk->sk_receive_queue.lock)\n __skb_unlink(skb, &sk->sk_receive_queue)\n spin_unlock(&sk->sk_receive_queue.lock)\n consume_skb(skb) [frees the SKB]\n `tail != last`: false\n `tail`: true\n `tail->len != last_len` ***UAF***\n```\n\nFix the UAF by removing the read of tail->len; checking tail->len would\nonly make sense if SKBs in the receive queue of a UNIX socket could grow,\nwhich can no longer happen.\n\nKuniyuki explained:\n\n> When commit 869e7c62486e ("net: af_unix: implement stream sendpage\n> support") added sendpage() support, data could be appended to the last\n> skb in the receiver's queue.\n>\n> That's why we needed to check if the length of the last skb was changed\n> while waiting for new data in unix_stream_data_wait().\n>\n> However, commit a0dbf5f818f9 ("af_unix: Support MSG_SPLICE_PAGES") and\n> commit 57d44a354a43 ("unix: Convert unix_stream_sendpage() to use\n> MSG_SPLICE_PAGES") refactored sendmsg(), and now data is always added\n> to a new skb.\n\nThat means this fix is not suitable for kernels before 6.5.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02906 |
debian: CVE-2026-64109 was patched at 2026-07-14
ubuntu: CVE-2026-64109 was patched at 2026-07-30
1414.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64153) - Medium [257]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/msm: Fix iommu_map_sgtable() return value check and avoid WARN Commit "iommu: return full error code from iommu_map_sg[_atomic]()" changed iommu_map_sgtable() to return an ssize_t and negative values in error cases, rather than a size_t and a zero. Store the return value in the appropriate type and in case of error, return it rather than WARNing. Patchwork: https://patchwork.freedesktop.org/patch/719685/', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm: Fix iommu_map_sgtable() return value check and avoid WARN\n\nCommit "iommu: return full error code from iommu_map_sg[_atomic]()"\nchanged iommu_map_sgtable() to return an ssize_t and negative values\nin error cases, rather than a size_t and a zero.\n\nStore the return value in the appropriate type and in case of error,\nreturn it rather than WARNing.\n\nPatchwork: https://patchwork.freedesktop.org/patch/719685/', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00139, EPSS Percentile is 0.03704 |
debian: CVE-2026-64153 was patched at 2026-07-14
ubuntu: CVE-2026-64153 was patched at 2026-07-30
1415.
Denial of Service - Unknown Product (CVE-2026-11946) - Medium [255]
Description: {'nvd_cve_data_all': 'An unauthenticated remote attacker can exhaust server memory via the GetEndpoints Discovery Service in open62541. The endpointUrl field of GetEndpointsRequest is not validated for length. An attacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32 length field) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out. The attack is pre-session and bypasses all encryption configurations. The issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An unauthenticated remote attacker can exhaust\nserver memory via the GetEndpoints Discovery Service in open62541. The\nendpointUrl field of GetEndpointsRequest is not validated for length. An\nattacker can declare an arbitrarily large string (up to ~4.09 GB via the UInt32\nlength field) delivered across intermediate chunks without ever sending the\nfinal chunk. The server buffers all chunks in RAM indefinitely until the\nSecureChannel times out. The attack is\npre-session and bypasses all encryption configurations.\n\n\n\nThe\xa0issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00381, EPSS Percentile is 0.30804 |
debian: CVE-2026-11946 was patched at 2026-07-14
1416.
Denial of Service - Unknown Product (CVE-2026-33592) - Medium [255]
Description: {'nvd_cve_data_all': 'An unauthenticated remote attacker can exhaust server memory via the FindServers Discovery Service in open62541. The serverUris field of FindServersRequest is not validated for length or array size. An attacker can declare an arbitrarily large string (up to ~3.9 GB) delivered across intermediate chunks without ever sending the final chunk. The server buffers all chunks in RAM indefinitely until the SecureChannel times out. The attack is pre-session and bypasses all encryption configuration. The issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An unauthenticated remote attacker can exhaust\nserver memory via the FindServers Discovery Service in open62541. The\nserverUris field of FindServersRequest is not validated for length or array\nsize. An attacker can declare an arbitrarily large string (up to ~3.9 GB)\ndelivered across intermediate chunks without ever sending the final chunk. The\nserver buffers all chunks in RAM indefinitely until the SecureChannel times\nout. The attack is pre-session and bypasses all encryption configuration. The\xa0issue affects open62541: from 1.4.0 through 1.4.16, from 1.5.0 through 1.5.4, master.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00382, EPSS Percentile is 0.30941 |
debian: CVE-2026-33592 was patched at 2026-07-14
1417.
Denial of Service - Unknown Product (CVE-2026-56770) - Medium [255]
Description: {'nvd_cve_data_all': 'libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range sequential message IDs. Remote attackers can crash services or vessel systems by sending crafted AIVDM sentences over VHF marine radio or IP feeds, causing out-of-bounds memory access and potential corruption.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libais through 0.15 VdmStream::AddLine uses an unchecked sentinel value as a vector index when processing AIS sentences with empty or out-of-range sequential message IDs. Remote attackers can crash services or vessel systems by sending crafted AIVDM sentences over VHF marine radio or IP feeds, causing out-of-bounds memory access and potential corruption.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00339, EPSS Percentile is 0.2655 |
debian: CVE-2026-56770 was patched at 2026-07-14
1418.
Denial of Service - Unknown Product (CVE-2026-59692) - Medium [255]
Description: {'nvd_cve_data_all': 'A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A stack buffer overflow vulnerability was found in GStreamer's DTLS plugin. During a DTLS handshake, the peer certificate Subject Distinguished Name is printed into a fixed-size 2048-byte stack buffer without bounds checking. A remote unauthenticated attacker can send a certificate with an oversized Subject DN that exceeds the buffer, causing a stack buffer overflow and process crash, resulting in denial of service.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00328, EPSS Percentile is 0.25335 |
altlinux: CVE-2026-59692 was patched at 2026-07-09
debian: CVE-2026-59692 was patched at 2026-07-14
oraclelinux: CVE-2026-59692 was patched at 2026-07-28, 2026-07-29
redhat: CVE-2026-59692 was patched at 2026-07-30
1419.
Denial of Service - gstreamer (CVE-2026-12892) - Medium [255]
Description: A flaw was found in GStreamer's gst-plugins-bad package. When processing a specially crafted H.264 video file containing malformed MVC or SVC extension slice NAL units, a 1-byte heap out-of-bounds read can occur during parsing. This happens when the parser attempts to check slice boundary information without first verifying that the NAL unit contains enough data beyond the extension header. An attacker could exploit this by tricking a user into opening a malicious H.264 video file, potentially causing the application
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by a:gstreamer:gstreamer (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01972 |
debian: CVE-2026-12892 was patched at 2026-07-14
1420.
Incorrect Calculation - Wget (CVE-2026-58470) - Medium [255]
Description: GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an integer overflow vulnerability in the parse_content_range() function within src/http.c that allows server-controlled values to cause signed integer arithmetic to overflow. Attackers can supply malicious Content-Range header values to trigger undefined behavior and download desynchronization in the affected client.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:gnu:wget (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00247, EPSS Percentile is 0.16111 |
debian: CVE-2026-58470 was patched at 2026-07-14
ubuntu: CVE-2026-58470 was patched at 2026-07-30
1421.
Incorrect Calculation - libexpat (CVE-2026-56403) - Medium [255]
Description: libexpat before 2.8.2 has an integer overflow in storeAtts.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02577 |
debian: CVE-2026-56403 was patched at 2026-06-24, 2026-07-30
1422.
Incorrect Calculation - libexpat (CVE-2026-56404) - Medium [255]
Description: libexpat before 2.8.2 has an integer overflow in addBinding.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02577 |
debian: CVE-2026-56404 was patched at 2026-06-24, 2026-07-30
1423.
Incorrect Calculation - libexpat (CVE-2026-56405) - Medium [255]
Description: libexpat before 2.8.2 has an integer overflow in getAttributeId.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02576 |
debian: CVE-2026-56405 was patched at 2026-06-24, 2026-07-30
1424.
Incorrect Calculation - libexpat (CVE-2026-56406) - Medium [255]
Description: libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03319 |
debian: CVE-2026-56406 was patched at 2026-06-24, 2026-07-30
1425.
Incorrect Calculation - libexpat (CVE-2026-56407) - Medium [255]
Description: libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02513 |
debian: CVE-2026-56407 was patched at 2026-06-24, 2026-07-30
1426.
Incorrect Calculation - libexpat (CVE-2026-56408) - Medium [255]
Description: libexpat before 2.8.2 has an integer overflow in copyString.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02577 |
debian: CVE-2026-56408 was patched at 2026-06-24, 2026-07-30
1427.
Incorrect Calculation - libexpat (CVE-2026-56409) - Medium [255]
Description: xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03352 |
debian: CVE-2026-56409 was patched at 2026-06-24, 2026-07-30
1428.
Incorrect Calculation - libexpat (CVE-2026-56410) - Medium [255]
Description: xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00139, EPSS Percentile is 0.03731 |
debian: CVE-2026-56410 was patched at 2026-06-24, 2026-07-30
1429.
Incorrect Calculation - libexpat (CVE-2026-56411) - Medium [255]
Description: xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00139, EPSS Percentile is 0.03731 |
debian: CVE-2026-56411 was patched at 2026-06-24, 2026-07-30
1430.
Information Disclosure - Unknown Product (CVE-2026-56210) - Medium [255]
Description: {'nvd_cve_data_all': 'A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A heap-buffer-overflow read vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows setting a spatial_layer_id exceeding the configured number of layers. This causes an out-of-bounds heap read of approximately 40,728 bytes when computing a layer context array index. An attacker who can influence SVC encoder parameters in a network-facing service could exploit this for information disclosure (heap content leak) or denial of service (segmentation fault from hitting unmapped memory).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00245, EPSS Percentile is 0.15816 |
debian: CVE-2026-56210 was patched at 2026-06-24
1431.
Memory Corruption - Xrdp (CVE-2026-55639) - Medium [255]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | xrdp is an open source remote desktop protocol server | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.16912 |
altlinux: CVE-2026-55639 was patched at 2026-07-08
debian: CVE-2026-55639 was patched at 2026-07-14
1432.
Memory Corruption - libexpat (CVE-2026-56132) - Medium [255]
Description: In libexpat before 2.8.2, there is a heap-based
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00107, EPSS Percentile is 0.01322 |
debian: CVE-2026-56132 was patched at 2026-06-24, 2026-07-30
1433.
Memory Corruption - nokogiri (CVE-2026-57436) - Medium [255]
Description: Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::Document#root= validated only that the new root was a Nokogiri::XML::Node, allowing a DTD node to be set as the document root. The result is a heap use-after-free during garbage collection or finalization, leading to an invalid memory read or potentially a segfault. This vulnerability is fixed in 1.19.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:nokogiri:nokogiri (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00321, EPSS Percentile is 0.24595 |
debian: CVE-2026-57436 was patched at 2026-07-14
1434.
Memory Corruption - nokogiri (CVE-2026-57437) - Medium [255]
Description: Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, Nokogiri::XML::XPathContext did not keep its source document alive for garbage collection. If an XPathContext outlived its document and the document was collected, evaluating an XPath expression could read invalid memory and potentially segfault. This is only reachable when application code constructs an XPathContext directly and lets the document become unreachable while continuing to use the context. The normal Document#xpath, #css, and related search methods are not affected, and it is not triggerable by malicious document input. This vulnerability is fixed in 1.19.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:nokogiri:nokogiri (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00321, EPSS Percentile is 0.24595 |
debian: CVE-2026-57437 was patched at 2026-07-14
1435.
Memory Corruption - nokogiri (CVE-2026-57438) - Medium [255]
Description: Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitution performed by Nokogiri::XML::Node#do_xinclude replaced each <xi:include> in place, freeing the include node along with its children (such as <xi:fallback> and its descendants) and any namespaces declared on them. If an application had already exposed one of those nodes or namespaces to Ruby, the corresponding Ruby object was left pointing at freed memory. Using the object could result in invalid reads or writes to memory. This vulnerability is fixed in 1.19.4.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:nokogiri:nokogiri (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.6. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00094, EPSS Percentile is 0.00704 |
debian: CVE-2026-57438 was patched at 2026-07-14
1436.
Path Traversal - Spice-vdagent (CVE-2026-57966) - Medium [255]
Description: A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to write arbitrary files to any location on the guest operating system. This occurs because the filename provided by the SPICE host during file transfers is not properly sanitized before being used. An attacker could exploit this to write to sensitive locations with the privileges of the spice-vdagent process, typically the logged-in user. This issue requires the SPICE host to be untrusted or compromised for exploitation.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0.5 | 14 | Product detected by a:spice-space:spice-vdagent (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02708 |
debian: CVE-2026-57966 was patched at 2026-07-14
1437.
Path Traversal - Unknown Product (CVE-2026-52868) - Medium [255]
Description: {'nvd_cve_data_all': 'An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An unauthenticated attacker can read worklist records from a directory outside the intended per-AE worklist storage area. In a multi-area deployment, this can cross departmental or clinic data separation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0041, EPSS Percentile is 0.33729 |
debian: CVE-2026-52868 was patched at 2026-07-14
1438.
Security Feature Bypass - Unknown Product (CVE-2026-33612) - Medium [255]
Description: {'nvd_cve_data_all': 'A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A malicious authoritative server can send a crafted zone via the ZoneToCache function that leads to cache poisoning.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00115, EPSS Percentile is 0.01816 |
debian: CVE-2026-33612 was patched at 2026-06-25, 2026-07-14
1439.
Security Feature Bypass - Unknown Product (CVE-2026-55223) - Medium [255]
Description: {'nvd_cve_data_all': 'c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deserialization gadgets. The JDBC spec's DataSource.getConnection() and ConnectionPoolDataSource.getPooledConnection() match the getXXX() form, so JavaBean libraries treat them as "properties" assumed safe while they actually call into JDBC drivers. Attackers can thus craft malicious DataSource objects whose property lookups invoke vulnerable drivers, then smuggle them in serialized form to where an application deserializes and auto-resolves bean properties — triggering the attack. This requires a susceptible DataSource/ConnectionPoolDataSource and JDBC driver on the CLASSPATH, plus a carrier that auto-looks-up JavaBean properties on = deserialization, most commonly a collection paired with an Apache commons-beanutils Comparator that sorts by bean properties. c3p0 supplied that susceptible DataSource/ConnectionPoolDataSource, which was an essential component of the trigger. This issue has been fixed in version 0.14.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'c3p0 is a JDBC Connection pooling library. In versions prior to 0.14.0, c3p0 in combination with other libraries, can compose to a "sink" for deserialization gadgets. The JDBC spec's DataSource.getConnection() and ConnectionPoolDataSource.getPooledConnection() match the getXXX() form, so JavaBean libraries treat them as "properties" assumed safe while they actually call into JDBC drivers. Attackers can thus craft malicious DataSource objects whose property lookups invoke vulnerable drivers, then smuggle them in serialized form to where an application deserializes and auto-resolves bean properties — triggering the attack. This requires a susceptible DataSource/ConnectionPoolDataSource and JDBC driver on the CLASSPATH, plus a carrier that auto-looks-up JavaBean properties on = deserialization, most commonly a collection paired with an Apache commons-beanutils Comparator that sorts by bean properties. c3p0 supplied that susceptible DataSource/ConnectionPoolDataSource, which was an essential component of the trigger. This issue has been fixed in version 0.14.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00284, EPSS Percentile is 0.20662 |
debian: CVE-2026-55223 was patched at 2026-07-14
1440.
Security Feature Bypass - Unknown Product (CVE-2026-58302) - Medium [255]
Description: {'nvd_cve_data_all': 'rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlopen() by using a user-supplied module name. Insufficient validation of the module name allows path traversal, enabling an unprivileged local user to load an arbitrary shared library. Because the process retains elevated privileges during module loading, this results in local privilege escalation to root.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege escalation. It is installed SUID root and loads shared library modules via dlopen() by using a user-supplied module name. Insufficient validation of the module name allows path traversal, enabling an unprivileged local user to load an arbitrary shared library. Because the process retains elevated privileges during module loading, this results in local privilege escalation to root.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04745 |
debian: CVE-2026-58302 was patched at 2026-07-14
1441.
Unknown Vulnerability Type - Perl (CVE-2026-15043) - Medium [254]
Description: {'nvd_cve_data_all': 'DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text. DBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge operator, and >= was evaluated using Perl's le operator. SQL::Nano is the fallback query engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly. The impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted <=/>= comparison silently returns the wrong rows.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted <= and >= SQL operators on text.\n\nDBI::SQL::Nano, DBI's built-in mini-SQL engine, evaluated WHERE predicates incorrectly in some cases. In the non-numeric string branch of the is_matched method, <= was evaluated using Perl's ge operator, and >= was evaluated using Perl's le operator.\n\nSQL::Nano is the fallback query engine for DBI's file-backed drivers (DBD::File, DBD::DBM, CSV-style drivers) whenever SQL::Statement is not installed, and is forced whenever DBI_SQL_NANO=1. Queries over such tables use these predicates directly.\n\nThe impact depends on the context. Where an application relies on a WHERE clause to filter file-backed data for policy or authorization, an inverted <=/>= comparison silently returns the wrong rows.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00387, EPSS Percentile is 0.31427 |
debian: CVE-2026-15043 was patched at 2026-07-14
1442.
Spoofing - Chromium (CVE-2026-13982) - Medium [252]
Description: Incorrect security UI in Passwords in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10693 |
altlinux: CVE-2026-13982 was patched at 2026-07-03
debian: CVE-2026-13982 was patched at 2026-07-05, 2026-07-14
1443.
Spoofing - Chromium (CVE-2026-14133) - Medium [252]
Description: Race in History Embeddings in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00149, EPSS Percentile is 0.0462 |
altlinux: CVE-2026-14133 was patched at 2026-07-03
debian: CVE-2026-14133 was patched at 2026-07-05, 2026-07-14
1444.
Spoofing - Chromium (CVE-2026-14144) - Medium [252]
Description: Incorrect security UI in Views in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.4 | 15 | Spoofing | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00136, EPSS Percentile is 0.03509 |
altlinux: CVE-2026-14144 was patched at 2026-07-03
debian: CVE-2026-14144 was patched at 2026-07-05, 2026-07-14
1445.
Unknown Vulnerability Type - Keycloak (CVE-2026-9099) - Medium [252]
Description: {'nvd_cve_data_all': 'A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited administrative privileges to reparent any existing group. When Fine-Grained Admin Permissions v2 (FGAPv2) is enabled, an attacker with management rights over a single low-privilege group can reparent a highly privileged group (such as one possessing the realm-admin role) under their managed group. Because group permissions follow a hierarchical structure, this action unauthorizedly grants the attacker management and password-reset capabilities over the members of the targeted privileged group. An attacker can exploit this to reset an administrator's password, compromise the account, and achieve a full realm takeover, leading to a complete compromise of confidentiality, integrity, and availability.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in Keycloak. A missing authorization check in the GroupResource.addChild() endpoint within the Admin REST API allows an authenticated user with limited administrative privileges to reparent any existing group. When Fine-Grained Admin Permissions v2 (FGAPv2) is enabled, an attacker with management rights over a single low-privilege group can reparent a highly privileged group (such as one possessing the realm-admin role) under their managed group.\n\nBecause group permissions follow a hierarchical structure, this action unauthorizedly grants the attacker management and password-reset capabilities over the members of the targeted privileged group. An attacker can exploit this to reset an administrator's password, compromise the account, and achieve a full realm takeover, leading to a complete compromise of confidentiality, integrity, and availability.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.8 | 10 | CVSS Base Score is 7.7. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00289, EPSS Percentile is 0.21152 |
altlinux: CVE-2026-9099 was patched at 2026-06-28, 2026-07-01, 2026-07-02
1446.
Memory Corruption - Linux Kernel (CVE-2023-53779) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00032, EPSS Percentile is 0.08845 |
redos: CVE-2023-53779 was patched at 2026-07-01
1447.
Memory Corruption - Linux Kernel (CVE-2025-40144) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00032, EPSS Percentile is 0.05082 |
redos: CVE-2025-40144 was patched at 2026-06-29
1448.
Memory Corruption - Linux Kernel (CVE-2026-63810) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06994 |
debian: CVE-2026-63810 was patched at 2026-07-14
1449.
Memory Corruption - Linux Kernel (CVE-2026-63821) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.05329 |
debian: CVE-2026-63821 was patched at 2026-07-14
1450.
Memory Corruption - Linux Kernel (CVE-2026-63826) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.05329 |
debian: CVE-2026-63826 was patched at 2026-07-14
1451.
Memory Corruption - Linux Kernel (CVE-2026-63876) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00209, EPSS Percentile is 0.11231 |
debian: CVE-2026-63876 was patched at 2026-07-14
ubuntu: CVE-2026-63876 was patched at 2026-07-30
1452.
Memory Corruption - Linux Kernel (CVE-2026-63877) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00209, EPSS Percentile is 0.1123 |
debian: CVE-2026-63877 was patched at 2026-07-14
ubuntu: CVE-2026-63877 was patched at 2026-07-30
1453.
Memory Corruption - Linux Kernel (CVE-2026-63882) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.10803 |
debian: CVE-2026-63882 was patched at 2026-07-14
ubuntu: CVE-2026-63882 was patched at 2026-07-30
1454.
Memory Corruption - Linux Kernel (CVE-2026-63898) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11449 |
debian: CVE-2026-63898 was patched at 2026-07-14
ubuntu: CVE-2026-63898 was patched at 2026-07-30
1455.
Memory Corruption - Linux Kernel (CVE-2026-63899) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11452 |
debian: CVE-2026-63899 was patched at 2026-07-14
ubuntu: CVE-2026-63899 was patched at 2026-07-30
1456.
Memory Corruption - Linux Kernel (CVE-2026-63901) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11447 |
debian: CVE-2026-63901 was patched at 2026-07-14
ubuntu: CVE-2026-63901 was patched at 2026-07-30
1457.
Memory Corruption - Linux Kernel (CVE-2026-63904) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.1145 |
debian: CVE-2026-63904 was patched at 2026-07-14
ubuntu: CVE-2026-63904 was patched at 2026-07-30
1458.
Memory Corruption - Linux Kernel (CVE-2026-63905) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11449 |
debian: CVE-2026-63905 was patched at 2026-07-14
ubuntu: CVE-2026-63905 was patched at 2026-07-30
1459.
Memory Corruption - Linux Kernel (CVE-2026-63928) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11447 |
debian: CVE-2026-63928 was patched at 2026-07-14
ubuntu: CVE-2026-63928 was patched at 2026-07-30
1460.
Memory Corruption - Linux Kernel (CVE-2026-63956) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11453 |
debian: CVE-2026-63956 was patched at 2026-07-14
ubuntu: CVE-2026-63956 was patched at 2026-07-30
1461.
Memory Corruption - Linux Kernel (CVE-2026-63957) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11453 |
debian: CVE-2026-63957 was patched at 2026-07-14
ubuntu: CVE-2026-63957 was patched at 2026-07-30
1462.
Memory Corruption - Linux Kernel (CVE-2026-63973) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.10803 |
debian: CVE-2026-63973 was patched at 2026-07-14
ubuntu: CVE-2026-63973 was patched at 2026-07-30
1463.
Memory Corruption - Linux Kernel (CVE-2026-63991) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07458 |
debian: CVE-2026-63991 was patched at 2026-07-14
ubuntu: CVE-2026-63991 was patched at 2026-07-30
1464.
Memory Corruption - Linux Kernel (CVE-2026-64014) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07455 |
debian: CVE-2026-64014 was patched at 2026-07-14
ubuntu: CVE-2026-64014 was patched at 2026-07-30
1465.
Memory Corruption - Linux Kernel (CVE-2026-64103) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07457 |
debian: CVE-2026-64103 was patched at 2026-07-14
ubuntu: CVE-2026-64103 was patched at 2026-07-30
1466.
Memory Corruption - Linux Kernel (CVE-2026-64139) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.0828 |
debian: CVE-2026-64139 was patched at 2026-07-14
ubuntu: CVE-2026-64139 was patched at 2026-07-30
1467.
Memory Corruption - Linux Kernel (CVE-2026-64165) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06879 |
debian: CVE-2026-64165 was patched at 2026-07-14
ubuntu: CVE-2026-64165 was patched at 2026-07-30
1468.
Memory Corruption - Linux Kernel (CVE-2026-64183) - Medium [251]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06027 |
debian: CVE-2026-64183 was patched at 2026-07-14
ubuntu: CVE-2026-64183 was patched at 2026-07-30
1469.
Denial of Service - ImageMagick (CVE-2026-61464) - Medium [248]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.2 | 10 | CVSS Base Score is 1.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00092, EPSS Percentile is 0.00619 |
debian: CVE-2026-61464 was patched at 2026-07-14, 2026-07-23
1470.
Unknown Vulnerability Type - Apache Tomcat (CVE-2026-53404) - Medium [247]
Description: {'nvd_cve_data_all': 'Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.\n\nUsers are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Apache Tomcat is a free and open-source implementation of the Jakarta Servlet, Jakarta Expression Language, and WebSocket technologies | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.0058, EPSS Percentile is 0.44394 |
altlinux: CVE-2026-53404 was patched at 2026-06-24, 2026-07-10, 2026-07-20
debian: CVE-2026-53404 was patched at 2026-07-14
redhat: CVE-2026-53404 was patched at 2026-07-22
ubuntu: CVE-2026-53404 was patched at 2026-07-30
1471.
Unknown Vulnerability Type - MinIO (CVE-2026-33419) - Medium [247]
Description: {'nvd_cve_data_all': 'MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security Token Service) AssumeRoleWithLDAPIdentity endpoint is vulnerable to LDAP credential brute-forcing due to two combined weaknesses: (1) distinguishable error responses that enable username enumeration, and (2) absence of rate limiting on authentication attempts. An unauthenticated network attacker can enumerate valid LDAP usernames and then perform unlimited password guessing to obtain temporary AWS-style STS credentials, gaining access to the victim's S3 buckets and objects. This issue has been patched in RELEASE.2026-03-17T21-25-16Z.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'MinIO is a high-performance object storage system. Prior to RELEASE.2026-03-17T21-25-16Z, MinIO AIStor's STS (Security Token Service) AssumeRoleWithLDAPIdentity endpoint is vulnerable to LDAP credential brute-forcing due to two combined weaknesses: (1) distinguishable error responses that enable username enumeration, and (2) absence of rate limiting on authentication attempts. An unauthenticated network attacker can enumerate valid LDAP usernames and then perform unlimited password guessing to obtain temporary AWS-style STS credentials, gaining access to the victim's S3 buckets and objects. This issue has been patched in RELEASE.2026-03-17T21-25-16Z.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | MinIO is a high-performance, S3-compatible object storage system designed for large-scale data infrastructure. It supports cloud-native workloads and provides APIs for storing, retrieving, and managing unstructured data such as photos, videos, log files, and backups, with a focus on scalability, speed, and simplicity. | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00394, EPSS Percentile is 0.32112 |
redos: CVE-2026-33419 was patched at 2026-07-14
1472.
Denial of Service - JOSE (CVE-2026-48990) - Medium [246]
Description: joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards. In versions 1.3.4 through 1.6.5, joserfc accepts oversized RFC7797 b64=false JWS payloads without applying JWSRegistry.max_payload_length, which can lead to resource exhaustion. The normal JWS compact and flattened JSON paths reject payloads above the configured payload-size limit with ExceededSizeError. The RFC7797 unencoded payload paths do not make the same check. A valid b64=false compact or flattened JSON JWS can therefore deserialize successfully with a payload larger than JWSRegistry.max_payload_length. Applications that accept lower-trust JWS values and
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.3 | 14 | JavaScript module for JSON Object Signing and Encryption (JOSE) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.05927 |
debian: CVE-2026-48990 was patched at 2026-06-24
1473.
Unknown Vulnerability Type - Django (CVE-2026-48588) - Medium [245]
Description: {'nvd_cve_data_all': 'An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Chris Whyland for reporting this issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.\n`UpdateCacheMiddleware` and the `cache_page()` decorator cache responses that vary on cookies when the incoming request carries unrelated cookies, which allows remote attackers to read private data from the shared cache.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Chris Whyland for reporting this issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | Django is a high-level Python web framework that encourages rapid development and clean, pragmatic design. It provides built-in tools for database models, authentication, URL routing, templates, and security features, making it one of the most widely used frameworks for building scalable and maintainable web applications. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00361, EPSS Percentile is 0.28809 |
altlinux: CVE-2026-48588 was patched at 2026-07-27
debian: CVE-2026-48588 was patched at 2026-07-14
1474.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-52908) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: RDMA: During rereg_mr ensure that REREG_ACCESS is compatible If IB_MR_REREG_ACCESS changes from RO to RW then the umem has to be re-evaluated to ensure it is properly pinned as RW. Since the umem is hidden inside each driver's mr struct add a ib_umem_check_rereg() function that each driver has to call before processing IB_MR_REREG_ACCESS. mlx4 has to retain its duplicate ib_access_writable check because it implements IB_MR_REREG_ACCESS | IB_MR_REREG_TRANS by changing both items in place sequentially while the MR is live, so it will continue to not support this combination.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA: During rereg_mr ensure that REREG_ACCESS is compatible\n\nIf IB_MR_REREG_ACCESS changes from RO to RW then the umem has to be\nre-evaluated to ensure it is properly pinned as RW. Since the umem is\nhidden inside each driver's mr struct add a ib_umem_check_rereg() function\nthat each driver has to call before processing IB_MR_REREG_ACCESS.\n\nmlx4 has to retain its duplicate ib_access_writable check because it\nimplements IB_MR_REREG_ACCESS | IB_MR_REREG_TRANS by changing both items\nin place sequentially while the MR is live, so it will continue to not\nsupport this combination.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02917 |
altlinux: CVE-2026-52908 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-52908 was patched at 2026-06-21, 2026-06-24
1475.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-52909) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ip6_vti: set netns_immutable on the fallback device. john1988 and Noam Rathaus reported that vti6_init_net() does not set the netns_immutable flag on the per-netns fallback tunnel device (ip6_vti0). Other similar tunnel drivers (like ip6_tunnel, sit, ip6_gre, and ip_tunnel) correctly set this flag during their fallback device initialization to prevent them from being moved to another network namespace.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nip6_vti: set netns_immutable on the fallback device.\n\njohn1988 and Noam Rathaus reported that vti6_init_net() does not set the\nnetns_immutable flag on the per-netns fallback tunnel device (ip6_vti0).\n\nOther similar tunnel drivers (like ip6_tunnel, sit, ip6_gre, and ip_tunnel)\ncorrectly set this flag during their fallback device initialization to\nprevent them from being moved to another network namespace.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02174 |
altlinux: CVE-2026-52909 was patched at 2026-06-19, 2026-06-22, 2026-07-04, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-52909 was patched at 2026-06-21, 2026-06-24, 2026-07-14
1476.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53133) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: RDMA/umem: Fix truncation for block sizes >= 4G When the iommu is used the linearization of the mapping can give a single block that is very large split across multiple SG entries. When __rdma_block_iter_next() reassembles the split SG entries it is overflowing the 32 bit stack values and computed the wrong DMA addresses for blocks after the truncation. Use the right types to hold DMA addresses.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/umem: Fix truncation for block sizes >= 4G\n\nWhen the iommu is used the linearization of the mapping can give a single\nblock that is very large split across multiple SG entries.\n\nWhen __rdma_block_iter_next() reassembles the split SG entries it is\noverflowing the 32 bit stack values and computed the wrong DMA addresses\nfor blocks after the truncation.\n\nUse the right types to hold DMA addresses.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02973 |
altlinux: CVE-2026-53133 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53133 was patched at 2026-07-14
1477.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53162) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: memcg: use round-robin victim selection in refill_stock Harry Yoo reported that get_random_u32_below() is not safe to call in the nmi context and memcg charge draining can happen in nmi context. More specifically get_random_u32_below() is neither reentrant- nor NMI-safe: it acquires a per-cpu local_lock via local_lock_irqsave() on the batched_entropy_u32 state. An NMI that lands on a CPU mid-update of the ChaCha batch state and recurses into the random subsystem would corrupt that state. The memcg_stock local_trylock prevents re-entry on the percpu stock itself, but cannot protect an unrelated subsystem's per-cpu lock. Replace the random pick with a per-cpu round-robin counter stored in memcg_stock_pcp and serialized by the same local_trylock that already guards cached[] and nr_pages[]. No atomics, no random calls, no extra locks needed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmemcg: use round-robin victim selection in refill_stock\n\nHarry Yoo reported that get_random_u32_below() is not safe to call in the\nnmi context and memcg charge draining can happen in nmi context.\n\nMore specifically get_random_u32_below() is neither reentrant- nor\nNMI-safe: it acquires a per-cpu local_lock via local_lock_irqsave() on the\nbatched_entropy_u32 state. An NMI that lands on a CPU mid-update of the\nChaCha batch state and recurses into the random subsystem would corrupt\nthat state. The memcg_stock local_trylock prevents re-entry on the percpu\nstock itself, but cannot protect an unrelated subsystem's per-cpu lock.\n\nReplace the random pick with a per-cpu round-robin counter stored in\nmemcg_stock_pcp and serialized by the same local_trylock that already\nguards cached[] and nr_pages[]. No atomics, no random calls, no extra\nlocks needed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02772 |
altlinux: CVE-2026-53162 was patched at 2026-06-19, 2026-06-22, 2026-07-06
1478.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53174) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ovl: keep err zero after successful ovl_cache_get() ovl_iterate_merged() stores PTR_ERR(cache) in err before checking IS_ERR(cache). On success err holds the truncated cache pointer and can be returned as a bogus non-zero error. The syzbot reproducer reaches this through overlay-on-overlay readdir: getdents64 iterate_dir(outer overlay file) ovl_iterate_merged() ovl_cache_get() ovl_dir_read_merged() ovl_dir_read() iterate_dir(inner overlay file) ovl_iterate_merged() Only compute PTR_ERR(cache) on the error path.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\novl: keep err zero after successful ovl_cache_get()\n\novl_iterate_merged() stores PTR_ERR(cache) in err before checking\nIS_ERR(cache). On success err holds the truncated cache pointer and\ncan be returned as a bogus non-zero error.\n\nThe syzbot reproducer reaches this through overlay-on-overlay readdir:\n\n getdents64\n iterate_dir(outer overlay file)\n ovl_iterate_merged()\n ovl_cache_get()\n ovl_dir_read_merged()\n ovl_dir_read()\n iterate_dir(inner overlay file)\n ovl_iterate_merged()\n\nOnly compute PTR_ERR(cache) on the error path.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02193 |
altlinux: CVE-2026-53174 was patched at 2026-06-19
ubuntu: CVE-2026-53174 was patched at 2026-07-30
1479.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53182) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: nl80211: reject oversized EMA RNR lists nl80211_parse_rnr_elems() stores the parsed element count in a u8-backed cfg80211_rnr_elems::cnt field and uses that count to size the flexible array allocation. Reject nested NL80211_ATTR_EMA_RNR_ELEMS input once the count reaches 255, before incrementing it again. This keeps the parser aligned with the data structure it fills and matches the existing bound check used by nl80211_parse_mbssid_elems().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: nl80211: reject oversized EMA RNR lists\n\nnl80211_parse_rnr_elems() stores the parsed element count in a\nu8-backed cfg80211_rnr_elems::cnt field and uses that count to size\nthe flexible array allocation.\n\nReject nested NL80211_ATTR_EMA_RNR_ELEMS input once the count reaches\n255, before incrementing it again. This keeps the parser aligned with\nthe data structure it fills and matches the existing bound check used\nby nl80211_parse_mbssid_elems().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02965 |
altlinux: CVE-2026-53182 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53182 was patched at 2026-07-14
1480.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53189) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: update file PMD counter before folio_put() __split_huge_pmd_locked() updates the file/shmem RSS counter after dropping the PMD mapping's folio reference. If folio_put() drops the last reference, mm_counter_file() can later read freed folio state via folio_test_swapbacked(). Move the counter update before folio_put().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/huge_memory: update file PMD counter before folio_put()\n\n__split_huge_pmd_locked() updates the file/shmem RSS counter after\ndropping the PMD mapping's folio reference. If folio_put() drops the last\nreference, mm_counter_file() can later read freed folio state via\nfolio_test_swapbacked().\n\nMove the counter update before folio_put().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02972 |
altlinux: CVE-2026-53189 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53189 was patched at 2026-07-14
1481.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53191) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: io_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries When a bundle recv retries inside io_recv_finish(), the merge logic OR the saved cflags from the previous iteration with the cflags returned by the new iteration: cflags = req->cqe.flags | (cflags & CQE_F_MASK); Bits listed in CQE_F_MASK are inherited from the new iteration, and all other bits (notably IORING_CQE_F_BUFFER and the buffer ID) come from the saved cflags. Before this change CQE_F_MASK covered only IORING_CQE_F_SOCK_NONEMPTY and IORING_CQE_F_MORE. When using provided buffer rings (IOU_PBUF_RING_INC) with incremental mode, and bundle recv, io_kbuf_inc_commit() can leave the head ring entry partially consumed, __io_put_kbufs() then sets IORING_CQE_F_BUF_MORE on the returned cflags so userspace knows the buffer ID will be reused for subsequent completions. Because IORING_CQE_F_BUF_MORE was not in CQE_F_MASK, the merge above silently dropped it whenever the final retry iteration partially consumed the buffer, and the subsequent req->cqe.flags = cflags & ~CQE_F_MASK save would have left a stale IORING_CQE_F_BUF_MORE in the carried-over cflags had one been present. Userspace would then wrongfully advance it ring head past an entry the kernel still uses. Add IORING_CQE_F_BUF_MORE to CQE_F_MASK so it is both inherited from the new iteration into the user-visible CQE and stripped from the saved cflags between iterations.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/net: inherit IORING_CQE_F_BUF_MORE across bundle recv retries\n\nWhen a bundle recv retries inside io_recv_finish(), the merge logic OR\nthe saved cflags from the previous iteration with the cflags returned by\nthe new iteration:\n cflags = req->cqe.flags | (cflags & CQE_F_MASK);\n\nBits listed in CQE_F_MASK are inherited from the new iteration, and all\nother bits (notably IORING_CQE_F_BUFFER and the buffer ID) come from the\nsaved cflags. Before this change CQE_F_MASK covered only\nIORING_CQE_F_SOCK_NONEMPTY and IORING_CQE_F_MORE.\n\nWhen using provided buffer rings (IOU_PBUF_RING_INC) with incremental\nmode, and bundle recv, io_kbuf_inc_commit() can leave the head ring\nentry partially consumed, __io_put_kbufs() then sets\nIORING_CQE_F_BUF_MORE on the returned cflags so userspace knows the\nbuffer ID will be reused for subsequent completions.\n\nBecause IORING_CQE_F_BUF_MORE was not in CQE_F_MASK, the merge above\nsilently dropped it whenever the final retry iteration partially\nconsumed the buffer, and the subsequent req->cqe.flags = cflags &\n~CQE_F_MASK save would have left a stale IORING_CQE_F_BUF_MORE in the\ncarried-over cflags had one been present. Userspace would then\nwrongfully advance it ring head past an entry the kernel still uses.\n\nAdd IORING_CQE_F_BUF_MORE to CQE_F_MASK so it is both inherited from the\nnew iteration into the user-visible CQE and stripped from the saved\ncflags between iterations.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.0291 |
altlinux: CVE-2026-53191 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53191 was patched at 2026-07-14
1482.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53201) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Revert "drm/xe: Skip exec queue schedule toggle if queue is idle during suspend" This reverts commit 8533051ce92015e9cc6f75e0d52119b9d91610b6. The idle-skip optimization bypasses GuC suspend, so the GPU may not perform the context switch that flushes TLB entries for invalidated userptr VMAs. In LR/preempt-fence VM mode, this can lead to missed TLB invalidation and page faults during userptr invalidation tests. Restore unconditional schedule toggling on suspend so the context-switch TLB flush is always performed. This optimization will be reintroduced with a fix that does not skip suspend in LR/preempt-fence VM mode. (cherry picked from commit 6a1e7934d9a6cf46aecae00a99c2603d1295e170)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRevert "drm/xe: Skip exec queue schedule toggle if queue is idle during suspend"\n\nThis reverts commit 8533051ce92015e9cc6f75e0d52119b9d91610b6.\n\nThe idle-skip optimization bypasses GuC suspend, so the GPU may not\nperform the context switch that flushes TLB entries for invalidated\nuserptr VMAs. In LR/preempt-fence VM mode, this can lead to missed TLB\ninvalidation and page faults during userptr invalidation tests.\n\nRestore unconditional schedule toggling on suspend so the context-switch\nTLB flush is always performed.\n\nThis optimization will be reintroduced with a fix that does not skip\nsuspend in LR/preempt-fence VM mode.\n\n(cherry picked from commit 6a1e7934d9a6cf46aecae00a99c2603d1295e170)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02831 |
altlinux: CVE-2026-53201 was patched at 2026-06-19
1483.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53262) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: l2tp: pppol2tp: hold reference to session in pppol2tp_ioctl() pppol2tp_ioctl() read sock->sk->sk_user_data directly without any locks or reference counting. If a controllable sleep was induced during copy_from_user() (e.g. via a userfaultfd page fault sleep), a concurrent socket close could trigger pppol2tp_session_close() asynchronously. This frees the l2tp_session structure via the l2tp_session_del_work workqueue. Upon resuming, the ioctl thread dereferences the stale session pointer, resulting in a Use-After-Free (UAF). Fix this by securely fetching the session reference using the RCU-safe, refcounted helper pppol2tp_sock_to_session(sk) on entry. This locks the session's refcount across the sleep. We structured the function to exit via standard err breaks, guaranteeing that l2tp_session_put() is cleanly called on all return paths to drop the reference. To preserve existing behavior we validate the session and its magic signature only for the specific L2TP commands that require it. This ensures that generic/unknown ioctls called on an unconnected socket still return -ENOIOCTLCMD and correctly fall back to generic handlers (e.g. in sock_do_ioctl()).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nl2tp: pppol2tp: hold reference to session in pppol2tp_ioctl()\n\npppol2tp_ioctl() read sock->sk->sk_user_data directly without any\nlocks or reference counting. If a controllable sleep was induced during\ncopy_from_user() (e.g. via a userfaultfd page fault sleep), a concurrent\nsocket close could trigger pppol2tp_session_close() asynchronously. This\nfrees the l2tp_session structure via the l2tp_session_del_work workqueue.\nUpon resuming, the ioctl thread dereferences the stale session pointer,\nresulting in a Use-After-Free (UAF).\n\nFix this by securely fetching the session reference using the RCU-safe,\nrefcounted helper pppol2tp_sock_to_session(sk) on entry. This locks the\nsession's refcount across the sleep. We structured the function to exit\nvia standard err breaks, guaranteeing that l2tp_session_put() is cleanly\ncalled on all return paths to drop the reference.\n\nTo preserve existing behavior we validate the session and its magic\nsignature only for the specific L2TP commands that require it. This\nensures that generic/unknown ioctls called on an unconnected socket\nstill return -ENOIOCTLCMD and correctly fall back to generic handlers\n(e.g. in sock_do_ioctl()).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02068 |
altlinux: CVE-2026-53262 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53262 was patched at 2026-07-14
1484.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53265) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: dm cache policy smq: check allocation under invalidate lock commit 2d1f7b65f5de ("dm cache policy smq: fix missing locks in invalidating cache blocks") added mq->lock around the destructive part of smq_invalidate_mapping(), but left the e->allocated check outside the critical section. That leaves a check-then-act race. Two concurrent invalidators can both observe e->allocated as true before either of them takes mq->lock. The first invalidator that acquires the lock removes the entry from the queues and hash table and then calls free_entry(), which clears e->allocated and puts the entry back on the free list. The second invalidator can then acquire mq->lock and continue with the stale result of the unlocked check. This can corrupt the SMQ queues or hash table by deleting an entry that is no longer on those structures. It can also hit the allocation check in free_entry() when the same entry is freed again. Move the allocation check under mq->lock so the predicate and the destructive operations are serialized by the same lock.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndm cache policy smq: check allocation under invalidate lock\n\ncommit 2d1f7b65f5de ("dm cache policy smq: fix missing locks in\ninvalidating cache blocks") added mq->lock around the destructive part of\nsmq_invalidate_mapping(), but left the e->allocated check outside the\ncritical section.\n\nThat leaves a check-then-act race. Two concurrent invalidators can both\nobserve e->allocated as true before either of them takes mq->lock. The\nfirst invalidator that acquires the lock removes the entry from the\nqueues and hash table and then calls free_entry(), which clears\ne->allocated and puts the entry back on the free list. The second\ninvalidator can then acquire mq->lock and continue with the stale result\nof the unlocked check.\n\nThis can corrupt the SMQ queues or hash table by deleting an entry that\nis no longer on those structures. It can also hit the allocation check in\nfree_entry() when the same entry is freed again.\n\nMove the allocation check under mq->lock so the predicate and the\ndestructive operations are serialized by the same lock.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02175 |
altlinux: CVE-2026-53265 was patched at 2026-06-19, 2026-06-22, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53265 was patched at 2026-07-14
1485.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53267) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: bail out on template ct in get eval I noticed this issue while looking at a historic syzbot report [1]. A rule like the one below is enough to trigger the bug: table ip t { chain pre { type filter hook prerouting priority raw; ct zone set 1 ct original saddr 1.2.3.4 accept } } The first expression attaches a per-cpu template ct via nft_ct_set_zone_eval() (nf_ct_tmpl_alloc -> kzalloc, tuple is all zero, nf_ct_l3num(ct) == 0). The next expression then calls nft_ct_get_eval() on the same skb, treats the template as a real ct and hits the 16-byte memcpy path. With dreg at NFT_REG32_15 this overflows past struct nft_regs on the kernel stack; with smaller dreg values it silently clobbers adjacent registers. Reject template ct at the eval entry and in nft_ct_get_fast_eval(), mirroring the check nft_ct_set_eval() already has. Additionally, bound the address copy in NFT_CT_SRC / NFT_CT_DST by priv->len instead of by nf_ct_l3num(ct): nf_ct_get_tuple() zeroes the tuple before pkt_to_tuple() fills in only the protocol-relevant leading bytes, so the trailing bytes of tuple->{src,dst}.u3.all are well-defined zero. priv->len is validated at rule load, so the copy size is now bounded by the destination register rather than by an untrusted field on the conntrack. [1]: https://syzkaller.appspot.com/bug?id=389cf09cb72926114fce90dc85a2c3231dcb647c', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_ct: bail out on template ct in get eval\n\nI noticed this issue while looking at a historic syzbot report [1].\n\nA rule like the one below is enough to trigger the bug:\n\n table ip t {\n chain pre {\n type filter hook prerouting priority raw;\n ct zone set 1\n ct original saddr 1.2.3.4 accept\n }\n }\n\nThe first expression attaches a per-cpu template ct via\nnft_ct_set_zone_eval() (nf_ct_tmpl_alloc -> kzalloc, tuple is all\nzero, nf_ct_l3num(ct) == 0). The next expression then calls\nnft_ct_get_eval() on the same skb, treats the template as a real ct\nand hits the 16-byte memcpy path. With dreg at NFT_REG32_15 this\noverflows past struct nft_regs on the kernel stack; with smaller\ndreg values it silently clobbers adjacent registers.\n\nReject template ct at the eval entry and in nft_ct_get_fast_eval(),\nmirroring the check nft_ct_set_eval() already has. Additionally,\nbound the address copy in NFT_CT_SRC / NFT_CT_DST by priv->len\ninstead of by nf_ct_l3num(ct): nf_ct_get_tuple() zeroes the tuple\nbefore pkt_to_tuple() fills in only the protocol-relevant leading\nbytes, so the trailing bytes of tuple->{src,dst}.u3.all are\nwell-defined zero. priv->len is validated at rule load, so the\ncopy size is now bounded by the destination register rather than\nby an untrusted field on the conntrack.\n\n[1]: https://syzkaller.appspot.com/bug?id=389cf09cb72926114fce90dc85a2c3231dcb647c', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.0214 |
altlinux: CVE-2026-53267 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53267 was patched at 2026-07-14
1486.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53270) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipvs: clear the svc scheduler ptr early on edit ip_vs_edit_service() while unbinding the old scheduler clears the svc->scheduler ptr after the scheduler module initiates RCU callbacks. This can cause packets to use the old scheduler at the time when svc->sched_data is already freed after RCU grace period. Fix it by clearing the ptr early in ip_vs_unbind_scheduler(), before the done_service method schedules any RCU callbacks. Also, if the new scheduler fails to initialize when replacing the old scheduler, try to restore the old scheduler while still returning the error code.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipvs: clear the svc scheduler ptr early on edit\n\nip_vs_edit_service() while unbinding the old scheduler clears\nthe svc->scheduler ptr after the scheduler module initiates\nRCU callbacks. This can cause packets to use the old\nscheduler at the time when svc->sched_data is already freed\nafter RCU grace period.\n\nFix it by clearing the ptr early in ip_vs_unbind_scheduler(),\nbefore the done_service method schedules any RCU callbacks.\n\nAlso, if the new scheduler fails to initialize when replacing\nthe old scheduler, try to restore the old scheduler while still\nreturning the error code.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02246 |
altlinux: CVE-2026-53270 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53270 was patched at 2026-07-14
1487.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53356) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/i915/gem: Fix phys BO pread/pwrite with offset sg_page() returns struct page pointer not (void *) so the scaling of pread/pwrite is wrong for phys BO and wrong parts of BO would be accessed if non-zero offset is used. Last impacted platform with overlay or cursor planes using phys mapping was Gen3/945G/Lakeport. (cherry picked from commit 3e49a2f85070b2fb672c1e0fdba281a4ea3aebe6)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/i915/gem: Fix phys BO pread/pwrite with offset\n\nsg_page() returns struct page pointer not (void *) so the scaling\nof pread/pwrite is wrong for phys BO and wrong parts of BO would be\naccessed if non-zero offset is used.\n\nLast impacted platform with overlay or cursor planes using phys\nmapping was Gen3/945G/Lakeport.\n\n(cherry picked from commit 3e49a2f85070b2fb672c1e0fdba281a4ea3aebe6)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02178 |
altlinux: CVE-2026-53356 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53356 was patched at 2026-07-14
1488.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53369) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: udf: reject descriptors with oversized CRC length udf_read_tagged() skips CRC verification when descCRCLength + sizeof(struct tag) exceeds the block size. A crafted UDF image can set descCRCLength to an oversized value to bypass CRC validation entirely; the descriptor is then accepted based solely on the 8-bit tag checksum, which is trivially recomputable. Reject such descriptors instead of silently accepting them. A legitimate single-block descriptor should never have a CRC length that exceeds the block.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nudf: reject descriptors with oversized CRC length\n\nudf_read_tagged() skips CRC verification when descCRCLength +\nsizeof(struct tag) exceeds the block size. A crafted UDF image can\nset descCRCLength to an oversized value to bypass CRC validation\nentirely; the descriptor is then accepted based solely on the 8-bit\ntag checksum, which is trivially recomputable.\n\nReject such descriptors instead of silently accepting them. A\nlegitimate single-block descriptor should never have a CRC length that\nexceeds the block.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00139, EPSS Percentile is 0.03738 |
debian: CVE-2026-53369 was patched at 2026-07-14
ubuntu: CVE-2026-53369 was patched at 2026-07-30
1489.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53386) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iio: adc: ti-ads1298: add bounds check to pga_settings index ads1298_pga_settings has 7 elements but ADS1298_MASK_CH_PGA can yield values 0-7. If it yields a value >= 7, this causes an out-of-bounds array access. Add a bounds check and return -EINVAL if the index is out of range. Note that the remaining value b111 is reserved so should not be seen in a correctly functioning system.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: ti-ads1298: add bounds check to pga_settings index\n\nads1298_pga_settings has 7 elements but ADS1298_MASK_CH_PGA can yield\nvalues 0-7. If it yields a value >= 7, this causes an out-of-bounds\narray access. Add a bounds check and return -EINVAL if the index\nis out of range.\n\nNote that the remaining value b111 is reserved so should not be seen\nin a correctly functioning system.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02906 |
debian: CVE-2026-53386 was patched at 2026-07-14
1490.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63805) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: crypto: nx - fix nx_crypto_ctx_exit argument nx_crypto_ctx_shash_exit calls nx_crypto_ctx_exit with crypto_shash_ctx(...) but crypto_shash_ctx gives a nx_crypto_ctx *, not a crypto_tfm *. Fix the type in nx_crypto_ctx_exit and drop the bogus crypto_tfm_ctx call. This fixes the following oops: BUG: Unable to handle kernel data access at 0xc0403effffffffc8 Faulting instruction address: 0xc000000000396cb4 Oops: Kernel access of bad area, sig: 11 [#15] Call Trace: nx_crypto_ctx_shash_exit+0x24/0x60 crypto_shash_exit_tfm+0x28/0x40 crypto_destroy_tfm+0x98/0x140 crypto_exit_ahash_using_shash+0x20/0x40 crypto_destroy_tfm+0x98/0x140 hash_release+0x1c/0x30 alg_sock_destruct+0x38/0x60 __sk_destruct+0x48/0x2b0 af_alg_release+0x58/0xb0 __sock_release+0x68/0x150 sock_close+0x20/0x40 __fput+0x110/0x3a0 sys_close+0x48/0xa0 system_call_exception+0x140/0x2d0 system_call_common+0xf4/0x258 .. which came from hardlink(1) opportunistically using AF_ALG. The same problem exists with nx_crypto_ctx_skcipher_exit getting a context it wasn't expecting, but apparently nobody hit that for years.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncrypto: nx - fix nx_crypto_ctx_exit argument\n\nnx_crypto_ctx_shash_exit calls nx_crypto_ctx_exit with crypto_shash_ctx(...)\nbut crypto_shash_ctx gives a nx_crypto_ctx *, not a crypto_tfm *.\n\nFix the type in nx_crypto_ctx_exit and drop the bogus crypto_tfm_ctx\ncall.\n\nThis fixes the following oops:\n\n BUG: Unable to handle kernel data access at 0xc0403effffffffc8\n Faulting instruction address: 0xc000000000396cb4\n Oops: Kernel access of bad area, sig: 11 [#15]\n Call Trace:\n nx_crypto_ctx_shash_exit+0x24/0x60\n crypto_shash_exit_tfm+0x28/0x40\n crypto_destroy_tfm+0x98/0x140\n crypto_exit_ahash_using_shash+0x20/0x40\n crypto_destroy_tfm+0x98/0x140\n hash_release+0x1c/0x30\n alg_sock_destruct+0x38/0x60\n __sk_destruct+0x48/0x2b0\n af_alg_release+0x58/0xb0\n __sock_release+0x68/0x150\n sock_close+0x20/0x40\n __fput+0x110/0x3a0\n sys_close+0x48/0xa0\n system_call_exception+0x140/0x2d0\n system_call_common+0xf4/0x258\n\n.. which came from hardlink(1) opportunistically using AF_ALG.\n\nThe same problem exists with nx_crypto_ctx_skcipher_exit getting a context\nit wasn't expecting, but apparently nobody hit that for years.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02773 |
debian: CVE-2026-63805 was patched at 2026-07-14
1491.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63812) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: f2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node() When __destroy_extent_node() sets the inode flag FI_NO_EXTENT, it does not reset the length of the largest extent to 0 and update the inode folio. Since modifications to the extent tree are disallowed afterward, the cached largest extent may become stale. This can trigger the following error in xfstests generic/388: F2FS-fs (dm-0): sanity_check_extent_cache: inode (ino=1761) extent info [220057, 57, 6] is incorrect, run fsck to fix In the f2fs_drop_inode path, __destroy_extent_node() does not need to guarantee that et->node_cnt is 0, because concurrency with writeback is expected in this path, and writeback may update the extent cache. This patch reverts commit ed78aeebef05 ("f2fs: fix node_cnt race between extent node destroy and writeback"), and remove the unnecessary zero check of et->node_cnt.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix incorrect FI_NO_EXTENT handling in __destroy_extent_node()\n\nWhen __destroy_extent_node() sets the inode flag FI_NO_EXTENT, it does\nnot reset the length of the largest extent to 0 and update the inode\nfolio. Since modifications to the extent tree are disallowed afterward,\nthe cached largest extent may become stale. This can trigger the\nfollowing error in xfstests generic/388:\n\nF2FS-fs (dm-0): sanity_check_extent_cache: inode (ino=1761) extent info [220057, 57, 6] is incorrect, run fsck to fix\n\nIn the f2fs_drop_inode path, __destroy_extent_node() does not need to\nguarantee that et->node_cnt is 0, because concurrency with writeback\nis expected in this path, and writeback may update the extent cache.\n\nThis patch reverts commit ed78aeebef05 ("f2fs: fix node_cnt race between\nextent node destroy and writeback"), and remove the unnecessary zero\ncheck of et->node_cnt.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02138 |
debian: CVE-2026-63812 was patched at 2026-07-14
1492.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63814) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: f2fs: validate ACL entry sizes in f2fs_acl_from_disk() f2fs_acl_count() only validates the aggregate ACL xattr length. A malformed ACL can still place ACL_USER or ACL_GROUP in a slot that only contains struct f2fs_acl_entry_short bytes, and f2fs_acl_from_disk() then reads entry->e_id before verifying that a full entry fits. Require a short entry before reading e_tag and e_perm, and require a full entry before reading e_id for ACL_USER and ACL_GROUP. Return -EFSCORRUPTED from these new truncated-entry checks, while keeping the pre-existing -EINVAL paths unchanged. Validation reproduced this kernel report: KASAN slab-out-of-bounds in __f2fs_get_acl+0x6fb/0x7e0 RIP: 0033:0x7f4b835ea7aa The buggy address belongs to the object at ffff888114589960 which belongs to the cache kmalloc-8 of size 8 The buggy address is located 0 bytes to the right of allocated 8-byte region [ffff888114589960, ffff888114589968) Read of size 4 Call trace: dump_stack_lvl+0x66/0xa0 (?:?) print_report+0xce/0x630 (?:?) __f2fs_get_acl+0x6fb/0x7e0 (fs/f2fs/acl.c:169) srso_alias_return_thunk+0x5/0xfbef5 (?:?) __virt_addr_valid+0x224/0x430 (?:?) kasan_report+0xe0/0x110 (?:?) __f2fs_get_acl+0x5/0x7e0 (fs/f2fs/acl.c:169) __get_acl+0x281/0x380 (?:?) vfs_get_acl+0x10b/0x190 (?:?) do_get_acl+0x2a/0x410 (?:?) do_get_acl+0x9/0x410 (?:?) do_getxattr+0xe8/0x260 (?:?) filename_getxattr+0xd1/0x140 (?:?) do_getname+0x2d/0x2d0 (?:?) path_getxattrat+0x16c/0x200 (?:?) lock_release+0xc8/0x290 (?:?) cgroup_update_frozen+0x9d/0x320 (?:?) lockdep_hardirqs_on_prepare+0xea/0x1a0 (?:?) trace_hardirqs_on+0x1a/0x170 (?:?) _raw_spin_unlock_irq+0x28/0x50 (?:?) do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87) entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: validate ACL entry sizes in f2fs_acl_from_disk()\n\nf2fs_acl_count() only validates the aggregate ACL xattr length. A\nmalformed ACL can still place ACL_USER or ACL_GROUP in a slot that only\ncontains struct f2fs_acl_entry_short bytes, and f2fs_acl_from_disk()\nthen reads entry->e_id before verifying that a full entry fits.\n\nRequire a short entry before reading e_tag and e_perm, and require a\nfull entry before reading e_id for ACL_USER and ACL_GROUP. Return\n-EFSCORRUPTED from these new truncated-entry checks, while keeping the\npre-existing -EINVAL paths unchanged.\n\nValidation reproduced this kernel report:\nKASAN slab-out-of-bounds in __f2fs_get_acl+0x6fb/0x7e0\nRIP: 0033:0x7f4b835ea7aa\nThe buggy address belongs to the object at ffff888114589960 which belongs\nto the cache kmalloc-8 of size 8\nThe buggy address is located 0 bytes to the right of allocated 8-byte\nregion [ffff888114589960, ffff888114589968)\nRead of size 4\nCall trace:\n dump_stack_lvl+0x66/0xa0 (?:?)\n print_report+0xce/0x630 (?:?)\n __f2fs_get_acl+0x6fb/0x7e0 (fs/f2fs/acl.c:169)\n srso_alias_return_thunk+0x5/0xfbef5 (?:?)\n __virt_addr_valid+0x224/0x430 (?:?)\n kasan_report+0xe0/0x110 (?:?)\n __f2fs_get_acl+0x5/0x7e0 (fs/f2fs/acl.c:169)\n __get_acl+0x281/0x380 (?:?)\n vfs_get_acl+0x10b/0x190 (?:?)\n do_get_acl+0x2a/0x410 (?:?)\n do_get_acl+0x9/0x410 (?:?)\n do_getxattr+0xe8/0x260 (?:?)\n filename_getxattr+0xd1/0x140 (?:?)\n do_getname+0x2d/0x2d0 (?:?)\n path_getxattrat+0x16c/0x200 (?:?)\n lock_release+0xc8/0x290 (?:?)\n cgroup_update_frozen+0x9d/0x320 (?:?)\n lockdep_hardirqs_on_prepare+0xea/0x1a0 (?:?)\n trace_hardirqs_on+0x1a/0x170 (?:?)\n _raw_spin_unlock_irq+0x28/0x50 (?:?)\n do_syscall_64+0x115/0x6a0 (arch/x86/entry/syscall_64.c:87)\n entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02753 |
debian: CVE-2026-63814 was patched at 2026-07-14, 2026-07-30
1493.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63816) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: f2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode - ioctl(F2FS_IOC_GARBAGE_COLLECT_RANGE)\t\t- shrink - f2fs_gc - gc_data_segment - ra_data_block(cow_inode) - mapping = F2FS_I(inode)->atomic_inode->i_mapping : f2fs_is_cow_file(cow_inode) is true \t\t\t\t\t\t - f2fs_evict_inode(atomic_inode) \t\t\t\t\t\t - clear_inode_flag(fi->cow_inode, FI_COW_FILE) \t\t\t\t\t\t - F2FS_I(fi->cow_inode)->atomic_inode = NULL \t\t\t\t\t\t ... \t\t\t\t\t\t - truncate_inode_pages_final(atomic_inode) - f2fs_grab_cache_folio(mapping) : create folio in atomic_inode->mapping \t\t\t\t\t\t - clear_inode(atomic_inode) \t\t\t\t\t\t - BUG_ON(atomic_inode->i_data.nrpages) We need to add a reference on fi->atomic_inode before using its mapping field during garbage collection, otherwise, it will cause UAF issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: atomic: fix UAF issue on f2fs_inode_info.atomic_inode\n\n- ioctl(F2FS_IOC_GARBAGE_COLLECT_RANGE)\t\t- shrink\n - f2fs_gc\n - gc_data_segment\n - ra_data_block(cow_inode)\n - mapping = F2FS_I(inode)->atomic_inode->i_mapping\n : f2fs_is_cow_file(cow_inode) is true\n\t\t\t\t\t\t - f2fs_evict_inode(atomic_inode)\n\t\t\t\t\t\t - clear_inode_flag(fi->cow_inode, FI_COW_FILE)\n\t\t\t\t\t\t - F2FS_I(fi->cow_inode)->atomic_inode = NULL\n\t\t\t\t\t\t ...\n\t\t\t\t\t\t - truncate_inode_pages_final(atomic_inode)\n - f2fs_grab_cache_folio(mapping)\n : create folio in atomic_inode->mapping\n\t\t\t\t\t\t - clear_inode(atomic_inode)\n\t\t\t\t\t\t - BUG_ON(atomic_inode->i_data.nrpages)\n\nWe need to add a reference on fi->atomic_inode before using its mapping\nfield during garbage collection, otherwise, it will cause UAF issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02136 |
debian: CVE-2026-63816 was patched at 2026-07-14, 2026-07-21
1494.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63817) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: f2fs: validate compress cache inode only when enabled F2FS_COMPRESS_INO() uses NM_I(sbi)->max_nid as the synthetic inode number for the compressed page cache inode. That inode only exists when the compress_cache mount option is enabled. When compress_cache is disabled, max_nid is outside the valid inode range. A corrupted directory entry that points to ino == max_nid should therefore be rejected by f2fs_check_nid_range(). However, is_meta_ino() currently treats F2FS_COMPRESS_INO() as a meta inode unconditionally, so f2fs_iget() bypasses do_read_inode() and its nid range check, and instantiates a fake internal inode instead. Gate the compressed cache inode case on COMPRESS_CACHE, matching f2fs_init_compress_inode(). With compress_cache disabled, ino == max_nid now follows the normal inode path and is rejected as an out-of-range nid.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: validate compress cache inode only when enabled\n\nF2FS_COMPRESS_INO() uses NM_I(sbi)->max_nid as the synthetic inode\nnumber for the compressed page cache inode. That inode only exists when\nthe compress_cache mount option is enabled.\n\nWhen compress_cache is disabled, max_nid is outside the valid inode\nrange. A corrupted directory entry that points to ino == max_nid should\ntherefore be rejected by f2fs_check_nid_range(). However, is_meta_ino()\ncurrently treats F2FS_COMPRESS_INO() as a meta inode unconditionally,\nso f2fs_iget() bypasses do_read_inode() and its nid range check, and\ninstantiates a fake internal inode instead.\n\nGate the compressed cache inode case on COMPRESS_CACHE, matching\nf2fs_init_compress_inode(). With compress_cache disabled, ino ==\nmax_nid now follows the normal inode path and is rejected as an\nout-of-range nid.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03321 |
debian: CVE-2026-63817 was patched at 2026-07-14, 2026-07-30
1495.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63818) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: f2fs: validate orphan inode entry count f2fs_recover_orphan_inodes() trusts the orphan block entry_count when replaying orphan inodes from the checkpoint pack. A corrupted entry_count larger than F2FS_ORPHANS_PER_BLOCK makes the recovery loop read past the ino[] array and interpret footer or following data as inode numbers. On a crafted image, mounting an unpatched kernel can drive orphan recovery into f2fs_bug_on() and panic the kernel. Validate entry_count before consuming entries so corrupted checkpoint data fails the mount with -EFSCORRUPTED and requests fsck instead. Set ERROR_INCONSISTENT_ORPHAN as well, so the corruption reason can be recorded in the superblock s_errors[] field. This gives fsck a persistent hint even though mount-time orphan recovery failure may leave no chance to persist SBI_NEED_FSCK through a checkpoint.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: validate orphan inode entry count\n\nf2fs_recover_orphan_inodes() trusts the orphan block entry_count when\nreplaying orphan inodes from the checkpoint pack. A corrupted entry_count\nlarger than F2FS_ORPHANS_PER_BLOCK makes the recovery loop read past the\nino[] array and interpret footer or following data as inode numbers.\n\nOn a crafted image, mounting an unpatched kernel can drive orphan recovery\ninto f2fs_bug_on() and panic the kernel. Validate entry_count before\nconsuming entries so corrupted checkpoint data fails the mount with\n-EFSCORRUPTED and requests fsck instead.\n\nSet ERROR_INCONSISTENT_ORPHAN as well, so the corruption reason can be\nrecorded in the superblock s_errors[] field. This gives fsck a persistent\nhint even though mount-time orphan recovery failure may leave no chance to\npersist SBI_NEED_FSCK through a checkpoint.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00132, EPSS Percentile is 0.03216 |
debian: CVE-2026-63818 was patched at 2026-07-14, 2026-07-21
1496.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63819) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: f2fs: fix to do sanity check on f2fs_get_node_folio_ra() kernel BUG at fs/f2fs/file.c:845! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI CPU: 0 UID: 0 PID: 5336 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full) Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014 RIP: 0010:f2fs_do_truncate_blocks+0x1115/0x1140 fs/f2fs/file.c:845 Code: fc fc 90 0f 0b e8 8b 9d 9a fd 90 0f 0b e8 83 9d 9a fd 48 89 df 48 c7 c6 60 d1 1a 8c e8 54 f1 fc fc 90 0f 0b e8 6c 9d 9a fd 90 <0f> 0b e8 64 9d 9a fd 90 0f 0b 90 e9 93 fd ff ff e8 56 9d 9a fd 90 RSP: 0018:ffffc9000e4474c0 EFLAGS: 00010283 RAX: ffffffff842b1d34 RBX: 0000000000000003 RCX: 0000000000100000 RDX: ffffc9000f03a000 RSI: 0000000000035503 RDI: 0000000000035504 RBP: ffffc9000e447608 R08: ffff8880123b0000 R09: 0000000000000002 R10: 00000000fffffffe R11: 0000000000000002 R12: 0000000000000001 R13: 0000000000000000 R14: 1ffff92001c88ea0 R15: 00000000ffff039c FS: 00007f7e02ee36c0(0000) GS:ffff88808c887000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007ff0305c4000 CR3: 0000000012d4c000 CR4: 0000000000352ef0 Call Trace: <TASK> f2fs_truncate_blocks+0x10a/0x300 fs/f2fs/file.c:882 f2fs_truncate+0x471/0x7c0 fs/f2fs/file.c:940 f2fs_evict_inode+0xa3f/0x1ac0 fs/f2fs/inode.c:907 evict+0x61e/0xb10 fs/inode.c:841 f2fs_fill_super+0x5f43/0x78f0 fs/f2fs/super.c:5224 get_tree_bdev_flags+0x431/0x4f0 fs/super.c:1694 vfs_get_tree+0x92/0x2a0 fs/super.c:1754 fc_mount fs/namespace.c:1193 [inline] do_new_mount_fc fs/namespace.c:3758 [inline] do_new_mount+0x341/0xd30 fs/namespace.c:3834 do_mount fs/namespace.c:4167 [inline] __do_sys_mount fs/namespace.c:4383 [inline] __se_sys_mount+0x31d/0x420 fs/namespace.c:4360 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x15f/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f \tcount = ADDRS_PER_PAGE(dn.node_folio, inode); \tcount -= dn.ofs_in_node; \tf2fs_bug_on(sbi, count < 0); The fuzz test will trigger above bug_on in f2fs. The root cause should be: in the corrupted inode, there is a direct node which has the same ino and nid in its footer, so in f2fs_do_truncate_blocks(), after f2fs_get_dnode_of_data() finds such dnode: 1) ADDRS_PER_PAGE(dn.node_folio, inode) will return 923 2) once dn.ofs_in_node points to addr[923, 1017] Then it will trigger the system panic. Let's introduce NODE_TYPE_NON_IXNODE to indicate current node should not be an inode or xattr node, and then use it in below path to detect inconsistent node chain in inode mapping table: - f2fs_do_truncate_blocks - f2fs_get_dnode_of_data - f2fs_get_node_folio_ra - __get_node_folio - f2fs_sanity_check_node_footer - case NODE_TYPE_NON_IXNODE -> check whether it is inode|xnode', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix to do sanity check on f2fs_get_node_folio_ra()\n\nkernel BUG at fs/f2fs/file.c:845!\nOops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\nCPU: 0 UID: 0 PID: 5336 Comm: syz.0.0 Not tainted syzkaller #0 PREEMPT(full)\nHardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.3-debian-1.16.3-2 04/01/2014\nRIP: 0010:f2fs_do_truncate_blocks+0x1115/0x1140 fs/f2fs/file.c:845\nCode: fc fc 90 0f 0b e8 8b 9d 9a fd 90 0f 0b e8 83 9d 9a fd 48 89 df 48 c7 c6 60 d1 1a 8c e8 54 f1 fc fc 90 0f 0b e8 6c 9d 9a fd 90 <0f> 0b e8 64 9d 9a fd 90 0f 0b 90 e9 93 fd ff ff e8 56 9d 9a fd 90\nRSP: 0018:ffffc9000e4474c0 EFLAGS: 00010283\nRAX: ffffffff842b1d34 RBX: 0000000000000003 RCX: 0000000000100000\nRDX: ffffc9000f03a000 RSI: 0000000000035503 RDI: 0000000000035504\nRBP: ffffc9000e447608 R08: ffff8880123b0000 R09: 0000000000000002\nR10: 00000000fffffffe R11: 0000000000000002 R12: 0000000000000001\nR13: 0000000000000000 R14: 1ffff92001c88ea0 R15: 00000000ffff039c\nFS: 00007f7e02ee36c0(0000) GS:ffff88808c887000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007ff0305c4000 CR3: 0000000012d4c000 CR4: 0000000000352ef0\nCall Trace:\n <TASK>\n f2fs_truncate_blocks+0x10a/0x300 fs/f2fs/file.c:882\n f2fs_truncate+0x471/0x7c0 fs/f2fs/file.c:940\n f2fs_evict_inode+0xa3f/0x1ac0 fs/f2fs/inode.c:907\n evict+0x61e/0xb10 fs/inode.c:841\n f2fs_fill_super+0x5f43/0x78f0 fs/f2fs/super.c:5224\n get_tree_bdev_flags+0x431/0x4f0 fs/super.c:1694\n vfs_get_tree+0x92/0x2a0 fs/super.c:1754\n fc_mount fs/namespace.c:1193 [inline]\n do_new_mount_fc fs/namespace.c:3758 [inline]\n do_new_mount+0x341/0xd30 fs/namespace.c:3834\n do_mount fs/namespace.c:4167 [inline]\n __do_sys_mount fs/namespace.c:4383 [inline]\n __se_sys_mount+0x31d/0x420 fs/namespace.c:4360\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x15f/0xf80 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\n\n\tcount = ADDRS_PER_PAGE(dn.node_folio, inode);\n\n\tcount -= dn.ofs_in_node;\n\tf2fs_bug_on(sbi, count < 0);\n\nThe fuzz test will trigger above bug_on in f2fs.\n\nThe root cause should be: in the corrupted inode, there is a direct node\nwhich has the same ino and nid in its footer, so in f2fs_do_truncate_blocks(),\nafter f2fs_get_dnode_of_data() finds such dnode:\n1) ADDRS_PER_PAGE(dn.node_folio, inode) will return 923\n2) once dn.ofs_in_node points to addr[923, 1017]\nThen it will trigger the system panic.\n\nLet's introduce NODE_TYPE_NON_IXNODE to indicate current node should\nnot be an inode or xattr node, and then use it in below path to detect\ninconsistent node chain in inode mapping table:\n\n- f2fs_do_truncate_blocks\n - f2fs_get_dnode_of_data\n - f2fs_get_node_folio_ra\n - __get_node_folio\n - f2fs_sanity_check_node_footer\n - case NODE_TYPE_NON_IXNODE -> check whether it is inode|xnode', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02036 |
debian: CVE-2026-63819 was patched at 2026-07-14
1497.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63823) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key() B: KEYCTL_INSTANTIATE_IOV ================ ========================= create auth key store rka in auth key wait for helper get auth key load rka from auth key copy user payload sleep on #PF helper completed detach and free rka destroy auth key wake up use rka->target_key **USE-AFTER-FREE** Give request_key_auth payloads a refcount. Take a payload reference while authkey->sem stabilizes the payload and revocation state. Hold that reference across the instantiate and reject paths. Drop the auth key owning reference from revoke and destroy. [jarkko: Replaced the first two paragraphs of text with an actual concurrency scenario.]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nkeys: Pin request_key_auth payload in instantiate paths\n\nA: request_key() B: KEYCTL_INSTANTIATE_IOV\n================ =========================\n\ncreate auth key\nstore rka in auth key\nwait for helper\n get auth key\n load rka from auth key\n copy user payload\n sleep on #PF\n\nhelper completed\ndetach and free rka\ndestroy auth key\n wake up\n use rka->target_key\n **USE-AFTER-FREE**\n\nGive request_key_auth payloads a refcount. Take a payload reference while\nauthkey->sem stabilizes the payload and revocation state. Hold that\nreference across the instantiate and reject paths. Drop the auth key\nowning reference from revoke and destroy.\n\n[jarkko: Replaced the first two paragraphs of text with an actual\n concurrency scenario.]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02528 |
debian: CVE-2026-63823 was patched at 2026-07-14, 2026-07-30
1498.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63824) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: KEYS: fix overflow in keyctl_pkey_params_get_2() The length for the internal output buffer is calculated incorrectly, which can result overflow when a too small buffer is provided. Fix the bug by allocating internal output with the size of the maximum length of the cryptographic primitive instead of caller provided size.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nKEYS: fix overflow in keyctl_pkey_params_get_2()\n\nThe length for the internal output buffer is calculated incorrectly, which\ncan result overflow when a too small buffer is provided.\n\nFix the bug by allocating internal output with the size of the maximum\nlength of the cryptographic primitive instead of caller provided size.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.0279 |
debian: CVE-2026-63824 was patched at 2026-07-14, 2026-07-30
1499.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63828) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: apparmor: mediate the implicit connect of TCP fast open sendmsg sendmsg()/sendto() with MSG_FASTOPEN is a combination of connect(2) and write(2): it opens the connection in the SYN. apparmor_socket_sendmsg() only checks AA_MAY_SEND, so a profile that grants send but denies connect lets a confined task open an outbound TCP/MPTCP connection that connect(2) would have refused, bypassing connect mediation. Mediate the implicit connect when MSG_FASTOPEN is set and a destination is supplied. Add it to apparmor_socket_sendmsg() (not the shared aa_sock_msg_perm() helper, which recvmsg also uses) and call aa_sk_perm() directly, mirroring the selinux and tomoyo fixes. sk_is_tcp() does not cover MPTCP fast open, so the SOCK_STREAM/IPPROTO_MPTCP arm is explicit.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\napparmor: mediate the implicit connect of TCP fast open sendmsg\n\nsendmsg()/sendto() with MSG_FASTOPEN is a combination of connect(2) and\nwrite(2): it opens the connection in the SYN. apparmor_socket_sendmsg()\nonly checks AA_MAY_SEND, so a profile that grants send but denies connect\nlets a confined task open an outbound TCP/MPTCP connection that connect(2)\nwould have refused, bypassing connect mediation.\n\nMediate the implicit connect when MSG_FASTOPEN is set and a destination\nis supplied. Add it to apparmor_socket_sendmsg() (not the shared\naa_sock_msg_perm() helper, which recvmsg also uses) and call aa_sk_perm()\ndirectly, mirroring the selinux and tomoyo fixes. sk_is_tcp() does not\ncover MPTCP fast open, so the SOCK_STREAM/IPPROTO_MPTCP arm is explicit.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00131, EPSS Percentile is 0.03107 |
debian: CVE-2026-63828 was patched at 2026-07-14, 2026-07-30
1500.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63842) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit 0f43893d3cd478fa57836697525b338817c9c23d)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/jpeg: set no_user_fence for JPEG v5.0.0 ring\n\nJPEG rings do not support 64-bit user fence writes, reject CS\nsubmissions with user fences.\n\n(cherry picked from commit 0f43893d3cd478fa57836697525b338817c9c23d)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02959 |
debian: CVE-2026-63842 was patched at 2026-07-14
ubuntu: CVE-2026-63842 was patched at 2026-07-30
1501.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63843) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit f05d0a4f21fc720116d6e238f23308b199891058)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.5 ring\n\nJPEG rings do not support 64-bit user fence writes, reject CS\nsubmissions with user fences.\n\n(cherry picked from commit f05d0a4f21fc720116d6e238f23308b199891058)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02959 |
debian: CVE-2026-63843 was patched at 2026-07-14
ubuntu: CVE-2026-63843 was patched at 2026-07-30
1502.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63844) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit 2f6afc97d259d530f4f86c7743efbc573a8da927)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/jpeg: set no_user_fence for JPEG v4.0.3 ring\n\nJPEG rings do not support 64-bit user fence writes, reject CS\nsubmissions with user fences.\n\n(cherry picked from commit 2f6afc97d259d530f4f86c7743efbc573a8da927)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02959 |
debian: CVE-2026-63844 was patched at 2026-07-14
ubuntu: CVE-2026-63844 was patched at 2026-07-30
1503.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63845) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit 8d0cac9478a3f046279c657d6a2545de49ae675a)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/jpeg: set no_user_fence for JPEG v4.0 ring\n\nJPEG rings do not support 64-bit user fence writes, reject CS\nsubmissions with user fences.\n\n(cherry picked from commit 8d0cac9478a3f046279c657d6a2545de49ae675a)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.0296 |
debian: CVE-2026-63845 was patched at 2026-07-14
ubuntu: CVE-2026-63845 was patched at 2026-07-30
1504.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63846) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit 4d7d774f100efb5089c86a1fb8c5bf47c63fc9ef)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/jpeg: set no_user_fence for JPEG v3.0 ring\n\nJPEG rings do not support 64-bit user fence writes, reject CS\nsubmissions with user fences.\n\n(cherry picked from commit 4d7d774f100efb5089c86a1fb8c5bf47c63fc9ef)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02958 |
debian: CVE-2026-63846 was patched at 2026-07-14
ubuntu: CVE-2026-63846 was patched at 2026-07-30
1505.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63847) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit 3216a7f4e2642bda5fd14f57586e835ae9202587)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/jpeg: set no_user_fence for JPEG v2.5 ring\n\nJPEG rings do not support 64-bit user fence writes, reject CS\nsubmissions with user fences.\n\n(cherry picked from commit 3216a7f4e2642bda5fd14f57586e835ae9202587)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02905 |
debian: CVE-2026-63847 was patched at 2026-07-14
ubuntu: CVE-2026-63847 was patched at 2026-07-30
1506.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63848) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring JPEG rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit 96179da0c6b059eb31706a0abe8dd6381c533143)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/jpeg: set no_user_fence for JPEG v2.0 ring\n\nJPEG rings do not support 64-bit user fence writes, reject CS\nsubmissions with user fences.\n\n(cherry picked from commit 96179da0c6b059eb31706a0abe8dd6381c533143)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02959 |
debian: CVE-2026-63848 was patched at 2026-07-14
ubuntu: CVE-2026-63848 was patched at 2026-07-30
1507.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63850) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit 49b1fbbb5a071197ee71e2d70959b1cb29bdc317)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: set no_user_fence for VCN v5.0.0 enc ring\n\nVCN encoder and decoder rings do not support 64-bit user fence writes,\nreject CS submissions with user fences.\n\n(cherry picked from commit 49b1fbbb5a071197ee71e2d70959b1cb29bdc317)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02958 |
debian: CVE-2026-63850 was patched at 2026-07-14
ubuntu: CVE-2026-63850 was patched at 2026-07-30
1508.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63851) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit 084d94ac93707bdda07efb5cee786f632de4219b)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: set no_user_fence for VCN v4.0.5 enc ring\n\nVCN encoder and decoder rings do not support 64-bit user fence writes,\nreject CS submissions with user fences.\n\n(cherry picked from commit 084d94ac93707bdda07efb5cee786f632de4219b)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02166 |
debian: CVE-2026-63851 was patched at 2026-07-14
ubuntu: CVE-2026-63851 was patched at 2026-07-30
1509.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63852) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit ff1a5a125c5a70c328806b9bc01d7d942cf3f9aa)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: set no_user_fence for VCN v4.0.3 enc ring\n\nVCN encoder and decoder rings do not support 64-bit user fence writes,\nreject CS submissions with user fences.\n\n(cherry picked from commit ff1a5a125c5a70c328806b9bc01d7d942cf3f9aa)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02166 |
debian: CVE-2026-63852 was patched at 2026-07-14
ubuntu: CVE-2026-63852 was patched at 2026-07-30
1510.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63853) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit fd852c048b46f9825e904a4f3f4538fe9d8827d9)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: set no_user_fence for VCN v4.0 enc ring\n\nVCN encoder and decoder rings do not support 64-bit user fence writes,\nreject CS submissions with user fences.\n\n(cherry picked from commit fd852c048b46f9825e904a4f3f4538fe9d8827d9)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02077 |
debian: CVE-2026-63853 was patched at 2026-07-14
ubuntu: CVE-2026-63853 was patched at 2026-07-30
1511.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63854) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit 663bed3c7b8b9a7624b0d95d300ddae034ad0614)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: set no_user_fence for VCN v3.0 enc/dec rings\n\nVCN encoder and decoder rings do not support 64-bit user fence writes,\nreject CS submissions with user fences.\n\n(cherry picked from commit 663bed3c7b8b9a7624b0d95d300ddae034ad0614)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02166 |
debian: CVE-2026-63854 was patched at 2026-07-14
ubuntu: CVE-2026-63854 was patched at 2026-07-30
1512.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63855) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit efc9dd5590894109bce9a0bfe1fa5592dd6b20b1)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: set no_user_fence for VCN v2.5 enc/dec rings\n\nVCN encoder and decoder rings do not support 64-bit user fence writes,\nreject CS submissions with user fences.\n\n(cherry picked from commit efc9dd5590894109bce9a0bfe1fa5592dd6b20b1)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02168 |
debian: CVE-2026-63855 was patched at 2026-07-14
ubuntu: CVE-2026-63855 was patched at 2026-07-30
1513.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63856) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings VCN encoder and decoder rings do not support 64-bit user fence writes, reject CS submissions with user fences. (cherry picked from commit e2b5499fca55f1a32960a311bbb62e35891eaf73)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdgpu/vcn: set no_user_fence for VCN v2.0 enc/dec rings\n\nVCN encoder and decoder rings do not support 64-bit user fence writes,\nreject CS submissions with user fences.\n\n(cherry picked from commit e2b5499fca55f1a32960a311bbb62e35891eaf73)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02166 |
debian: CVE-2026-63856 was patched at 2026-07-14
ubuntu: CVE-2026-63856 was patched at 2026-07-30
1514.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63858) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: add hook transactions for device deletions Restore the flag that indicates that the hook is going away, ie. NFT_HOOK_REMOVE, but add a new transaction object to track deletion of hooks without altering the basechain/flowtable hook_list during the preparation phase. The existing approach that moves the hook from the basechain/flowtable hook_list to transaction hook_list breaks netlink dump path readers of this RCU-protected list. It should be possible use an array for nft_trans_hook to store the deleted hooks to compact the representation but I am not expecting many hook object, specially now that wildcard support for devices is in place. Note that the nft_trans_chain_hooks() list contains a list of struct nft_trans_hook objects for DELCHAIN and DELFLOWTABLE commands, while this list stores struct nft_hook objects for NEWCHAIN and NEWFLOWTABLE. Note that new commands can be updated to use nft_trans_hook for consistency. This patch also adapts the event notification path to deal with the list of hook transactions.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: add hook transactions for device deletions\n\nRestore the flag that indicates that the hook is going away, ie.\nNFT_HOOK_REMOVE, but add a new transaction object to track deletion\nof hooks without altering the basechain/flowtable hook_list during\nthe preparation phase.\n\nThe existing approach that moves the hook from the basechain/flowtable\nhook_list to transaction hook_list breaks netlink dump path readers\nof this RCU-protected list.\n\nIt should be possible use an array for nft_trans_hook to store the\ndeleted hooks to compact the representation but I am not expecting\nmany hook object, specially now that wildcard support for devices\nis in place.\n\nNote that the nft_trans_chain_hooks() list contains a list of struct\nnft_trans_hook objects for DELCHAIN and DELFLOWTABLE commands, while\nthis list stores struct nft_hook objects for NEWCHAIN and NEWFLOWTABLE.\nNote that new commands can be updated to use nft_trans_hook for\nconsistency.\n\nThis patch also adapts the event notification path to deal with the list\nof hook transactions.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01605 |
debian: CVE-2026-63858 was patched at 2026-07-14
ubuntu: CVE-2026-63858 was patched at 2026-07-30
1515.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63860) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Prefer NLA_NUL_STRING These attributes are evaluated as c-string (passed to strcmp), but NLA_STRING doesn't check for the presence of a \\0 terminator. Either this needs to switch to nla_strcmp() and needs to adjust printf fmt specifier to not use plain %s, or this needs to use NLA_NUL_STRING. As the code has been this way for long time, it seems to me that userspace does include the terminating nul, even tough its not enforced so far, and thus NLA_NUL_STRING use is the simpler solution.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/core: Prefer NLA_NUL_STRING\n\nThese attributes are evaluated as c-string (passed to strcmp), but\nNLA_STRING doesn't check for the presence of a \\0 terminator.\n\nEither this needs to switch to nla_strcmp() and needs to adjust printf fmt\nspecifier to not use plain %s, or this needs to use NLA_NUL_STRING.\n\nAs the code has been this way for long time, it seems to me that userspace\ndoes include the terminating nul, even tough its not enforced so far, and\nthus NLA_NUL_STRING use is the simpler solution.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00132, EPSS Percentile is 0.03216 |
debian: CVE-2026-63860 was patched at 2026-07-14
ubuntu: CVE-2026-63860 was patched at 2026-07-30
1516.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63870) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit() The aoe driver (or similar) generates a non-IPv6 packet (e.g., ETH_P_AOE) and queues it for transmission via dev_queue_xmit() on a 6LoWPAN interface (configured by the user or test case). Since the packet is not IPv6, the 6LoWPAN header_ops->create function (lowpan_header_create or header_create) returns early without initializing the lowpan_addr_info structure in the skb headroom. In the transmit function (lowpan_xmit), the driver calls lowpan_header (or setup_header) which unconditionally copies and uses the lowpan_addr_info from the headroom, which contains uninitialized data. Fix this by dropping non IPv6 packets. A similar fix is needed in net/bluetooth/6lowpan.c bt_xmit().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nieee802154: 6lowpan: only accept IPv6 packets in lowpan_xmit()\n\nThe aoe driver (or similar) generates a non-IPv6 packet\n(e.g., ETH_P_AOE) and queues it for transmission via dev_queue_xmit()\non a 6LoWPAN interface (configured by the user or test case).\n\nSince the packet is not IPv6, the 6LoWPAN header_ops->create function\n(lowpan_header_create or header_create) returns early without initializing\nthe lowpan_addr_info structure in the skb headroom.\n\nIn the transmit function (lowpan_xmit), the driver calls lowpan_header\n(or setup_header) which unconditionally copies and uses the lowpan_addr_info\nfrom the headroom, which contains uninitialized data.\n\nFix this by dropping non IPv6 packets.\n\nA similar fix is needed in net/bluetooth/6lowpan.c bt_xmit().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02491 |
debian: CVE-2026-63870 was patched at 2026-07-14
1517.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63883) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: serial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ When uart_flush_buffer() runs before the DMA completion IRQ is delivered, the following race can occur (all steps serialized by uart_port_lock): 1. DMA starts: tx_remaining = N, kfifo contains N bytes 2. DMA completes in hardware; IRQ is pending but not yet delivered 3. uart_flush_buffer() acquires the port lock and calls kfifo_reset(), making kfifo_len() = 0 while tx_remaining remains N 4. uart_flush_buffer() releases the port lock 5. DMA IRQ fires; handle_tx_dma() acquires the port lock and calls uart_xmit_advance(uport, tx_remaining) on an empty kfifo uart_xmit_advance() increments kfifo->out by tx_remaining. Since kfifo_reset() already set both in and out to 0, out wraps past in, causing kfifo_len() to return UART_XMIT_SIZE - tx_remaining. The next start_tx_dma() call then submits a DMA transfer of stale buffer data. Fix this by snapshotting kfifo_len() at the start of handle_tx_dma() and skipping uart_xmit_advance() when fifo_len < tx_remaining, which indicates the kfifo was reset by a preceding flush.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nserial: qcom_geni: fix kfifo underflow when flush precedes DMA completion IRQ\n\nWhen uart_flush_buffer() runs before the DMA completion IRQ is delivered,\nthe following race can occur (all steps serialized by uart_port_lock):\n\n 1. DMA starts: tx_remaining = N, kfifo contains N bytes\n 2. DMA completes in hardware; IRQ is pending but not yet delivered\n 3. uart_flush_buffer() acquires the port lock and calls kfifo_reset(),\n making kfifo_len() = 0 while tx_remaining remains N\n 4. uart_flush_buffer() releases the port lock\n 5. DMA IRQ fires; handle_tx_dma() acquires the port lock and calls\n uart_xmit_advance(uport, tx_remaining) on an empty kfifo\n\nuart_xmit_advance() increments kfifo->out by tx_remaining. Since\nkfifo_reset() already set both in and out to 0, out wraps past in,\ncausing kfifo_len() to return UART_XMIT_SIZE - tx_remaining. The next\nstart_tx_dma() call then submits a DMA transfer of stale buffer data.\n\nFix this by snapshotting kfifo_len() at the start of handle_tx_dma()\nand skipping uart_xmit_advance() when fifo_len < tx_remaining, which\nindicates the kfifo was reset by a preceding flush.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00159, EPSS Percentile is 0.05542 |
debian: CVE-2026-63883 was patched at 2026-07-14
ubuntu: CVE-2026-63883 was patched at 2026-07-30
1518.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63914) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfrm: route MIGRATE notifications to caller's netns xfrm_send_migrate() in net/xfrm/xfrm_user.c and pfkey_send_migrate() in net/key/af_key.c both hardcode &init_net for the multicast that announces a successful XFRM_MSG_MIGRATE / SADB_X_MIGRATE. XFRM_MSG_MIGRATE arrives on a per-netns NETLINK_XFRM socket, and the rest of the xfrm/af_key netlink path was made netns-aware in 2008. The other 14 multicast paths in xfrm_user.c route their event using xs_net(x), xp_net(xp) or sock_net(skb->sk); only the migrate path was missed. Two consequences of the init_net hardcoding: 1. The notification (selector, old/new endpoint addresses, and the km_address) is delivered to listeners on init_net's XFRMNLGRP_MIGRATE / pfkey BROADCAST_ALL groups rather than on the issuing netns. An IKE daemon running in init_net therefore receives migration notifications originating from any other netns on the host. 2. An IKE daemon running inside a non-init netns and subscribed to its own XFRMNLGRP_MIGRATE / pfkey groups never receives the notification of its own migration. IKEv2 MOBIKE / address-update handling inside a netns is silently broken. Thread struct net through km_migrate() and the xfrm_mgr.migrate function pointer, drop the &init_net override in xfrm_send_migrate() and pfkey_send_migrate(), and pass the caller's net (already in scope in xfrm_migrate() via sock_net(skb->sk)) all the way down. struct xfrm_mgr is in-tree only and not exported as a stable API, so the function-pointer signature change is internal. pfkey_broadcast() is already netns-aware via net_generic(net, pfkey_net_id) since the pernet conversion. The five other pfkey_broadcast() callers in af_key.c already pass xs_net(x), sock_net(sk) or a per-netns net, so this only removes the &init_net outlier.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: route MIGRATE notifications to caller's netns\n\nxfrm_send_migrate() in net/xfrm/xfrm_user.c and pfkey_send_migrate()\nin net/key/af_key.c both hardcode &init_net for the multicast that\nannounces a successful XFRM_MSG_MIGRATE / SADB_X_MIGRATE.\n\nXFRM_MSG_MIGRATE arrives on a per-netns NETLINK_XFRM socket, and the\nrest of the xfrm/af_key netlink path was made netns-aware in 2008.\nThe other 14 multicast paths in xfrm_user.c route their event using\nxs_net(x), xp_net(xp) or sock_net(skb->sk); only the migrate path\nwas missed.\n\nTwo consequences of the init_net hardcoding:\n\n 1. The notification (selector, old/new endpoint addresses, and the\n km_address) is delivered to listeners on init_net's\n XFRMNLGRP_MIGRATE / pfkey BROADCAST_ALL groups rather than on\n the issuing netns. An IKE daemon running in init_net therefore\n receives migration notifications originating from any other\n netns on the host.\n\n 2. An IKE daemon running inside a non-init netns and subscribed\n to its own XFRMNLGRP_MIGRATE / pfkey groups never receives the\n notification of its own migration. IKEv2 MOBIKE / address-update\n handling inside a netns is silently broken.\n\nThread struct net through km_migrate() and the xfrm_mgr.migrate\nfunction pointer, drop the &init_net override in xfrm_send_migrate()\nand pfkey_send_migrate(), and pass the caller's net (already in\nscope in xfrm_migrate() via sock_net(skb->sk)) all the way down.\nstruct xfrm_mgr is in-tree only and not exported as a stable API,\nso the function-pointer signature change is internal.\n\npfkey_broadcast() is already netns-aware via net_generic(net,\npfkey_net_id) since the pernet conversion. The five other\npfkey_broadcast() callers in af_key.c already pass xs_net(x),\nsock_net(sk) or a per-netns net, so this only removes the\n&init_net outlier.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05215 |
debian: CVE-2026-63914 was patched at 2026-07-14
ubuntu: CVE-2026-63914 was patched at 2026-07-30
1519.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63985) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ethtool: eeprom: add more safeties to EEPROM Netlink fallback The Netlink fallback path for reading module EEPROM (fallback_set_params()) validates that offset < eeprom_len, but does not check that offset + length stays within eeprom_len. The ioctl equivalent (ethtool_get_any_eeprom() in ioctl.c) has always enforced both bounds: if (eeprom.offset + eeprom.len > total_len) return -EINVAL; This could lead to surprises in both drivers and device FW. Add the missing offset + length validation to fallback_set_params(), mirroring the ioctl. Similarly - ethtool core in general, and ethtool_get_any_eeprom() in particular tries to zero-init all buffers passed to the drivers to avoid any extra work of zeroing things out. eeprom_fallback() uses a plain kmalloc(), change it to zalloc.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: eeprom: add more safeties to EEPROM Netlink fallback\n\nThe Netlink fallback path for reading module EEPROM\n(fallback_set_params()) validates that offset < eeprom_len,\nbut does not check that offset + length stays within eeprom_len.\nThe ioctl equivalent (ethtool_get_any_eeprom() in ioctl.c) has\nalways enforced both bounds:\n\n if (eeprom.offset + eeprom.len > total_len)\n return -EINVAL;\n\nThis could lead to surprises in both drivers and device FW.\nAdd the missing offset + length validation to fallback_set_params(),\nmirroring the ioctl.\n\nSimilarly - ethtool core in general, and ethtool_get_any_eeprom()\nin particular tries to zero-init all buffers passed to the drivers\nto avoid any extra work of zeroing things out. eeprom_fallback()\nuses a plain kmalloc(), change it to zalloc.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02966 |
debian: CVE-2026-63985 was patched at 2026-07-14
ubuntu: CVE-2026-63985 was patched at 2026-07-30
1520.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63987) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES ethnl_update_profile() walks the ETHTOOL_A_PROFILE_IRQ_MODERATION nest list with an index 'i' and writes new_profile[i++] without bounding i. The destination is kmemdup()'d at NET_DIM_PARAMS_NUM_PROFILES entries (5), but the Netlink nest count is entirely user-controlled. Netlink policies do not have support for constraining the number of nested entries (or number of multi-attr entries).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: coalesce: cap profile updates at NET_DIM_PARAMS_NUM_PROFILES\n\nethnl_update_profile() walks the ETHTOOL_A_PROFILE_IRQ_MODERATION\nnest list with an index 'i' and writes new_profile[i++] without\nbounding i. The destination is kmemdup()'d at NET_DIM_PARAMS_NUM_PROFILES\nentries (5), but the Netlink nest count is entirely user-controlled.\nNetlink policies do not have support for constraining the number\nof nested entries (or number of multi-attr entries).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02905 |
debian: CVE-2026-63987 was patched at 2026-07-14
ubuntu: CVE-2026-63987 was patched at 2026-07-30
1521.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63995) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ethtool: cmis: validate start_cmd_payload_size from module The CMIS firmware update code reads start_cmd_payload_size from the module's FW Management Features CDB reply and uses it directly as the byte count for memcpy. The destination buffer is 112 bytes (ETHTOOL_CMIS_CDB_LPL_MAX_PL_LENGTH - 8). So a malicious module (or corrupted response) can cause a OOB write later on in cmis_fw_update_start_download(). Let's error out. If modules that expect longer LPL writes actually exist we should revisit. struct cmis_cdb_start_fw_download_pl's definition has to move, no change there.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: cmis: validate start_cmd_payload_size from module\n\nThe CMIS firmware update code reads start_cmd_payload_size from\nthe module's FW Management Features CDB reply and uses it directly\nas the byte count for memcpy. The destination buffer is 112 bytes\n(ETHTOOL_CMIS_CDB_LPL_MAX_PL_LENGTH - 8). So a malicious\nmodule (or corrupted response) can cause a OOB write later on in\ncmis_fw_update_start_download().\n\nLet's error out. If modules that expect longer LPL writes actually\nexist we should revisit.\n\nstruct cmis_cdb_start_fw_download_pl's definition has to move,\nno change there.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02909 |
debian: CVE-2026-63995 was patched at 2026-07-14
ubuntu: CVE-2026-63995 was patched at 2026-07-30
1522.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63996) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ethtool: cmis: require exact CDB reply length Malicious SFP module could respond with rpl_len longer than what cmis_cdb_process_reply() expected, leading to OOB writes. Malicious HW is a bit theoretical but some modules may just be buggy and/or the reads may occasionally get corrupted, so let's protect the kernel. The existing check protects from short replies. We need to protect from long ones, too. All callers that pass a non-zero rpl_exp_len cast the reply payload to a fixed-layout struct and read fields at fixed offsets, with no version negotiation or short-reply handling: - cmis_cdb_validate_password() - cmis_cdb_module_features_get() - cmis_fw_update_fw_mng_features_get() so let's assume that responses longer than expected do not have to be handled gracefully here. Add a warning message to make the debug easier in case my understanding is wrong... Note that page_data->length (argument of kmalloc) comes from last arg to ethtool_cmis_page_init() which is rpl_exp_len. Note2 that AIs also like to point out overflows in args->req.payload itself (which is a fixed-size 120 B buffer, on the stack), but callers should be reading structs defined by the standard, so protecting from requests for more data than max seem like defensive programming.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: cmis: require exact CDB reply length\n\nMalicious SFP module could respond with rpl_len longer than\nwhat cmis_cdb_process_reply() expected, leading to OOB writes.\nMalicious HW is a bit theoretical but some modules may just\nbe buggy and/or the reads may occasionally get corrupted,\nso let's protect the kernel.\n\nThe existing check protects from short replies. We need to\nprotect from long ones, too. All callers that pass a non-zero\nrpl_exp_len cast the reply payload to a fixed-layout struct\nand read fields at fixed offsets, with no version negotiation\nor short-reply handling:\n\n - cmis_cdb_validate_password()\n - cmis_cdb_module_features_get()\n - cmis_fw_update_fw_mng_features_get()\n\nso let's assume that responses longer than expected do not\nhave to be handled gracefully here. Add a warning message\nto make the debug easier in case my understanding is wrong...\n\nNote that page_data->length (argument of kmalloc) comes from\nlast arg to ethtool_cmis_page_init() which is rpl_exp_len.\n\nNote2 that AIs also like to point out overflows in args->req.payload\nitself (which is a fixed-size 120 B buffer, on the stack),\nbut callers should be reading structs defined by the standard,\nso protecting from requests for more data than max seem like\ndefensive programming.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02914 |
debian: CVE-2026-63996 was patched at 2026-07-14
ubuntu: CVE-2026-63996 was patched at 2026-07-30
1523.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64002) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() ipv4_sysctl_exit_net() is currently freeing net->ipv4.sysctl_local_reserved_ports too soon. Only after unregister_net_sysctl_table() we can be sure no threads can possibly use the sysctls, including /proc/sys/net/ipv4/ip_local_reserved_ports.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table()\n\nipv4_sysctl_exit_net() is currently freeing net->ipv4.sysctl_local_reserved_ports\ntoo soon.\n\nOnly after unregister_net_sysctl_table() we can be sure no threads can possibly\nuse the sysctls, including /proc/sys/net/ipv4/ip_local_reserved_ports.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02979 |
debian: CVE-2026-64002 was patched at 2026-07-14
ubuntu: CVE-2026-64002 was patched at 2026-07-30
1524.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64005) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/smc: Do not re-initialize smc hashtables INIT_HLIST_HEAD(&smc_v*_hashinfo.ht) are called after smc_nl_init(), proto_register() and sock_register(). This can lead to smc_v*_hashinfo.ht being reset even though hash entries already exist and are being used, possibly resulting in a corrupted list. Remove unnecessary and dangerous re-initialisation of smc_v*_hashinfo.ht in smc_init(); it is implicitly initialised to zero anyhow. Add HLIST_HEAD_INIT to the definitions for clarity.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/smc: Do not re-initialize smc hashtables\n\nINIT_HLIST_HEAD(&smc_v*_hashinfo.ht) are called after smc_nl_init(),\nproto_register() and sock_register(). This can lead to smc_v*_hashinfo.ht\nbeing reset even though hash entries already exist and are being used,\npossibly resulting in a corrupted list.\n\nRemove unnecessary and dangerous re-initialisation of smc_v*_hashinfo.ht in\nsmc_init(); it is implicitly initialised to zero anyhow. Add\nHLIST_HEAD_INIT to the definitions for clarity.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02954 |
debian: CVE-2026-64005 was patched at 2026-07-14
ubuntu: CVE-2026-64005 was patched at 2026-07-30
1525.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64009) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfrm: Check for underflow in xfrm_state_mtu Leo Lin reported OOB write issue in esp component: xfrm_state_mtu() returns u32 but performs its arithmetic in unsigned modulo-2^32 space using an attacker-influenced "header_len + authsize + net_adj" subtracted from a small "mtu" argument. A nobody user can install an IPv4 ESP tunnel SA with a large authentication key (XFRMA_ALG_AUTH_TRUNC, e.g. hmac(sha512), 64-byte key, 64-byte trunc), configure a small interface MTU (68 bytes), and set XFRMA_TFCPAD to a large value. When a single UDP datagram is then sent through the tunnel, xfrm_state_mtu() underflows to a near-2^32 value, and esp_output() consumes it as a signed int via: padto = min(x->tfcpad, xfrm_state_mtu(x, mtu_cached)) esp.tfclen = padto - skb->len (assigned to int) esp.tfclen ends up negative (e.g. -207). It is sign-extended to size_t when passed to memset() inside esp_output_fill_trailer(), producing a ~16 EB write of zeroes at skb_tail_pointer(skb). KASAN logs it as "Write of size 18446744073709551537 at addr ffff888...". Check for underflow and return 1. This causes the sendmsg attempt to fail with ENETUNREACH.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: Check for underflow in xfrm_state_mtu\n\nLeo Lin reported OOB write issue in esp component:\n\n xfrm_state_mtu() returns u32 but performs its arithmetic in unsigned\n modulo-2^32 space using an attacker-influenced "header_len + authsize +\n net_adj" subtracted from a small "mtu" argument. A nobody user can\n install an IPv4 ESP tunnel SA with a large authentication key\n (XFRMA_ALG_AUTH_TRUNC, e.g. hmac(sha512), 64-byte key, 64-byte trunc),\n configure a small interface MTU (68 bytes), and set XFRMA_TFCPAD to a\n large value. When a single UDP datagram is then sent through the\n tunnel, xfrm_state_mtu() underflows to a near-2^32 value, and\n esp_output() consumes it as a signed int via:\n\n padto = min(x->tfcpad, xfrm_state_mtu(x, mtu_cached))\n esp.tfclen = padto - skb->len (assigned to int)\n\n esp.tfclen ends up negative (e.g. -207). It is sign-extended to size_t\n when passed to memset() inside esp_output_fill_trailer(), producing a\n ~16 EB write of zeroes at skb_tail_pointer(skb). KASAN logs it as\n "Write of size 18446744073709551537 at addr ffff888...".\n\nCheck for underflow and return 1. This causes the sendmsg attempt to\nfail with ENETUNREACH.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00143, EPSS Percentile is 0.04135 |
debian: CVE-2026-64009 was patched at 2026-07-14
ubuntu: CVE-2026-64009 was patched at 2026-07-30
1526.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64015) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: security/keys: fix missed RCU read section on lookup Nicholas Carlini reports that the keyring code calls assoc_array_find() in find_key_to_update() without holding the RCU read lock, while the assoc_array_gc() code really is designed around removing the node from the tree and then freeing it after an RCU grace-period. The regular key handling doesn't see this because holding the keyring semaphore hides any lifetime issues, but the persistent key handling uses a different model. Instead of extending the keyring locking, just do the simple RCU locking that the assoc_array was designed for.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsecurity/keys: fix missed RCU read section on lookup\n\nNicholas Carlini reports that the keyring code calls assoc_array_find()\nin find_key_to_update() without holding the RCU read lock, while the\nassoc_array_gc() code really is designed around removing the node from\nthe tree and then freeing it after an RCU grace-period.\n\nThe regular key handling doesn't see this because holding the keyring\nsemaphore hides any lifetime issues, but the persistent key handling\nuses a different model.\n\nInstead of extending the keyring locking, just do the simple RCU locking\nthat the assoc_array was designed for.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02975 |
debian: CVE-2026-64015 was patched at 2026-07-14
ubuntu: CVE-2026-64015 was patched at 2026-07-30
1527.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64026) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: rxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg This improves the fix for CVE-2026-43500. Fix the pagecache corruption from in-place decryption of a DATA packet transmitted locally by splice() by getting rid of the packet sharing in the I/O thread and unconditionally extracting the packet content into a bounce buffer in which the buffer is decrypted. recvmsg() (or the kernel equivalent) then copies the data from the bounce buffer to the destination buffer. The sk_buff then remains unmodified. This has an additional advantage in that the packet is then arranged in the buffer with the correct alignment required for the crypto algorithms to process directly. The performance of the crypto does seem to be a little faster and, surprisingly, the unencrypted performance doesn't seem to change much - possibly due to removing complexity from the I/O thread. Yet another advantage is that the I/O thread doesn't have to copy packets which would slow down packet distribution, ACK generation, etc.. The buffer belongs to the call and is allocated initially at 2K, sufficiently large to hold a whole jumbo subpacket, but the buffer will be increased in size if needed. However, to take this work, MSG_PEEK may cause a later packet to be decrypted into the buffer, in which case the earlier one will need re-decrypting for a subsequent recvmsg(). Note that rx_pkt_offset may legitimately see 0 as a valid offset now, so switch to using USHRT_MAX to indicate an invalid offset. Note also that I would generally prefer to replace the buffers of the current sk_buff with a new kmalloc'd buffer of the right size, ditching the old data and frags as this makes the handling of MSG_PEEK easier and removes the re-decryption issue, but this looks like quite a complicated thing to achieve. skb_morph() looks half way to what I want, but I don't want to have to allocate a new sk_buff.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nrxrpc: Fix DATA decrypt vs splice() by copying data to buffer in recvmsg\n\nThis improves the fix for CVE-2026-43500.\n\nFix the pagecache corruption from in-place decryption of a DATA packet\ntransmitted locally by splice() by getting rid of the packet sharing in the\nI/O thread and unconditionally extracting the packet content into a bounce\nbuffer in which the buffer is decrypted. recvmsg() (or the kernel\nequivalent) then copies the data from the bounce buffer to the destination\nbuffer. The sk_buff then remains unmodified.\n\nThis has an additional advantage in that the packet is then arranged in the\nbuffer with the correct alignment required for the crypto algorithms to\nprocess directly. The performance of the crypto does seem to be a little\nfaster and, surprisingly, the unencrypted performance doesn't seem to\nchange much - possibly due to removing complexity from the I/O thread.\n\nYet another advantage is that the I/O thread doesn't have to copy packets\nwhich would slow down packet distribution, ACK generation, etc..\n\nThe buffer belongs to the call and is allocated initially at 2K,\nsufficiently large to hold a whole jumbo subpacket, but the buffer will be\nincreased in size if needed. However, to take this work, MSG_PEEK may\ncause a later packet to be decrypted into the buffer, in which case the\nearlier one will need re-decrypting for a subsequent recvmsg().\n\nNote that rx_pkt_offset may legitimately see 0 as a valid offset now, so\nswitch to using USHRT_MAX to indicate an invalid offset.\n\nNote also that I would generally prefer to replace the buffers of the\ncurrent sk_buff with a new kmalloc'd buffer of the right size, ditching the\nold data and frags as this makes the handling of MSG_PEEK easier and\nremoves the re-decryption issue, but this looks like quite a complicated\nthing to achieve. skb_morph() looks half way to what I want, but I don't\nwant to have to allocate a new sk_buff.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02912 |
debian: CVE-2026-64026 was patched at 2026-07-14
ubuntu: CVE-2026-64026 was patched at 2026-07-30
1528.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64036) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: cgroup/rstat: validate cpu before css_rstat_cpu() access css_rstat_updated() is exposed as a BPF kfunc and accepts a caller-provided cpu argument. The function uses cpu for per-cpu rstat lookups without checking whether it refers to a valid possible CPU. A BPF iter/cgroup program with CAP_BPF and CAP_PERFMON can pass an invalid cpu value. On an unfixed UBSCAN_BOUNDS test kernel, cpu == 0x7fffffff triggers: UBSAN: array-index-out-of-bounds in kernel/cgroup/rstat.c:31:9 index 2147483647 is out of range for type 'long unsigned int [64]' Call Trace: css_rstat_updated bpf_iter_run_prog cgroup_iter_seq_show bpf_seq_read Add cpu validation to the BPF-facing css_rstat_updated() kfunc and move the common implementation to __css_rstat_updated() for in-kernel callers.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncgroup/rstat: validate cpu before css_rstat_cpu() access\n\ncss_rstat_updated() is exposed as a BPF kfunc and accepts a\ncaller-provided cpu argument. The function uses cpu for per-cpu rstat\nlookups without checking whether it refers to a valid possible CPU.\n\nA BPF iter/cgroup program with CAP_BPF and CAP_PERFMON can pass an\ninvalid cpu value. On an unfixed UBSCAN_BOUNDS test kernel, cpu ==\n0x7fffffff triggers:\n\n UBSAN: array-index-out-of-bounds in kernel/cgroup/rstat.c:31:9\n index 2147483647 is out of range for type 'long unsigned int [64]'\n Call Trace:\n css_rstat_updated\n bpf_iter_run_prog\n cgroup_iter_seq_show\n bpf_seq_read\n\nAdd cpu validation to the BPF-facing css_rstat_updated() kfunc and\nmove the common implementation to __css_rstat_updated() for in-kernel\ncallers.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02769 |
debian: CVE-2026-64036 was patched at 2026-07-14
ubuntu: CVE-2026-64036 was patched at 2026-07-30
1529.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64051) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: accel/qaic: Add overflow check to remap_pfn_range during mmap The call to remap_pfn_range in qaic_gem_object_mmap is susceptible to (re)mapping beyond the VMA if the BO is too large. This can cause use after free issues when munmap() unmaps only the VMA region and not the additional mappings. To prevent this, check the remaining size of the VMA before remapping and truncate the remapped length if sg->length is too large. [jhugo: fix braces from checkpatch --strict]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\naccel/qaic: Add overflow check to remap_pfn_range during mmap\n\nThe call to remap_pfn_range in qaic_gem_object_mmap is susceptible to\n(re)mapping beyond the VMA if the BO is too large. This can cause use\nafter free issues when munmap() unmaps only the VMA region and not the\nadditional mappings. To prevent this, check the remaining size of the\nVMA before remapping and truncate the remapped length if sg->length is\ntoo large.\n\n[jhugo: fix braces from checkpatch --strict]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02905 |
debian: CVE-2026-64051 was patched at 2026-07-14
ubuntu: CVE-2026-64051 was patched at 2026-07-30
1530.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64053) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: block: don't overwrite bip_vcnt in bio_integrity_copy_user() bio_integrity_add_page() already sets bip_vcnt to 1 for the bounce segment. Overwriting it with nr_vecs breaks bip_vcnt <= bip_max_vcnt on WRITE (bip_max_vcnt is 1), so the gap-merge checks in block/blk.h read past the bip_vec[] flex array. On READ the read is in bounds but lands on a saved user bvec instead of the bounce. The line was added for split propagation, but bio_integrity_clone() doesn't copy bip_vcnt and BIP_CLONE_FLAGS excludes BIP_COPY_USER.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nblock: don't overwrite bip_vcnt in bio_integrity_copy_user()\n\nbio_integrity_add_page() already sets bip_vcnt to 1 for the bounce\nsegment. Overwriting it with nr_vecs breaks bip_vcnt <= bip_max_vcnt\non WRITE (bip_max_vcnt is 1), so the gap-merge checks in block/blk.h\nread past the bip_vec[] flex array. On READ the read is in bounds\nbut lands on a saved user bvec instead of the bounce.\n\nThe line was added for split propagation, but bio_integrity_clone()\ndoesn't copy bip_vcnt and BIP_CLONE_FLAGS excludes BIP_COPY_USER.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02911 |
debian: CVE-2026-64053 was patched at 2026-07-14
ubuntu: CVE-2026-64053 was patched at 2026-07-30
1531.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64058) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_read_folio() to wait on writeback Fix netfs_read_folio() to wait for an ongoing writeback to complete so that it can trust the dirty flag and whatever is attached to folio->private (folio->private may get cleaned up by the collector before it clears the writeback flag).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix netfs_read_folio() to wait on writeback\n\nFix netfs_read_folio() to wait for an ongoing writeback to complete so that\nit can trust the dirty flag and whatever is attached to folio->private\n(folio->private may get cleaned up by the collector before it clears the\nwriteback flag).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02769 |
debian: CVE-2026-64058 was patched at 2026-07-14
ubuntu: CVE-2026-64058 was patched at 2026-07-30
1532.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64076) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: bridge: eb_tables: close module init race sashiko reports for unrelated patch: Does the core ebtables initialization in ebtables.c suffer from a similar race? Once nf_register_sockopt() completes, the sockopts are exposed globally. sockopt has to be registered last, just like in ip/ip6/arptables.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: bridge: eb_tables: close module init race\n\nsashiko reports for unrelated patch:\n Does the core ebtables initialization in ebtables.c suffer from a similar race?\n Once nf_register_sockopt() completes, the sockopts are exposed globally.\n\nsockopt has to be registered last, just like in ip/ip6/arptables.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02773 |
debian: CVE-2026-64076 was patched at 2026-07-14
ubuntu: CVE-2026-64076 was patched at 2026-07-30
1533.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64077) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: move to two-stage removal scheme Like previous patches for x_tables, follow same pattern in ebtables. We can't reuse xt helpers: ebt_table struct layout is incompatible. table->ops assignment is now done while still holding the ebt mutex to make sure we never expose partially-filled table struct.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: ebtables: move to two-stage removal scheme\n\nLike previous patches for x_tables, follow same pattern in ebtables.\nWe can't reuse xt helpers: ebt_table struct layout is incompatible.\n\ntable->ops assignment is now done while still holding the ebt mutex\nto make sure we never expose partially-filled table struct.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02775 |
debian: CVE-2026-64077 was patched at 2026-07-14
ubuntu: CVE-2026-64077 was patched at 2026-07-30
1534.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64078) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: add and use xtables_unregister_table_exit Previous change added xtables_unregister_table_pre_exit to detach the table from the packetpath and to unlink it from the active table list. In case of rmmod, userspace that is doing set/getsockopt for this table will not be able to re-instantiate the table: 1. The larval table has been removed already 2. existing instantiated table is no longer on the xt pernet table list. This adds the second stage helper: unlink the table from the dying list, free the hook ops (if any) and do the audit notification. It replaces xt_unregister_table().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: x_tables: add and use xtables_unregister_table_exit\n\nPrevious change added xtables_unregister_table_pre_exit to detach the\ntable from the packetpath and to unlink it from the active table list.\nIn case of rmmod, userspace that is doing set/getsockopt for this table\nwill not be able to re-instantiate the table:\n 1. The larval table has been removed already\n 2. existing instantiated table is no longer on the xt pernet table list.\n\nThis adds the second stage helper:\n\nunlink the table from the dying list, free the hook ops (if any) and do\nthe audit notification. It replaces xt_unregister_table().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02775 |
debian: CVE-2026-64078 was patched at 2026-07-14
ubuntu: CVE-2026-64078 was patched at 2026-07-30
1535.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64082) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: riscv: Fix register corruption from uninitialized cregs on error compat_riscv_gpr_set() calls cregs_to_regs() unconditionally, even when user_regset_copyin() fails. Since cregs is an uninitialized stack variable, a copyin failure causes uninitialized stack data to be written into the target task's pt_regs, corrupting its register state and potentially leaking kernel stack contents. compat_restore_sigcontext() has the same issue: it calls cregs_to_regs() even when __copy_from_user() fails, leading to the same corruption of the signal-returning task's register state on error. Only call cregs_to_regs() when the user copy succeeds.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nriscv: Fix register corruption from uninitialized cregs on error\n\ncompat_riscv_gpr_set() calls cregs_to_regs() unconditionally, even when\nuser_regset_copyin() fails. Since cregs is an uninitialized stack\nvariable, a copyin failure causes uninitialized stack data to be written\ninto the target task's pt_regs, corrupting its register state and\npotentially leaking kernel stack contents.\n\ncompat_restore_sigcontext() has the same issue: it calls cregs_to_regs()\neven when __copy_from_user() fails, leading to the same corruption of\nthe signal-returning task's register state on error.\n\nOnly call cregs_to_regs() when the user copy succeeds.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02195 |
debian: CVE-2026-64082 was patched at 2026-07-14
ubuntu: CVE-2026-64082 was patched at 2026-07-30
1536.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64084) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR adm1266_gpio_get_multiple() iterates the PDIO portion of the caller-supplied mask using \tfor_each_set_bit_from(gpio_nr, mask, \t\t\t ADM1266_GPIO_NR + ADM1266_PDIO_STATUS) { \t\t... \t} where ADM1266_PDIO_STATUS is the PMBus command code (0xE9, i.e. 233), not the number of PDIO pins. The intended upper bound is ADM1266_GPIO_NR + ADM1266_PDIO_NR = 25. gpiolib hands in a mask sized for gc.ngpio (= 25 bits on this chip), so the iteration walks find_next_bit() up to 242, reading up to 217 extra bits (a handful of unsigned-long words: four on 64-bit, seven on 32-bit) of whatever lives past the end of the mask in the caller's stack. Any incidental set bit in that range then drives a set_bit(gpio_nr, bits) call that writes past the end of the caller-supplied bits array too -- both out-of-bounds. Substitute ADM1266_PDIO_NR for the constant so the scan stops at the last real PDIO bit.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) cap PDIO scan in get_multiple at ADM1266_PDIO_NR\n\nadm1266_gpio_get_multiple() iterates the PDIO portion of the\ncaller-supplied mask using\n\n\tfor_each_set_bit_from(gpio_nr, mask,\n\t\t\t ADM1266_GPIO_NR + ADM1266_PDIO_STATUS) {\n\t\t...\n\t}\n\nwhere ADM1266_PDIO_STATUS is the PMBus command code (0xE9, i.e. 233),\nnot the number of PDIO pins. The intended upper bound is\nADM1266_GPIO_NR + ADM1266_PDIO_NR = 25.\n\ngpiolib hands in a mask sized for gc.ngpio (= 25 bits on this chip),\nso the iteration walks find_next_bit() up to 242, reading up to 217\nextra bits (a handful of unsigned-long words: four on 64-bit, seven\non 32-bit) of whatever lives past the end of the mask in the\ncaller's stack. Any incidental set bit in that range then drives a\nset_bit(gpio_nr, bits) call that writes past the end of the\ncaller-supplied bits array too -- both out-of-bounds.\n\nSubstitute ADM1266_PDIO_NR for the constant so the scan stops at the\nlast real PDIO bit.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00139, EPSS Percentile is 0.03702 |
debian: CVE-2026-64084 was patched at 2026-07-14
ubuntu: CVE-2026-64084 was patched at 2026-07-30
1537.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64086) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer adm1266_pmbus_block_xfer() sets up the read transaction with \t.buf = data->read_buf, \t.len = ADM1266_PMBUS_BLOCK_MAX + 2, but read_buf in struct adm1266_data is declared as \tu8 read_buf[ADM1266_PMBUS_BLOCK_MAX + 1]; For a max-length block response (length byte = 255 + up to 1 PEC byte), the i2c controller is told to write 257 bytes into a 256-byte buffer, putting one byte past the end of read_buf. The same response also makes the subsequent PEC compare \tif (crc != msgs[1].buf[msgs[1].buf[0] + 1]) read a byte beyond the array. Bump the read_buf declaration to ADM1266_PMBUS_BLOCK_MAX + 2 so the buffer can hold the length byte, up to 255 payload bytes, and the PEC byte the i2c_msg length already accounts for.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) include PEC byte in pmbus_block_xfer read buffer\n\nadm1266_pmbus_block_xfer() sets up the read transaction with\n\n\t.buf = data->read_buf,\n\t.len = ADM1266_PMBUS_BLOCK_MAX + 2,\n\nbut read_buf in struct adm1266_data is declared as\n\n\tu8 read_buf[ADM1266_PMBUS_BLOCK_MAX + 1];\n\nFor a max-length block response (length byte = 255 + up to 1 PEC\nbyte), the i2c controller is told to write 257 bytes into a 256-byte\nbuffer, putting one byte past the end of read_buf. The same response\nalso makes the subsequent PEC compare\n\n\tif (crc != msgs[1].buf[msgs[1].buf[0] + 1])\n\nread a byte beyond the array.\n\nBump the read_buf declaration to ADM1266_PMBUS_BLOCK_MAX + 2 so the\nbuffer can hold the length byte, up to 255 payload bytes, and the PEC\nbyte the i2c_msg length already accounts for.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00139, EPSS Percentile is 0.03701 |
debian: CVE-2026-64086 was patched at 2026-07-14
ubuntu: CVE-2026-64086 was patched at 2026-07-30
1538.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64098) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/virtio: use uninterruptible resv lock for plane updates virtio_gpu_cursor_plane_update() and virtio_gpu_resource_flush() lock the framebuffer BO's dma_resv via virtio_gpu_array_lock_resv() and ignore its return value. The function can fail with -EINTR from dma_resv_lock_interruptible() (signal during lock wait) or with -ENOMEM from dma_resv_reserve_fences() (fence slot allocation), leaving the resv lock not held. The queue path then walks the object array and calls dma_resv_add_fence(), which requires the lock held; with lockdep enabled this trips dma_resv_assert_held(): WARNING: drivers/dma-buf/dma-resv.c:296 at dma_resv_add_fence+0x71e/0x840 Call Trace: virtio_gpu_array_add_fence virtio_gpu_queue_ctrl_sgs virtio_gpu_queue_fenced_ctrl_buffer virtio_gpu_cursor_plane_update drm_atomic_helper_commit_planes drm_atomic_helper_commit_tail commit_tail drm_atomic_helper_commit drm_atomic_commit drm_atomic_helper_update_plane __setplane_atomic drm_mode_cursor_universal drm_mode_cursor_common drm_mode_cursor_ioctl drm_ioctl __x64_sys_ioctl Beyond the WARN, mutating the dma_resv fence list without the lock races with concurrent readers/writers and can corrupt the list. Both call sites run inside the .atomic_update plane callback, which DRM atomic helpers do not allow to fail (by the time it runs, the commit has been signed off to userspace and there is no clean rollback path). Moving the lock acquisition to .prepare_fb was rejected because the broader lock scope deadlocks against other BO locking paths in the same atomic commit. Introduce virtio_gpu_lock_one_resv_uninterruptible() that uses dma_resv_lock() instead of dma_resv_lock_interruptible(). This eliminates the -EINTR failure mode -- the realistic syzbot trigger -- without extending the lock hold across the commit. The helper locks a single BO and rejects nents > 1 with -EINVAL; both fix sites lock exactly one BO. Use it from virtio_gpu_cursor_plane_update() and virtio_gpu_resource_flush(); check the return value to handle the remaining -ENOMEM case from dma_resv_reserve_fences() by freeing the objs and skipping the plane update for that frame. The framebuffer BOs touched here are not shared with other contexts and lock contention is expected to be brief, so the loss of signal-interruptibility is acceptable. Other callers of virtio_gpu_array_lock_resv() (the ioctl paths) continue to use the interruptible variant. The bug was reported by syzbot, triggered via fault injection (fail_nth) on the DRM_IOCTL_MODE_CURSOR path, which forces the -ENOMEM branch in dma_resv_reserve_fences().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/virtio: use uninterruptible resv lock for plane updates\n\nvirtio_gpu_cursor_plane_update() and virtio_gpu_resource_flush() lock\nthe framebuffer BO's dma_resv via virtio_gpu_array_lock_resv() and\nignore its return value. The function can fail with -EINTR from\ndma_resv_lock_interruptible() (signal during lock wait) or with\n-ENOMEM from dma_resv_reserve_fences() (fence slot allocation),\nleaving the resv lock not held. The queue path then walks the object\narray and calls dma_resv_add_fence(), which requires the lock held;\nwith lockdep enabled this trips dma_resv_assert_held():\n\n WARNING: drivers/dma-buf/dma-resv.c:296 at dma_resv_add_fence+0x71e/0x840\n Call Trace:\n virtio_gpu_array_add_fence\n virtio_gpu_queue_ctrl_sgs\n virtio_gpu_queue_fenced_ctrl_buffer\n virtio_gpu_cursor_plane_update\n drm_atomic_helper_commit_planes\n drm_atomic_helper_commit_tail\n commit_tail\n drm_atomic_helper_commit\n drm_atomic_commit\n drm_atomic_helper_update_plane\n __setplane_atomic\n drm_mode_cursor_universal\n drm_mode_cursor_common\n drm_mode_cursor_ioctl\n drm_ioctl\n __x64_sys_ioctl\n\nBeyond the WARN, mutating the dma_resv fence list without the lock\nraces with concurrent readers/writers and can corrupt the list.\n\nBoth call sites run inside the .atomic_update plane callback, which\nDRM atomic helpers do not allow to fail (by the time it runs, the\ncommit has been signed off to userspace and there is no clean\nrollback path). Moving the lock acquisition to .prepare_fb was\nrejected because the broader lock scope deadlocks against other BO\nlocking paths in the same atomic commit.\n\nIntroduce virtio_gpu_lock_one_resv_uninterruptible() that uses\ndma_resv_lock() instead of dma_resv_lock_interruptible(). This\neliminates the -EINTR failure mode -- the realistic syzbot trigger\n-- without extending the lock hold across the commit. The helper\nlocks a single BO and rejects nents > 1 with -EINVAL; both fix\nsites lock exactly one BO.\n\nUse it from virtio_gpu_cursor_plane_update() and\nvirtio_gpu_resource_flush(); check the return value to handle the\nremaining -ENOMEM case from dma_resv_reserve_fences() by freeing\nthe objs and skipping the plane update for that frame. The\nframebuffer BOs touched here are not shared with other contexts\nand lock contention is expected to be brief, so the loss of\nsignal-interruptibility is acceptable.\n\nOther callers of virtio_gpu_array_lock_resv() (the ioctl paths)\ncontinue to use the interruptible variant.\n\nThe bug was reported by syzbot, triggered via fault injection\n(fail_nth) on the DRM_IOCTL_MODE_CURSOR path, which forces the\n-ENOMEM branch in dma_resv_reserve_fences().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00146, EPSS Percentile is 0.04347 |
debian: CVE-2026-64098 was patched at 2026-07-14
ubuntu: CVE-2026-64098 was patched at 2026-07-30
1539.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64108) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: cifs: Fix busy dentry used after unmounting Since commit 340cea84f691c ("cifs: open files should not hold ref on superblock"), cifs file only holds the dentry ref_cnt, the cifs file close work(cfile->deferred) could be executed after unmounting, which will trigger a warning in generic_shutdown_super: BUG: Dentry 00000000a14a6845{i=c,n=file} still in use (1) [unmount of cifs cifs] The detailed processs is: process A process B kworker fd = open(PATH) vfs_open file->__f_path = *path // dentry->d_lockref.count = 1 cifs_open cifs_new_fileinfo cfile->dentry = dget(dentry) // dentry->d_lockref.count = 2 close(fd) __fput cifs_close queue_delayed_work(deferredclose_wq, cfile->deferred) dput(dentry) // dentry->d_lockref.count = 1 \t\t\t smb2_deferred_work_close \t\t\t\t\t _cifsFileInfo_put \t\t\t\t\t list_del(&cifs_file->flist) umount \t\t cleanup_mnt \t\t deactivate_super \t\t cifs_kill_sb \t\t cifs_close_all_deferred_files_sb \t\t\t cifs_close_all_deferred_files \t\t\t // cannot find cfile, skip _cifsFileInfo_put \t\t\tkill_anon_super \t\t\t generic_shutdown_super \t\t\t shrink_dcache_for_umount \t\t\t umount_check \t\t\t WARN ! // dentry->d_lockref.count = 1 \t\t\t\t\t cifsFileInfo_put_final \t\t\t\t\t dput(cifs_file->dentry) \t\t // dentry->d_lockref.count = 0 Fix it by flushing 'deferredclose_wq' before calling kill_anon_super. Fetch a reproducer in https://bugzilla.kernel.org/show_bug.cgi?id=221548.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ncifs: Fix busy dentry used after unmounting\n\nSince commit 340cea84f691c ("cifs: open files should not hold ref on\nsuperblock"), cifs file only holds the dentry ref_cnt, the cifs file\nclose work(cfile->deferred) could be executed after unmounting, which\nwill trigger a warning in generic_shutdown_super:\n BUG: Dentry 00000000a14a6845{i=c,n=file} still in use (1) [unmount of\n cifs cifs]\n\nThe detailed processs is:\n process A process B kworker\n fd = open(PATH)\n vfs_open\n file->__f_path = *path // dentry->d_lockref.count = 1\n cifs_open\n cifs_new_fileinfo\n cfile->dentry = dget(dentry) // dentry->d_lockref.count = 2\n close(fd)\n __fput\n cifs_close\n queue_delayed_work(deferredclose_wq, cfile->deferred)\n dput(dentry) // dentry->d_lockref.count = 1\n\t\t\t smb2_deferred_work_close\n\t\t\t\t\t _cifsFileInfo_put\n\t\t\t\t\t list_del(&cifs_file->flist)\n umount\n\t\t cleanup_mnt\n\t\t deactivate_super\n\t\t cifs_kill_sb\n\t\t cifs_close_all_deferred_files_sb\n\t\t\t cifs_close_all_deferred_files\n\t\t\t // cannot find cfile, skip _cifsFileInfo_put\n\t\t\tkill_anon_super\n\t\t\t generic_shutdown_super\n\t\t\t shrink_dcache_for_umount\n\t\t\t umount_check\n\t\t\t WARN ! // dentry->d_lockref.count = 1\n\t\t\t\t\t cifsFileInfo_put_final\n\t\t\t\t\t dput(cifs_file->dentry)\n\t\t // dentry->d_lockref.count = 0\n\nFix it by flushing 'deferredclose_wq' before calling kill_anon_super.\n\nFetch a reproducer in https://bugzilla.kernel.org/show_bug.cgi?id=221548.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02969 |
debian: CVE-2026-64108 was patched at 2026-07-14
ubuntu: CVE-2026-64108 was patched at 2026-07-30
1540.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64112) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: rbd: eliminate a race in lock_dwork draining on unmap Given how rbd_lock_add_request() and rbd_img_exclusive_lock() are written, lock_dwork may be (re)queued more than it's actually needed: for example in case a new I/O request comes in while we are in the middle of rbd_acquire_lock() on behalf of another I/O request. This is expected and with rbd_release_lock() preemptively canceling lock_dwork is benign under normal operation. A more problematic example is maybe_kick_acquire(): if (have_requests || delayed_work_pending(&rbd_dev->lock_dwork)) { dout("%s rbd_dev %p kicking lock_dwork\\n", __func__, rbd_dev); mod_delayed_work(rbd_dev->task_wq, &rbd_dev->lock_dwork, 0); } It's not unrealistic for lock_dwork to get canceled right after delayed_work_pending() returns true and for mod_delayed_work() to requeue it right there anyway. This is a classic TOCTOU race. When it comes to unmapping the image, there is an implicit assumption of no self-initiated exclusive lock activity past the point of return from rbd_dev_image_unlock() which unlocks the lock if it happens to be held. This unlock is assumed to be final and lock_dwork (as well as all other exclusive lock tasks, really) isn't expected to get queued again. However, lock_dwork is canceled only in cancel_tasks_sync() (i.e. later in the unmap sequence) and on top of that the cancellation can get in effect nullified by maybe_kick_acquire(). This may result in rbd_acquire_lock() executing after rbd_dev_device_release() and rbd_dev_image_release() run and free and/or reset a bunch of things. One of the possible failure modes then is a violated rbd_assert(rbd_image_format_valid(rbd_dev->image_format)); in rbd_dev_header_info() which is called via rbd_dev_refresh() from rbd_post_acquire_action(). Redo exclusive lock task draining to provide saner semantics and try to meet the assumptions around rbd_dev_image_unlock().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nrbd: eliminate a race in lock_dwork draining on unmap\n\nGiven how rbd_lock_add_request() and rbd_img_exclusive_lock() are\nwritten, lock_dwork may be (re)queued more than it's actually needed:\nfor example in case a new I/O request comes in while we are in the\nmiddle of rbd_acquire_lock() on behalf of another I/O request. This is\nexpected and with rbd_release_lock() preemptively canceling lock_dwork\nis benign under normal operation.\n\nA more problematic example is maybe_kick_acquire():\n\n if (have_requests || delayed_work_pending(&rbd_dev->lock_dwork)) {\n dout("%s rbd_dev %p kicking lock_dwork\\n", __func__, rbd_dev);\n mod_delayed_work(rbd_dev->task_wq, &rbd_dev->lock_dwork, 0);\n }\n\nIt's not unrealistic for lock_dwork to get canceled right after\ndelayed_work_pending() returns true and for mod_delayed_work() to\nrequeue it right there anyway. This is a classic TOCTOU race.\n\nWhen it comes to unmapping the image, there is an implicit assumption\nof no self-initiated exclusive lock activity past the point of return\nfrom rbd_dev_image_unlock() which unlocks the lock if it happens to be\nheld. This unlock is assumed to be final and lock_dwork (as well as\nall other exclusive lock tasks, really) isn't expected to get queued\nagain. However, lock_dwork is canceled only in cancel_tasks_sync()\n(i.e. later in the unmap sequence) and on top of that the cancellation\ncan get in effect nullified by maybe_kick_acquire(). This may result\nin rbd_acquire_lock() executing after rbd_dev_device_release() and\nrbd_dev_image_release() run and free and/or reset a bunch of things.\nOne of the possible failure modes then is a violated\n\n rbd_assert(rbd_image_format_valid(rbd_dev->image_format));\n\nin rbd_dev_header_info() which is called via rbd_dev_refresh() from\nrbd_post_acquire_action().\n\nRedo exclusive lock task draining to provide saner semantics and try\nto meet the assumptions around rbd_dev_image_unlock().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02908 |
debian: CVE-2026-64112 was patched at 2026-07-14
ubuntu: CVE-2026-64112 was patched at 2026-07-30
1541.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64114) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 raw_send_hdrinc() validates that the caller-supplied IPv4 header fits within the message length: iphlen = iph->ihl * 4; err = -EINVAL; if (iphlen > length) goto error_free; if (iphlen >= sizeof(*iph)) { /* fix up saddr, tot_len, id, csum, transport_header */ } It does not, however, reject ihl < 5. For such a packet the "if (iphlen >= sizeof(*iph))" branch is skipped, leaving the crafted iphdr untouched, but the packet is still handed to __ip_local_out() and onward. Downstream consumers that read iph->ihl assume a sane value: net/ipv4/ah4.c:ah_output() in particular subtracts sizeof(struct iphdr) from top_iph->ihl * 4 and passes the (signed-int-negative, then cast to size_t) result to memcpy(), producing an OOB access of length close to SIZE_MAX and a host kernel panic. An IPv4 header with ihl < 5 is malformed by definition (RFC 791: "Internet Header Length is the length of the internet header in 32 bit words ... Note that the minimum value for a correct header is 5."). The kernel should not be willing to inject such a packet into its own output path. Reject "iphlen < sizeof(*iph)" alongside the existing "iphlen > length" check. This matches the principle that locally constructed packets that re-enter the IP stack must pass the same basic sanity tests that a foreign packet would be subjected to. Once this lands, the "if (iphlen >= sizeof(*iph))" wrapper around the fixup branch becomes redundant; left in place to keep the patch minimal and backport-friendly. A follow-up can unwrap it. Note that commit 86f4c90a1c5c ("ipv4, ipv6: ensure raw socket message is big enough to hold an IP header") ensures the message buffer is large enough to hold an iphdr, but does not constrain the self-reported iph->ihl. Reachability: the malformed packet source is any caller with CAP_NET_RAW, including an unprivileged process in a user+net namespace on a kernel with CONFIG_USER_NS=y. The reproduced AH crash also requires a matching xfrm AH policy on the outgoing route; a container granted CAP_NET_ADMIN can install that state and policy in its netns. Loopback bypasses xfrm_output, so the trigger uses a real netdev. Reproduced on UML + KASAN: kernel-mode fault at addr 0x0 with memcpy_orig at the crash site. Same shape reproduces inside a rootless Docker container with --cap-add NET_ADMIN on a stock distro kernel.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: raw: reject IP_HDRINCL packets with ihl < 5\n\nraw_send_hdrinc() validates that the caller-supplied IPv4 header\nfits within the message length:\n\n iphlen = iph->ihl * 4;\n err = -EINVAL;\n if (iphlen > length)\n goto error_free;\n\n if (iphlen >= sizeof(*iph)) {\n /* fix up saddr, tot_len, id, csum, transport_header */\n }\n\nIt does not, however, reject ihl < 5. For such a packet the\n"if (iphlen >= sizeof(*iph))" branch is skipped, leaving the\ncrafted iphdr untouched, but the packet is still handed to\n__ip_local_out() and onward. Downstream consumers that read\niph->ihl assume a sane value: net/ipv4/ah4.c:ah_output() in\nparticular subtracts sizeof(struct iphdr) from top_iph->ihl * 4\nand passes the (signed-int-negative, then cast to size_t)\nresult to memcpy(), producing an OOB access of length close to\nSIZE_MAX and a host kernel panic.\n\nAn IPv4 header with ihl < 5 is malformed by definition (RFC 791:\n"Internet Header Length is the length of the internet header in\n32 bit words ... Note that the minimum value for a correct header\nis 5."). The kernel should not be willing to inject such a\npacket into its own output path.\n\nReject "iphlen < sizeof(*iph)" alongside the existing\n"iphlen > length" check. This matches the principle that locally\nconstructed packets that re-enter the IP stack must pass the same\nbasic sanity tests that a foreign packet would be subjected to.\n\nOnce this lands, the "if (iphlen >= sizeof(*iph))" wrapper around\nthe fixup branch becomes redundant; left in place to keep the\npatch minimal and backport-friendly. A follow-up can unwrap it.\n\nNote that commit 86f4c90a1c5c ("ipv4, ipv6: ensure raw socket\nmessage is big enough to hold an IP header") ensures the message\nbuffer is large enough to hold an iphdr, but does not constrain\nthe self-reported iph->ihl.\n\nReachability: the malformed packet source is any caller with\nCAP_NET_RAW, including an unprivileged process in a user+net\nnamespace on a kernel with CONFIG_USER_NS=y. The reproduced AH\ncrash also requires a matching xfrm AH policy on the outgoing\nroute; a container granted CAP_NET_ADMIN can install that state\nand policy in its netns. Loopback bypasses xfrm_output, so the\ntrigger uses a real netdev.\n\nReproduced on UML + KASAN: kernel-mode fault at addr 0x0 with\nmemcpy_orig at the crash site. Same shape reproduces inside a\nrootless Docker container with --cap-add NET_ADMIN on a stock\ndistro kernel.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00136, EPSS Percentile is 0.03465 |
debian: CVE-2026-64114 was patched at 2026-07-14
ubuntu: CVE-2026-64114 was patched at 2026-07-30
1542.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64118) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: qed: fix double free in qed_cxt_tables_alloc() If one of the later PF or VF CID bitmap allocations fails, qed_cid_map_alloc() jumps to cid_map_fail and frees the previously allocated CID bitmaps before returning an error. qed_cxt_tables_alloc() then calls qed_cxt_mngr_free(), which invokes qed_cid_map_free() again. Fix this by setting each CID bitmap pointer to NULL after bitmap_free() to avoid double free. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1-rc3. Runtime reproduction was not attempted because exercising the failing allocation path requires device-specific setup.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nqed: fix double free in qed_cxt_tables_alloc()\n\nIf one of the later PF or VF CID bitmap allocations fails,\nqed_cid_map_alloc() jumps to cid_map_fail and frees the previously\nallocated CID bitmaps before returning an error. qed_cxt_tables_alloc()\nthen calls qed_cxt_mngr_free(), which invokes qed_cid_map_free()\nagain.\n\nFix this by setting each CID bitmap pointer to NULL after bitmap_free()\nto avoid double free.\n\nThe bug was first flagged by an experimental analysis tool we are\ndeveloping for kernel memory-management bugs while analyzing\nv6.13-rc1. The tool is still under development and is not yet publicly\navailable. Manual inspection confirms that the bug is still\npresent in v7.1-rc3.\n\nRuntime reproduction was not attempted because exercising the failing\nallocation path requires device-specific setup.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 8.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04894 |
debian: CVE-2026-64118 was patched at 2026-07-14
ubuntu: CVE-2026-64118 was patched at 2026-07-30
1543.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64133) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: asihpi: Fix potential OOB array access at reading cache find_control() to retrieve a cached info accesses the array with the given index blindly, which may lead to an OOB array access. Add a sanity check for avoiding it.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: asihpi: Fix potential OOB array access at reading cache\n\nfind_control() to retrieve a cached info accesses the array with the\ngiven index blindly, which may lead to an OOB array access.\nAdd a sanity check for avoiding it.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02968 |
debian: CVE-2026-64133 was patched at 2026-07-14
ubuntu: CVE-2026-64133 was patched at 2026-07-30
1544.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64134) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: Don't setup bogus iov_iter for silencing At transition to the iov_iter for PCM data transfer, we blindly applied the iov_iter setup also for silencing (i.e. data = NULL), and it leads to a calculation of bogus iov_iter. Fortunately this didn't cause troubles on most of architectures but it goes wrong on RISC-V now, causing a NULL dereference. Handle the NULL data case to treat the silencing in interleaved_copy() for addressing the bug above. noninterleaved_copy() has already the NULL data handling, so it doesn't need changes.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: Don't setup bogus iov_iter for silencing\n\nAt transition to the iov_iter for PCM data transfer, we blindly\napplied the iov_iter setup also for silencing (i.e. data = NULL), and\nit leads to a calculation of bogus iov_iter. Fortunately this didn't\ncause troubles on most of architectures but it goes wrong on RISC-V\nnow, causing a NULL dereference.\n\nHandle the NULL data case to treat the silencing in interleaved_copy()\nfor addressing the bug above. noninterleaved_copy() has already the\nNULL data handling, so it doesn't need changes.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02909 |
debian: CVE-2026-64134 was patched at 2026-07-14
ubuntu: CVE-2026-64134 was patched at 2026-07-30
1545.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64137) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: smb: client: require net admin for CIFS SWN netlink CIFS_GENL_CMD_SWN_NOTIFY is the userspace witness-notify command. The intended sender is the cifs.witness helper, but the generic-netlink operation currently has no capability flag, so any local process can send RESOURCE_CHANGE or CLIENT_MOVE notifications to the in-kernel witness handler. The same family exposes CIFS_GENL_MCGRP_SWN without multicast-group capability flags. Register messages sent to that group include the witness registration id and, for NTLM-authenticated mounts, the username, domain, and password attributes copied from the CIFS session. An unprivileged local process should not be able to join that group and receive those messages. Require CAP_NET_ADMIN for incoming SWN_NOTIFY commands with GENL_ADMIN_PERM, and require CAP_NET_ADMIN over the network namespace for joining the SWN multicast group with GENL_MCAST_CAP_NET_ADMIN. The cifs.witness service runs with the privileges needed for both operations.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsmb: client: require net admin for CIFS SWN netlink\n\nCIFS_GENL_CMD_SWN_NOTIFY is the userspace witness-notify command. The\nintended sender is the cifs.witness helper, but the generic-netlink\noperation currently has no capability flag, so any local process can send\nRESOURCE_CHANGE or CLIENT_MOVE notifications to the in-kernel witness\nhandler.\n\nThe same family exposes CIFS_GENL_MCGRP_SWN without multicast-group\ncapability flags. Register messages sent to that group include the witness\nregistration id and, for NTLM-authenticated mounts, the username, domain,\nand password attributes copied from the CIFS session. An unprivileged\nlocal process should not be able to join that group and receive those\nmessages.\n\nRequire CAP_NET_ADMIN for incoming SWN_NOTIFY commands with\nGENL_ADMIN_PERM, and require CAP_NET_ADMIN over the network namespace for\njoining the SWN multicast group with GENL_MCAST_CAP_NET_ADMIN. The\ncifs.witness service runs with the privileges needed for both operations.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02978 |
debian: CVE-2026-64137 was patched at 2026-07-14
ubuntu: CVE-2026-64137 was patched at 2026-07-30
1546.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64191) - Medium [245]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: i2c: stub: Reject I2C block transfers with invalid length The I2C_SMBUS_I2C_BLOCK_DATA case in stub_xfer() uses data->block[0] as the transfer length. The existing check only clamps it to avoid overrunning the chip->words[256] register array, but does not validate it against I2C_SMBUS_BLOCK_MAX (32), which is the limit of the union i2c_smbus_data.block buffer (34 bytes total). The driver is a development/test tool (CONFIG_I2C_STUB=m, not built by default) that must be loaded with a chip_addr= parameter. A local user with access to /dev/i2c-* can issue an I2C_SMBUS ioctl with I2C_SMBUS_I2C_BLOCK_DATA and data->block[0] > 32, causing stub_xfer() to read or write past the end of the union i2c_smbus_data.block buffer: BUG: KASAN: stack-out-of-bounds in stub_xfer (drivers/i2c/i2c-stub.c:223) Read of size 1 at addr ffff88800abcfd92 by task exploit/81 Call Trace: <TASK> stub_xfer (drivers/i2c/i2c-stub.c:223) __i2c_smbus_xfer (drivers/i2c/i2c-core-smbus.c:593) i2c_smbus_xfer (drivers/i2c/i2c-core-smbus.c:536) i2cdev_ioctl_smbus (drivers/i2c/i2c-dev.c:391) i2cdev_ioctl (drivers/i2c/i2c-dev.c:478) __x64_sys_ioctl (fs/ioctl.c:583) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130) </TASK> The bug exists because i2c-stub implements .smbus_xfer directly, bypassing the I2C_SMBUS_BLOCK_MAX validation in i2c_smbus_xfer_emulated(). The I2C_SMBUS_BLOCK_DATA case in the same function correctly validates against I2C_SMBUS_BLOCK_MAX, but the I2C_SMBUS_I2C_BLOCK_DATA case does not. Fix by rejecting transfers with data->block[0] == 0 or data->block[0] > I2C_SMBUS_BLOCK_MAX with -EINVAL, consistent with both the I2C_SMBUS_BLOCK_DATA case in the same function and the I2C_SMBUS_I2C_BLOCK_DATA validation in i2c_smbus_xfer_emulated().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: stub: Reject I2C block transfers with invalid length\n\nThe I2C_SMBUS_I2C_BLOCK_DATA case in stub_xfer() uses data->block[0]\nas the transfer length. The existing check only clamps it to avoid\noverrunning the chip->words[256] register array, but does not validate\nit against I2C_SMBUS_BLOCK_MAX (32), which is the limit of the union\ni2c_smbus_data.block buffer (34 bytes total). The driver is a\ndevelopment/test tool (CONFIG_I2C_STUB=m, not built by default)\nthat must be loaded with a chip_addr= parameter.\n\nA local user with access to /dev/i2c-* can issue an I2C_SMBUS ioctl\nwith I2C_SMBUS_I2C_BLOCK_DATA and data->block[0] > 32, causing\nstub_xfer() to read or write past the end of the union\ni2c_smbus_data.block buffer:\n\n BUG: KASAN: stack-out-of-bounds in stub_xfer (drivers/i2c/i2c-stub.c:223)\n Read of size 1 at addr ffff88800abcfd92 by task exploit/81\n Call Trace:\n <TASK>\n stub_xfer (drivers/i2c/i2c-stub.c:223)\n __i2c_smbus_xfer (drivers/i2c/i2c-core-smbus.c:593)\n i2c_smbus_xfer (drivers/i2c/i2c-core-smbus.c:536)\n i2cdev_ioctl_smbus (drivers/i2c/i2c-dev.c:391)\n i2cdev_ioctl (drivers/i2c/i2c-dev.c:478)\n __x64_sys_ioctl (fs/ioctl.c:583)\n do_syscall_64 (arch/x86/entry/syscall_64.c:94)\n entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)\n </TASK>\n\nThe bug exists because i2c-stub implements .smbus_xfer directly,\nbypassing the I2C_SMBUS_BLOCK_MAX validation in\ni2c_smbus_xfer_emulated(). The I2C_SMBUS_BLOCK_DATA case in the same\nfunction correctly validates against I2C_SMBUS_BLOCK_MAX, but the\nI2C_SMBUS_I2C_BLOCK_DATA case does not.\n\nFix by rejecting transfers with data->block[0] == 0 or\ndata->block[0] > I2C_SMBUS_BLOCK_MAX with -EINVAL, consistent with\nboth the I2C_SMBUS_BLOCK_DATA case in the same function and the\nI2C_SMBUS_I2C_BLOCK_DATA validation in i2c_smbus_xfer_emulated().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00127, EPSS Percentile is 0.02762 |
debian: CVE-2026-64191 was patched at 2026-07-14, 2026-07-30
1547.
Command Injection - Unknown Product (CVE-2026-47242) - Medium [244]
Description: {'nvd_cve_data_all': 'Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value strings are correctly quoted (escaping quoted specials), they were not validated to prohibit CRLF sequences. While Net::IMAP#enable does process its arguments for aliases, it does not validate them as valid atoms (or as a list of valid atoms). The #to_s value is sent verbatim. Arguments to either command could be used by an attacker to inject arbitrary IMAP commands. This vulnerability is fixed in 0.6.5 and 0.5.15.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.97 | 15 | Command Injection | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00131, EPSS Percentile is 0.03135 |
debian: CVE-2026-47242 was patched at 2026-07-14
1548.
Denial of Service - Unknown Product (CVE-2026-51105) - Medium [244]
Description: {'nvd_cve_data_all': 'Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via the OP_SERVERMESSAGE Handler.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a remote attacker to cause a denial of service via the OP_SERVERMESSAGE Handler.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00319, EPSS Percentile is 0.24301 |
debian: CVE-2026-51105 was patched at 2026-07-14
1549.
Denial of Service - Unknown Product (CVE-2026-9375) - Medium [244]
Description: {'nvd_cve_data_all': 'urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in its streaming API (`preload_content=False`) when using Brotli support. The issue arises due to three independent code paths in `response.py` that bypass the `max_length` protection introduced in version 2.6.0 to mitigate CVE-2025-66471. Specifically, negative `max_length` values can be produced due to buffer arithmetic in `read()`, `flush_decoder` unconditionally overrides `max_length` to `-1`, and `_flush_decoder()` passes no limit at all, defaulting to unlimited decompression. This allows a malicious HTTP server to trigger an out-of-memory (OOM) condition by decompressing large payloads into memory, leading to a denial of service (DoS). The vulnerability affects urllib3 2.6.3 and Brotli 1.2.0 and impacts applications and libraries using `requests` or `urllib3` to stream content from untrusted sources.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'urllib3 version 2.6.3 is vulnerable to a decompression bomb bypass in its streaming API (`preload_content=False`) when using Brotli support. The issue arises due to three independent code paths in `response.py` that bypass the `max_length` protection introduced in version 2.6.0 to mitigate CVE-2025-66471. Specifically, negative `max_length` values can be produced due to buffer arithmetic in `read()`, `flush_decoder` unconditionally overrides `max_length` to `-1`, and `_flush_decoder()` passes no limit at all, defaulting to unlimited decompression. This allows a malicious HTTP server to trigger an out-of-memory (OOM) condition by decompressing large payloads into memory, leading to a denial of service (DoS). The vulnerability affects urllib3 2.6.3 and Brotli 1.2.0 and impacts applications and libraries using `requests` or `urllib3` to stream content from untrusted sources.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00304, EPSS Percentile is 0.22752 |
debian: CVE-2026-9375 was patched at 2026-06-24
1550.
Denial of Service - op-tee (CVE-2026-41434) - Medium [244]
Description: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.10.0 and prior to version 4.11.0, an unbounded recursion
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.5 | 14 | Product detected by o:trustedfirmware:op-tee (does NOT exist in CPE dict) | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00105, EPSS Percentile is 0.01255 |
debian: CVE-2026-41434 was patched at 2026-07-14
1551.
Incorrect Calculation - concurrent_ruby (CVE-2026-54905) - Medium [244]
Description: concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReentrantReadWriteLock can incorrectly grant a write lock after one thread acquires the read lock 32,768 times. The lock stores a thread's local read and write hold counts in one integer. The low 15 bits are used for the read hold count, and bit 15 is used as WRITE_LOCK_HELD. After 32,768 reentrant read acquisitions, the local read count crosses into the write-lock bit. try_write_lock then treats the thread as already holding a write lock and returns true without setting the global RUNNING_WRITER bit. This breaks the core mutual-exclusion guarantee: the caller is told it has a write lock, but other threads can still hold or acquire read locks at the same time. This vulnerability is fixed in 1.3.7.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:rubyconcurrency:concurrent_ruby (does NOT exist in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00106, EPSS Percentile is 0.01288 |
debian: CVE-2026-54905 was patched at 2026-07-14
1552.
Incorrect Calculation - wolfssl (CVE-2026-6678) - Medium [244]
Description: Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0019, EPSS Percentile is 0.08929 |
debian: CVE-2026-6678 was patched at 2026-07-14
1553.
Memory Corruption - 389 Directory Server (CVE-2026-12528) - Medium [244]
Description: A flaw was found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | 389 Directory Server is a highly usable, fully featured, reliable and secure LDAP server implementation | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00226, EPSS Percentile is 0.13439 |
debian: CVE-2026-12528 was patched at 2026-06-24
1554.
Memory Corruption - gstreamer (CVE-2026-12891) - Medium [244]
Description: A flaw was found in the GStreamer gst-plugins-bad package. When processing a malformed H.266/VVC video stream with a crafted aspect ratio indicator value, the H.266 parser performs an out-of-bounds read of up to 8 bytes from adjacent memory. This flaw allows an attacker to craft a malicious H.266 video file or stream that, when processed by a GStreamer-based application, could leak limited memory contents through video metadata, potentially exposing sensitive information from the application's address space.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:gstreamer:gstreamer (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00272, EPSS Percentile is 0.1938 |
debian: CVE-2026-12891 was patched at 2026-07-14
1555.
Memory Corruption - libexpat (CVE-2026-56412) - Medium [244]
Description: libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a use-after-free can occur. NOTE: this issue exists because of an incomplete fix for CVE-2026-50219.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03617 |
debian: CVE-2026-56412 was patched at 2026-06-24, 2026-07-30
1556.
Memory Corruption - op-tee (CVE-2026-40257) - Medium [244]
Description: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.21.0 and prior to version 4.11.0, the ARM Crypto Extensions accelerated SHA-3 implementation has an off-by-one error that can cause a massive heap overflow that corrupts all TEE kernel memory following the hash state. This affects all platforms built with `CFG_CRYPTO_WITH_CE82=y` (ARMv8.2+ with SHA3 Crypto Extensions). Version 4.11.0 contains a patch. As a workaround, disable SHA3 Crypto Extensions with `CFG_CRYPTO_WITH_CE82=n`.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by o:trustedfirmware:op-tee (does NOT exist in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00109, EPSS Percentile is 0.01433 |
debian: CVE-2026-40257 was patched at 2026-07-14
1557.
Path Traversal - Unknown Product (CVE-2026-44942) - Medium [244]
Description: {'nvd_cve_data_all': 'A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A path traversal in handling the "path" component of .repo files processed by libzypp before 17.38.13 in the 17.x series, or before 16.22.19 could be used by attackers to fill directories on the system outside of the zypp cache with content.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00417, EPSS Percentile is 0.34301 |
debian: CVE-2026-44942 was patched at 2026-06-24
1558.
Path Traversal - Unknown Product (CVE-2026-50163) - Medium [244]
Description: {'nvd_cve_data_all': 'oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but returns the unresolved target, causing os.Link("victim.secret", "<extract_base>/payload.tar.gz/evil_cwd_link") to resolve header.Linkname against the process current working directory for a Typeflag=TypeLink entry such as Name=payload.tar.gz/evil_cwd_link and Linkname="victim.secret" with io.deis.oras.content.unpack: "true", which can expose or tamper with files such as .env, .git/config, .aws/credentials, and ~/.ssh/config. This issue is fixed in version 2.6.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, ensureLinkPath in content/file/utils.go:262-275 validates a hardlink target relative to the extract base but returns the unresolved target, causing os.Link("victim.secret", "<extract_base>/payload.tar.gz/evil_cwd_link") to resolve header.Linkname against the process current working directory for a Typeflag=TypeLink entry such as Name=payload.tar.gz/evil_cwd_link and Linkname="victim.secret" with io.deis.oras.content.unpack: "true", which can expose or tamper with files such as .env, .git/config, .aws/credentials, and ~/.ssh/config. This issue is fixed in version 2.6.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.27137 |
debian: CVE-2026-50163 was patched at 2026-07-14
1559.
Unknown Vulnerability Type - Gitea (CVE-2026-26231) - Medium [244]
Description: {'nvd_cve_data_all': 'Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to repositories that the user can read but should not be able to write.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.8 | 10 | CVSS Base Score is 8.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00291, EPSS Percentile is 0.21412 |
redos: CVE-2026-26231 was patched at 2026-07-14
1560.
Incorrect Calculation - Oj (CVE-2026-54903) - Medium [242]
Description: Oj (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.35 | 14 | Oj (Optimized JSON) is a high-performance JSON parser and object serialization library packaged as a Ruby gem, designed to provide fast JSON encoding and decoding for Ruby applications. | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.1683 |
debian: CVE-2026-54903 was patched at 2026-07-14
1561.
Memory Corruption - Oj (CVE-2026-54502) - Medium [242]
Description: Oj (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.35 | 14 | Oj (Optimized JSON) is a high-performance JSON parser and object serialization library packaged as a Ruby gem, designed to provide fast JSON encoding and decoding for Ruby applications. | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00257, EPSS Percentile is 0.17348 |
debian: CVE-2026-54502 was patched at 2026-07-14
1562.
Memory Corruption - Oj (CVE-2026-54899) - Medium [242]
Description: Oj (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.35 | 14 | Oj (Optimized JSON) is a high-performance JSON parser and object serialization library packaged as a Ruby gem, designed to provide fast JSON encoding and decoding for Ruby applications. | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16829 |
debian: CVE-2026-54899 was patched at 2026-07-14
1563.
Memory Corruption - Oj (CVE-2026-54901) - Medium [242]
Description: Oj (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.35 | 14 | Oj (Optimized JSON) is a high-performance JSON parser and object serialization library packaged as a Ruby gem, designed to provide fast JSON encoding and decoding for Ruby applications. | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16829 |
debian: CVE-2026-54901 was patched at 2026-07-14
1564.
Unknown Vulnerability Type - Python (CVE-2026-49855) - Medium [242]
Description: {'nvd_cve_data_all': 'Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, Tornado gzip decompression routines processed limited-size chunks but did not enforce an overall limit on accumulated decompressed chunks, allowing a malicious server accessed by SimpleAsyncHTTPClient or an HTTPServer configured with decompress_request=True to consume effectively unlimited memory. This issue is fixed in version 6.5.6.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00572, EPSS Percentile is 0.44018 |
debian: CVE-2026-49855 was patched at 2026-07-14
1565.
Unknown Vulnerability Type - Chromium (CVE-2026-13923) - Medium [240]
Description: {'nvd_cve_data_all': 'Uninitialized Use in GPU in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in GPU in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00322, EPSS Percentile is 0.24709 |
altlinux: CVE-2026-13923 was patched at 2026-07-03
debian: CVE-2026-13923 was patched at 2026-07-05, 2026-07-14
1566.
Unknown Vulnerability Type - Chromium (CVE-2026-13943) - Medium [240]
Description: {'nvd_cve_data_all': 'Uninitialized Use in CSS in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in CSS in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00322, EPSS Percentile is 0.2471 |
altlinux: CVE-2026-13943 was patched at 2026-07-03
debian: CVE-2026-13943 was patched at 2026-07-05, 2026-07-14
1567.
Unknown Vulnerability Type - Chromium (CVE-2026-13958) - Medium [240]
Description: {'nvd_cve_data_all': 'Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00311, EPSS Percentile is 0.23482 |
altlinux: CVE-2026-13958 was patched at 2026-07-03
debian: CVE-2026-13958 was patched at 2026-07-05, 2026-07-14
1568.
Unknown Vulnerability Type - Chromium (CVE-2026-14008) - Medium [240]
Description: {'nvd_cve_data_all': 'Uninitialized Use in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in WebXR in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0025, EPSS Percentile is 0.16439 |
altlinux: CVE-2026-14008 was patched at 2026-07-03
debian: CVE-2026-14008 was patched at 2026-07-05, 2026-07-14
1569.
Unknown Vulnerability Type - Chromium (CVE-2026-14010) - Medium [240]
Description: {'nvd_cve_data_all': 'Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in Codecs in Google Chrome on Windows prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00311, EPSS Percentile is 0.23482 |
altlinux: CVE-2026-14010 was patched at 2026-07-03
debian: CVE-2026-14010 was patched at 2026-07-05, 2026-07-14
1570.
Unknown Vulnerability Type - Chromium (CVE-2026-14051) - Medium [240]
Description: {'nvd_cve_data_all': 'Uninitialized Use in GamepadAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in GamepadAPI in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00259, EPSS Percentile is 0.17616 |
altlinux: CVE-2026-14051 was patched at 2026-07-03
debian: CVE-2026-14051 was patched at 2026-07-05, 2026-07-14
1571.
Unknown Vulnerability Type - Chromium (CVE-2026-14088) - Medium [240]
Description: {'nvd_cve_data_all': 'Uninitialized Use in Canvas in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in Canvas in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00259, EPSS Percentile is 0.17616 |
altlinux: CVE-2026-14088 was patched at 2026-07-03
debian: CVE-2026-14088 was patched at 2026-07-05, 2026-07-14
1572.
Unknown Vulnerability Type - Chromium (CVE-2026-14125) - Medium [240]
Description: {'nvd_cve_data_all': 'Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00265, EPSS Percentile is 0.18344 |
altlinux: CVE-2026-14125 was patched at 2026-07-03
debian: CVE-2026-14125 was patched at 2026-07-05, 2026-07-14
1573.
Unknown Vulnerability Type - Chromium (CVE-2026-15766) - Medium [240]
Description: {'nvd_cve_data_all': 'Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22616 |
altlinux: CVE-2026-15766 was patched at 2026-07-15
debian: CVE-2026-15766 was patched at 2026-07-14, 2026-07-16
1574.
Unknown Vulnerability Type - Chromium (CVE-2026-15770) - Medium [240]
Description: {'nvd_cve_data_all': 'Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in V8 in Google Chrome prior to 150.0.7871.125 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00303, EPSS Percentile is 0.22616 |
altlinux: CVE-2026-15770 was patched at 2026-07-15
debian: CVE-2026-15770 was patched at 2026-07-14, 2026-07-16
1575.
Memory Corruption - Linux Kernel (CVE-2026-64190) - Medium [239]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04735 |
debian: CVE-2026-64190 was patched at 2026-07-14
1576.
Denial of Service - Wasmtime (CVE-2026-54786) - Medium [238]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0.25 | 14 | Standalone WebAssembly runtime written in Rust | |
| 0.5 | 10 | CVSS Base Score is 5.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00217, EPSS Percentile is 0.12271 |
debian: CVE-2026-54786 was patched at 2026-07-14
1577.
Server-Side Request Forgery - Unknown Product (CVE-2026-15146) - Medium [238]
Description: {'nvd_cve_data_all': 'GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'GNU Wget does not validate the IP address provided by an FTP PASV response while operating in FTP passive mode. A malicious FTP server, or an HTTP server that redirects to an FTP URL, can exploit this behavior to redirect Wget’s data connection to an arbitrary IP address and port. This allows an attacker to forge server-side requests (SSRF) from the machine running Wget, potentially accessing localhost services or internal network resources.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.0608 |
debian: CVE-2026-15146 was patched at 2026-07-14
ubuntu: CVE-2026-15146 was patched at 2026-07-30
1578.
Unknown Vulnerability Type - Kotlin (CVE-2022-24329) - Medium [238]
Description: {'nvd_cve_data_all': 'In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In JetBrains Kotlin before 1.6.0, it was not possible to lock dependencies for Multiplatform Gradle Projects.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:jetbrains:kotlin (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.8 | 10 | EPSS Probability is 0.02212, EPSS Percentile is 0.80822 |
altlinux: CVE-2022-24329 was patched at 2026-06-26, 2026-07-06
1579.
Unknown Vulnerability Type - NGINX (CVE-2026-60005) - Medium [238]
Description: {'nvd_cve_data_all': 'NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart. Impact: This vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only. Note: The ngx_http_slice_module module is not enabled by default; it's enabled with the --with-http_slice_module configuration parameter. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice\xa0directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process, leading to limited disclosure of memory or a restart.\n\nImpact:\nThis vulnerability may allow remote, unauthenticated attackers to have limited control to disclose memory contents or restart the NGINX worker process. There is no control plane exposure; this is a data plane issue only.\nNote: The ngx_http_slice_module\xa0module is not enabled by default; it's enabled with the --with-http_slice_module\xa0configuration parameter.\n\nNote: Software versions which have reached End of Technical Support (EoTS) are not evaluated.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Nginx is an open-source web server that can also be used as a reverse proxy, load balancer, mail proxy and HTTP cache | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to NVD data source | |
| 0.5 | 10 | EPSS Probability is 0.0071, EPSS Percentile is 0.49914 |
altlinux: CVE-2026-60005 was patched at 2026-07-17, 2026-07-21, 2026-07-22
debian: CVE-2026-60005 was patched at 2026-07-14
ubuntu: CVE-2026-60005 was patched at 2026-07-30
1580.
Unknown Vulnerability Type - Shiro (CVE-2026-49268) - Medium [238]
Description: {'nvd_cve_data_all': 'A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially bypassing authentication or impersonating other users. This issue affects all Apache Shiro versions through 2.2.0, and 3.0.0-alpha-1 when using DefaultLdapRealm Upgrade to Apache Shiro 2.2.1 or 3.0.0-alpha-2 or later, which fixes the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A remote attacker can inject LDAP special characters into the Distinguished Name (DN) construction in DefaultLdapRealm class. User-supplied username input is directly concatenated into the LDAP DN template without any escaping of RFC 2253 special characters. This allows an attacker to manipulate the DN structure used for LDAP bind authentication, potentially bypassing authentication or impersonating other users.\n\nThis issue affects all Apache Shiro versions through 2.2.0, and 3.0.0-alpha-1 when using\xa0DefaultLdapRealm\nUpgrade to Apache Shiro 2.2.1 or 3.0.0-alpha-2 or later, which fixes the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:apache:shiro (exists in CPE dict) | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00494, EPSS Percentile is 0.39708 |
debian: CVE-2026-49268 was patched at 2026-06-24
1581.
Unknown Vulnerability Type - Symfony (CVE-2026-47767) - Medium [238]
Description: {'nvd_cve_data_all': 'Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a crafted query string to leave $_GET empty while $_SERVER['argv'] still carries attacker-controlled --env or --no-debug flags that change APP_ENV or APP_DEBUG. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 5.4.46 until 5.4.52, 6.4.40, 7.4.12, and 8.0.12, the CVE-2024-50340 fix gated runtime argv parsing on empty($_GET), but parse_str() and the web SAPI can disagree, allowing a crafted query string to leave $_GET empty while $_SERVER['argv'] still carries attacker-controlled --env or --no-debug flags that change APP_ENV or APP_DEBUG. This issue is fixed in versions 5.4.52, 6.4.40, 7.4.12, and 8.0.12.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:sensiolabs:symfony (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00389, EPSS Percentile is 0.31643 |
debian: CVE-2026-47767 was patched at 2026-07-14
1582.
Unknown Vulnerability Type - freeswitch (CVE-2026-49841) - Medium [238]
Description: {'nvd_cve_data_all': 'FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, the mod_verto HTTP request handler allocates a fixed 2 MiB buffer for a POST application/x-www-form-urlencoded body but accepts Content-Length up to just under 10 MiB. The body-read loop is bounded by Content-Length rather than the buffer size, producing an attacker-controlled heap overflow of up to ~8 MiB -- before the HTTP basic-auth check runs. This issue has been patched in version 1.11.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, the mod_verto HTTP request handler allocates a fixed 2 MiB buffer for a POST application/x-www-form-urlencoded body but accepts Content-Length up to just under 10 MiB. The body-read loop is bounded by Content-Length rather than the buffer size, producing an attacker-controlled heap overflow of up to ~8 MiB -- before the HTTP basic-auth check runs. This issue has been patched in version 1.11.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:freeswitch:freeswitch (exists in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00394, EPSS Percentile is 0.3222 |
altlinux: CVE-2026-49841 was patched at 2026-06-24, 2026-06-26, 2026-07-16
1583.
Unknown Vulnerability Type - imager (CVE-2026-14454) - Medium [238]
Description: {'nvd_cve_data_all': 'Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed. Imager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process. An attacker could craft an image with EXIF data that terminates a worker process.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry counts as signed.\n\nImager mishandled large EXIF IFD entry count values, treating them as negative numbers. This could lead to an attempt to allocate a block nearly the size of the address space, which fails and kills the process.\n\nAn attacker could craft an image with EXIF data that terminates a worker process.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:tonycoz:imager (does NOT exist in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00374, EPSS Percentile is 0.30149 |
debian: CVE-2026-14454 was patched at 2026-07-14
1584.
Elevation of Privilege - Unknown Product (CVE-2026-54369) - Medium [235]
Description: {'nvd_cve_data_all': 'acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate privileges by replacing any pathname component with a symbolic link. Attackers who control any component of a pathname processed by a privileged caller can redirect ACL read or write operations to arbitrary files or directories, enabling unauthorized manipulation of access control lists and local privilege escalation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00147, EPSS Percentile is 0.0445 |
almalinux: CVE-2026-54369 was patched at 2026-07-21, 2026-07-22
debian: CVE-2026-54369 was patched at 2026-07-14
oraclelinux: CVE-2026-54369 was patched at 2026-07-21, 2026-07-22
redhat: CVE-2026-54369 was patched at 2026-07-21, 2026-07-22
1585.
Memory Corruption - dhcpcd (CVE-2026-56117) - Medium [235]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.45 | 14 | dhcpcd is an open-source DHCP and network configuration client used on Linux, BSD, and other Unix-like operating systems to automatically configure network interfaces, IP addresses, routes, and DNS settings. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00093, EPSS Percentile is 0.00701 |
debian: CVE-2026-56117 was patched at 2026-06-24
1586.
Unknown Vulnerability Type - Django (CVE-2026-53878) - Medium [233]
Description: {'nvd_cve_data_all': 'An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16. `DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers. Earlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected. Django would like to thank Bence Nagy for reporting this issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in Django 6.0 before 6.0.7 and 5.2 before 5.2.16.\n`DomainNameValidator` does not prohibit newlines in domain names (unless used via a form field, since `CharField` strips newlines). If an application uses values with newlines in an HTTP response, header injection can occur. Django itself is unaffected because `HttpResponse` prohibits newlines in HTTP headers.\nEarlier, unsupported Django series (such as 5.0.x, 4.1.x, and 3.2.x) were not evaluated and may also be affected.\nDjango would like to thank Bence Nagy for reporting this issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | Django is a high-level Python web framework that encourages rapid development and clean, pragmatic design. It provides built-in tools for database models, authentication, URL routing, templates, and security features, making it one of the most widely used frameworks for building scalable and maintainable web applications. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.10867 |
altlinux: CVE-2026-53878 was patched at 2026-07-27
debian: CVE-2026-53878 was patched at 2026-07-14
1587.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53132) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: vsock/virtio: fix potential unbounded skb queue virtio_transport_inc_rx_pkt() checks vvs->rx_bytes + len > vvs->buf_alloc. virtio_transport_recv_enqueue() skips coalescing for packets with VIRTIO_VSOCK_SEQ_EOM. If fed with packets with len == 0 and VIRTIO_VSOCK_SEQ_EOM, a very large number of packets can be queued because vvs->rx_bytes stays at 0. Fix this by estimating the skb metadata size: \t(Number of skbs in the queue) * SKB_TRUESIZE(0)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nvsock/virtio: fix potential unbounded skb queue\n\nvirtio_transport_inc_rx_pkt() checks vvs->rx_bytes + len > vvs->buf_alloc.\n\nvirtio_transport_recv_enqueue() skips coalescing for packets\nwith VIRTIO_VSOCK_SEQ_EOM.\n\nIf fed with packets with len == 0 and VIRTIO_VSOCK_SEQ_EOM,\na very large number of packets can be queued\nbecause vvs->rx_bytes stays at 0.\n\nFix this by estimating the skb metadata size:\n\n\t(Number of skbs in the queue) * SKB_TRUESIZE(0)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03669 |
altlinux: CVE-2026-53132 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53132 was patched at 2026-07-14
1588.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53153) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/list_lru: drain before clearing xarray entry on reparent memcg_reparent_list_lrus() clears the dying memcg's xarray entry with xas_store(&xas, NULL) before reparenting its per-node lists into the parent. This opens a window where a concurrent list_lru_del() arriving for the dying memcg sees xa_load() == NULL, walks to the parent in lock_list_lru_of_memcg(), takes the parent's per-node lock, and calls list_del_init() on an item still physically linked on the dying memcg's list. If another in-flight thread holds the dying memcg's per-node lock at the same moment (another list_lru_del, or a list_lru_walk_one running an isolate callback), both threads modify ->next/->prev pointers on the same physical list under different locks. Adjacent items can corrupt each other's links. Fix it by reversing the order: reparent each per-node list and mark the child's list lru dead and then clear the xarray entry. Any concurrent list_lru op that finds the still-set xarray entry either takes the dying memcg's per-node lock (synchronizing with the drain) or sees LONG_MIN and walks to the parent, where the items now live.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/list_lru: drain before clearing xarray entry on reparent\n\nmemcg_reparent_list_lrus() clears the dying memcg's xarray entry with\nxas_store(&xas, NULL) before reparenting its per-node lists into the\nparent. This opens a window where a concurrent list_lru_del() arriving\nfor the dying memcg sees xa_load() == NULL, walks to the parent in\nlock_list_lru_of_memcg(), takes the parent's per-node lock, and calls\nlist_del_init() on an item still physically linked on the dying memcg's\nlist.\n\nIf another in-flight thread holds the dying memcg's per-node lock at the\nsame moment (another list_lru_del, or a list_lru_walk_one running an\nisolate callback), both threads modify ->next/->prev pointers on the same\nphysical list under different locks. Adjacent items can corrupt each\nother's links.\n\nFix it by reversing the order: reparent each per-node list and mark the\nchild's list lru dead and then clear the xarray entry. Any concurrent\nlist_lru op that finds the still-set xarray entry either takes the dying\nmemcg's per-node lock (synchronizing with the drain) or sees LONG_MIN and\nwalks to the parent, where the items now live.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00099, EPSS Percentile is 0.00957 |
altlinux: CVE-2026-53153 was patched at 2026-06-19, 2026-06-22, 2026-07-06
1589.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53223) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: guard timestamp cmsgs to real error queue skbs skb_is_err_queue() treats PACKET_OUTGOING as the sole marker for an skb from sk_error_queue. That assumption is not true for AF_PACKET sockets: outgoing packet taps are also delivered to packet sockets with skb->pkt_type == PACKET_OUTGOING, but their skb->cb is owned by AF_PACKET instead of struct sock_exterr_skb. If such an skb is received with timestamping enabled, the generic timestamp cmsg path can read AF_PACKET control-buffer state as sock_exterr_skb::opt_stats. With SO_RXQ_OVFL enabled, the packet drop counter overlaps opt_stats. An odd drop count makes the path emit SCM_TIMESTAMPING_OPT_STATS with skb->len and skb->data. For non-linear skbs this copies past the linear head and can trigger hardened usercopy or disclose adjacent heap contents. Keep skb_is_err_queue() local to net/socket.c, but make it verify that the PACKET_OUTGOING marker is paired with the sock_rmem_free destructor installed by sock_queue_err_skb(). AF_PACKET receive skbs use normal receive ownership and no longer pass as error-queue skbs, while legitimate sk_error_queue entries keep the PACKET_OUTGOING marker and sock_rmem_free ownership.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: guard timestamp cmsgs to real error queue skbs\n\nskb_is_err_queue() treats PACKET_OUTGOING as the sole marker for an skb\nfrom sk_error_queue. That assumption is not true for AF_PACKET sockets:\noutgoing packet taps are also delivered to packet sockets with\nskb->pkt_type == PACKET_OUTGOING, but their skb->cb is owned by AF_PACKET\ninstead of struct sock_exterr_skb.\n\nIf such an skb is received with timestamping enabled, the generic\ntimestamp cmsg path can read AF_PACKET control-buffer state as\nsock_exterr_skb::opt_stats. With SO_RXQ_OVFL enabled, the packet drop\ncounter overlaps opt_stats. An odd drop count makes the path emit\nSCM_TIMESTAMPING_OPT_STATS with skb->len and skb->data. For non-linear\nskbs this copies past the linear head and can trigger hardened usercopy or\ndisclose adjacent heap contents.\n\nKeep skb_is_err_queue() local to net/socket.c, but make it verify that\nthe PACKET_OUTGOING marker is paired with the sock_rmem_free destructor\ninstalled by sock_queue_err_skb(). AF_PACKET receive skbs use normal\nreceive ownership and no longer pass as error-queue skbs, while legitimate\nsk_error_queue entries keep the PACKET_OUTGOING marker and sock_rmem_free\nownership.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00126, EPSS Percentile is 0.02657 |
altlinux: CVE-2026-53223 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53223 was patched at 2026-07-14
1590.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53329) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Use krealloc_array() in dal_vector_reserve() [Why & How] dal_vector_reserve() computes the allocation size as "capacity * vector->struct_size" using uint32_t arithmetic, which can silently wrap to a small value on overflow. This would cause krealloc to return a smaller buffer than expected, leading to heap overflows on subsequent vector appends. Replace krealloc() with krealloc_array() which performs an internal overflow check and returns NULL on wrap, preventing the issue. (cherry picked from commit 37668568641ccc4cc1dbca4923d0a16609dd5707)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amd/display: Use krealloc_array() in dal_vector_reserve()\n\n[Why & How]\ndal_vector_reserve() computes the allocation size as\n"capacity * vector->struct_size" using uint32_t arithmetic, which can\nsilently wrap to a small value on overflow. This would cause krealloc to\nreturn a smaller buffer than expected, leading to heap overflows on\nsubsequent vector appends.\n\nReplace krealloc() with krealloc_array() which performs an internal\noverflow check and returns NULL on wrap, preventing the issue.\n\n(cherry picked from commit 37668568641ccc4cc1dbca4923d0a16609dd5707)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03357 |
altlinux: CVE-2026-53329 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53329 was patched at 2026-07-14
1591.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53361) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: af_unix: Set gc_in_progress to true in unix_gc(). Igor Ushakov reported that unix_gc() could run with gc_in_progress being false if the work is scheduled while running: Thread 1 Thread 2 Thread 3 -------- -------- -------- unix_schedule_gc() unix_schedule_gc() `- if (!gc_in_progress) `- if (!gc_in_progress) |- gc_in_progress = true | `- queue_work() | unix_gc() <----------------/ | | |- gc_in_progress = true ... `- queue_work() | | `- gc_in_progress = false | | unix_gc() <---------------------------------------------' | ... /* gc_in_progress == false */ | `- gc_in_progress = false unix_peek_fpl() relies on gc_in_progress not to confuse GC by MSG_PEEK. Let's set gc_in_progress to true in unix_gc().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\naf_unix: Set gc_in_progress to true in unix_gc().\n\nIgor Ushakov reported that unix_gc() could run with gc_in_progress\nbeing false if the work is scheduled while running:\n\n Thread 1 Thread 2 Thread 3\n -------- -------- --------\n unix_schedule_gc() unix_schedule_gc()\n `- if (!gc_in_progress) `- if (!gc_in_progress)\n |- gc_in_progress = true |\n `- queue_work() |\n unix_gc() <----------------/ |\n | |- gc_in_progress = true\n ... `- queue_work()\n | |\n `- gc_in_progress = false |\n |\n unix_gc() <---------------------------------------------'\n |\n ... /* gc_in_progress == false */\n |\n `- gc_in_progress = false\n\nunix_peek_fpl() relies on gc_in_progress not to confuse GC\nby MSG_PEEK.\n\nLet's set gc_in_progress to true in unix_gc().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02522 |
altlinux: CVE-2026-53361 was patched at 2026-07-04, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53361 was patched at 2026-07-05, 2026-07-14
1592.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53368) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: f2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage f2fs_need_dentry_mark() reads nat_entry flags without mutual exclusion with the checkpoint path, which can result in an incorrect inode block marking state. The scenario is as follows: create & write & fsync 'file A' write checkpoint - f2fs_do_sync_file // inline inode - f2fs_write_inode // inode folio is dirty - f2fs_write_checkpoint - f2fs_flush_merged_writes - f2fs_sync_node_pages - f2fs_fsync_node_pages // no dirty node - f2fs_need_inode_block_update // return true - f2fs_fsync_node_pages // inode dirtied - f2fs_need_dentry_mark //return true - f2fs_flush_nat_entries - f2fs_write_checkpoint end - __write_node_folio // inode with DENT_BIT_SHIFT set SPO, "fsck --dry-run" find inode has already checkpointed but still with DENT_BIT_SHIFT set The state observed by f2fs_need_dentry_mark() can differ from the state observed in __write_node_folio() after acquiring sbi->node_write. The root cause is that the semantics of IS_CHECKPOINTED and HAS_FSYNCED_INODE are only guaranteed after the checkpoint write has fully completed. This patch moves set_dentry_mark() into __write_node_folio() and protects it with the sbi->node_write lock.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: fix fsck inconsistency caused by incorrect nat_entry flag usage\n\nf2fs_need_dentry_mark() reads nat_entry flags without mutual exclusion\nwith the checkpoint path, which can result in an incorrect inode block\nmarking state. The scenario is as follows:\n\ncreate & write & fsync 'file A' write checkpoint\n- f2fs_do_sync_file // inline inode\n - f2fs_write_inode // inode folio is dirty\n - f2fs_write_checkpoint\n - f2fs_flush_merged_writes\n - f2fs_sync_node_pages\n - f2fs_fsync_node_pages // no dirty node\n - f2fs_need_inode_block_update // return true\n - f2fs_fsync_node_pages // inode dirtied\n - f2fs_need_dentry_mark //return true\n - f2fs_flush_nat_entries\n - f2fs_write_checkpoint end\n - __write_node_folio // inode with DENT_BIT_SHIFT set\n SPO, "fsck --dry-run" find inode has already checkpointed but still\n with DENT_BIT_SHIFT set\n\nThe state observed by f2fs_need_dentry_mark() can differ from the state\nobserved in __write_node_folio() after acquiring sbi->node_write. The\nroot cause is that the semantics of IS_CHECKPOINTED and\nHAS_FSYNCED_INODE are only guaranteed after the checkpoint write has\nfully completed.\n\nThis patch moves set_dentry_mark() into __write_node_folio() and\nprotects it with the sbi->node_write lock.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00116, EPSS Percentile is 0.01878 |
debian: CVE-2026-53368 was patched at 2026-07-14
ubuntu: CVE-2026-53368 was patched at 2026-07-30
1593.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53387) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iio: light: veml6075: add bounds check to veml6075_it_ms index veml6075_it_ms has 5 elements but VEML6075_CONF_IT can yield values 0-7. If it returns a value >= 5, this causes an out-of-bounds array access. Add a bounds check and return -EINVAL if the index is out of range. The problem values are reserved so should never be read from the register. Hence this is hardening against fault device, missprogramming or bus corruption.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niio: light: veml6075: add bounds check to veml6075_it_ms index\n\nveml6075_it_ms has 5 elements but VEML6075_CONF_IT can yield values 0-7.\nIf it returns a value >= 5, this causes an out-of-bounds array access.\nAdd a bounds check and return -EINVAL if the index is out of range.\n\nThe problem values are reserved so should never be read from the\nregister. Hence this is hardening against fault device, missprogramming\nor bus corruption.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02615 |
debian: CVE-2026-53387 was patched at 2026-07-14
1594.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63833) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ntfs3: reject direct userspace writes to reserved $LX* xattrs NTFS3 uses $LXUID, $LXGID, $LXMOD and $LXDEV as internal WSL permission metadata and reloads them into i_uid, i_gid and i_mode from ntfs_get_wsl_perm(). Because the empty-prefix xattr handler also lets file owners call setxattr() on these names directly, an unprivileged writer on a writable ntfs3 mount can plant root ownership and S_ISUID on their own file and gain euid 0 after inode reload. Reject direct userspace writes to the reserved $LX* names. Internal ntfs3 metadata updates are unchanged because ntfs_save_wsl_perm() writes them via ntfs_set_ea() directly. [almaz.alexandrovich@paragon-software.com: added an additional check for non privileged users]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nntfs3: reject direct userspace writes to reserved $LX* xattrs\n\nNTFS3 uses $LXUID, $LXGID, $LXMOD and $LXDEV as internal WSL\npermission metadata and reloads them into i_uid, i_gid and i_mode\nfrom ntfs_get_wsl_perm().\n\nBecause the empty-prefix xattr handler also lets file owners call\nsetxattr() on these names directly, an unprivileged writer on a\nwritable ntfs3 mount can plant root ownership and S_ISUID on their own\nfile and gain euid 0 after inode reload.\n\nReject direct userspace writes to the reserved $LX* names. Internal\nntfs3 metadata updates are unchanged because ntfs_save_wsl_perm()\nwrites them via ntfs_set_ea() directly.\n\n[almaz.alexandrovich@paragon-software.com: added an additional check for non privileged users]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.0259 |
debian: CVE-2026-63833 was patched at 2026-07-14, 2026-07-30
1595.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64111) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: lsm: hold cred_guard_mutex for lsm_set_self_attr() Just as proc_pid_attr_write() already does before calling the LSM hook. This only matters for SELinux and AppArmor which check whether the process is being ptraced and if so, whether to allow the transition.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nlsm: hold cred_guard_mutex for lsm_set_self_attr()\n\nJust as proc_pid_attr_write() already does before calling the LSM\nhook. This only matters for SELinux and AppArmor which check\nwhether the process is being ptraced and if so, whether to\nallow the transition.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00135, EPSS Percentile is 0.03426 |
debian: CVE-2026-64111 was patched at 2026-07-14
ubuntu: CVE-2026-64111 was patched at 2026-07-30
1596.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64158) - Medium [233]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfs: Fix write streaming disablement if fd open O_RDWR In netfs_perform_write(), "write streaming" (the caching of dirty data in dirty but !uptodate folios) is performed to avoid the need to read data that is just going to get immediately overwritten. However, this is/will be disabled in three circumstances: if the fd is open O_RDWR, if fscache is in use (as we need to round out the blocks for DIO) or if content encryption is enabled (again for rounding out purposes). The idea behind disabling it if the fd is open O_RDWR is that we'd need to flush the write-streaming page before we could read the data, particularly through mmap. But netfs now fills in the gaps if ->read_folio() is called on the page, so that is unnecessary. Further, this doesn't actually work if a separate fd is open for reading. Fix this by removing the check for O_RDWR, thereby allowing streaming writes even when we might read. This caused a number of problems with the generic/522 xfstest, but those are now fixed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix write streaming disablement if fd open O_RDWR\n\nIn netfs_perform_write(), "write streaming" (the caching of dirty data in\ndirty but !uptodate folios) is performed to avoid the need to read data\nthat is just going to get immediately overwritten. However, this is/will\nbe disabled in three circumstances: if the fd is open O_RDWR, if fscache is\nin use (as we need to round out the blocks for DIO) or if content\nencryption is enabled (again for rounding out purposes).\n\nThe idea behind disabling it if the fd is open O_RDWR is that we'd need to\nflush the write-streaming page before we could read the data, particularly\nthrough mmap. But netfs now fills in the gaps if ->read_folio() is called\non the page, so that is unnecessary. Further, this doesn't actually work\nif a separate fd is open for reading.\n\nFix this by removing the check for O_RDWR, thereby allowing streaming\nwrites even when we might read.\n\nThis caused a number of problems with the generic/522 xfstest, but those\nare now fixed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00085, EPSS Percentile is 0.00378 |
debian: CVE-2026-64158 was patched at 2026-07-14
ubuntu: CVE-2026-64158 was patched at 2026-07-30
1597.
Denial of Service - Unknown Product (CVE-2026-54463) - Medium [232]
Description: {'nvd_cve_data_all': 'websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that allows an arbitrarily large integer to be encoded as bytes with the high bit set, and a server or client can send an indefinite sequence of 0x80 or higher bytes that the peer parses into an ever-growing Ruby integer. This can make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory. This issue is fixed in version 0.8.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that allows an arbitrarily large integer to be encoded as bytes with the high bit set, and a server or client can send an indefinite sequence of 0x80 or higher bytes that the peer parses into an ever-growing Ruby integer. This can make a WebSocket connection consume an unbounded amount of memory and lead to the host process running out of memory. This issue is fixed in version 0.8.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00324, EPSS Percentile is 0.24913 |
debian: CVE-2026-54463 was patched at 2026-07-14
1598.
Denial of Service - Unknown Product (CVE-2026-59691) - Medium [232]
Description: {'nvd_cve_data_all': 'A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A heap buffer overflow vulnerability was found in GStreamer's rfbsrc plugin. When a client connects to a malicious RFB/VNC server that advertises a 16bpp framebuffer and sends Hextile-encoded updates, the Hextile background fill path writes 32-bit pixel values into a buffer allocated for 16-bit pixels. This type mismatch causes an out-of-bounds heap write that can lead to denial of service (process crash) and potential memory corruption.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16806 |
altlinux: CVE-2026-59691 was patched at 2026-07-09
debian: CVE-2026-59691 was patched at 2026-07-14
oraclelinux: CVE-2026-59691 was patched at 2026-07-28, 2026-07-29
redhat: CVE-2026-59691 was patched at 2026-07-30
1599.
Memory Corruption - libexpat (CVE-2026-56131) - Medium [232]
Description: libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50219 situation).
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.5 | 14 | Product detected by a:libexpat_project:libexpat (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00135, EPSS Percentile is 0.03397 |
debian: CVE-2026-56131 was patched at 2026-06-24, 2026-07-30
1600.
Path Traversal - Unknown Product (CVE-2026-13503) - Medium [232]
Description: {'nvd_cve_data_all': 'A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component tokenVocab Grammar Option Handler. The manipulation results in path traversal. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component tokenVocab Grammar Option Handler. The manipulation results in path traversal. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00551, EPSS Percentile is 0.42948 |
debian: CVE-2026-13503 was patched at 2026-07-14
1601.
Security Feature Bypass - Unknown Product (CVE-2026-38974) - Medium [232]
Description: {'nvd_cve_data_all': 'Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Dulwich through 1.1.0 was found to be missing SSH host key verification in contrib/paramiko_vendor.py.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09453 |
debian: CVE-2026-38974 was patched at 2026-07-14
1602.
Security Feature Bypass - Unknown Product (CVE-2026-42390) - Medium [232]
Description: {'nvd_cve_data_all': 'An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10697 |
debian: CVE-2026-42390 was patched at 2026-06-25, 2026-07-14
1603.
Information Disclosure - Unknown Product (CVE-2026-52584) - Medium [231]
Description: {'nvd_cve_data_all': 'Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01936 |
debian: CVE-2026-52584 was patched at 2026-07-14
1604.
Information Disclosure - Unknown Product (CVE-2026-8804) - Medium [231]
Description: {'nvd_cve_data_all': 'Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache. Affected versions of the resource_api module include all versions between 1.5.0 - 1.9.1 and 2.0.0 The issue was fixed in puppet resource_api 1.9.2 and 2.0.1 released with Puppet Core 8.20.0 and PE 2023.8.10 & PE 2025.11.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Puppet resource_api (shipped in Puppet Core 8.x and Puppet Enterprise 2023.8.x and 2025.x) does not preserve the sensitive flag on parameters defined via the resource-api, causing values such as passwords to be stored in cleartext in the agent's local transaction state cache. Affected versions of the resource_api module include all versions between 1.5.0 - 1.9.1 and 2.0.0 The issue was fixed in puppet resource_api\xa01.9.2 and 2.0.1 released with Puppet Core 8.20.0 and PE 2023.8.10 & PE 2025.11.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.7. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00079, EPSS Percentile is 0.00186 |
debian: CVE-2026-8804 was patched at 2026-07-14
1605.
Unknown Vulnerability Type - Perl (CVE-2026-15747) - Medium [230]
Description: {'nvd_cve_data_all': 'Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle. _csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden `csrf_token` input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed, the chosen values and the resulting compressed lengths form a BREACH oracle. An attacker able to query it can recover the token and pass csrf_protect validation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Mojolicious versions from 4.59 before 9.48 for Perl expose a stable representation of the session CSRF token to a BREACH compression oracle.\n\n_csrf_token generates and caches one token per session and returns the same value on every call, and _csrf_field places that value in a hidden `csrf_token` input. When a response carrying the token also echoes attacker-controlled input and is gzip-compressed, the chosen values and the resulting compressed lengths form a BREACH oracle.\n\nAn attacker able to query it can recover the token and pass csrf_protect validation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.9 | 10 | CVSS Base Score is 9.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00255, EPSS Percentile is 0.17082 |
debian: CVE-2026-15747 was patched at 2026-07-14
1606.
Unknown Vulnerability Type - Perl (CVE-2026-49147) - Medium [230]
Description: {'nvd_cve_data_all': 'App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes. When ack prints a filename whose basename contains terminal control bytes such as ANSI escape sequences, those bytes reach the terminal unchanged. Version 3.10.0 added a _safe_filename helper that sanitises the filenames printed by -f, -g, the colored match heading, and per-match lines, but the --show-types, -l/-L, and -c paths still emit the raw filename. A file whose name embeds cursor-movement or color escapes can overwrite or recolor earlier terminal output, or be passed unchanged to a downstream consumer.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'App::Ack versions through 3.10.0 for Perl print unsanitised terminal escape sequences from filenames in several output modes.\n\nWhen ack prints a filename whose basename contains terminal control bytes such as ANSI escape sequences, those bytes reach the terminal unchanged. Version 3.10.0 added a _safe_filename helper that sanitises the filenames printed by -f, -g, the colored match heading, and per-match lines, but the --show-types, -l/-L, and -c paths still emit the raw filename.\n\nA file whose name embeds cursor-movement or color escapes can overwrite or recolor earlier terminal output, or be passed unchanged to a downstream consumer.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00329, EPSS Percentile is 0.25468 |
debian: CVE-2026-49147 was patched at 2026-07-14
1607.
Open Redirect - Unknown Product (CVE-2026-12804) - Medium [229]
Description: {'nvd_cve_data_all': 'A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing a manipulation of the argument url results in open redirect. The attack is possible to be carried out remotely. The exploit is now public and may be used. Applying a patch is the recommended action to fix this issue. The vendor confirms, that "it has been fixed some days ago and will be available in 2.23.1. CDC is quite never used, so the impact is very low."', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie Endpoint. Performing a manipulation of the argument url results in open redirect. The attack is possible to be carried out remotely. The exploit is now public and may be used. Applying a patch is the recommended action to fix this issue. The vendor confirms, that "it has been fixed some days ago and will be available in 2.23.1. CDC is quite never used, so the impact is very low."', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.75 | 15 | Open Redirect | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00446, EPSS Percentile is 0.36594 |
debian: CVE-2026-12804 was patched at 2026-06-24
1608.
Unknown Vulnerability Type - Angular (CVE-2026-54266) - Medium [229]
Description: {'nvd_cve_data_all': 'Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, Angular's HttpTransferCache caches HTTP requests made during Server-Side Rendering (SSR) so that they can be reused during client-side hydration. This avoids repeating the same HTTP requests on the client. The cached responses are stored in TransferState using a cache key generated by hashing request properties (method, response type, mapped URL, serialized body, and sorted query parameters). The cache keys are generated using a weak 32-bit DJB2-like polynomial rolling hash. The 32-bit hash space is extremely small, allowing attackers to find hash collisions. An attacker can easily find a query parameter string (e.g., q=aaCAZMMM for a search request) that produces the exact same 32-bit hash as a sensitive endpoint (e.g., /api/user/profile). When a victim visits a crafted link containing the colliding parameter, the SSR process executes both the search request and the profile request. Due to the hash collision, the search response overwrites the profile response in the TransferState cache. This vulnerability is fixed in 22.0.1, 21.2.17, and 20.3.25.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, Angular's HttpTransferCache caches HTTP requests made during Server-Side Rendering (SSR) so that they can be reused during client-side hydration. This avoids repeating the same HTTP requests on the client. The cached responses are stored in TransferState using a cache key generated by hashing request properties (method, response type, mapped URL, serialized body, and sorted query parameters). The cache keys are generated using a weak 32-bit DJB2-like polynomial rolling hash. The 32-bit hash space is extremely small, allowing attackers to find hash collisions. An attacker can easily find a query parameter string (e.g., q=aaCAZMMM for a search request) that produces the exact same 32-bit hash as a sensitive endpoint (e.g., /api/user/profile). When a victim visits a crafted link containing the colliding parameter, the SSR process executes both the search request and the profile request. Due to the hash collision, the search response overwrites the profile response in the TransferState cache. This vulnerability is fixed in 22.0.1, 21.2.17, and 20.3.25.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.95 | 14 | Angular is a development platform for building mobile and desktop web applications using TypeScript, JavaScript, and other languages. It provides a component-based architecture, declarative templates, dependency injection, powerful tooling, and extensive ecosystem support for creating scalable, high-performance web apps. | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0009, EPSS Percentile is 0.00547 |
debian: CVE-2026-54266 was patched at 2026-06-24
1609.
Unknown Vulnerability Type - Chromium (CVE-2026-13940) - Medium [228]
Description: {'nvd_cve_data_all': 'Uninitialized Use in Cast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via malicious network traffic. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in Cast in Google Chrome prior to 150.0.7871.47 allowed an attacker on the local network segment to obtain potentially sensitive information from process memory via malicious network traffic. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00212, EPSS Percentile is 0.11705 |
altlinux: CVE-2026-13940 was patched at 2026-07-03
debian: CVE-2026-13940 was patched at 2026-07-05, 2026-07-14
1610.
Unknown Vulnerability Type - Chromium (CVE-2026-14399) - Medium [228]
Description: {'nvd_cve_data_all': 'Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00224, EPSS Percentile is 0.13241 |
altlinux: CVE-2026-14399 was patched at 2026-07-03
debian: CVE-2026-14399 was patched at 2026-07-05, 2026-07-14
1611.
Unknown Vulnerability Type - Chromium (CVE-2026-14402) - Medium [228]
Description: {'nvd_cve_data_all': 'Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in ANGLE in Google Chrome on Windows prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00224, EPSS Percentile is 0.13241 |
altlinux: CVE-2026-14402 was patched at 2026-07-03
debian: CVE-2026-14402 was patched at 2026-07-05, 2026-07-14
1612.
Unknown Vulnerability Type - Chromium (CVE-2026-14408) - Medium [228]
Description: {'nvd_cve_data_all': 'Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in Dawn in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00224, EPSS Percentile is 0.13241 |
altlinux: CVE-2026-14408 was patched at 2026-07-03
debian: CVE-2026-14408 was patched at 2026-07-05, 2026-07-14
1613.
Unknown Vulnerability Type - Chromium (CVE-2026-14421) - Medium [228]
Description: {'nvd_cve_data_all': 'Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in Dawn in Google Chrome on ChromeOS prior to 150.0.7871.46 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00215, EPSS Percentile is 0.12081 |
altlinux: CVE-2026-14421 was patched at 2026-07-03
debian: CVE-2026-14421 was patched at 2026-07-05, 2026-07-14
1614.
Unknown Vulnerability Type - Chromium (CVE-2026-15109) - Medium [228]
Description: {'nvd_cve_data_all': 'Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in ANGLE in Google Chrome prior to 150.0.7871.115 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00216, EPSS Percentile is 0.121 |
altlinux: CVE-2026-15109 was patched at 2026-07-09
debian: CVE-2026-15109 was patched at 2026-07-11, 2026-07-14
1615.
Unknown Vulnerability Type - OpenSSH (CVE-2026-59998) - Medium [228]
Description: {'nvd_cve_data_all': 'sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'sshd in OpenSSH before 10.4 has an undocumented security-relevant behavior: GSSAPIStrictAcceptorCheck has no value if the server is in Windows Active Directory.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07775 |
debian: CVE-2026-59998 was patched at 2026-07-14
ubuntu: CVE-2026-59998 was patched at 2026-07-30
1616.
Unknown Vulnerability Type - RPC (CVE-2026-46608) - Medium [228]
Description: {'nvd_cve_data_all': 'Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s) introduced a configurable CORS origin list in version 4.5.3 as a mitigation for CVE-2026-33533. However, the implementation silently falls back to Access-Control-Allow-Origin: * whenever cors_origins contains more than one entry. An operator who configures an explicit two-entry allowlist (e.g. two internal dashboard origins) intending to restrict browser access instead receives the unrestricted wildcard. A malicious web page served from any origin can issue a CORS simple request to /RPC2 and read the full system monitoring dataset without the victim's knowledge. This vulnerability is fixed in 4.5.5.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s) introduced a configurable CORS origin list in version 4.5.3 as a mitigation for CVE-2026-33533. However, the implementation silently falls back to Access-Control-Allow-Origin: * whenever cors_origins contains more than one entry. An operator who configures an explicit two-entry allowlist (e.g. two internal dashboard origins) intending to restrict browser access instead receives the unrestricted wildcard. A malicious web page served from any origin can issue a CORS simple request to /RPC2 and read the full system monitoring dataset without the victim's knowledge. This vulnerability is fixed in 4.5.5.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Remote Procedure Call Runtime | |
| 0.7 | 10 | CVSS Base Score is 7.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00232, EPSS Percentile is 0.14254 |
debian: CVE-2026-46608 was patched at 2026-07-14
1617.
Unknown Vulnerability Type - youtube-dl (CVE-2026-55404) - Medium [226]
Description: {'nvd_cve_data_all': 'yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'yt-dlp and youtube-dl are command-line audio/video downloaders. Prior to 2026.7.4, the --write-link, --write-url-link, and --write-desktop-link options can write .url or .desktop shortcut files using attacker-controlled webpage_url or filename metadata without sufficient validation or escaping, allowing malicious file:// URI injection on Windows or newline-based desktop entry key injection on Linux that can execute commands if the generated shortcut is opened. This issue is fixed in version 2026.7.4.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | youtube-dl is a free and open source software tool for downloading video and audio from YouTube and over 1,000 other video hosting websites | |
| 0.9 | 10 | CVSS Base Score is 8.8. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00412, EPSS Percentile is 0.33923 |
altlinux: CVE-2026-55404 was patched at 2026-07-27
debian: CVE-2026-55404 was patched at 2026-07-14
1618.
Memory Corruption - ImageMagick (CVE-2026-61864) - Medium [224]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.3 | 10 | CVSS Base Score is 2.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00102, EPSS Percentile is 0.01106 |
debian: CVE-2026-61864 was patched at 2026-07-14
1619.
Memory Corruption - ImageMagick (CVE-2026-61865) - Medium [224]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.3 | 10 | CVSS Base Score is 2.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00102, EPSS Percentile is 0.01107 |
debian: CVE-2026-61865 was patched at 2026-07-14
1620.
Elevation of Privilege - Unknown Product (CVE-2026-48821) - Medium [223]
Description: {'nvd_cve_data_all': 'Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vulnerability in the Thumbnail Synchronizer feature. When an administrator runs the thumbnail update process, malicious bookmark titles are returned via an AJAX response and inserted into the DOM using innerHTML without proper sanitization. The issue originates from the interaction between the backend thumbnail update endpoint and the frontend JavaScript responsible for rendering update progress. On the backend, the ThumbnailsController::ajaxUpdate method returns bookmark data formatted using the 'raw' formatter. This includes the unescaped bookmark title in the JSON response. On the client side, the script thumbnails-update.js processes this AJAX response and dynamically updates the progress interface. Administrators using the thumbnail synchronization feature are affected and exploitation could lead to session hijacking, privilege escalation, backdoor injection and full compromise. This issue has been fixed in version 0.16.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a DOM-based Cross-Site Scripting (XSS) vulnerability in the Thumbnail Synchronizer feature. When an administrator runs the thumbnail update process, malicious bookmark titles are returned via an AJAX response and inserted into the DOM using innerHTML without proper sanitization. The issue originates from the interaction between the backend thumbnail update endpoint and the frontend JavaScript responsible for rendering update progress. On the backend, the ThumbnailsController::ajaxUpdate method returns bookmark data formatted using the 'raw' formatter. This includes the unescaped bookmark title in the JSON response. On the client side, the script thumbnails-update.js processes this AJAX response and dynamically updates the progress interface. Administrators using the thumbnail synchronization feature are affected and exploitation could lead to session hijacking, privilege escalation, backdoor injection and full compromise. This issue has been fixed in version 0.16.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0013, EPSS Percentile is 0.03004 |
debian: CVE-2026-48821 was patched at 2026-06-24
1621.
Elevation of Privilege - Unknown Product (CVE-2026-54370) - Medium [223]
Description: {'nvd_cve_data_all': 'acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an lstat() check and subsequent symlink-following operations such as stat(), chown(), chmod(), acl_get_file(), and acl_set_file(). Attackers who control a pathname component can redirect file access control list operations to arbitrary files when getfacl, setfacl, or chacl is invoked by a privileged process over an attacker-controlled path, resulting in local privilege escalation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00088, EPSS Percentile is 0.00478 |
almalinux: CVE-2026-54370 was patched at 2026-07-21, 2026-07-22
debian: CVE-2026-54370 was patched at 2026-07-14
oraclelinux: CVE-2026-54370 was patched at 2026-07-21, 2026-07-22
redhat: CVE-2026-54370 was patched at 2026-07-21, 2026-07-22
1622.
Elevation of Privilege - Unknown Product (CVE-2026-54371) - Medium [223]
Description: {'nvd_cve_data_all': 'attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during directory hierarchy traversal. Attackers who control a pathname component can redirect getfattr and setfattr operations to arbitrary files by substituting a symlink, leading to local privilege escalation when getfattr or setfattr is invoked by a privileged process over an attacker-controlled path.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.85 | 15 | Elevation of Privilege | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00131, EPSS Percentile is 0.03096 |
debian: CVE-2026-54371 was patched at 2026-07-14
1623.
Unknown Vulnerability Type - Envoy (CVE-2026-48497) - Medium [223]
Description: {'nvd_cve_data_all': 'Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, in cases where UDP DNS filter is configured with local resolution containing a name with the length of 255 octets or remote resolution for a name of 255 octets long can complete successfully, a query with such name will result in abnormal process termination. The abnormal process termination is triggered by an invalid runtime precondition that the query name is strictly less than 255 octets, contradicting DNS specification rfc1035#section-2.3.4 that the name can be 255 or less octets. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, in cases where UDP DNS filter is configured with local resolution containing a name with the length of 255 octets or remote resolution for a name of 255 octets long can complete successfully, a query with such name will result in abnormal process termination. The abnormal process termination is triggered by an invalid runtime precondition that the query name is strictly less than 255 octets, contradicting DNS specification rfc1035#section-2.3.4 that the name can be 255 or less octets. This vulnerability is fixed in 1.35.11, 1.36.7, 1.37.3, and 1.38.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00231, EPSS Percentile is 0.14123 |
altlinux: CVE-2026-48497 was patched at 2026-06-25, 2026-07-02
1624.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-52930) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipc/shm: serialize orphan cleanup with shm_nattch updates shm_destroy_orphaned() walks the shm idr under shm_ids(ns).rwsem, but that does not serialize all fields tested by shm_may_destroy(). In particular, shm_nattch is updated while holding shm_perm.lock, and attach paths can do that without holding the rwsem. Do not decide that an orphaned segment is unused before taking the object lock. Move the shm_may_destroy() check under shm_perm.lock, matching the other destroy paths, and unlock the segment when it no longer qualifies for removal.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipc/shm: serialize orphan cleanup with shm_nattch updates\n\nshm_destroy_orphaned() walks the shm idr under shm_ids(ns).rwsem, but that\ndoes not serialize all fields tested by shm_may_destroy(). In particular,\nshm_nattch is updated while holding shm_perm.lock, and attach paths can do\nthat without holding the rwsem.\n\nDo not decide that an orphaned segment is unused before taking the object\nlock. Move the shm_may_destroy() check under shm_perm.lock, matching the\nother destroy paths, and unlock the segment when it no longer qualifies\nfor removal.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00115, EPSS Percentile is 0.01779 |
altlinux: CVE-2026-52930 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-52930 was patched at 2026-07-14
1625.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-52940) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tun: zero the whole vnet header in tun_put_user() tun_put_user() declares an on-stack struct virtio_net_hdr_v1_hash_tunnel without zeroing it. For a non-tunnel skb, virtio_net_hdr_tnl_from_skb() only initializes the first 10 bytes (sizeof(struct virtio_net_hdr)), leaving bytes 10..23 (num_buffers and the hash/tunnel fields) as stack garbage. An unprivileged user can set the vnet header size to 24 with TUNSETVNETHDRSZ, so __tun_vnet_hdr_put() copies all 24 bytes of the partially-initialized struct to userspace, leaking 14 bytes of kernel stack on every read of a non-tunnel packet. Fix it the same way tun_get_user() already does by zeroing the whole header right after declaration.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntun: zero the whole vnet header in tun_put_user()\n\ntun_put_user() declares an on-stack struct virtio_net_hdr_v1_hash_tunnel\nwithout zeroing it. For a non-tunnel skb, virtio_net_hdr_tnl_from_skb()\nonly initializes the first 10 bytes (sizeof(struct virtio_net_hdr)),\nleaving bytes 10..23 (num_buffers and the hash/tunnel fields) as stack\ngarbage.\n\nAn unprivileged user can set the vnet header size to 24 with\nTUNSETVNETHDRSZ, so __tun_vnet_hdr_put() copies all 24 bytes of the\npartially-initialized struct to userspace, leaking 14 bytes of kernel\nstack on every read of a non-tunnel packet.\n\nFix it the same way tun_get_user() already does by zeroing the whole\nheader right after declaration.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01629 |
altlinux: CVE-2026-52940 was patched at 2026-06-19, 2026-06-22, 2026-07-06
1626.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53134) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_fib: fix stale stack leak via the OIFNAME register For NFT_FIB_RESULT_OIFNAME the destination register is declared with len = IFNAMSIZ (four 32-bit registers), but on the lookup-fail, RTN_LOCAL and oif-mismatch paths nft_fib{4,6}_eval() only writes one register via "*dest = 0". The remaining three registers are left as whatever was on the stack in nft_do_chain()'s struct nft_regs, and a downstream expression that loads the register span can leak that uninitialised kernel stack to userspace. The NFTA_FIB_F_PRESENT existence check has the same shape: it is only meaningful for NFT_FIB_RESULT_OIF, yet it was accepted for any result type while the eval stores a single byte via nft_reg_store8(), leaving the rest of the declared span stale. Fix both: - replace the bare "*dest = 0" in the eval with nft_fib_store_result(), which strscpy_pad()s the whole IFNAMSIZ for OIFNAME (and is already used on the other early-return path), and - restrict NFTA_FIB_F_PRESENT to NFT_FIB_RESULT_OIF and declare its destination as a single u8, so the marked span matches the one byte the eval writes.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_fib: fix stale stack leak via the OIFNAME register\n\nFor NFT_FIB_RESULT_OIFNAME the destination register is declared with\nlen = IFNAMSIZ (four 32-bit registers), but on the lookup-fail,\nRTN_LOCAL and oif-mismatch paths nft_fib{4,6}_eval() only writes one\nregister via "*dest = 0". The remaining three registers are left as\nwhatever was on the stack in nft_do_chain()'s struct nft_regs, and a\ndownstream expression that loads the register span can leak that\nuninitialised kernel stack to userspace.\n\nThe NFTA_FIB_F_PRESENT existence check has the same shape: it is only\nmeaningful for NFT_FIB_RESULT_OIF, yet it was accepted for any result type\nwhile the eval stores a single byte via nft_reg_store8(), leaving the rest\nof the declared span stale.\n\nFix both:\n\n - replace the bare "*dest = 0" in the eval with nft_fib_store_result(),\n which strscpy_pad()s the whole IFNAMSIZ for OIFNAME (and is already\n used on the other early-return path), and\n\n - restrict NFTA_FIB_F_PRESENT to NFT_FIB_RESULT_OIF and declare its\n destination as a single u8, so the marked span matches the one byte\n the eval writes.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02409 |
altlinux: CVE-2026-53134 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53134 was patched at 2026-07-14
1627.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53139) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Skip CSD when it has zeroed workgroups A compute shader dispatch encodes its workgroup counts in the CFG0..CFG2 registers. Kicking off a dispatch with a zero count in any of the three dimensions is invalid. First, the hardware will process 0 as 65536, while the user-space driver exposes a maximum of 65535. Over that, a submission with a zeroed workgroup dimension should be a no-op. These zeroed counts can reach the dispatch path through an indirect CSD job, whose workgroup counts are only known once the indirect buffer is read and may legitimately be zero, but such scenario should only result in a no-op. Overwrite the indirect CSD job workgroup counts with the indirect BO ones, even if they are zeroed, and don't submit the job to the hardware when any of the workgroup counts is zero, so the job completes immediately instead of running the shader.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Skip CSD when it has zeroed workgroups\n\nA compute shader dispatch encodes its workgroup counts in the CFG0..CFG2\nregisters. Kicking off a dispatch with a zero count in any of the three\ndimensions is invalid. First, the hardware will process 0 as 65536,\nwhile the user-space driver exposes a maximum of 65535. Over that, a\nsubmission with a zeroed workgroup dimension should be a no-op.\n\nThese zeroed counts can reach the dispatch path through an indirect CSD\njob, whose workgroup counts are only known once the indirect buffer is\nread and may legitimately be zero, but such scenario should only result in\na no-op.\n\nOverwrite the indirect CSD job workgroup counts with the indirect BO\nones, even if they are zeroed, and don't submit the job to the hardware\nwhen any of the workgroup counts is zero, so the job completes immediately\ninstead of running the shader.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02404 |
altlinux: CVE-2026-53139 was patched at 2026-06-19, 2026-06-22, 2026-07-04, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53139 was patched at 2026-07-05, 2026-07-14, 2026-07-30
1628.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53140) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups v3d_rewrite_csd_job_wg_counts_from_indirect() maps both the indirect buffer and the workgroup buffer and is expected to release them before returning. When any of the workgroup counts read from the buffer is zero, the function bailed out early and skipped the cleanup, leaking the vaddr mappings of both BOs. Jump to the cleanup path instead of returning directly, so the mappings are always dropped.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Fix vaddr leak when indirect CSD has zeroed workgroups\n\nv3d_rewrite_csd_job_wg_counts_from_indirect() maps both the indirect\nbuffer and the workgroup buffer and is expected to release them before\nreturning. When any of the workgroup counts read from the buffer is zero,\nthe function bailed out early and skipped the cleanup, leaking the vaddr\nmappings of both BOs.\n\nJump to the cleanup path instead of returning directly, so the mappings\nare always dropped.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02356 |
altlinux: CVE-2026-53140 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53140 was patched at 2026-07-14
1629.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53141) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/v3d: Fix global performance monitor reference counting In the SET_GLOBAL ioctl, v3d_perfmon_find() bumps the reference count on the perfmon it returns, but v3d_perfmon_set_global_ioctl() and v3d_perfmon_delete() fail to release that reference on several paths: 1. v3d_perfmon_set_global_ioctl() leaks the reference on its error paths. 2. CLEAR_GLOBAL leaks both the find reference and the reference previously stashed in v3d->global_perfmon by the SET_GLOBAL ioctl that configured it. 3. Destroying a perfmon that is the current global perfmon leaks the reference stashed by the SET_GLOBAL ioctl. Release each of these references explicitly.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/v3d: Fix global performance monitor reference counting\n\nIn the SET_GLOBAL ioctl, v3d_perfmon_find() bumps the reference count on\nthe perfmon it returns, but v3d_perfmon_set_global_ioctl() and\nv3d_perfmon_delete() fail to release that reference on several paths:\n\n 1. v3d_perfmon_set_global_ioctl() leaks the reference on its error\n paths.\n\n 2. CLEAR_GLOBAL leaks both the find reference and the reference\n previously stashed in v3d->global_perfmon by the SET_GLOBAL ioctl\n that configured it.\n\n 3. Destroying a perfmon that is the current global perfmon leaks the\n reference stashed by the SET_GLOBAL ioctl.\n\nRelease each of these references explicitly.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02239 |
altlinux: CVE-2026-53141 was patched at 2026-06-19, 2026-06-22, 2026-07-06
1630.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53154) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/hugetlb: restore reservation on error in hugetlb folio copy paths Two sites in mm/hugetlb.c allocate a hugetlb folio via alloc_hugetlb_folio() (consuming a VMA reservation) and then call copy_user_large_folio(), which became int-returning in commit 1cb9dc4b475c ("mm: hwpoison: support recovery from HugePage copy-on-write faults") and can now fail (e.g. -EHWPOISON on a hwpoisoned source page). On the failure path, folio_put() restores the global hugetlb pool count through free_huge_folio(), but the per-VMA reservation map entry is left marked consumed: - hugetlb_mfill_atomic_pte() resubmission path (UFFDIO_COPY) - copy_hugetlb_page_range() fork-time CoW path when hugetlb_try_dup_anon_rmap() fails (rare: pinned hugetlb anon folio under fork) User-visible effect: on UFFDIO_COPY into a private hugetlb VMA where the resubmission copy fails, the reservation for that address is leaked from the VMA's reserve map. A subsequent fault at the same address takes the no-reservation path, and under hugetlb pool pressure the task is SIGBUSed at an address it had previously reserved. The fork-time CoW path leaks the same way in the child VMA's reserve map, though it requires the much rarer combination of pinned hugetlb anon page + hwpoisoned source. Add the missing restore_reserve_on_error() call before folio_put() on both error paths.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/hugetlb: restore reservation on error in hugetlb folio copy paths\n\nTwo sites in mm/hugetlb.c allocate a hugetlb folio via\nalloc_hugetlb_folio() (consuming a VMA reservation) and then call\ncopy_user_large_folio(), which became int-returning in commit 1cb9dc4b475c\n("mm: hwpoison: support recovery from HugePage copy-on-write faults") and\ncan now fail (e.g. -EHWPOISON on a hwpoisoned source page). On the\nfailure path, folio_put() restores the global hugetlb pool count through\nfree_huge_folio(), but the per-VMA reservation map entry is left marked\nconsumed:\n\n - hugetlb_mfill_atomic_pte() resubmission path (UFFDIO_COPY)\n - copy_hugetlb_page_range() fork-time CoW path when\n hugetlb_try_dup_anon_rmap() fails (rare: pinned hugetlb anon\n folio under fork)\n\nUser-visible effect: on UFFDIO_COPY into a private hugetlb VMA where the\nresubmission copy fails, the reservation for that address is leaked from\nthe VMA's reserve map. A subsequent fault at the same address takes the\nno-reservation path, and under hugetlb pool pressure the task is SIGBUSed\nat an address it had previously reserved. The fork-time CoW path leaks\nthe same way in the child VMA's reserve map, though it requires the much\nrarer combination of pinned hugetlb anon page + hwpoisoned source.\n\nAdd the missing restore_reserve_on_error() call before folio_put() on both\nerror paths.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02334 |
altlinux: CVE-2026-53154 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53154 was patched at 2026-07-14
1631.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53155) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: use correct flags for device private PMD entry Commit 65edfda6f3f2 ("mm/rmap: extend rmap and migration support device-private entries") updated set_pmd_migration_entry() to use pmdp_huge_get_and_clear() in the softleaf case, but made no further adjustments to the function itself. Therefore this function continues to incorrectly use pmd_write(), pmd_soft_dirty() and pmd_uffd_wp() to determine whether the installed migration entry should be marked writable, softdirty or uffd-wp respectively. Whilst all are incorrect, the most problematic of these is pmd_write(), as this can lead to corrupted rmap state. On x86-64 _PAGE_SWP_SOFT_DIRTY is aliased to _PAGE_RW. So calling pmd_write() on a softleaf will return the softdirty state encoded in the entry, assuming CONFIG_MEM_SOFT_DIRTY was enabled. This was observed when running the hmm.hmm_device_private.anon_write_child selftest: 1. The test faults in a range then migrates it such that a device-private THP range is established. 2. The parent then migrates it to a device-private writable PMD entry whose folio is entirely AnonExclusive with entire_mapcount=1, softdirty set (accidentally correct write state). 3. The parent forks and the PMD entries are set to device-private read only entries, entire_mapcount=2, softdirty still set. 4. [BUG] The child writes to the range then migrates to RAM - intending to install non-writable migration entries - but replacing parent and child PMD mappings with WRITABLE entries due to misinterpreting the softdirty bit. 5. In remove_migration_pmd(), if !softleaf_is_migration_read(entry) we set the RMAP_EXCLUSIVE flag when calling folio_add_anon_rmap_pmd() for both parent and child, which are therefore AnonExclusive. 6. [SPLAT] Child sets migrated folio entire_mapcount=1, parent sets entire_mapcount=2 and we end up with an AnonExclusive folio with entire_mapcount=2! Assert fires in __folio_add_anon_rmap(): \t\tVM_WARN_ON_FOLIO(folio_test_large(folio) && \t\t\t\t folio_entire_mapcount(folio) > 1 && \t\t\t\t PageAnonExclusive(cur_page), folio) This patch fixes the issue by correctly referencing the softleaf entry fields for writable, softdirty and uffd-wp in set_pmd_migration_entry(). It also only updates A/D flags if the entry is present as these are otherwise not meaningful for a softleaf entry. This patch also flips the if (!present) { ... } else { ... } logic in set_pmd_migration_entry() so it is easier to understand, and adds some comments to make things clearer. I was able to bisect this to commit 775465fd26a3 ("lib/test_hmm: add zone device private THP test infrastructure") which first exposes this bug as it was the commit that permitted test_hmm to generate the test. However commit 65edfda6f3f2 ("mm/rmap: extend rmap and migration support device-private entries") is the commit that actually enabled this behaviour.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/huge_memory: use correct flags for device private PMD entry\n\nCommit 65edfda6f3f2 ("mm/rmap: extend rmap and migration support\ndevice-private entries") updated set_pmd_migration_entry() to use\npmdp_huge_get_and_clear() in the softleaf case, but made no further\nadjustments to the function itself.\n\nTherefore this function continues to incorrectly use pmd_write(),\npmd_soft_dirty() and pmd_uffd_wp() to determine whether the installed\nmigration entry should be marked writable, softdirty or uffd-wp\nrespectively.\n\nWhilst all are incorrect, the most problematic of these is pmd_write(), as\nthis can lead to corrupted rmap state.\n\nOn x86-64 _PAGE_SWP_SOFT_DIRTY is aliased to _PAGE_RW. So calling\npmd_write() on a softleaf will return the softdirty state encoded in the\nentry, assuming CONFIG_MEM_SOFT_DIRTY was enabled.\n\nThis was observed when running the hmm.hmm_device_private.anon_write_child\nselftest:\n\n1. The test faults in a range then migrates it such that a device-private\n THP range is established.\n\n2. The parent then migrates it to a device-private writable PMD entry whose\n folio is entirely AnonExclusive with entire_mapcount=1, softdirty set\n (accidentally correct write state).\n\n3. The parent forks and the PMD entries are set to device-private read only\n entries, entire_mapcount=2, softdirty still set.\n\n4. [BUG] The child writes to the range then migrates to RAM - intending to\n install non-writable migration entries - but replacing parent and child\n PMD mappings with WRITABLE entries due to misinterpreting the softdirty\n bit.\n\n5. In remove_migration_pmd(), if !softleaf_is_migration_read(entry) we\n set the RMAP_EXCLUSIVE flag when calling folio_add_anon_rmap_pmd() for\n both parent and child, which are therefore AnonExclusive.\n\n6. [SPLAT] Child sets migrated folio entire_mapcount=1, parent sets\n entire_mapcount=2 and we end up with an AnonExclusive folio with\n entire_mapcount=2! Assert fires in __folio_add_anon_rmap():\n\n\t\tVM_WARN_ON_FOLIO(folio_test_large(folio) &&\n\t\t\t\t folio_entire_mapcount(folio) > 1 &&\n\t\t\t\t PageAnonExclusive(cur_page), folio)\n\nThis patch fixes the issue by correctly referencing the softleaf entry\nfields for writable, softdirty and uffd-wp in set_pmd_migration_entry().\n\nIt also only updates A/D flags if the entry is present as these are\notherwise not meaningful for a softleaf entry.\n\nThis patch also flips the if (!present) { ... } else { ... } logic in\nset_pmd_migration_entry() so it is easier to understand, and adds some\ncomments to make things clearer.\n\nI was able to bisect this to commit 775465fd26a3 ("lib/test_hmm: add zone\ndevice private THP test infrastructure") which first exposes this bug as\nit was the commit that permitted test_hmm to generate the test.\n\nHowever commit 65edfda6f3f2 ("mm/rmap: extend rmap and migration support\ndevice-private entries") is the commit that actually enabled this\nbehaviour.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00107, EPSS Percentile is 0.01355 |
altlinux: CVE-2026-53155 was patched at 2026-06-19
1632.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53159) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: misc: fastrpc: fix DMA address corruption due to find_vma misuse fastrpc_get_args() uses find_vma() to look up the VMA for a user-provided pointer and compute a DMA address offset. When the address falls in a gap before the returned VMA, (ptr & PAGE_MASK) - vma->vm_start underflows, corrupting the DMA address sent to the DSP. Replace find_vma() with vma_lookup(), which returns NULL when the address is not contained within any VMA.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmisc: fastrpc: fix DMA address corruption due to find_vma misuse\n\nfastrpc_get_args() uses find_vma() to look up the VMA for a user-provided\npointer and compute a DMA address offset. When the address falls in a gap\nbefore the returned VMA, (ptr & PAGE_MASK) - vma->vm_start underflows,\ncorrupting the DMA address sent to the DSP.\n\nReplace find_vma() with vma_lookup(), which returns NULL when the address\nis not contained within any VMA.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.0298 |
altlinux: CVE-2026-53159 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53159 was patched at 2026-07-14
1633.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53164) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iommu/dma: Do not try to iommu_map a 0 length region in swiotlb iommu_dma_iova_link_swiotlb() processes a mapping that is unaligned in three parts, the head, middle and trailer. If the middle is empty because there are no aligned pages it will call down to iommu_map() with a 0 size which the iommupt implementation will fail as illegal. It then tries to do an error unwind and starts from the wrong spot corrupting the mapping so the eventual destruction triggers a WARN_ON. Check for 0 length and avoid mapping and use offset not 0 as the starting point to unlink. This is frequently triggered by using some kinds of thunderbolt NVMe drives that trigger forced SWIOTLB for unaligned memory. NVMe seems to pass in oddly aligned buffers for the passthrough commands from smartctl that hit this condition.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niommu/dma: Do not try to iommu_map a 0 length region in swiotlb\n\niommu_dma_iova_link_swiotlb() processes a mapping that is unaligned in three\nparts, the head, middle and trailer. If the middle is empty because there\nare no aligned pages it will call down to iommu_map() with a 0 size\nwhich the iommupt implementation will fail as illegal.\n\nIt then tries to do an error unwind and starts from the wrong spot\ncorrupting the mapping so the eventual destruction triggers a WARN_ON.\n\nCheck for 0 length and avoid mapping and use offset not 0 as the starting\npoint to unlink.\n\nThis is frequently triggered by using some kinds of thunderbolt NVMe\ndrives that trigger forced SWIOTLB for unaligned memory. NVMe seems to\npass in oddly aligned buffers for the passthrough commands from smartctl\nthat hit this condition.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.0222 |
altlinux: CVE-2026-53164 was patched at 2026-06-19, 2026-06-22, 2026-07-06
1634.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53167) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios FUSE_NOTIFY_RETRIEVE must be limited to uptodate folios; !uptodate folios can contain uninitialized data. Since FUSE_NOTIFY_RETRIEVE is intended to only return data that is already in the page cache and not wait for data from the FUSE daemon, treat !uptodate folios as if they weren't present. This only has security impact on systems that don't enable automatic zero-initialization of all page allocations via CONFIG_INIT_ON_ALLOC_DEFAULT_ON or init_on_alloc=1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: limit FUSE_NOTIFY_RETRIEVE to uptodate folios\n\nFUSE_NOTIFY_RETRIEVE must be limited to uptodate folios; !uptodate folios\ncan contain uninitialized data.\nSince FUSE_NOTIFY_RETRIEVE is intended to only return data that is already\nin the page cache and not wait for data from the FUSE daemon, treat\n!uptodate folios as if they weren't present.\n\nThis only has security impact on systems that don't enable automatic\nzero-initialization of all page allocations via\nCONFIG_INIT_ON_ALLOC_DEFAULT_ON or init_on_alloc=1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02407 |
altlinux: CVE-2026-53167 was patched at 2026-06-19, 2026-06-22, 2026-07-06
debian: CVE-2026-53167 was patched at 2026-07-05, 2026-07-14, 2026-07-30
1635.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53168) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: fuse: reject fuse_notify() pagecache ops on directories The operations FUSE_NOTIFY_STORE and FUSE_NOTIFY_RETRIEVE allow the FUSE daemon to actively write/read pagecache contents. For directories with FOPEN_CACHE_DIR, the pagecache is used as kernel-internal cache storage, and userspace is not supposed to have direct access to this cache - in particular, fuse_parse_cache() will hit WARN_ON() if the cache contains bogus data. Reject FUSE_NOTIFY_STORE and FUSE_NOTIFY_RETRIEVE on anything other than regular files with -EINVAL.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfuse: reject fuse_notify() pagecache ops on directories\n\nThe operations FUSE_NOTIFY_STORE and FUSE_NOTIFY_RETRIEVE allow the\nFUSE daemon to actively write/read pagecache contents.\n\nFor directories with FOPEN_CACHE_DIR, the pagecache is used as\nkernel-internal cache storage, and userspace is not supposed to have\ndirect access to this cache - in particular, fuse_parse_cache() will hit\nWARN_ON() if the cache contains bogus data.\n\nReject FUSE_NOTIFY_STORE and FUSE_NOTIFY_RETRIEVE on anything other than\nregular files with -EINVAL.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02407 |
altlinux: CVE-2026-53168 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53168 was patched at 2026-07-14
1636.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53190) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait() dma_fence_unwrap_for_each() internally calls dma_fence_unwrap_first() which does cursor->chain = dma_fence_get(head), taking an extra reference. On normal loop completion, dma_fence_unwrap_next() releases this via dma_fence_chain_walk() -> dma_fence_put(). When virtio_gpu_do_fence_wait() fails and the function returns early from inside the loop, the cursor->chain reference is never released. This is the only caller in the entire kernel that does an early return inside dma_fence_unwrap_for_each. Add dma_fence_put(itr.chain) before the early return.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/virtio: fix dma_fence refcount leak on error in virtio_gpu_dma_fence_wait()\n\ndma_fence_unwrap_for_each() internally calls dma_fence_unwrap_first()\nwhich does cursor->chain = dma_fence_get(head), taking an extra\nreference. On normal loop completion, dma_fence_unwrap_next()\nreleases this via dma_fence_chain_walk() -> dma_fence_put().\n\nWhen virtio_gpu_do_fence_wait() fails and the function returns early\nfrom inside the loop, the cursor->chain reference is never released.\nThis is the only caller in the entire kernel that does an early return\ninside dma_fence_unwrap_for_each.\n\nAdd dma_fence_put(itr.chain) before the early return.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.0233 |
altlinux: CVE-2026-53190 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53190 was patched at 2026-07-14
1637.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53197) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state() iptfs_destroy_state() calls hrtimer_cancel() while holding a spinlock that the timer callback also acquires, leading to an ABBA deadlock on SMP systems. For the output timer (iptfs_timer): - iptfs_destroy_state() holds x->lock, calls hrtimer_cancel() - iptfs_delay_timer() callback takes x->lock For the drop timer (drop_timer): - iptfs_destroy_state() holds drop_lock, calls hrtimer_cancel() - iptfs_drop_timer() callback takes drop_lock Both timers use HRTIMER_MODE_REL_SOFT, so their callbacks run in softirq context. When hrtimer_cancel() is called for a soft timer that is currently executing on another CPU, hrtimer_cancel_wait_running() spins on softirq_expiry_lock -- the same lock held by the softirq running the callback. If the callback is blocked waiting for the spinlock held by the caller of hrtimer_cancel(), a circular dependency forms: CPU 0: holds lock_A -> waits for softirq_expiry_lock CPU 1: holds softirq_expiry_lock -> waits for lock_A Fix by calling hrtimer_cancel() before acquiring the respective locks. hrtimer_cancel() is safe to call without holding any lock and will wait for any in-progress callback to complete. For the output timer, the lock is still acquired afterwards to drain the packet queue. For the drop timer, the lock/unlock pair is removed entirely since it only existed to serialize with the timer callback, which hrtimer_cancel() already guarantees. Found by source code audit.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfrm: iptfs: fix ABBA deadlock in iptfs_destroy_state()\n\niptfs_destroy_state() calls hrtimer_cancel() while holding a spinlock\nthat the timer callback also acquires, leading to an ABBA deadlock on\nSMP systems.\n\nFor the output timer (iptfs_timer):\n - iptfs_destroy_state() holds x->lock, calls hrtimer_cancel()\n - iptfs_delay_timer() callback takes x->lock\n\nFor the drop timer (drop_timer):\n - iptfs_destroy_state() holds drop_lock, calls hrtimer_cancel()\n - iptfs_drop_timer() callback takes drop_lock\n\nBoth timers use HRTIMER_MODE_REL_SOFT, so their callbacks run in softirq\ncontext. When hrtimer_cancel() is called for a soft timer that is\ncurrently executing on another CPU, hrtimer_cancel_wait_running() spins\non softirq_expiry_lock -- the same lock held by the softirq running the\ncallback. If the callback is blocked waiting for the spinlock held by\nthe caller of hrtimer_cancel(), a circular dependency forms:\n\n CPU 0: holds lock_A -> waits for softirq_expiry_lock\n CPU 1: holds softirq_expiry_lock -> waits for lock_A\n\nFix by calling hrtimer_cancel() before acquiring the respective locks.\nhrtimer_cancel() is safe to call without holding any lock and will wait\nfor any in-progress callback to complete. For the output timer, the\nlock is still acquired afterwards to drain the packet queue. For the\ndrop timer, the lock/unlock pair is removed entirely since it only\nexisted to serialize with the timer callback, which hrtimer_cancel()\nalready guarantees.\n\nFound by source code audit.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00093, EPSS Percentile is 0.00688 |
altlinux: CVE-2026-53197 was patched at 2026-06-19, 2026-06-22, 2026-07-06
1638.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53206) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: accel/ivpu: Add bounds check for firmware runtime memory Validate that the firmware runtime memory specified in the image header is properly aligned and sized to hold the firmware image. This prevents errors during memory allocation and image transfer.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\naccel/ivpu: Add bounds check for firmware runtime memory\n\nValidate that the firmware runtime memory specified in the image\nheader is properly aligned and sized to hold the firmware image.\nThis prevents errors during memory allocation and image transfer.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00107, EPSS Percentile is 0.01361 |
altlinux: CVE-2026-53206 was patched at 2026-06-19
1639.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53207) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison Two concurrent madvise(MADV_HWPOISON) calls on the same hugetlb page can trigger a recursive spinlock self-deadlock (AA deadlock) on hugetlb_lock when racing with a concurrent unmap: thread#0 thread#1 -------- -------- madvise(folio, MADV_HWPOISON) -> poisons the folio successfully madvise(folio, MADV_HWPOISON) unmap(folio) try_memory_failure_hugetlb get_huge_page_for_hwpoison spin_lock_irq(&hugetlb_lock) <- held __get_huge_page_for_hwpoison hugetlb_update_hwpoison() -> MF_HUGETLB_FOLIO_PRE_POISONED goto out: folio_put() refcount: 1 -> 0 free_huge_folio() spin_lock_irqsave(&hugetlb_lock) -> AA DEADLOCK! The out: path in __get_huge_page_for_hwpoison() calls folio_put() to drop the GUP reference while the hugetlb_lock is still held by the hugetlb.c wrapper get_huge_page_for_hwpoison(). If concurrent unmap has released the page table mapping reference, folio_put() drops the folio refcount to zero, triggering free_huge_folio() which attempts to re-acquire the non-recursive hugetlb_lock. Fix this by moving hugetlb_lock acquisition from the hugetlb.c wrapper into get_huge_page_for_hwpoison(). Place spin_unlock_irq() before the folio_put() at the out: label so the folio is always released outside the lock. [akpm@linux-foundation.org: fix race, rename label per Miaohe]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/memory-failure: fix hugetlb_lock AA deadlock in get_huge_page_for_hwpoison\n\nTwo concurrent madvise(MADV_HWPOISON) calls on the same hugetlb page can\ntrigger a recursive spinlock self-deadlock (AA deadlock) on hugetlb_lock\nwhen racing with a concurrent unmap:\n\n thread#0 thread#1\n -------- --------\n madvise(folio, MADV_HWPOISON)\n -> poisons the folio successfully\n madvise(folio, MADV_HWPOISON) unmap(folio)\n try_memory_failure_hugetlb\n get_huge_page_for_hwpoison\n spin_lock_irq(&hugetlb_lock) <- held\n __get_huge_page_for_hwpoison\n hugetlb_update_hwpoison()\n -> MF_HUGETLB_FOLIO_PRE_POISONED\n goto out:\n folio_put()\n refcount: 1 -> 0\n free_huge_folio()\n spin_lock_irqsave(&hugetlb_lock)\n -> AA DEADLOCK!\n\nThe out: path in __get_huge_page_for_hwpoison() calls folio_put() to drop\nthe GUP reference while the hugetlb_lock is still held by the hugetlb.c\nwrapper get_huge_page_for_hwpoison(). If concurrent unmap has released\nthe page table mapping reference, folio_put() drops the folio refcount to\nzero, triggering free_huge_folio() which attempts to re-acquire the\nnon-recursive hugetlb_lock.\n\nFix this by moving hugetlb_lock acquisition from the hugetlb.c wrapper\ninto get_huge_page_for_hwpoison(). Place spin_unlock_irq() before the\nfolio_put() at the out: label so the folio is always released outside the\nlock.\n\n[akpm@linux-foundation.org: fix race, rename label per Miaohe]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00095, EPSS Percentile is 0.00751 |
altlinux: CVE-2026-53207 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53207 was patched at 2026-07-14
1640.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53208) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig net/bluetooth/l2cap_core.c:l2cap_sig_channel() accepts BR/EDR signaling packets up to the channel MTU and dispatches each command without enforcing the signaling MTU (MTUsig). A Bluetooth BR/EDR peer within radio range can send a fixed-channel CID 0x0001 packet that is larger than MTUsig and contains many L2CAP_ECHO_REQ commands before pairing. In a real-radio stock-kernel run, one 681-byte signaling packet containing 168 zero-length ECHO_REQ commands made the target transmit 168 ECHO_RSP frames over about 220 ms. Impact: a Bluetooth BR/EDR peer within radio range, before pairing, can force 168 ECHO_RSP frames from one 681-byte fixed-channel signaling packet containing packed ECHO_REQ commands. Define Linux's BR/EDR signaling MTU as the spec minimum of 48 bytes and reject any larger signaling packet with one L2CAP_COMMAND_REJECT_RSP carrying L2CAP_REJ_MTU_EXCEEDED before any command is dispatched. The Bluetooth Core spec wording for MTUExceeded says the reject identifier shall match the first request command in the packet, and that packets containing only responses shall be silently discarded. Linux intentionally deviates from that prescription: silently discarding desynchronizes the peer because the remote stack never learns its responses were dropped, and locating the first request command requires walking command headers past MTUsig, i.e. processing bytes from a packet we have already decided is too large to process. We therefore always emit one reject and use the identifier from the first command header, a single fixed-offset byte read. The unrestricted BR/EDR signaling parser and ECHO_REQ response path both trace to the initial git import; no later introducing commit is available for a Fixes tag.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: reject BR/EDR signaling packets over MTUsig\n\nnet/bluetooth/l2cap_core.c:l2cap_sig_channel() accepts BR/EDR\nsignaling packets up to the channel MTU and dispatches each command\nwithout enforcing the signaling MTU (MTUsig). A Bluetooth BR/EDR peer\nwithin radio range can send a fixed-channel CID 0x0001 packet that is\nlarger than MTUsig and contains many L2CAP_ECHO_REQ commands before\npairing. In a real-radio stock-kernel run, one 681-byte signaling\npacket containing 168 zero-length ECHO_REQ commands made the target\ntransmit 168 ECHO_RSP frames over about 220 ms.\n\nImpact: a Bluetooth BR/EDR peer within radio range, before pairing, can\nforce 168 ECHO_RSP frames from one 681-byte fixed-channel signaling\npacket containing packed ECHO_REQ commands.\n\nDefine Linux's BR/EDR signaling MTU as the spec minimum of 48 bytes and\nreject any larger signaling packet with one L2CAP_COMMAND_REJECT_RSP\ncarrying L2CAP_REJ_MTU_EXCEEDED before any command is dispatched.\n\nThe Bluetooth Core spec wording for MTUExceeded says the reject\nidentifier shall match the first request command in the packet, and\nthat packets containing only responses shall be silently discarded.\nLinux intentionally deviates from that prescription: silently\ndiscarding desynchronizes the peer because the remote stack never\nlearns its responses were dropped, and locating the first request\ncommand requires walking command headers past MTUsig, i.e. processing\nbytes from a packet we have already decided is too large to process.\nWe therefore always emit one reject and use the identifier from the\nfirst command header, a single fixed-offset byte read.\n\nThe unrestricted BR/EDR signaling parser and ECHO_REQ response path both\ntrace to the initial git import; no later introducing commit is\navailable for a Fixes tag.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02394 |
altlinux: CVE-2026-53208 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53208 was patched at 2026-07-14
1641.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53210) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tee: shm: fix shm leak in register_shm_helper() register_shm_helper() allocates shm before calling iov_iter_npages(). If iov_iter_npages() returns 0, the function jumps to err_ctx_put and leaks shm. This can be triggered by TEE_IOC_SHM_REGISTER with struct tee_ioctl_shm_register_data where length is 0. Jump to err_free_shm instead.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntee: shm: fix shm leak in register_shm_helper()\n\nregister_shm_helper() allocates shm before calling\niov_iter_npages(). If iov_iter_npages() returns 0, the function\njumps to err_ctx_put and leaks shm.\n\nThis can be triggered by TEE_IOC_SHM_REGISTER with\nstruct tee_ioctl_shm_register_data where length is 0.\n\nJump to err_free_shm instead.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02333 |
altlinux: CVE-2026-53210 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53210 was patched at 2026-07-14
1642.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53211) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register NFT_META_BRI_IIFHWADDR declares its destination register with len = ETH_ALEN (6 bytes), which the register-init tracking rounds up to two 32-bit registers (8 bytes). nft_meta_bridge_get_eval() then does memcpy(dest, br_dev->dev_addr, ETH_ALEN), writing only 6 bytes and leaving the upper 2 bytes of the second register as uninitialised nft_do_chain() stack. A downstream load of that register span leaks those stale bytes to userspace. Zero the second register before the memcpy so the full declared span is written.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_meta_bridge: fix stale stack leak via IIFHWADDR register\n\nNFT_META_BRI_IIFHWADDR declares its destination register with\nlen = ETH_ALEN (6 bytes), which the register-init tracking rounds up to\ntwo 32-bit registers (8 bytes). nft_meta_bridge_get_eval() then does\nmemcpy(dest, br_dev->dev_addr, ETH_ALEN), writing only 6 bytes and\nleaving the upper 2 bytes of the second register as uninitialised\nnft_do_chain() stack. A downstream load of that register span leaks\nthose stale bytes to userspace.\n\nZero the second register before the memcpy so the full declared span is\nwritten.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00121, EPSS Percentile is 0.02234 |
altlinux: CVE-2026-53211 was patched at 2026-06-19, 2026-06-22, 2026-07-06
1643.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53218) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_exthdr: fix register tracking for F_PRESENT flag nft_exthdr_init() passes user-controlled priv->len to nft_parse_register_store(), which marks that many bytes in the register bitmap as initialized. However, when NFT_EXTHDR_F_PRESENT is set, the eval paths write only 1 byte (nft_reg_store8) or 4 bytes (*dest = 0 on TCP/DCCP error path). When len > 4, registers beyond the first are never written, retaining uninitialized stack data from nft_regs. Bail out if userspace requests too much data when F_PRESENT is set.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nft_exthdr: fix register tracking for F_PRESENT flag\n\nnft_exthdr_init() passes user-controlled priv->len to\nnft_parse_register_store(), which marks that many bytes in the\nregister bitmap as initialized. However, when NFT_EXTHDR_F_PRESENT\nis set, the eval paths write only 1 byte (nft_reg_store8) or\n4 bytes (*dest = 0 on TCP/DCCP error path). When len > 4,\nregisters beyond the first are never written, retaining\nuninitialized stack data from nft_regs.\n\nBail out if userspace requests too much data when F_PRESENT is set.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02434 |
altlinux: CVE-2026-53218 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53218 was patched at 2026-07-14
1644.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53219) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: avoid leaking percpu counter pointers The native and compat get-entries paths copy the fixed rule entry header from the kernelized rule blob to userspace before overwriting the entry's counter fields with a sanitized counter snapshot. On SMP kernels, entry->counters.pcnt contains the percpu allocation address used by x_tables rule counters. A caller can provide a userspace buffer that faults during the initial fixed-header copy after pcnt has been copied but before the later sanitized counter copy runs. The syscall then returns -EFAULT while leaving the raw percpu pointer in userspace. Copy only the fixed entry prefix before counters from the kernelized rule blob, then copy the sanitized counter snapshot into the counter field. Apply this ordering to the IPv4, IPv6, and ARP native and compat get-entries implementations so a fault cannot expose the internal percpu counter pointer.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: x_tables: avoid leaking percpu counter pointers\n\nThe native and compat get-entries paths copy the fixed rule entry header\nfrom the kernelized rule blob to userspace before overwriting the entry's\ncounter fields with a sanitized counter snapshot.\n\nOn SMP kernels, entry->counters.pcnt contains the percpu allocation\naddress used by x_tables rule counters. A caller can provide a userspace\nbuffer that faults during the initial fixed-header copy after pcnt has\nbeen copied but before the later sanitized counter copy runs. The syscall\nthen returns -EFAULT while leaving the raw percpu pointer in userspace.\n\nCopy only the fixed entry prefix before counters from the kernelized rule\nblob, then copy the sanitized counter snapshot into the counter field.\nApply this ordering to the IPv4, IPv6, and ARP native and compat\nget-entries implementations so a fault cannot expose the internal percpu\ncounter pointer.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02431 |
altlinux: CVE-2026-53219 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53219 was patched at 2026-07-14
1645.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53227) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: fix possible kfree_skb of ERR_PTR After the patch in the "Fixes" tag, the allocation of the "reply" skb can happen either before or after locking the ovs_mutex. However, error cleanups still follow the classical reversed order, assuming "reply" is allocated before locking: it is freed after unlocking. If "reply" allocation happens after locking the mutex and it fails, "reply" is left with an ERR_PTR, and execution jumps to the correspondent cleanup stage which will try to free an invalid pointer. Fix this by setting the pointer to NULL after having saved its error value.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: openvswitch: fix possible kfree_skb of ERR_PTR\n\nAfter the patch in the "Fixes" tag, the allocation of the "reply" skb\ncan happen either before or after locking the ovs_mutex.\n\nHowever, error cleanups still follow the classical reversed order,\nassuming "reply" is allocated before locking: it is freed after unlocking.\n\nIf "reply" allocation happens after locking the mutex and it fails,\n"reply" is left with an ERR_PTR, and execution jumps to the correspondent\ncleanup stage which will try to free an invalid pointer.\n\nFix this by setting the pointer to NULL after having saved its error\nvalue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0013, EPSS Percentile is 0.03034 |
altlinux: CVE-2026-53227 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53227 was patched at 2026-07-14
1646.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53231) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: phy: don't try to setup PHY-driven SFP cages when using genphy We don't have support for PHY-driver SFP cages with the genphy code. On top of that, it was found by sashiko that running sfp_bus_add_upstream() for genphy deadlocks, as for genphy the PHY probing runs under RTNL, which isn't the case for non-genphy drivers. This problem was reproduced, and does lead to a deadlock on RTNL. Before the blamed commit, the phy_sfp_probe() call was made by individual PHY drivers, so there was no way to get to the SFP probing path when using genphy. Let's therefore only run phy_sfp_probe when not using genphy.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: phy: don't try to setup PHY-driven SFP cages when using genphy\n\nWe don't have support for PHY-driver SFP cages with the genphy code.\n\nOn top of that, it was found by sashiko that running\nsfp_bus_add_upstream() for genphy deadlocks, as for genphy the PHY\nprobing runs under RTNL, which isn't the case for non-genphy drivers.\n\nThis problem was reproduced, and does lead to a deadlock on RTNL.\n\nBefore the blamed commit, the phy_sfp_probe() call was made by\nindividual PHY drivers, so there was no way to get to the SFP probing\npath when using genphy.\n\nLet's therefore only run phy_sfp_probe when not using genphy.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00083, EPSS Percentile is 0.00302 |
altlinux: CVE-2026-53231 was patched at 2026-06-19
1647.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53236) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tcp: restrict SO_ATTACH_FILTER to priv users This patch restricts the use of SO_ATTACH_FILTER (cBPF) on TCP sockets to users with CAP_NET_ADMIN capability. This blocks potential side-channel attack where an unprivileged application attaches a filter to leak TCP sequence/acknowledgment numbers.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntcp: restrict SO_ATTACH_FILTER to priv users\n\nThis patch restricts the use of SO_ATTACH_FILTER (cBPF) on TCP sockets\nto users with CAP_NET_ADMIN capability.\n\nThis blocks potential side-channel attack where an unprivileged application\nattaches a filter to leak TCP sequence/acknowledgment numbers.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02393 |
altlinux: CVE-2026-53236 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53236 was patched at 2026-07-14
1648.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53238) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netlabel: validate unlabeled address and mask attribute lengths netlbl_unlabel_addrinfo_get() used the address attribute length to determine whether the attribute data could be read as an IPv4 or IPv6 address, but did not independently validate the corresponding mask attribute length. A crafted Generic Netlink request could therefore provide a valid IPv4/IPv6 address attribute with a shorter mask attribute, which would later be read as a full struct in_addr or struct in6_addr. NLA_BINARY policy lengths are maximum lengths by default, so use NLA_POLICY_EXACT_LEN() for the unlabeled IPv4/IPv6 address and mask attributes. This rejects short attributes during policy validation and also exposes the exact length requirements through policy introspection.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetlabel: validate unlabeled address and mask attribute lengths\n\nnetlbl_unlabel_addrinfo_get() used the address attribute length to\ndetermine whether the attribute data could be read as an IPv4 or IPv6\naddress, but did not independently validate the corresponding mask\nattribute length. A crafted Generic Netlink request could therefore\nprovide a valid IPv4/IPv6 address attribute with a shorter mask\nattribute, which would later be read as a full struct in_addr or\nstruct in6_addr.\n\nNLA_BINARY policy lengths are maximum lengths by default, so use\nNLA_POLICY_EXACT_LEN() for the unlabeled IPv4/IPv6 address and mask\nattributes. This rejects short attributes during policy validation and\nalso exposes the exact length requirements through policy introspection.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02393 |
altlinux: CVE-2026-53238 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53238 was patched at 2026-07-14
1649.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53241) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: dummy: fix UMP event stack overread The dummy sequencer port forwards events by copying an incoming struct snd_seq_event into a stack temporary, rewriting source and destination, and dispatching the temporary to subscribers. That legacy event storage is smaller than struct snd_seq_ump_event. When a UMP event reaches the dummy client, the copy leaves the UMP flag set but only provides legacy-sized stack storage. The subscriber delivery path then uses snd_seq_event_packet_size() and copies a UMP-sized packet from that stack object, reading past the end of the temporary. Use the existing union __snd_seq_event storage and copy the packet size reported for the incoming event before rewriting the common routing fields. This preserves the full UMP packet for UMP events while keeping legacy event handling unchanged.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: seq: dummy: fix UMP event stack overread\n\nThe dummy sequencer port forwards events by copying an incoming\nstruct snd_seq_event into a stack temporary, rewriting source and\ndestination, and dispatching the temporary to subscribers. That legacy\nevent storage is smaller than struct snd_seq_ump_event.\n\nWhen a UMP event reaches the dummy client, the copy leaves the UMP flag\nset but only provides legacy-sized stack storage. The subscriber\ndelivery path then uses snd_seq_event_packet_size() and copies a\nUMP-sized packet from that stack object, reading past the end of the\ntemporary.\n\nUse the existing union __snd_seq_event storage and copy the packet size\nreported for the incoming event before rewriting the common routing\nfields. This preserves the full UMP packet for UMP events while keeping\nlegacy event handling unchanged.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02354 |
altlinux: CVE-2026-53241 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53241 was patched at 2026-07-14
1650.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53243) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: rseq: Fix using an uninitialized stack variable in rseq_exit_user_update() There is an bug in which an uninitialized stack variable is used in rseq_exit_user_update() as reported by syzbot: BUG: KMSAN: kernel-infoleak in rseq_set_ids_get_csaddr include/linux/rseq_entry.h:502 [inline] The local variable: \tstruct rseq_ids ids = { \t\t.cpu_id\t = task_cpu(t), \t\t.mm_cid\t = task_mm_cid(t), \t\t.node_id = cpu_to_node(ids.cpu_id), \t}; According to the C standard, the evaluation order of expressions in an initializer list is indeterminately sequenced. The compiler (Clang, in this KMSAN build) evaluates `cpu_to_node(ids.cpu_id)` *before* `ids.cpu_id` is initialized with `task_cpu(t)`. This is fixed by moving the assignment of ids.node_id outside the structure initialization.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nrseq: Fix using an uninitialized stack variable in rseq_exit_user_update()\n\nThere is an bug in which an uninitialized stack variable is used in\nrseq_exit_user_update() as reported by syzbot:\n\nBUG: KMSAN: kernel-infoleak in rseq_set_ids_get_csaddr include/linux/rseq_entry.h:502 [inline]\n\nThe local variable:\n\n\tstruct rseq_ids ids = {\n\t\t.cpu_id\t = task_cpu(t),\n\t\t.mm_cid\t = task_mm_cid(t),\n\t\t.node_id = cpu_to_node(ids.cpu_id),\n\t};\n\nAccording to the C standard, the evaluation order of expressions in an\ninitializer list is indeterminately sequenced. The compiler (Clang, in\nthis KMSAN build) evaluates `cpu_to_node(ids.cpu_id)` *before*\n`ids.cpu_id` is initialized with `task_cpu(t)`.\n\nThis is fixed by moving the assignment of ids.node_id outside the\nstructure initialization.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00107, EPSS Percentile is 0.01364 |
altlinux: CVE-2026-53243 was patched at 2026-06-19
1651.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53245) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr In mrp_pdu_parse_vecattr(), vector attribute events are encoded three per byte and valen tracks the number of events left to process. The parser decrements valen after processing the first and second events from each event byte, but not after processing the third one. When valen is exactly a multiple of three, the loop continues after the last valid event and consumes the next byte as a new event byte, applying a spurious event to the MRP applicant state. Additionally, when valen is zero the parser unconditionally consumes attrlen bytes as FirstValue and advances the offset, even though per IEEE 802.1ak a VectorAttribute with only a LeaveAllEvent has valen of zero and no FirstValue or Vector fields. This corrupts the offset for subsequent PDU parsing. Also, when valen exceeds three the loop crosses byte boundaries but the attribute value is not incremented between the last event of one byte and the first event of the next. This causes the first event of the next byte to use the same attribute value as the third event rather than the next consecutive value. Decrement valen after processing the third event, skip FirstValue consumption when valen is zero, and increment the attribute value at the end of each loop iteration.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/802/mrp: fix vector attribute parsing in mrp_pdu_parse_vecattr\n\nIn mrp_pdu_parse_vecattr(), vector attribute events are encoded three\nper byte and valen tracks the number of events left to process.\n\nThe parser decrements valen after processing the first and second events\nfrom each event byte, but not after processing the third one. When valen\nis exactly a multiple of three, the loop continues after the last valid\nevent and consumes the next byte as a new event byte, applying a\nspurious event to the MRP applicant state.\n\nAdditionally, when valen is zero the parser unconditionally consumes\nattrlen bytes as FirstValue and advances the offset, even though per\nIEEE 802.1ak a VectorAttribute with only a LeaveAllEvent has valen of\nzero and no FirstValue or Vector fields. This corrupts the offset for\nsubsequent PDU parsing.\n\nAlso, when valen exceeds three the loop crosses byte boundaries but\nthe attribute value is not incremented between the last event of one\nbyte and the first event of the next. This causes the first event of\nthe next byte to use the same attribute value as the third event\nrather than the next consecutive value.\n\nDecrement valen after processing the third event, skip FirstValue\nconsumption when valen is zero, and increment the attribute value at\nthe end of each loop iteration.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02435 |
altlinux: CVE-2026-53245 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53245 was patched at 2026-07-14
1652.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53249) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv4: restrict IPOPT_SSRR and IPOPT_LSRR options This patch restricts setting Loose Source and Record Route (LSRR) and Strict Source and Record Route (SSRR) IP options to users with CAP_NET_RAW capability. This prevents unprivileged applications from forcing packets to route through attacker-controlled nodes to leak TCP ISN and possibly other protocol information. While LSRR and SSRR are commonly filtered in many network environments, they may still be supported and forwarded along some network paths. RFC 7126 (Recommendations on Filtering of IPv4 Packets Containing IPv4 Options) recommend to drop these options in 4.3 and 4.4.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv4: restrict IPOPT_SSRR and IPOPT_LSRR options\n\nThis patch restricts setting Loose Source and Record Route (LSRR)\nand Strict Source and Record Route (SSRR) IP options to users\nwith CAP_NET_RAW capability.\n\nThis prevents unprivileged applications from forcing packets to route\nthrough attacker-controlled nodes to leak TCP ISN and possibly other\nprotocol information.\n\nWhile LSRR and SSRR are commonly filtered in many network environments,\nthey may still be supported and forwarded along some network paths.\n\nRFC 7126 (Recommendations on Filtering of IPv4 Packets Containing\nIPv4 Options) recommend to drop these options in 4.3 and 4.4.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02392 |
altlinux: CVE-2026-53249 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53249 was patched at 2026-07-14
1653.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53251) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync hci_get_route() returns a reference-counted hci_dev pointer via hci_dev_hold(). The function exits normally or with an error without ever releasing it.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: Fix not releasing hdev reference on iso_conn_big_sync\n\nhci_get_route() returns a reference-counted hci_dev pointer via\nhci_dev_hold(). The function exits normally or with an error without ever\nreleasing it.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.0235 |
altlinux: CVE-2026-53251 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53251 was patched at 2026-07-14
1654.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53257) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: enforce HE/EHT cap/oper consistency Xiang Mei reports that mac80211 could crash if eht_cap is set but eht_oper isn't. Rather than fixing that for the individual user(s), enforce that both HE/EHT have consistent elements.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: enforce HE/EHT cap/oper consistency\n\nXiang Mei reports that mac80211 could crash if eht_cap is set\nbut eht_oper isn't. Rather than fixing that for the individual\nuser(s), enforce that both HE/EHT have consistent elements.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.001, EPSS Percentile is 0.01012 |
altlinux: CVE-2026-53257 was patched at 2026-06-19
1655.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53258) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: fix leak if split 6 GHz scanning fails rdev->int_scan_req is leaked if cfg80211_scan() fails. Note that it's supposed to be released at ___cfg80211_scan_done() but this doesn't happen as rdev->scan_req is NULL at that point, too, leading to the early return from the freeing function. unreferenced object 0xffff8881161d0800 (size 512): comm "wpa_supplicant", pid 379, jiffies 4294749765 hex dump (first 32 bytes): 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................ 00 00 00 00 00 00 00 00 f0 81 13 16 81 88 ff ff ................ backtrace (crc c867fdb6): kmemleak_alloc+0x89/0x90 __kmalloc_noprof+0x2fd/0x410 cfg80211_scan+0x133/0x730 nl80211_trigger_scan+0xc69/0x1cc0 genl_family_rcv_msg_doit+0x204/0x2f0 genl_rcv_msg+0x431/0x6b0 netlink_rcv_skb+0x143/0x3f0 genl_rcv+0x27/0x40 netlink_unicast+0x4f6/0x820 netlink_sendmsg+0x797/0xce0 __sock_sendmsg+0xc4/0x160 ____sys_sendmsg+0x5e4/0x890 ___sys_sendmsg+0xf8/0x180 __sys_sendmsg+0x136/0x1e0 __x64_sys_sendmsg+0x76/0xc0 x64_sys_call+0x13f0/0x17d0 Found by Linux Verification Center (linuxtesting.org).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: fix leak if split 6 GHz scanning fails\n\nrdev->int_scan_req is leaked if cfg80211_scan() fails. Note that it's\nsupposed to be released at ___cfg80211_scan_done() but this doesn't happen\nas rdev->scan_req is NULL at that point, too, leading to the early return\nfrom the freeing function.\n\nunreferenced object 0xffff8881161d0800 (size 512):\n comm "wpa_supplicant", pid 379, jiffies 4294749765\n hex dump (first 32 bytes):\n 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................\n 00 00 00 00 00 00 00 00 f0 81 13 16 81 88 ff ff ................\n backtrace (crc c867fdb6):\n kmemleak_alloc+0x89/0x90\n __kmalloc_noprof+0x2fd/0x410\n cfg80211_scan+0x133/0x730\n nl80211_trigger_scan+0xc69/0x1cc0\n genl_family_rcv_msg_doit+0x204/0x2f0\n genl_rcv_msg+0x431/0x6b0\n netlink_rcv_skb+0x143/0x3f0\n genl_rcv+0x27/0x40\n netlink_unicast+0x4f6/0x820\n netlink_sendmsg+0x797/0xce0\n __sock_sendmsg+0xc4/0x160\n ____sys_sendmsg+0x5e4/0x890\n ___sys_sendmsg+0xf8/0x180\n __sys_sendmsg+0x136/0x1e0\n __x64_sys_sendmsg+0x76/0xc0\n x64_sys_call+0x13f0/0x17d0\n\nFound by Linux Verification Center (linuxtesting.org).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01628 |
altlinux: CVE-2026-53258 was patched at 2026-06-19, 2026-06-22, 2026-07-06
debian: CVE-2026-53258 was patched at 2026-07-14
1656.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53261) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: devlink: Release nested relation on devlink free devlink relation state is normally released from devl_unregister(), which calls devlink_rel_put(). This misses devlink instances that get a nested relation before registration and then fail probe before devl_register() is reached. That flow can happen for SFs. The child devlink gets linked to its parent before registration, then a later probe error calls devlink_free() directly. Since the instance was never registered, devl_unregister() is not called and devlink->rel is leaked. Release any pending relation from devlink_free() as well. The registered path is unchanged because devl_unregister() already clears devlink->rel before devlink_free() runs.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndevlink: Release nested relation on devlink free\n\ndevlink relation state is normally released from devl_unregister(), which\ncalls devlink_rel_put(). This misses devlink instances that get a nested\nrelation before registration and then fail probe before devl_register() is\nreached.\n\nThat flow can happen for SFs. The child devlink gets linked to its\nparent before registration, then a later probe error calls devlink_free()\ndirectly. Since the instance was never registered, devl_unregister() is not\ncalled and devlink->rel is leaked.\n\nRelease any pending relation from devlink_free() as well. The registered\npath is unchanged because devl_unregister() already clears devlink->rel\nbefore devlink_free() runs.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.01704 |
altlinux: CVE-2026-53261 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53261 was patched at 2026-07-14
1657.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53269) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: add mutex to guard hook reference counting As the synproxy infrastructure register netfilter hooks on-demand when a user adds the first iptables target or nftables expression, if done concurrently they can race each other. Introduce a mutex to serialize the refcount control blocks access from both frontends. While a per namespace mutex might be more efficient, it is not needed for target/expression like SYNPROXY.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: synproxy: add mutex to guard hook reference counting\n\nAs the synproxy infrastructure register netfilter hooks on-demand when a\nuser adds the first iptables target or nftables expression, if done\nconcurrently they can race each other.\n\nIntroduce a mutex to serialize the refcount control blocks access from\nboth frontends. While a per namespace mutex might be more efficient, it\nis not needed for target/expression like SYNPROXY.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.01759 |
altlinux: CVE-2026-53269 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53269 was patched at 2026-07-14
1658.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53326) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: debugobjects: Don't call fill_pool() in early boot hardirq context When booting a debug PREEMPT_RT kernel on an ARM64 system, a "inconsistent {HARDIRQ-ON-W} -> {IN-HARDIRQ-W} usage" lockdep warning message was reported to the console. During early boot, interrupts are enabled before the scheduler is enabled. In this window (before SYSTEM_SCHEDULING is set) interrupts can fire and in the hard interrupt context handler attempt to fill the pool This can lead to a deadlock when the interrupt occurred when the interrupt hits a region which holds a lock that is required to be taken in the allocation path. Add a new can_fill_pool() helper and reorder the exception rule and forbid this scenario by excluding allocations from hard interrupt context.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndebugobjects: Don't call fill_pool() in early boot hardirq context\n\nWhen booting a debug PREEMPT_RT kernel on an ARM64 system, a "inconsistent\n{HARDIRQ-ON-W} -> {IN-HARDIRQ-W} usage" lockdep warning message was\nreported to the console.\n\nDuring early boot, interrupts are enabled before the scheduler is\nenabled. In this window (before SYSTEM_SCHEDULING is set) interrupts can\nfire and in the hard interrupt context handler attempt to fill the pool\n\nThis can lead to a deadlock when the interrupt occurred when the interrupt\nhits a region which holds a lock that is required to be taken in the\nallocation path.\n\nAdd a new can_fill_pool() helper and reorder the exception rule and forbid\nthis scenario by excluding allocations from hard interrupt context.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00095, EPSS Percentile is 0.00754 |
altlinux: CVE-2026-53326 was patched at 2026-06-19
1659.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53327) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: debugobjects: Do not fill_pool() if pi_blocked_on On RT enabled kernels, fill_pool() ends up calling rtlock_lock(), which asserts if current::pi_blocked_on is set, because a task can obviously only block on one lock as otherwise the priority inheritenace chain gets corrupted. Prevent this by expanding the conditional to take current::pi_blocked_on into account.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndebugobjects: Do not fill_pool() if pi_blocked_on\n\nOn RT enabled kernels, fill_pool() ends up calling rtlock_lock(), which\nasserts if current::pi_blocked_on is set, because a task can obviously only\nblock on one lock as otherwise the priority inheritenace chain gets\ncorrupted.\n\nPrevent this by expanding the conditional to take current::pi_blocked_on\ninto account.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00129, EPSS Percentile is 0.02994 |
altlinux: CVE-2026-53327 was patched at 2026-06-19, 2026-06-27, 2026-06-28, 2026-07-04, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53327 was patched at 2026-07-05, 2026-07-14, 2026-07-30
1660.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53328) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: sched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task() A WARN fires when systemd's user manager writes "+cpu +memory +pids" to its own subtree_control while a sched_ext scheduler is loaded: WARNING: at kernel/sched/ext.c:3227 scx_cgroup_move_task+0xa8/0xb0 scx_cgroup_move_task+0xa8/0xb0 sched_move_task+0x134/0x290 cpu_cgroup_attach+0x39/0x70 cgroup_migrate_execute+0x37d/0x450 cgroup_update_dfl_csses+0x1e3/0x270 cgroup_subtree_control_write+0x3e7/0x440 scx_cgroup_can_attach() arms cgrp_moving_from only when a task's cpu cgroup changes. It can still be NULL when scx_cgroup_move_task() runs, through this sequence: Step Result --------------------------------- ---------------------------------- 1. cpu enabled on cgroup G cpu css = A 2. cpu toggled off then on for G A killed, B created (same cgroup) 3. an exiting task keeps A alive migration skips it, A now stale 4. +memory migrates G stale A vs current B pulls cpu in 5. cpu attach runs for all tasks hits a live, cpu-unchanged task 6. scx_cgroup_move_task() on it cgrp_moving_from NULL -> WARN The mismatch is that scx_cgroup_can_attach() keys on cgroup identity while migration drives the move on css identity, so a NULL cgrp_moving_from here is a legitimate css-only migration, not a missing prep. The call is already gated on cgrp_moving_from, so just drop the warning. ops.cgroup_prep_move() and ops.cgroup_move() stay paired.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsched_ext: Don't warn on NULL cgrp_moving_from in scx_cgroup_move_task()\n\nA WARN fires when systemd's user manager writes "+cpu +memory +pids" to\nits own subtree_control while a sched_ext scheduler is loaded:\n\n WARNING: at kernel/sched/ext.c:3227 scx_cgroup_move_task+0xa8/0xb0\n scx_cgroup_move_task+0xa8/0xb0\n sched_move_task+0x134/0x290\n cpu_cgroup_attach+0x39/0x70\n cgroup_migrate_execute+0x37d/0x450\n cgroup_update_dfl_csses+0x1e3/0x270\n cgroup_subtree_control_write+0x3e7/0x440\n\nscx_cgroup_can_attach() arms cgrp_moving_from only when a task's cpu\ncgroup changes. It can still be NULL when scx_cgroup_move_task() runs,\nthrough this sequence:\n\n Step Result\n --------------------------------- ----------------------------------\n 1. cpu enabled on cgroup G cpu css = A\n 2. cpu toggled off then on for G A killed, B created (same cgroup)\n 3. an exiting task keeps A alive migration skips it, A now stale\n 4. +memory migrates G stale A vs current B pulls cpu in\n 5. cpu attach runs for all tasks hits a live, cpu-unchanged task\n 6. scx_cgroup_move_task() on it cgrp_moving_from NULL -> WARN\n\nThe mismatch is that scx_cgroup_can_attach() keys on cgroup identity\nwhile migration drives the move on css identity, so a NULL cgrp_moving_from\nhere is a legitimate css-only migration, not a missing prep.\n\nThe call is already gated on cgrp_moving_from, so just drop the warning.\nops.cgroup_prep_move() and ops.cgroup_move() stay paired.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02331 |
altlinux: CVE-2026-53328 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53328 was patched at 2026-07-14
1661.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53331) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock During the SSR/PDR down notification the tx_lock is taken with the intent to provide synchronization with active DMA transfers. But during this period qcom_slim_ngd_down() is invoked, which ends up in slim_report_absent(), which takes the slim_controller lock. In multiple other codepaths these two locks are taken in the opposite order (i.e. slim_controller then tx_lock). The result is a lockdep splat, and a possible deadlock: rprocctl/449 is trying to acquire lock: ffff00009793e620 (&ctrl->lock){+.+.}-{4:4}, at: slim_report_absent (drivers/slimbus/core.c:322) slimbus but task is already holding lock: ffff00009793fb50 (&ctrl->tx_lock){+.+.}-{4:4}, at: qcom_slim_ngd_ssr_pdr_notify (drivers/slimbus/qcom-ngd-ctrl.c:1475) slim_qcom_ngd_ctrl which lock already depends on the new lock. Possible unsafe locking scenario: CPU0 CPU1 ---- ---- lock(&ctrl->tx_lock); lock(&ctrl->lock); lock(&ctrl->tx_lock); lock(&ctrl->lock); The assumption is that the comment refers to the desire to not call qcom_slim_ngd_exit_dma() while we have an ongoing DMA TX transaction. But any such transaction is initiated and completed within a single qcom_slim_ngd_xfer_msg(). Prior to calling qcom_slim_ngd_exit_dma() the slim_controller is torn down, all child devices are notified that the slimbus is gone and the child devices are removed. Stop taking the tx_lock in qcom_slim_ngd_ssr_pdr_notify() to avoid the deadlock.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nslimbus: qcom-ngd-ctrl: Avoid ABBA on tx_lock/ctrl->lock\n\nDuring the SSR/PDR down notification the tx_lock is taken with the\nintent to provide synchronization with active DMA transfers.\n\nBut during this period qcom_slim_ngd_down() is invoked, which ends up in\nslim_report_absent(), which takes the slim_controller lock. In multiple\nother codepaths these two locks are taken in the opposite order (i.e.\nslim_controller then tx_lock).\n\nThe result is a lockdep splat, and a possible deadlock:\n\n rprocctl/449 is trying to acquire lock:\n ffff00009793e620 (&ctrl->lock){+.+.}-{4:4}, at: slim_report_absent (drivers/slimbus/core.c:322) slimbus\n\n but task is already holding lock:\n ffff00009793fb50 (&ctrl->tx_lock){+.+.}-{4:4}, at: qcom_slim_ngd_ssr_pdr_notify (drivers/slimbus/qcom-ngd-ctrl.c:1475) slim_qcom_ngd_ctrl\n\n which lock already depends on the new lock.\n\n Possible unsafe locking scenario:\n\n CPU0 CPU1\n ---- ----\n lock(&ctrl->tx_lock);\n lock(&ctrl->lock);\n lock(&ctrl->tx_lock);\n lock(&ctrl->lock);\n\nThe assumption is that the comment refers to the desire to not call\nqcom_slim_ngd_exit_dma() while we have an ongoing DMA TX transaction.\nBut any such transaction is initiated and completed within a single\nqcom_slim_ngd_xfer_msg().\n\nPrior to calling qcom_slim_ngd_exit_dma() the slim_controller is torn\ndown, all child devices are notified that the slimbus is gone and the\nchild devices are removed.\n\nStop taking the tx_lock in qcom_slim_ngd_ssr_pdr_notify() to avoid the\ndeadlock.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02411 |
altlinux: CVE-2026-53331 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53331 was patched at 2026-07-14
1662.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53332) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: slimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd When the remoteproc starts in parallel with the NGD driver being probed, or the remoteproc is already up when the PDR lookup is being registered, or in the theoretical event that we get an interrupt from the hardware, these callbacks will operate on uninitialized data. This result in issues to boot the affected boards. One such example can be seen in the following fault, where qcom_slim_ngd_ssr_pdr_notify() schedules work on the NULL ngd_up_work. [ 21.858578] ------------[ cut here ]------------ [ 21.858745] WARNING: kernel/workqueue.c:2338 at __queue_work+0x5e0/0x790, CPU#2: kworker/2:2/116 ... [ 21.859251] Call trace: [ 21.859255] __queue_work+0x5e0/0x790 (P) [ 21.859265] queue_work_on+0x6c/0xf0 [ 21.859273] qcom_slim_ngd_ssr_pdr_notify+0x110/0x150 [slim_qcom_ngd_ctrl] [ 21.859304] qcom_slim_ngd_ssr_notify+0x24/0x40 [slim_qcom_ngd_ctrl] [ 21.859318] notifier_call_chain+0xa4/0x230 [ 21.859329] srcu_notifier_call_chain+0x64/0xb8 [ 21.859338] ssr_notify_start+0x40/0x78 [qcom_common] [ 21.859355] rproc_start+0x130/0x230 [ 21.859367] rproc_boot+0x3d4/0x518 ... Move the enablement of interrupts, and the registration of SSR and PDR until after the NGD device has been registered. This could be further refined by moving initialization to the control driver probe and by removing the platform driver model from the picture.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nslimbus: qcom-ngd-ctrl: Register callbacks after creating the ngd\n\nWhen the remoteproc starts in parallel with the NGD driver being probed,\nor the remoteproc is already up when the PDR lookup is being registered,\nor in the theoretical event that we get an interrupt from the hardware,\nthese callbacks will operate on uninitialized data. This result in\nissues to boot the affected boards.\n\nOne such example can be seen in the following fault, where\nqcom_slim_ngd_ssr_pdr_notify() schedules work on the NULL ngd_up_work.\n\n[ 21.858578] ------------[ cut here ]------------\n[ 21.858745] WARNING: kernel/workqueue.c:2338 at __queue_work+0x5e0/0x790, CPU#2: kworker/2:2/116\n...\n[ 21.859251] Call trace:\n[ 21.859255] __queue_work+0x5e0/0x790 (P)\n[ 21.859265] queue_work_on+0x6c/0xf0\n[ 21.859273] qcom_slim_ngd_ssr_pdr_notify+0x110/0x150 [slim_qcom_ngd_ctrl]\n[ 21.859304] qcom_slim_ngd_ssr_notify+0x24/0x40 [slim_qcom_ngd_ctrl]\n[ 21.859318] notifier_call_chain+0xa4/0x230\n[ 21.859329] srcu_notifier_call_chain+0x64/0xb8\n[ 21.859338] ssr_notify_start+0x40/0x78 [qcom_common]\n[ 21.859355] rproc_start+0x130/0x230\n[ 21.859367] rproc_boot+0x3d4/0x518\n...\n\nMove the enablement of interrupts, and the registration of SSR and PDR\nuntil after the NGD device has been registered.\n\nThis could be further refined by moving initialization to the control\ndriver probe and by removing the platform driver model from the picture.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.0241 |
altlinux: CVE-2026-53332 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53332 was patched at 2026-07-14
1663.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53333) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/mincore: handle non-swap entries before !CONFIG_SWAP guard mincore_swap() also fields migration/hwpoison entries (and shmem swapin-error entries), which can exist on !CONFIG_SWAP builds when CONFIG_MIGRATION or CONFIG_MEMORY_FAILURE is enabled. The !IS_ENABLED(CONFIG_SWAP) guard ran before the non-swap-entry early return, so mincore_pte_range() can spuriously WARN and report these pages nonresident on !CONFIG_SWAP kernels. Move the guard below the non-swap-entry check so only true swap entries trip the WARN, and migration/hwpoison entries take the existing "uptodate / non-shmem" path.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/mincore: handle non-swap entries before !CONFIG_SWAP guard\n\nmincore_swap() also fields migration/hwpoison entries (and shmem\nswapin-error entries), which can exist on !CONFIG_SWAP builds when\nCONFIG_MIGRATION or CONFIG_MEMORY_FAILURE is enabled. The\n!IS_ENABLED(CONFIG_SWAP) guard ran before the non-swap-entry early return,\nso mincore_pte_range() can spuriously WARN and report these pages\nnonresident on !CONFIG_SWAP kernels.\n\nMove the guard below the non-swap-entry check so only true swap entries\ntrip the WARN, and migration/hwpoison entries take the existing "uptodate\n/ non-shmem" path.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01611 |
altlinux: CVE-2026-53333 was patched at 2026-06-19, 2026-06-22, 2026-07-06
1664.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53336) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nvmem: layouts: onie-tlv: fix hang on unknown types The EEPROM on my board has a vendor specific entry of type 0x41. When stumbling upon that, this driver hangs in an endless loop. Fix it by keep incrementing the offset on unknown entries, so the loop will eventually stop.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnvmem: layouts: onie-tlv: fix hang on unknown types\n\nThe EEPROM on my board has a vendor specific entry of type 0x41. When\nstumbling upon that, this driver hangs in an endless loop.\n\nFix it by keep incrementing the offset on unknown entries, so the loop\nwill eventually stop.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.01709 |
altlinux: CVE-2026-53336 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53336 was patched at 2026-07-14
1665.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53340) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: i2c: imx: fix clock and pinctrl state inconsistency in runtime PM In i2c_imx_runtime_suspend(), the clock is disabled before switching the pinctrl state to sleep. If pinctrl_pm_select_sleep_state() fails, the runtime suspend is aborted but the clock remains disabled, causing a system crash when the hardware is subsequently accessed. Fix this by switching the pinctrl state before disabling the clock so that a pinctrl failure leaves the clock enabled and the hardware accessible. In i2c_imx_runtime_resume(), restore the pinctrl state back to sleep if clk_enable() fails to keep the consistent.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: imx: fix clock and pinctrl state inconsistency in runtime PM\n\nIn i2c_imx_runtime_suspend(), the clock is disabled before switching\nthe pinctrl state to sleep. If pinctrl_pm_select_sleep_state() fails,\nthe runtime suspend is aborted but the clock remains disabled, causing\na system crash when the hardware is subsequently accessed.\n\nFix this by switching the pinctrl state before disabling the clock so\nthat a pinctrl failure leaves the clock enabled and the hardware\naccessible.\n\nIn i2c_imx_runtime_resume(), restore the pinctrl state back to sleep\nif clk_enable() fails to keep the consistent.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01627 |
altlinux: CVE-2026-53340 was patched at 2026-06-19, 2026-06-22, 2026-07-06
1666.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53342) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: arm64: mm: call pagetable dtor when freeing hot-removed page tables Since 5e8eb9aeeda3 ("arm64: mm: always call PTE/PMD ctor in __create_pgd_mapping()") page-table allocation on ARM64 always calls pagetable_{pte,pmd,pud,p4d}_ctor(). This sets the page_type to PGTY_table, increments NR_PAGETABLE and possible allocates a PTL. However the matching pagetable_dtor() calls were never added. With DEBUG_VM enabled on kernel versions prior to v6.17 without 2dfcd1608f3a9 ("mm/page_alloc: let page freeing clear any set page type") this leads to the following warning when freeing these pages due to page->page_type sharing page->_mapcount: BUG: Bad page state in process ... pfn:284fbb page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x284fbb flags: 0x17fffc000000000(node=0|zone=2|lastcpupid=0x1ffff) page_type: f2(table) page dumped because: nonzero mapcount Call trace: bad_page+0x13c/0x160 __free_frozen_pages+0x6cc/0x860 ___free_pages+0xf4/0x180 free_pages+0x54/0x80 free_hotplug_page_range.part.0+0x58/0x90 free_empty_tables+0x438/0x500 __remove_pgd_mapping.constprop.0+0x60/0xa8 arch_remove_memory+0x48/0x80 try_remove_memory+0x158/0x1d8 offline_and_remove_memory+0x138/0x180 It can also lead to leaking the ptl allocation if ALLOC_SPLIT_PTLOCKS is defined and incorrect NR_PAGETABLE stats. Fix this by calling pagetable_dtor() in free_hotplug_pgtable_page() prior to freeing the page to undo the effects of calling pagetable_*_ctor().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\narm64: mm: call pagetable dtor when freeing hot-removed page tables\n\nSince 5e8eb9aeeda3 ("arm64: mm: always call PTE/PMD ctor in\n__create_pgd_mapping()") page-table allocation on ARM64 always calls\npagetable_{pte,pmd,pud,p4d}_ctor(). This sets the page_type to\nPGTY_table, increments NR_PAGETABLE and possible allocates a PTL. However\nthe matching pagetable_dtor() calls were never added.\n\nWith DEBUG_VM enabled on kernel versions prior to v6.17 without\n2dfcd1608f3a9 ("mm/page_alloc: let page freeing clear any set page type")\nthis leads to the following warning when freeing these pages due to\npage->page_type sharing page->_mapcount:\n\n BUG: Bad page state in process ... pfn:284fbb\n page: refcount:0 mapcount:0 mapping:0000000000000000 index:0x0 pfn:0x284fbb\n flags: 0x17fffc000000000(node=0|zone=2|lastcpupid=0x1ffff)\n page_type: f2(table)\n page dumped because: nonzero mapcount\n Call trace:\n bad_page+0x13c/0x160\n __free_frozen_pages+0x6cc/0x860\n ___free_pages+0xf4/0x180\n free_pages+0x54/0x80\n free_hotplug_page_range.part.0+0x58/0x90\n free_empty_tables+0x438/0x500\n __remove_pgd_mapping.constprop.0+0x60/0xa8\n arch_remove_memory+0x48/0x80\n try_remove_memory+0x158/0x1d8\n offline_and_remove_memory+0x138/0x180\n\nIt can also lead to leaking the ptl allocation if ALLOC_SPLIT_PTLOCKS is\ndefined and incorrect NR_PAGETABLE stats. Fix this by calling\npagetable_dtor() in free_hotplug_pgtable_page() prior to freeing the page\nto undo the effects of calling pagetable_*_ctor().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01612 |
altlinux: CVE-2026-53342 was patched at 2026-06-19, 2026-06-22, 2026-07-06
1667.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53343) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow Commit 44e9a3bb76e5 ("ARM: 9430/1: entry: Do a dummy read from VMAP shadow") added a dummy read from the KASAN VMAP stack shadow in __switch_to(). The read uses ldr, but the KASAN shadow address is byte-granular and is not guaranteed to be word aligned. ARMv5 faults unaligned word loads. With CONFIG_KASAN_VMALLOC and CONFIG_VMAP_STACK enabled, ARM926/VersatilePB crashes in __switch_to() with an alignment exception before reaching init. Use ldrb for the dummy shadow access. The code only needs to fault in the shadow mapping if the stack shadow is missing, so a byte load is sufficient and matches the granularity of KASAN shadow memory.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nARM: 9475/1: entry: use byte load for KASAN VMAP stack shadow\n\nCommit 44e9a3bb76e5 ("ARM: 9430/1: entry: Do a dummy read from\nVMAP shadow") added a dummy read from the KASAN VMAP stack shadow in\n__switch_to(). The read uses ldr, but the KASAN shadow address is\nbyte-granular and is not guaranteed to be word aligned.\n\nARMv5 faults unaligned word loads. With CONFIG_KASAN_VMALLOC and\nCONFIG_VMAP_STACK enabled, ARM926/VersatilePB crashes in __switch_to()\nwith an alignment exception before reaching init.\n\nUse ldrb for the dummy shadow access. The code only needs to fault in the\nshadow mapping if the stack shadow is missing, so a byte load is sufficient\nand matches the granularity of KASAN shadow memory.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.0173 |
altlinux: CVE-2026-53343 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53343 was patched at 2026-07-14
1668.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53347) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/virtio: Fix driver removal with disabled KMS DRM atomic and modesetting aren't initialized if virtio-gpu driver built with disabled KMS, leading to access of uninitialized data on driver removal/unbinding and crashing kernel. Fix it by skipping shutting down atomic core with unavailable KMS.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/virtio: Fix driver removal with disabled KMS\n\nDRM atomic and modesetting aren't initialized if virtio-gpu driver built\nwith disabled KMS, leading to access of uninitialized data on driver\nremoval/unbinding and crashing kernel. Fix it by skipping shutting down\natomic core with unavailable KMS.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.01707 |
altlinux: CVE-2026-53347 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53347 was patched at 2026-07-14
1669.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53349) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack: destroy stale expectfn expectations on unregister NAT helpers such as nf_nat_h323 store a raw pointer to module text in exp->expectfn (e.g. ip_nat_q931_expect). nf_ct_helper_expectfn_unregister() only unlinks the callback descriptor and never walks the expectation table, so an expectation pending at module removal survives with a dangling exp->expectfn into freed module text. When the expected connection arrives, init_conntrack() invokes exp->expectfn(), now a stale pointer into the unloaded module. Reproduced on a KASAN build by loading the H.323 helpers, creating a Q.931 expectation, unloading nf_nat_h323, then connecting to the expected port: Oops: int3: 0000 [#1] SMP KASAN NOPTI RIP: 0010:0xffffffffa06102d1 init_conntrack.isra.0 (net/netfilter/nf_conntrack_core.c:1862) nf_conntrack_in (net/netfilter/nf_conntrack_core.c:2049) ipv4_conntrack_local (net/netfilter/nf_conntrack_proto.c:223) nf_hook_slow (net/netfilter/core.c:619) __ip_local_out (net/ipv4/ip_output.c:120) __tcp_transmit_skb (net/ipv4/tcp_output.c:1715) tcp_connect (net/ipv4/tcp_output.c:4374) tcp_v4_connect (net/ipv4/tcp_ipv4.c:345) __sys_connect (net/socket.c:2167) Modules linked in: nf_conntrack_h323 [last unloaded: nf_nat_h323] Reaching the dangling state requires CAP_SYS_MODULE in the initial user namespace to remove a NAT helper that still has live expectations, so this is a robustness fix; leaving an expectation pointing at freed text is wrong regardless. Add nf_ct_helper_expectfn_destroy(), which walks the expectation table and drops every expectation whose ->expectfn matches the descriptor being torn down. Call it from each NAT helper's exit path after the existing RCU grace period, so no expectation outlives the code it points at and no extra synchronize_rcu() is introduced. With the fix, the same reproducer runs to completion without the Oops.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_conntrack: destroy stale expectfn expectations on unregister\n\nNAT helpers such as nf_nat_h323 store a raw pointer to module text in\nexp->expectfn (e.g. ip_nat_q931_expect). nf_ct_helper_expectfn_unregister()\nonly unlinks the callback descriptor and never walks the expectation table,\nso an expectation pending at module removal survives with a dangling\nexp->expectfn into freed module text.\n\nWhen the expected connection arrives, init_conntrack() invokes\nexp->expectfn(), now a stale pointer into the unloaded module. Reproduced\non a KASAN build by loading the H.323 helpers, creating a Q.931\nexpectation, unloading nf_nat_h323, then connecting to the expected port:\n\n Oops: int3: 0000 [#1] SMP KASAN NOPTI\n RIP: 0010:0xffffffffa06102d1\n init_conntrack.isra.0 (net/netfilter/nf_conntrack_core.c:1862)\n nf_conntrack_in (net/netfilter/nf_conntrack_core.c:2049)\n ipv4_conntrack_local (net/netfilter/nf_conntrack_proto.c:223)\n nf_hook_slow (net/netfilter/core.c:619)\n __ip_local_out (net/ipv4/ip_output.c:120)\n __tcp_transmit_skb (net/ipv4/tcp_output.c:1715)\n tcp_connect (net/ipv4/tcp_output.c:4374)\n tcp_v4_connect (net/ipv4/tcp_ipv4.c:345)\n __sys_connect (net/socket.c:2167)\n Modules linked in: nf_conntrack_h323 [last unloaded: nf_nat_h323]\n\nReaching the dangling state requires CAP_SYS_MODULE in the initial user\nnamespace to remove a NAT helper that still has live expectations, so this\nis a robustness fix; leaving an expectation pointing at freed text is wrong\nregardless.\n\nAdd nf_ct_helper_expectfn_destroy(), which walks the expectation table and\ndrops every expectation whose ->expectfn matches the descriptor being torn\ndown. Call it from each NAT helper's exit path after the existing RCU grace\nperiod, so no expectation outlives the code it points at and no extra\nsynchronize_rcu() is introduced. With the fix, the same reproducer runs to\ncompletion without the Oops.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.0175 |
altlinux: CVE-2026-53349 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-53349 was patched at 2026-07-14
1670.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53351) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: riscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_CFI Fixes a warning while dumping core: [54983.546369][ C7] WARNING: [!note_name] fs/binfmt_elf.c:1771 at elf_core_dump+0x910/0xf68, CPU#7: abort01/31982', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nriscv/ptrace: Use USER_REGSET_NOTE_TYPE for REGSET_CFI\n\nFixes a warning while dumping core:\n\n[54983.546369][ C7] WARNING: [!note_name] fs/binfmt_elf.c:1771 at elf_core_dump+0x910/0xf68, CPU#7: abort01/31982', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.001, EPSS Percentile is 0.01008 |
altlinux: CVE-2026-53351 was patched at 2026-06-19
1671.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53353) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hsr: Remove WARN_ONCE() in hsr_addr_is_self(). syzbot reported the warning [0] in hsr_addr_is_self(), whose assumption is simply wrong. hsr->self_node is cleared in hsr_del_self_node(), which is called from hsr_dellink(). Since dev->rtnl_link_ops->dellink() is called before unregister_netdevice_many(), there is a window when user can find the device but without hsr->self_node. Let's remove WARN_ONCE() in hsr_addr_is_self(). [0]: HSR: No self node WARNING: net/hsr/hsr_framereg.c:39 at hsr_addr_is_self+0x211/0x3f0 net/hsr/hsr_framereg.c:39, CPU#0: syz.4.16848/17220 Modules linked in: CPU: 0 UID: 0 PID: 17220 Comm: syz.4.16848 Tainted: G L syzkaller #0 PREEMPT_{RT,(full)} Tainted: [L]=SOFTLOCKUP Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026 RIP: 0010:hsr_addr_is_self+0x211/0x3f0 net/hsr/hsr_framereg.c:39 Code: 33 2f 41 0f b7 dd 89 ee 09 de 31 ff e8 c8 b4 c6 f6 09 dd 74 54 e8 0f b0 c6 f6 31 ed eb 53 e8 06 b0 c6 f6 48 8d 3d 2f 50 9c 04 <67> 48 0f b9 3a 31 ed eb 42 e8 c1 13 1f 00 89 c5 31 ff 89 c6 e8 96 RSP: 0018:ffffc900041c70e0 EFLAGS: 00010283 RAX: ffffffff8afdc6ca RBX: ffffffff8afdc4e6 RCX: 0000000000080000 RDX: ffffc90010493000 RSI: 0000000000000948 RDI: ffffffff8f9a1700 RBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000 R10: ffffc900041c71e8 R11: fffff52000838e3f R12: dffffc0000000000 R13: ffff888041f9e3c0 R14: ffff888086ee3802 R15: 0000000000000000 FS: 00007f6fe985d6c0(0000) GS:ffff888126176000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007f80bd437dac CR3: 0000000025096000 CR4: 00000000003526f0 DR0: ffffffffffffffff DR1: 00000000000001f8 DR2: 0000000000000002 DR3: ffffffffefffff15 DR6: 00000000ffff0ff0 DR7: 0000000000000400 Call Trace: <TASK> check_local_dest net/hsr/hsr_forward.c:592 [inline] fill_frame_info net/hsr/hsr_forward.c:728 [inline] hsr_forward_skb+0xa11/0x2a80 net/hsr/hsr_forward.c:739 hsr_dev_xmit+0x253/0x370 net/hsr/hsr_device.c:236 __netdev_start_xmit include/linux/netdevice.h:5368 [inline] netdev_start_xmit include/linux/netdevice.h:5377 [inline] xmit_one net/core/dev.c:3888 [inline] dev_hard_start_xmit+0x2df/0x860 net/core/dev.c:3904 __dev_queue_xmit+0x1428/0x3900 net/core/dev.c:4870 neigh_output include/net/neighbour.h:556 [inline] ip_finish_output2+0xcec/0x10b0 net/ipv4/ip_output.c:237 ip_send_skb net/ipv4/ip_output.c:1510 [inline] ip_push_pending_frames+0x8b/0x110 net/ipv4/ip_output.c:1530 raw_sendmsg+0x1547/0x1a50 net/ipv4/raw.c:659 sock_sendmsg_nosec net/socket.c:787 [inline] __sock_sendmsg net/socket.c:802 [inline] ____sys_sendmsg+0x7da/0x9c0 net/socket.c:2698 ___sys_sendmsg+0x2a5/0x360 net/socket.c:2752 __sys_sendmsg net/socket.c:2784 [inline] __do_sys_sendmsg net/socket.c:2789 [inline] __se_sys_sendmsg net/socket.c:2787 [inline] __x64_sys_sendmsg+0x1c3/0x2a0 net/socket.c:2787 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0x15f/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f RIP: 0033:0x7f6feb62ce59 Code: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48 RSP: 002b:00007f6fe985d028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e RAX: ffffffffffffffda RBX: 00007f6feb8a6090 RCX: 00007f6feb62ce59 RDX: 0000000000000000 RSI: 0000200000000000 RDI: 0000000000000004 RBP: 00007f6feb6c2d6f R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000 R13: 00007f6feb8a6128 R14: 00007f6feb8a6090 R15: 00007ffcf01cc488 </TASK>', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhsr: Remove WARN_ONCE() in hsr_addr_is_self().\n\nsyzbot reported the warning [0] in hsr_addr_is_self(),\nwhose assumption is simply wrong.\n\nhsr->self_node is cleared in hsr_del_self_node(), which\nis called from hsr_dellink().\n\nSince dev->rtnl_link_ops->dellink() is called before\nunregister_netdevice_many(), there is a window when\nuser can find the device but without hsr->self_node.\n\nLet's remove WARN_ONCE() in hsr_addr_is_self().\n\n[0]:\nHSR: No self node\nWARNING: net/hsr/hsr_framereg.c:39 at hsr_addr_is_self+0x211/0x3f0 net/hsr/hsr_framereg.c:39, CPU#0: syz.4.16848/17220\nModules linked in:\nCPU: 0 UID: 0 PID: 17220 Comm: syz.4.16848 Tainted: G L syzkaller #0 PREEMPT_{RT,(full)}\nTainted: [L]=SOFTLOCKUP\nHardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 04/18/2026\nRIP: 0010:hsr_addr_is_self+0x211/0x3f0 net/hsr/hsr_framereg.c:39\nCode: 33 2f 41 0f b7 dd 89 ee 09 de 31 ff e8 c8 b4 c6 f6 09 dd 74 54 e8 0f b0 c6 f6 31 ed eb 53 e8 06 b0 c6 f6 48 8d 3d 2f 50 9c 04 <67> 48 0f b9 3a 31 ed eb 42 e8 c1 13 1f 00 89 c5 31 ff 89 c6 e8 96\nRSP: 0018:ffffc900041c70e0 EFLAGS: 00010283\nRAX: ffffffff8afdc6ca RBX: ffffffff8afdc4e6 RCX: 0000000000080000\nRDX: ffffc90010493000 RSI: 0000000000000948 RDI: ffffffff8f9a1700\nRBP: 0000000000000001 R08: 0000000000000000 R09: 0000000000000000\nR10: ffffc900041c71e8 R11: fffff52000838e3f R12: dffffc0000000000\nR13: ffff888041f9e3c0 R14: ffff888086ee3802 R15: 0000000000000000\nFS: 00007f6fe985d6c0(0000) GS:ffff888126176000(0000) knlGS:0000000000000000\nCS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\nCR2: 00007f80bd437dac CR3: 0000000025096000 CR4: 00000000003526f0\nDR0: ffffffffffffffff DR1: 00000000000001f8 DR2: 0000000000000002\nDR3: ffffffffefffff15 DR6: 00000000ffff0ff0 DR7: 0000000000000400\nCall Trace:\n <TASK>\n check_local_dest net/hsr/hsr_forward.c:592 [inline]\n fill_frame_info net/hsr/hsr_forward.c:728 [inline]\n hsr_forward_skb+0xa11/0x2a80 net/hsr/hsr_forward.c:739\n hsr_dev_xmit+0x253/0x370 net/hsr/hsr_device.c:236\n __netdev_start_xmit include/linux/netdevice.h:5368 [inline]\n netdev_start_xmit include/linux/netdevice.h:5377 [inline]\n xmit_one net/core/dev.c:3888 [inline]\n dev_hard_start_xmit+0x2df/0x860 net/core/dev.c:3904\n __dev_queue_xmit+0x1428/0x3900 net/core/dev.c:4870\n neigh_output include/net/neighbour.h:556 [inline]\n ip_finish_output2+0xcec/0x10b0 net/ipv4/ip_output.c:237\n ip_send_skb net/ipv4/ip_output.c:1510 [inline]\n ip_push_pending_frames+0x8b/0x110 net/ipv4/ip_output.c:1530\n raw_sendmsg+0x1547/0x1a50 net/ipv4/raw.c:659\n sock_sendmsg_nosec net/socket.c:787 [inline]\n __sock_sendmsg net/socket.c:802 [inline]\n ____sys_sendmsg+0x7da/0x9c0 net/socket.c:2698\n ___sys_sendmsg+0x2a5/0x360 net/socket.c:2752\n __sys_sendmsg net/socket.c:2784 [inline]\n __do_sys_sendmsg net/socket.c:2789 [inline]\n __se_sys_sendmsg net/socket.c:2787 [inline]\n __x64_sys_sendmsg+0x1c3/0x2a0 net/socket.c:2787\n do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline]\n do_syscall_64+0x15f/0xf80 arch/x86/entry/syscall_64.c:94\n entry_SYSCALL_64_after_hwframe+0x77/0x7f\nRIP: 0033:0x7f6feb62ce59\nCode: ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 48 89 f8 48 89 f7 48 89 d6 48 89 ca 4d 89 c2 4d 89 c8 4c 8b 4c 24 08 0f 05 <48> 3d 01 f0 ff ff 73 01 c3 48 c7 c1 e8 ff ff ff f7 d8 64 89 01 48\nRSP: 002b:00007f6fe985d028 EFLAGS: 00000246 ORIG_RAX: 000000000000002e\nRAX: ffffffffffffffda RBX: 00007f6feb8a6090 RCX: 00007f6feb62ce59\nRDX: 0000000000000000 RSI: 0000200000000000 RDI: 0000000000000004\nRBP: 00007f6feb6c2d6f R08: 0000000000000000 R09: 0000000000000000\nR10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000\nR13: 00007f6feb8a6128 R14: 00007f6feb8a6090 R15: 00007ffcf01cc488\n </TASK>', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.01696 |
altlinux: CVE-2026-53353 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
debian: CVE-2026-53353 was patched at 2026-07-14
1672.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53376) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: Add upper bound check for num_of_nodes drm/amdkfd: Add upper bound check for num_of_nodes in kfd_ioctl_get_process_apertures_new. (cherry picked from commit 98ff46a5ea090c14d2cdb4f5b993b05d74f3949f)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/amdkfd: Add upper bound check for num_of_nodes\n\ndrm/amdkfd: Add upper bound check for num_of_nodes\nin kfd_ioctl_get_process_apertures_new.\n\n(cherry picked from commit 98ff46a5ea090c14d2cdb4f5b993b05d74f3949f)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02585 |
debian: CVE-2026-53376 was patched at 2026-07-14
ubuntu: CVE-2026-53376 was patched at 2026-07-30
1673.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53377) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/msm: always recover the gpu Previously, in case there was no more work to do, recover worker wouldn't trigger recovery and would instead rely on the gpu going to sleep and then resuming when more work is submitted. Recover_worker will first increment the fence of the hung ring so, if there's only one job submitted to a ring and that causes an hang, it will early out. There's no guarantee that the gpu will suspend and resume before more work is submitted and if the gpu is in a hung state it will stay in that state and probably trigger a timeout again. Just stop checking and always recover the gpu. Patchwork: https://patchwork.freedesktop.org/patch/704066/', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm: always recover the gpu\n\nPreviously, in case there was no more work to do, recover worker\nwouldn't trigger recovery and would instead rely on the gpu going to\nsleep and then resuming when more work is submitted.\n\nRecover_worker will first increment the fence of the hung ring so, if\nthere's only one job submitted to a ring and that causes an hang, it\nwill early out.\n\nThere's no guarantee that the gpu will suspend and resume before more\nwork is submitted and if the gpu is in a hung state it will stay in that\nstate and probably trigger a timeout again.\n\nJust stop checking and always recover the gpu.\n\nPatchwork: https://patchwork.freedesktop.org/patch/704066/', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00123, EPSS Percentile is 0.02493 |
debian: CVE-2026-53377 was patched at 2026-07-14
ubuntu: CVE-2026-53377 was patched at 2026-07-30
1674.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53379) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: media: i2c: ov8856: free control handler on error in ov8856_init_controls() The control handler wasn't freed if adding controls failed, add an error exit label and convert the existing error return to use it.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmedia: i2c: ov8856: free control handler on error in ov8856_init_controls()\n\nThe control handler wasn't freed if adding controls failed, add an error\nexit label and convert the existing error return to use it.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02198 |
debian: CVE-2026-53379 was patched at 2026-07-14
ubuntu: CVE-2026-53379 was patched at 2026-07-30
1675.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-53393) - Medium [221]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: nfsd: reset write verifier on deferred writeback errors nfsd_vfs_write() and nfsd_commit() both call filemap_check_wb_err() to detect deferred writeback errors, but neither rotates the server's write verifier (nn->writeverf) when this check fails. Every other durable-storage-failure path in these functions calls commit_reset_write_verifier() before returning an error. The missing rotation means clients holding UNSTABLE write data under the current verifier will COMMIT, receive the unchanged verifier back, and conclude their data is durable — silently dropping data that failed writeback. This violates the UNSTABLE+COMMIT durability contract (RFC 1813 §3.3.7, RFC 8881 §18.32). Add commit_reset_write_verifier() calls at both filemap_check_wb_err() error sites, matching the pattern used by adjacent error paths in the same functions. The helper already filters -EAGAIN and -ESTALE internally, so the calls are unconditionally safe.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnfsd: reset write verifier on deferred writeback errors\n\nnfsd_vfs_write() and nfsd_commit() both call filemap_check_wb_err() to\ndetect deferred writeback errors, but neither rotates the server's write\nverifier (nn->writeverf) when this check fails. Every other\ndurable-storage-failure path in these functions calls\ncommit_reset_write_verifier() before returning an error.\n\nThe missing rotation means clients holding UNSTABLE write data under the\ncurrent verifier will COMMIT, receive the unchanged verifier back, and\nconclude their data is durable — silently dropping data that failed\nwriteback. This violates the UNSTABLE+COMMIT durability contract\n(RFC 1813 §3.3.7, RFC 8881 §18.32).\n\nAdd commit_reset_write_verifier() calls at both filemap_check_wb_err()\nerror sites, matching the pattern used by adjacent error paths in the\nsame functions. The helper already filters -EAGAIN and -ESTALE\ninternally, so the calls are unconditionally safe.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.0336 |
debian: CVE-2026-53393 was patched at 2026-07-14
1676.
Denial of Service - Unknown Product (CVE-2026-48125) - Medium [220]
Description: {'nvd_cve_data_all': 'UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service vulnerability exists when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to an application that calls UAParser(headers).withClientHints(), an attacker can cause excessive CPU time due to catastrophic backtracking in the device regex because Client Hints values are copied without the UA_MAX_LENGTH limit used for User-Agent values. This issue is fixed in version 2.0.10.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service vulnerability exists when using the Client Hints API. By sending a crafted Sec-CH-UA-Model header to an application that calls UAParser(headers).withClientHints(), an attacker can cause excessive CPU time due to catastrophic backtracking in the device regex because Client Hints values are copied without the UA_MAX_LENGTH limit used for User-Agent values. This issue is fixed in version 2.0.10.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00372, EPSS Percentile is 0.29889 |
debian: CVE-2026-48125 was patched at 2026-07-14
1677.
Denial of Service - Unknown Product (CVE-2026-54464) - Medium [220]
Description: {'nvd_cve_data_all': '### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket server or client can be made to accept messages that are larger than the configured maximum message size. This is because this limit is checked against the message frames' length headers, which give the size of the compressed data, not the size after decompression. This can lead to applications accepting larger messages than expected and exceeding their intended resource usage. ### Patches The issue has been patched in version 0.8.1, by checking the length of messages after they are processed by incoming extensions. All users should upgrade to this version. ### Workarounds No known workarounds exist. ### Acknowledgements This issue was discovered and reported by Pranjali Thakur, DepthFirst Security Research Team.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': '### Impact\n\nIf this library is used in tandem with the `permessage-deflate` extension, a\nWebSocket server or client can be made to accept messages that are larger than\nthe configured maximum message size. This is because this limit is checked\nagainst the message frames' length headers, which give the size of the\ncompressed data, not the size after decompression. This can lead to applications\naccepting larger messages than expected and exceeding their intended resource\nusage.\n\n### Patches\n\nThe issue has been patched in version 0.8.1, by checking the length of messages\nafter they are processed by incoming extensions. All users should upgrade to\nthis version.\n\n### Workarounds\n\nNo known workarounds exist.\n\n### Acknowledgements\n\nThis issue was discovered and reported by Pranjali Thakur, DepthFirst Security\nResearch Team.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00324, EPSS Percentile is 0.24913 |
debian: CVE-2026-54464 was patched at 2026-07-14
1678.
Denial of Service - Unknown Product (CVE-2026-54465) - Medium [220]
Description: {'nvd_cve_data_all': 'websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a TCP server using WebSocket::Driver.server() or to complement a WebSocket client, a peer can make a single connection consume an unbounded amount of memory by sending an HTTP request or response with a never-ending list of headers. This can lead to the receiving process running out of memory. This issue is fixed in version 0.8.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a TCP server using WebSocket::Driver.server() or to complement a WebSocket client, a peer can make a single connection consume an unbounded amount of memory by sending an HTTP request or response with a never-ending list of headers. This can lead to the receiving process running out of memory. This issue is fixed in version 0.8.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00324, EPSS Percentile is 0.24913 |
debian: CVE-2026-54465 was patched at 2026-07-14
1679.
Denial of Service - Unknown Product (CVE-2026-54490) - Medium [220]
Description: {'nvd_cve_data_all': 'websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library is used with the permessage-deflate extension, a WebSocket server or client can be made to accept messages that are larger than the configured maximum message size because the limit is checked against the message frames' length headers, which give the size of the compressed data, not the size after decompression in lib/websocket/driver/hybi.js. This can lead to applications accepting larger messages than expected and exceeding their intended resource usage. This issue is fixed in version 0.7.5.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, if this library is used with the permessage-deflate extension, a WebSocket server or client can be made to accept messages that are larger than the configured maximum message size because the limit is checked against the message frames' length headers, which give the size of the compressed data, not the size after decompression in lib/websocket/driver/hybi.js. This can lead to applications accepting larger messages than expected and exceeding their intended resource usage. This issue is fixed in version 0.7.5.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.18024 |
debian: CVE-2026-54490 was patched at 2026-07-14
1680.
Denial of Service - Unknown Product (CVE-2026-54908) - Medium [220]
Description: {'nvd_cve_data_all': 'Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote Denial of Service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message. This issue has been fixed in version 3.1.4.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Pion DTLS is a Go implementation of Datagram Transport Layer Security. Versions prior to 3.1.4 are vulnerable to Remote Denial of Service via panic while parsing a crafted ECDHE_PSK ServerKeyExchange message. This issue has been fixed in version 3.1.4.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.3. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.0032, EPSS Percentile is 0.24484 |
debian: CVE-2026-54908 was patched at 2026-07-14
1681.
Incorrect Calculation - op-tee (CVE-2026-53763) - Medium [220]
Description: OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.0.0 and prior to version 4.11.0, 32-bit integer overflows in OP-TEE core's AES-GCM implementation cause the authentication tag to be computed with incorrect bit-length values after processing more than 512 megabytes of payload or Additional Authenticated Data (AAD). Version 4.11.0 contains a patch. No known workarounds are available.
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.5 | 14 | Product detected by o:trustedfirmware:op-tee (does NOT exist in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 3.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00149, EPSS Percentile is 0.04646 |
debian: CVE-2026-53763 was patched at 2026-07-14
1682.
Memory Corruption - Unknown Product (CVE-2026-46602) - Medium [220]
Description: {'nvd_cve_data_all': 'The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00335, EPSS Percentile is 0.26045 |
debian: CVE-2026-46602 was patched at 2026-07-14
1683.
Path Traversal - Unknown Product (CVE-2026-49342) - Medium [220]
Description: {'nvd_cve_data_all': 'YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as `/../yard-cache-secret.html` is joined against that root and can return a readable sibling `.html` file outside the intended static tree. Version 0.9.44 patches the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanup runs. When a server is configured with a document root, a traversal path such as `/../yard-cache-secret.html` is joined against that root and can return a readable sibling `.html` file outside the intended static tree. Version 0.9.44 patches the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00403, EPSS Percentile is 0.33083 |
debian: CVE-2026-49342 was patched at 2026-06-24
1684.
Path Traversal - Unknown Product (CVE-2026-53925) - Medium [220]
Description: {'nvd_cve_data_all': 'Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the secure_popen() function in glances/secure.py interprets > (file redirection), | (pipe), and && (command chaining) operators in command strings. These operators are applied without any validation on the target file path, piped command, or chained command. When Application Monitoring Process (AMP) modules load their command or service_cmd configuration values from glances.conf, those values are passed directly to secure_popen() with no sanitization. This allows an attacker who can modify the Glances configuration file to write arbitrary content to arbitrary filesystem paths (via >), chain arbitrary commands (via &&), or pipe command output to arbitrary programs (via |). This vulnerability is fixed in 4.5.5.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Glances is an open-source system cross-platform monitoring tool. From 4.0.8 until 4.5.5, the secure_popen() function in glances/secure.py interprets > (file redirection), | (pipe), and && (command chaining) operators in command strings. These operators are applied without any validation on the target file path, piped command, or chained command. When Application Monitoring Process (AMP) modules load their command or service_cmd configuration values from glances.conf, those values are passed directly to secure_popen() with no sanitization. This allows an attacker who can modify the Glances configuration file to write arbitrary content to arbitrary filesystem paths (via >), chain arbitrary commands (via &&), or pipe command output to arbitrary programs (via |). This vulnerability is fixed in 4.5.5.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Path Traversal | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00137, EPSS Percentile is 0.03573 |
debian: CVE-2026-53925 was patched at 2026-07-14
1685.
Security Feature Bypass - Unknown Product (CVE-2026-47085) - Medium [220]
Description: {'nvd_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge a working URLAUTH token by computing an HMAC-SHA1 value with a predictable key, giving them read access to the mailbox. (URLAUTH is an obscure feature, meaning that the odds of any user actually being susceptible to this attack are very low. Perhaps no public clients use URLAUTH.)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH token forgery can occur via a missing mboxkey. If an attacker knew a folder name on the victim's account for which the victim had never issued an auth URL, they could forge a working URLAUTH token by computing an HMAC-SHA1 value with a predictable key, giving them read access to the mailbox. (URLAUTH is an obscure feature, meaning that the odds of any user actually being susceptible to this attack are very low. Perhaps no public clients use URLAUTH.)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00199, EPSS Percentile is 0.09983 |
debian: CVE-2026-47085 was patched at 2026-07-14
1686.
Security Feature Bypass - Unknown Product (CVE-2026-54431) - Medium [220]
Description: {'nvd_cve_data_all': 'In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key material. RFC 9449 section 4.3 step 7 requires the verifier to reject such a proof but oauth2_token_verify() function returns success for a malformed DPoP proof that embeds the private Elliptic Curve (EC) key in the header. This issue was fixed in version 2.3.0', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier accepts a proof whose JSON Web Key (jwk) header contains private key\xa0material. RFC 9449 section 4.3 step 7 requires the verifier to reject\xa0such a proof but\xa0oauth2_token_verify() function returns success for a malformed DPoP\xa0proof that embeds the private Elliptic Curve (EC) key in the header.\n\nThis issue was fixed in version 2.3.0', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.9 | 15 | Security Feature Bypass | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02822 |
debian: CVE-2026-54431 was patched at 2026-07-14
1687.
Memory Corruption - Oj (CVE-2026-54500) - Medium [219]
Description: Oj (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.35 | 14 | Oj (Optimized JSON) is a high-performance JSON parser and object serialization library packaged as a Ruby gem, designed to provide fast JSON encoding and decoding for Ruby applications. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00198, EPSS Percentile is 0.09821 |
debian: CVE-2026-54500 was patched at 2026-07-14
1688.
Unknown Vulnerability Type - Python (CVE-2026-55195) - Medium [219]
Description: {'nvd_cve_data_all': 'py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, py7zr's Worker.decompress() extracted archive entries without tracking total decompressed size, allowing a crafted .7z file such as a 15.6 KB archive that expands to 100 MB to exhaust disk or memory before extraction completes. This issue is fixed in version 1.1.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, py7zr's Worker.decompress() extracted archive entries without tracking total decompressed size, allowing a crafted .7z file such as a 15.6 KB archive that expands to 100 MB to exhaust disk or memory before extraction completes. This issue is fixed in version 1.1.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11351 |
debian: CVE-2026-55195 was patched at 2026-07-14
1689.
Unknown Vulnerability Type - Python (CVE-2026-55206) - Medium [219]
Description: {'nvd_cve_data_all': 'py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for attacker-controlled numstreams values parsed from archive headers, allowing a crafted .7z archive to cause excessive CPU consumption during SevenZipFile.init() before extraction. This issue is fixed in version 1.1.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3, PackInfo._read() in archiveinfo.py used an O(n^2) cumulative sum pattern for attacker-controlled numstreams values parsed from archive headers, allowing a crafted .7z archive to cause excessive CPU consumption during SevenZipFile.init() before extraction. This issue is fixed in version 1.1.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.9 | 10 | CVSS Base Score is 8.7. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.1135 |
debian: CVE-2026-55206 was patched at 2026-07-14
1690.
Unknown Vulnerability Type - Chromium (CVE-2026-13947) - Medium [216]
Description: {'nvd_cve_data_all': 'Uninitialized Use in XR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in XR in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00307, EPSS Percentile is 0.23085 |
altlinux: CVE-2026-13947 was patched at 2026-07-03
debian: CVE-2026-13947 was patched at 2026-07-05, 2026-07-14
1691.
Unknown Vulnerability Type - Chromium (CVE-2026-13950) - Medium [216]
Description: {'nvd_cve_data_all': 'Uninitialized Use in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00307, EPSS Percentile is 0.23085 |
altlinux: CVE-2026-13950 was patched at 2026-07-03
debian: CVE-2026-13950 was patched at 2026-07-05, 2026-07-14
1692.
Unknown Vulnerability Type - Chromium (CVE-2026-13969) - Medium [216]
Description: {'nvd_cve_data_all': 'Uninitialized Use in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in UI in Google Chrome on Android prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00287, EPSS Percentile is 0.20942 |
altlinux: CVE-2026-13969 was patched at 2026-07-03
debian: CVE-2026-13969 was patched at 2026-07-05, 2026-07-14
1693.
Unknown Vulnerability Type - Chromium (CVE-2026-13970) - Medium [216]
Description: {'nvd_cve_data_all': 'Uninitialized Use in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in Media in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00287, EPSS Percentile is 0.20942 |
altlinux: CVE-2026-13970 was patched at 2026-07-03
debian: CVE-2026-13970 was patched at 2026-07-05, 2026-07-14
1694.
Unknown Vulnerability Type - Chromium (CVE-2026-13971) - Medium [216]
Description: {'nvd_cve_data_all': 'Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00287, EPSS Percentile is 0.20942 |
altlinux: CVE-2026-13971 was patched at 2026-07-03
debian: CVE-2026-13971 was patched at 2026-07-05, 2026-07-14
1695.
Unknown Vulnerability Type - Keycloak (CVE-2026-11986) - Medium [216]
Description: {'nvd_cve_data_all': 'A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to perform granular permission checks when deleting role mappings. This allows a delegated administrator with limited permissions to remove highly privileged roles from other users or groups, potentially disrupting administrative access control.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Keycloak is an open‑source identity and access management (IAM) solution that provides single sign‑on (SSO), user federation, identity brokering, and access control for applications and services. | |
| 0.5 | 10 | CVSS Base Score is 4.9. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00251, EPSS Percentile is 0.1663 |
altlinux: CVE-2026-11986 was patched at 2026-07-11, 2026-07-13, 2026-07-14, 2026-07-16
1696.
Unknown Vulnerability Type - Node.js (CVE-2026-59875) - Medium [216]
Description: {'nvd_cve_data_all': 'node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'node-tar is a tar archive manipulation library for Node.js. Prior to 7.5.17, node-tar does not strip NUL bytes from PAX path and linkpath records in src/pax.ts, allowing a crafted archive with values to reach fs.lstat or fs.open and terminate the process with an uncaught exception. This issue is fixed in version 7.5.17.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Node.js is a cross-platform, open-source server environment that can run on Windows, Linux, Unix, macOS, and more | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00292, EPSS Percentile is 0.21437 |
debian: CVE-2026-59875 was patched at 2026-07-14
1697.
Unknown Vulnerability Type - OpenSSH (CVE-2026-59995) - Medium [216]
Description: {'nvd_cve_data_all': 'sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'sftp in OpenSSH before 10.4 does not properly constrain the location of downloaded files when "sftp server:/path ." is used with an attacker-controlled server.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0025, EPSS Percentile is 0.16516 |
debian: CVE-2026-59995 was patched at 2026-07-14
ubuntu: CVE-2026-59995 was patched at 2026-07-30
1698.
Unknown Vulnerability Type - OpenSSH (CVE-2026-59996) - Medium [216]
Description: {'nvd_cve_data_all': 'scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'scp in OpenSSH before 10.4 may place a file in the parent directory of an intended directory when the copy occurs between two remote destinations.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0025, EPSS Percentile is 0.16516 |
almalinux: CVE-2026-59996 was patched at 2026-07-29
debian: CVE-2026-59996 was patched at 2026-07-14
oraclelinux: CVE-2026-59996 was patched at 2026-07-30
redhat: CVE-2026-59996 was patched at 2026-07-29
ubuntu: CVE-2026-59996 was patched at 2026-07-30
1699.
Unknown Vulnerability Type - OpenSSL (CVE-2026-14355) - Medium [216]
Description: {'nvd_cve_data_all': 'In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In PHP versions 8.2.* before 8.2.32, 8.3.* before 8.3.32, 8.4.* before 8.4.23, 8.5.* before 8.5.8, the AES-WRAP-PAD algorithm implementation in OpenSSL extension contains a buffer allocation flaw. The output buffer for the AES key-wrap-with-padding operation is sized from the plaintext length without accounting for RFC 5649 expansion. This may cause OpenSSL to write beyond allocated memory, corrupting heap metadata and triggering application abort.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | A software library for applications that secure communications over computer networks against eavesdropping or need to identify the party at the other end | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00279, EPSS Percentile is 0.20167 |
altlinux: CVE-2026-14355 was patched at 2026-07-12, 2026-07-15, 2026-07-23
debian: CVE-2026-14355 was patched at 2026-07-04, 2026-07-14
oraclelinux: CVE-2026-14355 was patched at 2026-07-17
ubuntu: CVE-2026-14355 was patched at 2026-07-30
1700.
Cross Site Scripting - Unknown Product (CVE-2026-54163) - Medium [214]
Description: {'nvd_cve_data_all': 'secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and build_sandbox_list_directive, build_media_type_list_directive, and build_report_to_directive interpolate caller-supplied strings without scrubbing ;, \\r, or \\n. When untrusted input reaches SecureHeaders.override_content_security_policy_directives or append APIs for :sandbox, :plugin_types, or :report_to, an attacker can inject a CSP directive such as script-src 'unsafe-inline' * before the legitimate script-src, enabling XSS reachability through these sinks or CSP report exfiltration. This issue is fixed in version 7.3.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds the Content-Security-Policy value by stitching directives with ; separators, and build_sandbox_list_directive, build_media_type_list_directive, and build_report_to_directive interpolate caller-supplied strings without scrubbing ;, \\r, or \\n. When untrusted input reaches SecureHeaders.override_content_security_policy_directives or append APIs for :sandbox, :plugin_types, or :report_to, an attacker can inject a CSP directive such as script-src 'unsafe-inline' * before the legitimate script-src, enabling XSS reachability through these sinks or CSP report exfiltration. This issue is fixed in version 7.3.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00174, EPSS Percentile is 0.07118 |
debian: CVE-2026-54163 was patched at 2026-07-14
1701.
Unknown Vulnerability Type - Node.js (CVE-2026-48615) - Medium [214]
Description: {'nvd_cve_data_all': 'A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages.\r \r When proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers.\r \r This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages.\r\n\r\nWhen proxy credentials are embedded in the proxy URL, they may be exposed through error handling paths and captured by logs, diagnostics, or other error consumers.\r\n\r\nThis vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:nodejs:node.js (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00421, EPSS Percentile is 0.34659 |
almalinux: CVE-2026-48615 was patched at 2026-07-06, 2026-07-15, 2026-07-20
altlinux: CVE-2026-48615 was patched at 2026-07-23
debian: CVE-2026-48615 was patched at 2026-06-24
oraclelinux: CVE-2026-48615 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-48615 was patched at 2026-07-06, 2026-07-15, 2026-07-20
1702.
Unknown Vulnerability Type - ProFTPD (CVE-2026-35025) - Medium [214]
Description: {'nvd_cve_data_all': 'ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler. Attackers can exploit the unresolved symlink components in dir_canonical_path() to cause dir_check() to perform lexical path comparisons that match no configured Directory block, enabling rename operations on files in DenyAll-protected directories and subsequent retrieval of those files. Mitigation: Sessions configured with DefaultRoot (chroot) are not affected, as chroot changes the directory to which /proc/self/root resolves.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass vulnerability that allows authenticated FTP users to circumvent Directory ACL restrictions by prefixing paths with /proc/self/root in the RNFR command handler. Attackers can exploit the unresolved symlink components in dir_canonical_path() to cause dir_check() to perform lexical path comparisons that match no configured Directory block, enabling rename operations on files in DenyAll-protected directories and subsequent retrieval of those files. Mitigation: Sessions configured with DefaultRoot (chroot) are not affected, as chroot changes the directory to which /proc/self/root resolves.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | ProFTPD is a highly configurable and modular open-source FTP server designed for Unix-like systems, offering advanced features such as virtual hosting, authentication modules, and flexible configuration similar to Apache. | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00349, EPSS Percentile is 0.27545 |
debian: CVE-2026-35025 was patched at 2026-07-14
1703.
Unknown Vulnerability Type - concurrent_ruby (CVE-2026-54906) - Medium [214]
Description: {'nvd_cve_data_all': 'concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread with access to the lock object can release an active write lock held by another thread. A second writer can then enter its critical section while the first writer is still running. Concurrent::ReadWriteLock#release_read_lock also decrements the shared counter even when no read lock is held. Calling it on a fresh lock changes the counter from 0 to -1, after which normal read acquisition raises Concurrent::ResourceLimitError. This is a synchronization correctness issue in the public Concurrent::ReadWriteLock API. This vulnerability is fixed in 1.3.7.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'concurrent-ruby is a modern concurrency tools for Ruby. Prior to 1.3.7, Concurrent::ReadWriteLock#release_write_lock does not verify that the calling thread acquired the write lock. Any thread with access to the lock object can release an active write lock held by another thread. A second writer can then enter its critical section while the first writer is still running. Concurrent::ReadWriteLock#release_read_lock also decrements the shared counter even when no read lock is held. Calling it on a fresh lock changes the counter from 0 to -1, after which normal read acquisition raises Concurrent::ResourceLimitError. This is a synchronization correctness issue in the public Concurrent::ReadWriteLock API. This vulnerability is fixed in 1.3.7.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:rubyconcurrency:concurrent_ruby (does NOT exist in CPE dict) | |
| 1.0 | 10 | CVSS Base Score is 9.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0016, EPSS Percentile is 0.05668 |
debian: CVE-2026-54906 was patched at 2026-07-14
1704.
Unknown Vulnerability Type - fast-uri (CVE-2026-13676) - Medium [214]
Description: {'nvd_cve_data_all': 'fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) before passing the same URL to Node's URL or fetch can be bypassed when the two implementations resolve the same input to different hosts. Patches: upgrade to fast-uri 3.1.3 for the 3.x line or 4.0.1 for the 4.x line. Workarounds: enforce host policy using the same URL parser used for the actual request, or reject non-ASCII hosts before policy checks.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leaving the host in its original Unicode form while normalize() and equal() still return values that differ from a WHATWG-compatible URL parser. Applications that use fast-uri to enforce host-based policy (denylists, loopback filtering, redirect validation, outbound proxy routing) before passing the same URL to Node's URL or fetch can be bypassed when the two implementations resolve the same input to different hosts. Patches: upgrade to fast-uri 3.1.3 for the 3.x line or 4.0.1 for the 4.x line. Workarounds: enforce host policy using the same URL parser used for the actual request, or reject non-ASCII hosts before policy checks.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:openjsf:fast-uri (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00384, EPSS Percentile is 0.31149 |
debian: CVE-2026-13676 was patched at 2026-07-14
1705.
Unknown Vulnerability Type - freeswitch (CVE-2026-49847) - Medium [214]
Description: {'nvd_cve_data_all': 'FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, a single unauthenticated WebSocket frame containing a deeply nested JSON document crashes the FreeSWITCH process via stack overflow, terminating all calls and sessions on the host. The recursion drives the worker thread's stack pointer into the stack guard page, raising SIGSEGV from the kernel before any usable write primitive develops. This issue has been patched in version 1.11.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.1, a single unauthenticated WebSocket frame containing a deeply nested JSON document crashes the FreeSWITCH process via stack overflow, terminating all calls and sessions on the host. The recursion drives the worker thread's stack pointer into the stack guard page, raising SIGSEGV from the kernel before any usable write primitive develops. This issue has been patched in version 1.11.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:freeswitch:freeswitch (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00414, EPSS Percentile is 0.34092 |
altlinux: CVE-2026-49847 was patched at 2026-06-24, 2026-06-26, 2026-07-16
1706.
Unknown Vulnerability Type - nats-server (CVE-2026-58208) - Medium [214]
Description: {'nvd_cve_data_all': 'NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an unauthenticated client with access to the WebSocket listener to reach uninitialized MQTT state and crash the server process. This issue is fixed in versions 2.14.3 and 2.12.12.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a WebSocket listener could route requests for the MQTT-over-WebSocket path into MQTT handling even when MQTT was not configured, allowing an unauthenticated client with access to the WebSocket listener to reach uninitialized MQTT state and crash the server process. This issue is fixed in versions 2.14.3 and 2.12.12.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:linuxfoundation:nats-server (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00337, EPSS Percentile is 0.26248 |
altlinux: CVE-2026-58208 was patched at 2026-07-10, 2026-07-13, 2026-07-14
debian: CVE-2026-58208 was patched at 2026-07-14
1707.
Memory Corruption - ImageMagick (CVE-2026-61872) - Medium [213]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.2 | 10 | CVSS Base Score is 2.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00096, EPSS Percentile is 0.00831 |
debian: CVE-2026-61872 was patched at 2026-07-14
1708.
Authentication Bypass - Unknown Product (CVE-2026-56130) - Medium [210]
Description: {'nvd_cve_data_all': '"Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie and reuse it indefinitely, even after the configured expiration time has passed. This issue affects all Apache Shiro versions from 1.2.4 through 2.x, and 3.0.0-alpha-1, only when RememberMe functionality is enabled. Upgrade to version 3.0.0 or later, which fixes the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': '"Remember me" cookie age is not verified on the server. This potentially allows an attacker to intercept a valid cookie and reuse it indefinitely, even after the configured expiration time has passed.\nThis issue affects all Apache Shiro versions from 1.2.4 through 2.x, and 3.0.0-alpha-1, only when RememberMe functionality is enabled.\n\n\nUpgrade to version 3.0.0 or later, which fixes the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.98 | 15 | Authentication Bypass | |
| 0 | 14 | Unknown Product | |
| 0.2 | 10 | CVSS Base Score is 2.0. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00225, EPSS Percentile is 0.13258 |
debian: CVE-2026-56130 was patched at 2026-07-14
1709.
Incorrect Calculation - jqlang jq (CVE-2026-54679) - Medium [210]
Description:
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.3 | 14 | jq is a lightweight and flexible command-line JSON processor, allowing powerful querying and manipulation of JSON data streams. | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00103, EPSS Percentile is 0.01134 |
altlinux: CVE-2026-54679 was patched at 2026-06-22, 2026-06-24, 2026-06-25, 2026-06-29
debian: CVE-2026-54679 was patched at 2026-07-14
1710.
Unknown Vulnerability Type - Erlang/OTP (CVE-2026-55952) - Medium [209]
Description: {'nvd_cve_data_all': 'The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passing them to the session ticket handler. In tls_handshake_1_3:handle_pre_shared_key/3, an OfferedPreSharedKeys record with a mismatched number of identities and binders is forwarded directly to tls_server_session_ticket:use/4, which crashes the session ticket handler process. An unauthenticated remote attacker can send a single crafted ClientHello to a TLS 1.3 server with session tickets enabled (stateful or stateless mode) and permanently disrupt session ticket handling on that listener. New TLS 1.3 handshakes complete but subsequently crash when the server attempts to issue a session ticket, effectively making TLS 1.3 unusable on the affected listener until the ssl application is restarted. TLS 1.2 connections are not affected. This issue affects OTP from OTP 22.2 before OTP 29.0.3, OTP 28.5.0.3 and OTP 27.3.4.14, corresponding to ssl from 9.5 before 11.7.3, 11.6.0.3 and 11.2.12.10.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The Erlang/OTP ssl application does not validate that the PSK identity list and binder list carried in a TLS 1.3 ClientHello pre-shared key extension have equal length before passing them to the session ticket handler. In tls_handshake_1_3:handle_pre_shared_key/3, an OfferedPreSharedKeys record with a mismatched number of identities and binders is forwarded directly to tls_server_session_ticket:use/4, which crashes the session ticket handler process.\n\nAn unauthenticated remote attacker can send a single crafted ClientHello to a TLS 1.3 server with session tickets enabled (stateful or stateless mode) and permanently disrupt session ticket handling on that listener. New TLS 1.3 handshakes complete but subsequently crash when the server attempts to issue a session ticket, effectively making TLS 1.3 unusable on the affected listener until the ssl application is restarted. TLS 1.2 connections are not affected.\n\nThis issue affects OTP from OTP 22.2 before OTP\xa029.0.3, OTP\xa028.5.0.3 and OTP\xa027.3.4.14, corresponding to ssl from 9.5 before 11.7.3, 11.6.0.3 and 11.2.12.10.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.4 | 14 | Erlang/OTP is a set of libraries for the Erlang programming language | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.4 | 10 | EPSS Probability is 0.00481, EPSS Percentile is 0.38887 |
debian: CVE-2026-55952 was patched at 2026-07-14
1711.
Denial of Service - Unknown Product (CVE-2026-11771) - Medium [208]
Description: {'nvd_cve_data_all': 'OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'OpenVPN version 2.1.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows attackers via an off-by-one buffer write in the NTLM proxy authentication to potentially cause a crash via a crafted NTLM response from a malicious proxy server', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.0. According to Vulners data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-11771 was patched at 2026-07-03, 2026-07-14
ubuntu: CVE-2026-11771 was patched at 2026-07-30
1712.
Denial of Service - Unknown Product (CVE-2026-40209) - Medium [208]
Description: {'nvd_cve_data_all': 'An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to this backend, or if the process runs out of file descriptors.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker might be able to cause outgoing TCP connections to backend to be stuck until a timeout occurs instead of being released immediately, by sending IXFR queries. This could be used to cause a denial of service if there is a limit to the number of concurrent connections to this backend, or if the process runs out of file descriptors.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0029, EPSS Percentile is 0.21297 |
altlinux: CVE-2026-40209 was patched at 2026-06-29, 2026-06-30
debian: CVE-2026-40209 was patched at 2026-06-25, 2026-07-14
1713.
Denial of Service - Unknown Product (CVE-2026-40211) - Medium [208]
Description: {'nvd_cve_data_all': 'An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will be freed at the end of the QUIC connection, but on some setups it might be possible to open enough concurrent DoH3 streams to trigger an out-of-memory condition, resulting in a denial of service.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will be freed at the end of the QUIC connection, but on some setups it might be possible to open enough concurrent DoH3 streams to trigger an out-of-memory condition, resulting in a denial of service.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00296, EPSS Percentile is 0.21922 |
altlinux: CVE-2026-40211 was patched at 2026-06-29, 2026-06-30
debian: CVE-2026-40211 was patched at 2026-06-25, 2026-07-14
1714.
Denial of Service - Unknown Product (CVE-2026-42005) - Medium [208]
Description: {'nvd_cve_data_all': 'An attacker can send a web request that causes unlimited memory allocation in the internal web server, leading to a denial of service. The internal web server is disabled by default.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker can send a web request that causes unlimited memory \nallocation in the internal web server, leading to a denial of service. \nThe internal web server is disabled by default.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00344, EPSS Percentile is 0.27008 |
altlinux: CVE-2026-42005 was patched at 2026-06-29, 2026-06-30
debian: CVE-2026-42005 was patched at 2026-06-25, 2026-07-14
1715.
Memory Corruption - Unknown Product (CVE-2026-22879) - Medium [208]
Description: {'nvd_cve_data_all': 'vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow vulnerability', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00321, EPSS Percentile is 0.24529 |
debian: CVE-2026-22879 was patched at 2026-07-14
1716.
Unknown Vulnerability Type - Gitea (CVE-2026-25714) - Medium [208]
Description: {'nvd_cve_data_all': 'Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Gitea versions up to and including 1.26.1 do not apply public-only token filtering consistently to the user organization API, leaving an incomplete fix for CVE-2025-68941.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00332, EPSS Percentile is 0.25745 |
redos: CVE-2026-25714 was patched at 2026-07-14
1717.
Unknown Vulnerability Type - Chromium (CVE-2026-13023) - Medium [204]
Description: {'nvd_cve_data_all': 'Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in GPU in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00186, EPSS Percentile is 0.08511 |
debian: CVE-2026-13023 was patched at 2026-06-25, 2026-07-14
1718.
Unknown Vulnerability Type - Chromium (CVE-2026-13030) - Medium [204]
Description: {'nvd_cve_data_all': 'Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.197 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00186, EPSS Percentile is 0.0851 |
debian: CVE-2026-13030 was patched at 2026-06-25, 2026-07-14
1719.
Unknown Vulnerability Type - Chromium (CVE-2026-13874) - Medium [204]
Description: {'nvd_cve_data_all': 'Race in DataTransfer in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Race in DataTransfer in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11367 |
altlinux: CVE-2026-13874 was patched at 2026-07-03
debian: CVE-2026-13874 was patched at 2026-07-05, 2026-07-14
1720.
Unknown Vulnerability Type - OpenSSH (CVE-2026-55655) - Medium [204]
Description: {'nvd_cve_data_all': 'A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in OpenSSH. A local unprivileged attacker on a Linux client host can hijack client-side X11 forwarding connections. This is possible by pre-binding the preferred abstract X socket name when X11 forwarding is enabled and a local UNIX-domain X socket is used. A successful attack can compromise the confidentiality of forwarded X11 traffic, including sensitive window contents and input, and may allow some manipulation of the forwarded session.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00099, EPSS Percentile is 0.00966 |
almalinux: CVE-2026-55655 was patched at 2026-07-29
debian: CVE-2026-55655 was patched at 2026-06-24
oraclelinux: CVE-2026-55655 was patched at 2026-07-30
redhat: CVE-2026-55655 was patched at 2026-07-29, 2026-07-30
1721.
Unknown Vulnerability Type - OpenSSH (CVE-2026-59997) - Medium [204]
Description: {'nvd_cve_data_all': 'internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'internal-sftp in sshd in OpenSSH before 10.4 recognizes only the first 9 command-line arguments, which can be important if a later command-line argument would have helped to ensure the intended security properties of an SFTP connection.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | OpenSSH is a suite of secure networking utilities based on the Secure Shell protocol, which provides a secure channel over an unsecured network in a client–server architecture | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07188 |
debian: CVE-2026-59997 was patched at 2026-07-14
ubuntu: CVE-2026-59997 was patched at 2026-07-30
1722.
Cross Site Scripting - Unknown Product (CVE-2026-48823) - Medium [202]
Description: {'nvd_cve_data_all': 'Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the tag filtering functionality of Shaarli. An authenticated user can inject arbitrary JavaScript into the tags field when creating a bookmark (Shaare). The malicious payload is stored and later executed when users interact with the "Filter by tag" search feature on the homepage. User-supplied input in the tags field is not properly sanitized or output-escaped before being rendered in the tag filtering interface. When a bookmark is created with a malicious payload inside the tag field, the payload is stored in the database. Later, when a user searches using the "Filter by tag" functionality on the homepage, the application renders matching tags dynamically. If the tag value contains HTML with JavaScript event handlers, it is injected into the DOM. This impacts anyone interacting with the "Filter by tag" search functionality, administrators and privileged users. This issue has been fixed in version 0.16.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Shaarli is a personal bookmarking service. Versions 0.16.1 and prior contain a stored Cross-Site Scripting (XSS) vulnerability in the tag filtering functionality of Shaarli. An authenticated user can inject arbitrary JavaScript into the tags field when creating a bookmark (Shaare). The malicious payload is stored and later executed when users interact with the "Filter by tag" search feature on the homepage. User-supplied input in the tags field is not properly sanitized or output-escaped before being rendered in the tag filtering interface. When a bookmark is created with a malicious payload inside the tag field, the payload is stored in the database. Later, when a user searches using the "Filter by tag" functionality on the homepage, the application renders matching tags dynamically. If the tag value contains HTML with JavaScript event handlers, it is injected into the DOM. This impacts anyone interacting with the "Filter by tag" search functionality, administrators and privileged users. This issue has been fixed in version 0.16.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00115, EPSS Percentile is 0.01827 |
debian: CVE-2026-48823 was patched at 2026-06-24
1723.
Cross Site Scripting - Unknown Product (CVE-2026-6658) - Medium [202]
Description: {'nvd_cve_data_all': 'A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.mermaid` output in HTML exports. The `data_mermaid` block in `share/templates/lab/base.html.j2` renders `text/vnd.mermaid` cell output directly into HTML without escaping, enabling attackers to inject arbitrary HTML/JavaScript by breaking out of the `<pre>` tag. This vulnerability impacts any server using nbconvert to render notebooks as HTML, allowing attackers to execute arbitrary JavaScript in the context of users viewing the HTML export.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows for Cross-site Scripting (XSS) via unsanitized `text/vnd.mermaid` output in HTML exports. The `data_mermaid` block in `share/templates/lab/base.html.j2` renders `text/vnd.mermaid` cell output directly into HTML without escaping, enabling attackers to inject arbitrary HTML/JavaScript by breaking out of the `<pre>` tag. This vulnerability impacts any server using nbconvert to render notebooks as HTML, allowing attackers to execute arbitrary JavaScript in the context of users viewing the HTML export.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.8 | 15 | Cross Site Scripting | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00134, EPSS Percentile is 0.03324 |
debian: CVE-2026-6658 was patched at 2026-07-14
1724.
Unknown Vulnerability Type - openbao (CVE-2026-42186) - Medium [202]
Description: {'nvd_cve_data_all': 'OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affect any outstanding leases as well as potentially leaving unrelated storage entries around. This vulnerability is fixed in 2.5.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'OpenBao is an open source identity-based secrets management system. Prior to 2.5.3, when OpenBao's initial namespace deletion fails, subsequent retries fail to properly remove all data before marking the namespace as deleted. This can affect any outstanding leases as well as potentially leaving unrelated storage entries around. This vulnerability is fixed in 2.5.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:openbao:openbao (does NOT exist in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00248, EPSS Percentile is 0.16268 |
redos: CVE-2026-42186 was patched at 2026-06-26
1725.
Denial of Service - Unknown Product (CVE-2026-14330) - Low [196]
Description: {'nvd_cve_data_all': 'Multiple unbounded alloca() calls in the PulseAudio protocol server.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Multiple unbounded alloca() calls in the PulseAudio protocol server.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.001, EPSS Percentile is 0.01007 |
debian: CVE-2026-14330 was patched at 2026-07-14
ubuntu: CVE-2026-14330 was patched at 2026-07-30
1726.
Denial of Service - Unknown Product (CVE-2026-46378) - Low [196]
Description: {'nvd_cve_data_all': 'Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the selector lexer matchRegexPattern closure in (*Tokenizer).parseCurRune in selector/lexer/tokenize.go loops while tokenizing an unterminated regex literal such as r/ because peekRuneEqual returns false after the end of input, allowing attacker-controlled selector strings to consume CPU indefinitely. This issue is fixed in version 3.10.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the selector lexer matchRegexPattern closure in (*Tokenizer).parseCurRune in selector/lexer/tokenize.go loops while tokenizing an unterminated regex literal such as r/ because peekRuneEqual returns false after the end of input, allowing attacker-controlled selector strings to consume CPU indefinitely. This issue is fixed in version 3.10.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.0162 |
debian: CVE-2026-46378 was patched at 2026-07-14
1727.
Memory Corruption - Unknown Product (CVE-2026-45382) - Low [196]
Description: {'nvd_cve_data_all': 'libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_slice_unit_tiles` (libde265/decctx.cc:920) reads `pps.CtbAddrRStoTS[ctbAddrRS]` at line 966 where `ctbAddrRS = ctbY * ctbsWidth + ctbX` is computed from PPS-supplied `colBd[]`/`rowBd[]` arrays without validating the result against `CtbAddrRStoTS.size() == sps->PicSizeInCtbsY`. A malformed PPS that passes `set_derived_values` but encodes geometry inconsistent with the SPS produces a `ctbAddrRS` past the allocation, causing a 4-byte heap-buffer-overflow READ. Version 1.0.19 fixes the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.19, `decoder_context::decode_slice_unit_tiles` (libde265/decctx.cc:920) reads `pps.CtbAddrRStoTS[ctbAddrRS]` at line 966 where `ctbAddrRS = ctbY * ctbsWidth + ctbX` is computed from PPS-supplied `colBd[]`/`rowBd[]` arrays without validating the result against `CtbAddrRStoTS.size() == sps->PicSizeInCtbsY`. A malformed PPS that passes `set_derived_values` but encodes geometry inconsistent with the SPS produces a `ctbAddrRS` past the allocation, causing a 4-byte heap-buffer-overflow READ. Version 1.0.19 fixes the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16828 |
debian: CVE-2026-45382 was patched at 2026-07-14
ubuntu: CVE-2026-45382 was patched at 2026-07-30
1728.
Memory Corruption - Unknown Product (CVE-2026-45383) - Low [196]
Description: {'nvd_cve_data_all': 'libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow (out-of-bounds READ) exists in `decoder_context::decode_slice_unit_WPP()` in `libde265/decctx.cc`. When decoding a WPP (Wavefront Parallel Processing) HEVC slice, `ctbAddrRS` is computed as `ctbRow * ctbsWidth` inside the entry-point loop. If the PPS/SPS headers are crafted so that this value exceeds `pps.CtbAddrRStoTS.size()`, the subsequent array access `pps.CtbAddrRStoTS[ctbAddrRS]` reads past the end of the allocated vector, triggering a heap-buffer-overflow confirmed by AddressSanitizer. Version 1.0.19 patches the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.0.19 have a heap buffer overflow (out-of-bounds READ) exists in `decoder_context::decode_slice_unit_WPP()` in `libde265/decctx.cc`. When decoding a WPP (Wavefront Parallel Processing) HEVC slice, `ctbAddrRS` is computed as `ctbRow * ctbsWidth` inside the entry-point loop. If the PPS/SPS headers are crafted so that this value exceeds `pps.CtbAddrRStoTS.size()`, the subsequent array access `pps.CtbAddrRStoTS[ctbAddrRS]` reads past the end of the allocated vector, triggering a heap-buffer-overflow confirmed by AddressSanitizer. Version 1.0.19 patches the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00257, EPSS Percentile is 0.17348 |
debian: CVE-2026-45383 was patched at 2026-07-14
ubuntu: CVE-2026-45383 was patched at 2026-07-30
1729.
Memory Corruption - Unknown Product (CVE-2026-48029) - Low [196]
Description: {'nvd_cve_data_all': 'libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libheif is a HEIF and AVIF file format decoder and encoder. Versions 1.19.0 through 1.21.2 have a heap OOB read in ImageItem_Grid::decode_grid_tile via irot-induced tile-coordinate underflow. Version 1.22.0 fixes the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.1. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00267, EPSS Percentile is 0.18738 |
debian: CVE-2026-48029 was patched at 2026-07-14
ubuntu: CVE-2026-48029 was patched at 2026-07-30
1730.
Unknown Vulnerability Type - Gitea (CVE-2026-27783) - Low [196]
Description: {'nvd_cve_data_all': 'Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Gitea versions up to and including 1.26.1 do not enforce repository-unit authorization on issue-template API endpoints.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.75 | 14 | Gitea is a lightweight self-hosted Git service that provides source code hosting, pull requests, issue tracking, CI integrations, and user management through a web interface. | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00284, EPSS Percentile is 0.20633 |
redos: CVE-2026-27783 was patched at 2026-07-14
1731.
Information Disclosure - Unknown Product (CVE-2026-59180) - Low [195]
Description: {'nvd_cve_data_all': 'Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to 1.11.0, Apprise HTTP-based notification plugins and HTTP attachment and config loaders in apprise/attachment/http.py and apprise/config/http.py follow HTTP redirects by default and resend user-configured auth headers and query parameters on the redirected request, allowing a compromised trusted destination or on-path attacker to receive secrets such as Authorization headers, bearer tokens, custom headers, and service keys. This issue is fixed in version 1.11.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Apprise is an open source library which allows you to send a notification to almost all of the most popular notification services available. Prior to 1.11.0, Apprise HTTP-based notification plugins and HTTP attachment and config loaders in apprise/attachment/http.py and apprise/config/http.py follow HTTP redirects by default and resend user-configured auth headers and query parameters on the redirected request, allowing a compromised trusted destination or on-path attacker to receive secrets such as Authorization headers, bearer tokens, custom headers, and service keys. This issue is fixed in version 1.11.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.83 | 15 | Information Disclosure | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00195, EPSS Percentile is 0.09467 |
debian: CVE-2026-59180 was patched at 2026-07-14
1732.
Unknown Vulnerability Type - Python (CVE-2026-47180) - Low [195]
Description: {'nvd_cve_data_all': 'Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_labels_at_offset recurses once per DNS-name compression pointer, and a single mDNS packet carrying chained pointers can trigger a RecursionError that escapes DNSIncoming.__init__, causing sustained CPU burn, log flooding, and degraded mDNS-dependent features for unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb). This issue is fixed in version 0.149.5.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_labels_at_offset recurses once per DNS-name compression pointer, and a single mDNS packet carrying chained pointers can trigger a RecursionError that escapes DNSIncoming.__init__, causing sustained CPU burn, log flooding, and degraded mDNS-dependent features for unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb). This issue is fixed in version 0.149.5.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0023, EPSS Percentile is 0.13938 |
debian: CVE-2026-47180 was patched at 2026-07-14
1733.
Unknown Vulnerability Type - Python (CVE-2026-49854) - Low [195]
Description: {'nvd_cve_data_all': 'Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.6, the optional native extension tornado.speedups implemented websocket_mask without validating that the mask argument is exactly four bytes, allowing the C function to read up to three bytes beyond the provided buffer when reached through Tornado XSRF token decoding with the native extension active. This issue is fixed in version 6.5.6.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00338, EPSS Percentile is 0.26382 |
debian: CVE-2026-49854 was patched at 2026-07-14
1734.
Unknown Vulnerability Type - PHP (CVE-2026-59947) - Low [192]
Description: {'nvd_cve_data_all': 'Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repository or package URL, such as a GitHub Personal Access Token in https://TOKEN@host/, to debug output because AuthHelper, Url::sanitize, and ProcessExecutor did not sanitize username-only URL credentials. This issue is fixed in versions 2.2.29 and 2.10.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, when Composer is run with -vvv debug verbosity, it could print a credential embedded in the username slot of a repository or package URL, such as a GitHub Personal Access Token in https://TOKEN@host/, to debug output because AuthHelper, Url::sanitize, and ProcessExecutor did not sanitize username-only URL credentials. This issue is fixed in versions 2.2.29 and 2.10.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | PHP is a general-purpose scripting language geared towards web development. It was originally created by Danish-Canadian programmer Rasmus Lerdorf in 1993 and released in 1995. | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02151 |
debian: CVE-2026-59947 was patched at 2026-07-14
1735.
Incorrect Calculation - GPAC (CVE-2026-14801) - Low [191]
Description: A security vulnerability has been detected in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01615 |
debian: CVE-2026-14801 was patched at 2026-07-14
1736.
Memory Corruption - GPAC (CVE-2026-14790) - Low [191]
Description: A flaw has been found in
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00115, EPSS Percentile is 0.01793 |
debian: CVE-2026-14790 was patched at 2026-07-14
1737.
Server-Side Request Forgery - Unknown Product (CVE-2026-48978) - Low [191]
Description: {'nvd_cve_data_all': 'oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, auth.Client follows the realm URL from a registry's WWW-Authenticate: Bearer challenge without validating the scheme or host, allowing a malicious or compromised registry to cause SSRF to internal networks such as http://169.254.169.254/, http://10.0.0.x/, and http://127.0.0.1/, or to downgrade a registry contacted over https:// to an http:// token endpoint in registry/remote/auth/client.go through Client.Do(), Client.fetchBearerToken(), fetchDistributionToken, and fetchOAuth2Token. This issue is fixed in version 2.6.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.87 | 15 | Server-Side Request Forgery | |
| 0 | 14 | Unknown Product | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11481 |
debian: CVE-2026-48978 was patched at 2026-07-14
1738.
Unknown Vulnerability Type - Excon (CVE-2026-54171) - Low [190]
Description: {'nvd_cve_data_all': 'Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could cause inadvertent leakage of sensitive data when the initial request includes header information that is not intended for the new target. This issue is fixed in version 1.5.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and did not provide a custom list of headers to strip. This could cause inadvertent leakage of sensitive data when the initial request includes header information that is not intended for the new target. This issue is fixed in version 1.5.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:excon_project:excon (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00304, EPSS Percentile is 0.22737 |
debian: CVE-2026-54171 was patched at 2026-07-14
1739.
Unknown Vulnerability Type - Go (CVE-2026-39822) - Low [190]
Description: {'nvd_cve_data_all': 'On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'On Unix systems, opening a file in an os.Root improperly follows symlinks to locations outside of the Root when the final path component of the a path is a symbolic link and the path ends in /. For example, 'root.Open("symlink/")' will open "symlink" even when "symlink" is a symbolic link pointing outside of the root.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:golang:go (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00232, EPSS Percentile is 0.1426 |
almalinux: CVE-2026-39822 was patched at 2026-07-09, 2026-07-13
altlinux: CVE-2026-39822 was patched at 2026-07-08, 2026-07-09, 2026-07-22, 2026-07-25
debian: CVE-2026-39822 was patched at 2026-07-14
oraclelinux: CVE-2026-39822 was patched at 2026-07-10, 2026-07-14, 2026-07-16
redhat: CVE-2026-39822 was patched at 2026-07-09, 2026-07-13
1740.
Unknown Vulnerability Type - Jackson-databind (CVE-2026-54518) - Low [190]
Description: {'nvd_cve_data_all': 'jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters but never consults prop.visibleInView(activeView). The normal property-based creator path gates creator properties on the active view, but this unwrapped-creator replay path bypasses that check, so a constructor parameter annotated with both @JsonView(AdminView.class) and @JsonUnwrapped is populated from attacker JSON even when a more restrictive view is active. This vulnerability is fixed in 2.21.4 and 3.1.4.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters but never consults prop.visibleInView(activeView). The normal property-based creator path gates creator properties on the active view, but this unwrapped-creator replay path bypasses that check, so a constructor parameter annotated with both @JsonView(AdminView.class) and @JsonUnwrapped is populated from attacker JSON even when a more restrictive view is active. This vulnerability is fixed in 2.21.4 and 3.1.4.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:fasterxml:jackson-databind (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00264, EPSS Percentile is 0.18229 |
debian: CVE-2026-54518 was patched at 2026-07-14
1741.
Unknown Vulnerability Type - undici (CVE-2026-9678) - Low [190]
Description: {'nvd_cve_data_all': 'Impact: Undici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=" authorization" or no-cache="\\tauthorization". The parser preserves the surrounding whitespace, so later comparisons against the literal authorization field name fail and the response is stored. In shared-cache mode, this allows a response containing one user's authenticated data to be served from cache to a subsequent caller, including an unauthenticated caller, when both requests resolve to the same cache key. Affected applications are those that explicitly enable the cache interceptor (interceptors.cache()) in shared mode, forward Authorization headers upstream, and receive cacheable responses with non-canonical qualified private or no-cache directives. Patches: Upgrade to undici v7.28.0 or v8.5.0. Workarounds: If upgrade is not immediately possible, disable shared-cache mode for traffic that includes Authorization headers, avoid caching responses to authenticated requests, or add Vary: Authorization upstream.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Impact:\nUndici's cache interceptor incorrectly classifies some responses as cacheable when the upstream Cache-Control header uses whitespace-padded qualified private or no-cache field names such as private=" authorization" or no-cache="\\tauthorization". The parser preserves the surrounding whitespace, so later comparisons against the literal authorization field name fail and the response is stored.\n\nIn shared-cache mode, this allows a response containing one user's authenticated data to be served from cache to a subsequent caller, including an unauthenticated caller, when both requests resolve to the same cache key.\n\nAffected applications are those that explicitly enable the cache interceptor (interceptors.cache()) in shared mode, forward Authorization headers upstream, and receive cacheable responses with non-canonical qualified private or no-cache directives.\n\nPatches:\nUpgrade to undici v7.28.0 or v8.5.0.\n\nWorkarounds:\nIf upgrade is not immediately possible, disable shared-cache mode for traffic that includes Authorization headers, avoid caching responses to authenticated requests, or add Vary: Authorization upstream.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.0036, EPSS Percentile is 0.28724 |
almalinux: CVE-2026-9678 was patched at 2026-07-06, 2026-07-15, 2026-07-20
debian: CVE-2026-9678 was patched at 2026-06-24
oraclelinux: CVE-2026-9678 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-9678 was patched at 2026-07-06, 2026-07-15, 2026-07-20
1742.
Denial of Service - Unknown Product (CVE-2026-49337) - Low [184]
Description: {'nvd_cve_data_all': 'libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object that has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`) to attach slice headers to a finished picture object\nthat has no active image unit, resulting in attacker-controlled unbounded heap growth. The retained headers are never freed until the picture is released, which may not happen during continuous streaming. Version 1.0.20 patches the issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00194, EPSS Percentile is 0.09426 |
debian: CVE-2026-49337 was patched at 2026-06-24
redos: CVE-2026-49337 was patched at 2026-07-14
ubuntu: CVE-2026-49337 was patched at 2026-07-30
1743.
Denial of Service - Unknown Product (CVE-2026-8484) - Low [184]
Description: {'nvd_cve_data_all': 'A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS). All versions are believed to be vulnerable. This project is unmaintained at the time of CVE assignment.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" wrapper due to a lack of size verification for the argument array before the system call. This can lead to heap corruption and application crashes (DoS).\nAll versions are believed to be vulnerable.\xa0This project is unmaintained at the time of CVE assignment.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.0014, EPSS Percentile is 0.03867 |
debian: CVE-2026-8484 was patched at 2026-06-24
1744.
Memory Corruption - Unknown Product (CVE-2026-14324) - Low [184]
Description: {'nvd_cve_data_all': 'RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'RAOP module accepts unbounded Content-Length values and does not check the pw_array_add() return.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07254 |
debian: CVE-2026-14324 was patched at 2026-07-14
ubuntu: CVE-2026-14324 was patched at 2026-07-30
1745.
Unknown Vulnerability Type - ImageMagick (CVE-2026-61858) - Low [183]
Description: {'nvd_cve_data_all': 'ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in the APNG encoder and external delegates due to missing validation checks. Attackers can write files to disallowed paths by bypassing configured policy restrictions through the APNG encoding process.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00246, EPSS Percentile is 0.16023 |
altlinux: CVE-2026-61858 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-61858 was patched at 2026-07-14
1746.
Unknown Vulnerability Type - Gogs (CVE-2026-23632) - Low [182]
Description: {'nvd_cve_data_all': 'Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/contents/*" does not require write permissions and allows access with read permission only via repoAssignment(). After passing the permission check, PutContents() invokes UpdateRepoFile(), which results in commit creation and the execution of git push. As a result, a token with read-only permission can be used to modify repository contents. This issue has been patched in versions 0.13.4 and 0.14.0+dev.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/contents/*" does not require write permissions and allows access with read permission only via repoAssignment(). After passing the permission check, PutContents() invokes UpdateRepoFile(), which results in commit creation and the execution of git push. As a result, a token with read-only permission can be used to modify repository contents. This issue has been patched in versions 0.13.4 and 0.14.0+dev.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00282, EPSS Percentile is 0.20449 |
altlinux: CVE-2026-23632 was patched at 2026-06-25
1747.
Unknown Vulnerability Type - Chromium (CVE-2026-13905) - Low [180]
Description: {'nvd_cve_data_all': 'Race in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via physical access to the device. (Chromium security severity: Medium)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Race in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker to obtain potentially sensitive information from process memory via physical access to the device. (Chromium security severity: Medium)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.8 | 14 | Chromium is a free and open-source web browser project, mainly developed and maintained by Google | |
| 0.4 | 10 | CVSS Base Score is 4.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00137, EPSS Percentile is 0.03595 |
altlinux: CVE-2026-13905 was patched at 2026-07-03
debian: CVE-2026-13905 was patched at 2026-07-05, 2026-07-14
1748.
Unknown Vulnerability Type - Jackson-databind (CVE-2026-54515) - Low [178]
Description: {'nvd_cve_data_all': 'jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are applied by _handleByNameInclusion(), producing a contextual deserializer whose BeanPropertyMap has the ignored properties removed. The subsequent per-property case-insensitivity block (triggered by @JsonFormat(ACCEPT_CASE_INSENSITIVE_PROPERTIES)) rebuilds from this._beanProperties (the original, unfiltered map) instead of contextual._beanProperties, then overwrites the filtered map — restoring every property _handleByNameInclusion had just removed. The ignored property becomes writable again. This vulnerability is fixed in 2.18.9, 2.21.5, and 3.1.4.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:fasterxml:jackson-databind (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00345, EPSS Percentile is 0.27179 |
debian: CVE-2026-54515 was patched at 2026-07-14
1749.
Unknown Vulnerability Type - ModSecurity (CVE-2026-52761) - Low [178]
Description: {'nvd_cve_data_all': 'ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in src/actions/transformations/utf8_to_unicode.cc produces wrong output on i386 architecture because snprintf uses sizeof on a char pointer rather than the length of the unicode buffer, allowing rules that use this transformation to be bypassed on i386 architecture. This issue is fixed in version 3.0.16.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 through 3.0.15, the t:utf8toUnicode transformation in src/actions/transformations/utf8_to_unicode.cc produces wrong output on i386 architecture because snprintf uses sizeof on a char pointer rather than the length of the unicode buffer, allowing rules that use this transformation to be bypassed on i386 architecture. This issue is fixed in version 3.0.16.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00414, EPSS Percentile is 0.34054 |
debian: CVE-2026-52761 was patched at 2026-07-14
1750.
Unknown Vulnerability Type - Psr-7 (CVE-2026-59882) - Low [178]
Description: {'nvd_cve_data_all': 'guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.3, Uri::assertValidHost() does not reject URI host components containing authority delimiters, embedded ports, or malformed IPv6 brackets, allowing Uri::getHost() to disagree with the URI authority used for security or routing decisions. This issue is fixed in version 2.12.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:guzzlephp:psr-7 (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00186, EPSS Percentile is 0.0848 |
debian: CVE-2026-59882 was patched at 2026-07-14
1751.
Unknown Vulnerability Type - containerd (CVE-2026-53489) - Low [178]
Description: {'nvd_cve_data_all': 'containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'containerd is an open-source container runtime. Versions prior to 2.3.2, 2.2.5 and 2.1.9 contain a bug where the CRI plugin restores container.log from a checkpoint image without validating a symlinked path. This could result in reading an arbitrary file on the host via kubectl logs. This issue has been fixed in versions 2.3.2, 2.2.5 and 2.1.9.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:linuxfoundation:containerd (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00186, EPSS Percentile is 0.08549 |
altlinux: CVE-2026-53489 was patched at 2026-06-19, 2026-07-14, 2026-07-15
ubuntu: CVE-2026-53489 was patched at 2026-07-30
1752.
Unknown Vulnerability Type - nats-server (CVE-2026-58254) - Low [178]
Description: {'nvd_cve_data_all': 'NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destination checks were applied to ordinary client connections but not consistently to messages arriving through leafnode connections, allowing a leafnode operator to send trace events to subjects that would not otherwise be permitted and to use trace-only behavior to prevent normal delivery or storage of affected messages. This issue is fixed in versions 2.14.3 and 2.12.8.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.8, message trace destination checks were applied to ordinary client connections but not consistently to messages arriving through leafnode connections, allowing a leafnode operator to send trace events to subjects that would not otherwise be permitted and to use trace-only behavior to prevent normal delivery or storage of affected messages. This issue is fixed in versions 2.14.3 and 2.12.8.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:linuxfoundation:nats-server (exists in CPE dict) | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.0779 |
altlinux: CVE-2026-58254 was patched at 2026-07-10, 2026-07-13, 2026-07-14
debian: CVE-2026-58254 was patched at 2026-07-14
1753.
Unknown Vulnerability Type - wolfssl (CVE-2026-55967) - Low [178]
Description: {'nvd_cve_data_all': 'AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowing counter wrap, keystream reuse, and consequent plaintext recovery.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowing counter wrap, keystream reuse, and consequent plaintext recovery.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:wolfssl:wolfssl (exists in CPE dict) | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00114, EPSS Percentile is 0.01761 |
debian: CVE-2026-55967 was patched at 2026-07-14
1754.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63891) - Low [173]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() A DIRECTORY entry's value field is used as the dir_offset for a recursive call into __tb_property_parse_dir() with no depth counter. A crafted peer that chains DIRECTORY entries into a back-reference loop drives the parser until the kernel stack is exhausted and the guard page fires. Any untrusted XDomain peer (cable, dock, in-line inspector, adjacent host) that reaches the PROPERTIES_REQUEST control-plane exchange can trigger this without authentication. Thread a depth counter through tb_property_parse() and __tb_property_parse_dir(), and reject blocks that exceed TB_PROPERTY_MAX_DEPTH = 8. That is comfortably larger than any observed legitimate XDomain layout. Operators who do not need XDomain host-to-host discovery can disable the path entirely with thunderbolt.xdomain=0 on the kernel command line.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: property: Cap recursion depth in __tb_property_parse_dir()\n\nA DIRECTORY entry's value field is used as the dir_offset for a\nrecursive call into __tb_property_parse_dir() with no depth counter.\nA crafted peer that chains DIRECTORY entries into a back-reference\nloop drives the parser until the kernel stack is exhausted and the\nguard page fires. Any untrusted XDomain peer (cable, dock, in-line\ninspector, adjacent host) that reaches the PROPERTIES_REQUEST\ncontrol-plane exchange can trigger this without authentication.\n\nThread a depth counter through tb_property_parse() and\n__tb_property_parse_dir(), and reject blocks that exceed\nTB_PROPERTY_MAX_DEPTH = 8. That is comfortably larger than any\nobserved legitimate XDomain layout.\n\nOperators who do not need XDomain host-to-host discovery can disable\nthe path entirely with thunderbolt.xdomain=0 on the kernel command\nline.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.18121 |
debian: CVE-2026-63891 was patched at 2026-07-14
ubuntu: CVE-2026-63891 was patched at 2026-07-30
1755.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63895) - Low [173]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_fs: copy only received bytes on short ep0 read ffs_ep0_read() allocates its control-OUT data buffer with kmalloc() (not kzalloc) at the Length value from the Setup packet, then copies that full len to userspace regardless of how many bytes were actually received: data = kmalloc(len, GFP_KERNEL); ... ret = __ffs_ep0_queue_wait(ffs, data, len); if ((ret > 0) && (copy_to_user(buf, data, len))) ret = -EFAULT; __ffs_ep0_queue_wait() returns req->actual, which on a short control OUT transfer is strictly less than len. The copy_to_user() call still copies len bytes, so on a short OUT the last (len - ret) bytes of the kmalloc() buffer -- uninitialised slab residue -- are delivered to the FunctionFS daemon. Short ep0 OUT completions are specified USB control-transfer behavior and are produced by in-tree UDCs: * dwc2 continues on req->actual < req->length for ep0 DATA OUT (short-not-ok is the only ep0-OUT stall path). * aspeed_udc ends ep0 OUT on rx_len < ep->ep.maxpacket. * renesas_usbf logs "ep0 short packet" and completes the request. * dwc3 stalls on short IN but not on short OUT. A short ep0 OUT is therefore not evidence of a broken UDC; it is a normal condition f_fs has to cope with. The sibling gadgetfs implementation in drivers/usb/gadget/legacy/inode.c already does this correctly via min(len, dev->req->actual) before copy_to_user(). This patch brings f_fs.c to the same safe pattern rather than trimming at a defensive layer. The bug is reached from the FunctionFS device node, which in real deployments is owned by the privileged gadget daemon (adbd, UMS, composite gadget services, etc.); it is not reachable from unprivileged userspace. Linux host stacks normally reject short-wLength control OUTs before they reach the gadget, so reproducing this required a build that bypasses that host-side check. With the bypass in place, a 1-byte payload on a 64-byte Setup produces 63 bytes of non-canary slab residue in the daemon's read buffer. Fix by copying only ret (actually received) bytes to userspace.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: f_fs: copy only received bytes on short ep0 read\n\nffs_ep0_read() allocates its control-OUT data buffer with\nkmalloc() (not kzalloc) at the Length value from the Setup\npacket, then copies that full len to userspace regardless of\nhow many bytes were actually received:\n\n data = kmalloc(len, GFP_KERNEL);\n ...\n ret = __ffs_ep0_queue_wait(ffs, data, len);\n if ((ret > 0) && (copy_to_user(buf, data, len)))\n ret = -EFAULT;\n\n__ffs_ep0_queue_wait() returns req->actual, which on a short\ncontrol OUT transfer is strictly less than len. The\ncopy_to_user() call still copies len bytes, so on a short OUT\nthe last (len - ret) bytes of the kmalloc() buffer --\nuninitialised slab residue -- are delivered to the FunctionFS\ndaemon.\n\nShort ep0 OUT completions are specified USB control-transfer\nbehavior and are produced by in-tree UDCs:\n\n * dwc2 continues on req->actual < req->length for ep0 DATA OUT\n (short-not-ok is the only ep0-OUT stall path).\n * aspeed_udc ends ep0 OUT on rx_len < ep->ep.maxpacket.\n * renesas_usbf logs "ep0 short packet" and completes the\n request.\n * dwc3 stalls on short IN but not on short OUT.\n\nA short ep0 OUT is therefore not evidence of a broken UDC; it is\na normal condition f_fs has to cope with. The sibling gadgetfs\nimplementation in drivers/usb/gadget/legacy/inode.c already does\nthis correctly via min(len, dev->req->actual) before\ncopy_to_user(). This patch brings f_fs.c to the same safe\npattern rather than trimming at a defensive layer.\n\nThe bug is reached from the FunctionFS device node, which in\nreal deployments is owned by the privileged gadget daemon\n(adbd, UMS, composite gadget services, etc.); it is not\nreachable from unprivileged userspace. Linux host stacks\nnormally reject short-wLength control OUTs before they reach\nthe gadget, so reproducing this required a build that\nbypasses that host-side check. With the bypass in place, a\n1-byte payload on a 64-byte Setup produces 63 bytes of\nnon-canary slab residue in the daemon's read buffer.\n\nFix by copying only ret (actually received) bytes to\nuserspace.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.2 | 10 | EPSS Probability is 0.00244, EPSS Percentile is 0.15716 |
debian: CVE-2026-63895 was patched at 2026-07-14
ubuntu: CVE-2026-63895 was patched at 2026-07-30
1756.
Memory Corruption - Unknown Product (CVE-2026-14461) - Low [172]
Description: {'nvd_cve_data_all': 'mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT response used for AS lookups can trigger this bug by returning a DNS response that is larger than 512 bytes and uses a crafted compression pointer in the answer NAME field. ipinfo_lookup() function uses the length of the response as the end-of-message boundary for dn_expand() function. The result is a reliable crash. This issue exists in the mtr through version 0.96 and it was fixed in commit 48e1794414d338ce47abc0f27c25ade8788af9c3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'mtr is vulnerable to Out-of-bound read vulnerability in ipinfo_lookup() function. An attacker who can influence the TXT response used for AS lookups can trigger this bug by returning a DNS response that is larger than 512 bytes and uses a crafted compression pointer in the answer NAME field.\xa0ipinfo_lookup() function uses the length of the response as the\xa0end-of-message boundary for dn_expand() function.\xa0The result is a reliable crash.\n\n\nThis issue exists in the mtr through version 0.96 and it was fixed in commit\xa048e1794414d338ce47abc0f27c25ade8788af9c3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00304, EPSS Percentile is 0.22737 |
debian: CVE-2026-14461 was patched at 2026-07-14
1757.
Memory Corruption - Unknown Product (CVE-2026-40210) - Low [172]
Description: {'nvd_cve_data_all': 'An out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being sent over the network or a crash.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An out-of-bounds read might happen when SetMacAddrAction is used, potentially resulting in uninitialized memory being sent over the network or a crash.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00261, EPSS Percentile is 0.17808 |
altlinux: CVE-2026-40210 was patched at 2026-06-29, 2026-06-30
debian: CVE-2026-40210 was patched at 2026-06-25, 2026-07-14
1758.
Memory Corruption - Unknown Product (CVE-2026-56109) - Low [172]
Description: {'nvd_cve_data_all': 'The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The Advanced Linux Sound Architecture (ALSA) library before 1.2.16.1 contains a double-free vulnerability in parse_def() in src/conf.c that allows attackers to corrupt memory by supplying maliciously crafted ALSA configuration text. When parsing nested compound or array configuration blocks, parse_def() fails to check return values before continuing, causing snd_config_delete() to be called twice on the same already-freed node, resulting in a NULL-pointer write or invalid memory read.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.8. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03669 |
debian: CVE-2026-56109 was patched at 2026-06-24
ubuntu: CVE-2026-56109 was patched at 2026-07-30
1759.
Memory Corruption - Unknown Product (CVE-2026-7701) - Low [172]
Description: {'nvd_cve_data_all': 'A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the component Bot API. The manipulation of the argument login_url leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. There is ongoing doubt regarding the real existence of this vulnerability. Upgrading to version 6.7.6 is able to resolve this issue. Upgrading the affected component is recommended. The vendor provides this rationale for the dispute: "[T]he described scenario does not lead to any security issue or vulnerability, and only causes a one-time crash. In the outlined scenario, the targeted user must perform an active action, which doesn't produce any consequences after the app is relaunched."', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A security vulnerability has been detected in Telegram Desktop up to 6.7.5. This vulnerability affects the function RequestButton of the file Telegram/SourceFiles/boxes/url_auth_box.cpp of the component Bot API. The manipulation of the argument login_url leads to null pointer dereference. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. There is ongoing doubt regarding the real existence of this vulnerability. Upgrading to version 6.7.6 is able to resolve this issue. Upgrading the affected component is recommended. The vendor provides this rationale for the dispute: "[T]he described scenario does not lead to any security issue or vulnerability, and only causes a one-time crash. In the outlined scenario, the targeted user must perform an active action, which doesn't produce any consequences after the app is relaunched."', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00389, EPSS Percentile is 0.31641 |
debian: CVE-2026-7701 was patched at 2026-07-14
1760.
Memory Corruption - Oj (CVE-2026-54896) - Low [171]
Description: Oj (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.35 | 14 | Oj (Optimized JSON) is a high-performance JSON parser and object serialization library packaged as a Ruby gem, designed to provide fast JSON encoding and decoding for Ruby applications. | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00119, EPSS Percentile is 0.02079 |
debian: CVE-2026-54896 was patched at 2026-07-14
1761.
Memory Corruption - Oj (CVE-2026-54897) - Low [171]
Description: Oj (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.35 | 14 | Oj (Optimized JSON) is a high-performance JSON parser and object serialization library packaged as a Ruby gem, designed to provide fast JSON encoding and decoding for Ruby applications. | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01953 |
debian: CVE-2026-54897 was patched at 2026-07-14
1762.
Memory Corruption - Oj (CVE-2026-54898) - Low [171]
Description: Oj (
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0.35 | 14 | Oj (Optimized JSON) is a high-performance JSON parser and object serialization library packaged as a Ruby gem, designed to provide fast JSON encoding and decoding for Ruby applications. | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01953 |
debian: CVE-2026-54898 was patched at 2026-07-14
1763.
Unknown Vulnerability Type - ImageMagick (CVE-2026-55628) - Low [171]
Description: {'nvd_cve_data_all': 'ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version 7.1.2-26.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-26he, the `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy. This issue has been fixed in version 7.1.2-26.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00098, EPSS Percentile is 0.00899 |
debian: CVE-2026-55628 was patched at 2026-07-07, 2026-07-14
1764.
Unknown Vulnerability Type - Perl (CVE-2026-13758) - Low [171]
Description: {'nvd_cve_data_all': 'CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt_done path. The decrypt_done($tag) form compares it against the computed tag with memNE (memcmp() != 0), which short-circuits on the first differing byte, so its run time depends on the number of matching leading bytes. This affects all five AEAD modes: GCM, CCM, ChaCha20Poly1305, EAX and OCB. The one-shot *_decrypt_verify helpers are unaffected; they verify the tag inside libtomcrypt with a constant-time comparison. The timing difference is a tag-verification oracle. An attacker who can submit many candidate tags for the same nonce, ciphertext and associated data while measuring the timing precisely enough may recover the expected tag byte by byte and forge a message that verifies.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'CryptX versions before 0.088_001 for Perl compare AEAD authentication tags in non-constant time in the streaming decrypt_done path.\n\nThe decrypt_done($tag) form compares it against the computed tag with memNE (memcmp() != 0), which short-circuits on the first differing byte, so its run time depends on the number of matching leading bytes. This affects all five AEAD modes: GCM, CCM, ChaCha20Poly1305, EAX and OCB. The one-shot *_decrypt_verify helpers are unaffected; they verify the tag inside libtomcrypt with a constant-time comparison.\n\nThe timing difference is a tag-verification oracle. An attacker who can submit many candidate tags for the same nonce, ciphertext and associated data while measuring the timing precisely enough may recover the expected tag byte by byte and forge a message that verifies.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00295, EPSS Percentile is 0.21776 |
debian: CVE-2026-13758 was patched at 2026-07-14
1765.
Unknown Vulnerability Type - Perl (CVE-2026-9537) - Low [171]
Description: {'nvd_cve_data_all': 'Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison. The decode() method compares the supplied signature to the recomputed HMAC with Perl's eq operator, which stops at the first differing byte, so the comparison time varies with the number of matching leading bytes. A caller that decodes attacker supplied tokens leaks the expected signature through this timing variation, which can be aggregated over many requests to recover the signature and forge a token.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a non-constant-time string comparison.\n\nThe decode() method compares the supplied signature to the recomputed HMAC with Perl's eq operator, which stops at the first differing byte, so the comparison time varies with the number of matching leading bytes.\n\nA caller that decodes attacker supplied tokens leaks the expected signature through this timing variation, which can be aggregated over many requests to recover the signature and forge a token.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Perl is a family of two high-level, general-purpose, interpreted, dynamic programming languages | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00228, EPSS Percentile is 0.13719 |
debian: CVE-2026-9537 was patched at 2026-07-14
1766.
Unknown Vulnerability Type - Python (CVE-2026-44722) - Low [171]
Description: {'nvd_cve_data_all': 'pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python operator precedence bug in pyzipper/zipfile_aes.py caused the AE-2 format to never be automatically selected during encryption, causing encrypted entries to be written in AE-1 format and exposing the plaintext CRC32 checksum in the ZIP header and, for unseekable zip archives, in the datadescripter section, allowing an attacker who possesses the archive to brute-force candidate plaintexts for small or low-entropy files by comparing CRC32 values. This issue is fixed in version 0.4.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'pyzipper is a replacement for Python's zipfile that can read and write AES encrypted zip files. Prior to 0.4.0, a Python operator precedence bug in pyzipper/zipfile_aes.py caused the AE-2 format to never be automatically selected during encryption, causing encrypted entries to be written in AE-1 format and exposing the plaintext CRC32 checksum in the ZIP header and, for unseekable zip archives, in the datadescripter section, allowing an attacker who possesses the archive to brute-force candidate plaintexts for small or low-entropy files by comparing CRC32 values. This issue is fixed in version 0.4.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00087, EPSS Percentile is 0.00454 |
debian: CVE-2026-44722 was patched at 2026-07-14
1767.
Unknown Vulnerability Type - Python (CVE-2026-48487) - Low [171]
Description: {'nvd_cve_data_all': 'Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/incoming.py advanced self.offset by attacker-declared RDLENGTH without checking it against self._data_len, allowing unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb) to send a TXT, HINFO, or A/AAAA record with rdlength=65535 and seed DNSCache and ServiceInfo.properties with truncated, attacker-shaped key/value or address records. This issue is fixed in version 0.149.16.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/incoming.py advanced self.offset by attacker-declared RDLENGTH without checking it against self._data_len, allowing unauthenticated hosts on the local link over UDP/5353 (224.0.0.251 / ff02::fb) to send a TXT, HINFO, or A/AAAA record with rdlength=65535 and seed DNSCache and ServiceInfo.properties with truncated, attacker-shaped key/value or address records. This issue is fixed in version 0.149.16.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | Python is a high-level, general-purpose programming language | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to Vulners data source | |
| 0.1 | 10 | EPSS Probability is 0.00203, EPSS Percentile is 0.10505 |
debian: CVE-2026-48487 was patched at 2026-07-14
1768.
Unknown Vulnerability Type - Go (CVE-2026-42505) - Low [166]
Description: {'nvd_cve_data_all': 'Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Handshakes which used Encrypted Client Hello could be de-anonymized by a passive network observer due to a disclosure of pre-shared key identities in the unencrypted client hello.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:golang:go (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.16966 |
altlinux: CVE-2026-42505 was patched at 2026-07-08, 2026-07-09, 2026-07-22, 2026-07-25
debian: CVE-2026-42505 was patched at 2026-07-14
1769.
Unknown Vulnerability Type - HashiCorp Nomad (CVE-2026-6959) - Low [166]
Description: {'nvd_cve_data_all': 'HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'HashiCorp Nomad and Nomad Enterprise prior to 2.0.1 are vulnerable to arbitrary file read and write on the client host as the Nomad process user through a symlink attack. This vulnerability (CVE-2026-6959) is fixed in Nomad 2.0.1, 1.11.5 and 1.10.11.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | HashiCorp Nomad is a workload scheduler and orchestrator designed to deploy and manage applications, including containerized and non-containerized workloads, across various infrastructure platforms | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00169, EPSS Percentile is 0.06532 |
redos: CVE-2026-6959 was patched at 2026-07-07
1770.
Unknown Vulnerability Type - Jackson-databind (CVE-2026-54516) - Low [166]
Description: {'nvd_cve_data_all': 'jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty("renamed") on the getter and @JsonIgnore on the setter to be renamed rather than dropped. With MapperFeature.INFER_PROPERTY_MUTATORS enabled (default), the private backing field is retained; during deserialization BeanDeserializerFactory.addBeanProps() sees hasField()==true, builds a FieldProperty, and makes the backing field writable. An attacker supplying the renamed JSON key writes the backing field directly, bypassing the @JsonIgnore on the setter. This vulnerability is fixed in 3.1.4.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty("renamed") on the getter and @JsonIgnore on the setter to be renamed rather than dropped. With MapperFeature.INFER_PROPERTY_MUTATORS enabled (default), the private backing field is retained; during deserialization BeanDeserializerFactory.addBeanProps() sees hasField()==true, builds a FieldProperty, and makes the backing field writable. An attacker supplying the renamed JSON key writes the backing field directly, bypassing the @JsonIgnore on the setter. This vulnerability is fixed in 3.1.4.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:fasterxml:jackson-databind (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00283, EPSS Percentile is 0.20537 |
debian: CVE-2026-54516 was patched at 2026-07-14
1771.
Unknown Vulnerability Type - Jackson-databind (CVE-2026-54517) - Low [166]
Description: {'nvd_cve_data_all': 'jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied only to creator properties; the regular property-buffering branch performed no prop.visibleInView(activeView) check. A change making SetterlessProperty.isMerging() return true routed setterless Collection/Map properties through this unguarded path, so a setterless collection annotated with a restricted @JsonView is populated from attacker JSON even when the active view excludes it. This vulnerability is fixed in 2.21.4 and 3.1.4.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was applied only to creator properties; the regular property-buffering branch performed no prop.visibleInView(activeView) check. A change making SetterlessProperty.isMerging() return true routed setterless Collection/Map properties through this unguarded path, so a setterless collection annotated with a restricted @JsonView is populated from attacker JSON even when the active view excludes it. This vulnerability is fixed in 2.21.4 and 3.1.4.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:fasterxml:jackson-databind (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00297, EPSS Percentile is 0.21963 |
debian: CVE-2026-54517 was patched at 2026-07-14
1772.
Unknown Vulnerability Type - postgresql_jdbc_driver (CVE-2026-54291) - Low [166]
Description: {'nvd_cve_data_all': 'pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'pgjdbc is an open source postgresql JDBC Driver. In releases 42.7.4 through 42.7.11, channelBinding=require connections can be silently downgraded from SCRAM-SHA-256-PLUS with channel binding to plain SCRAM-SHA-256 without it, losing the man-in-the-middle protection the setting is meant to guarantee. An attacker who can intercept the TLS connection can trigger the downgrade with a certificate whose signature algorithm has no tls-server-end-point channel-binding hash, because the bundled com.ongres.scram:scram-client returns an empty byte array instead of failing and pgJDBC ScramAuthenticator checks only that the server advertised a PLUS mechanism, without rejecting the empty binding or checking that the negotiated mechanism uses channel binding. This issue is fixed in version 42.7.12.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:postgresql:postgresql_jdbc_driver (exists in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.9. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00203, EPSS Percentile is 0.10442 |
debian: CVE-2026-54291 was patched at 2026-07-14
1773.
Unknown Vulnerability Type - wolfSSL (CVE-2026-6291) - Low [166]
Description: {'nvd_cve_data_all': 'Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key transport, wolfSSL returned distinguishable error codes depending on whether RSA padding validation failed versus whether the decrypted content was malformed. An attacker able to submit crafted EnvelopedData messages and observe error responses could use this as a padding oracle to incrementally recover the encrypted Content Encryption Key (CEK). The fix generates a deterministic pseudo-random fake CEK on padding failure (via HMAC-SHA256) and proceeds with decryption identically, using constant-time operations throughout, so that all failure paths produce the same error regardless of padding validity.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key transport, wolfSSL returned distinguishable error codes depending on whether RSA padding validation failed versus whether the decrypted content was malformed. An attacker able to submit crafted EnvelopedData messages and observe error responses could use this as a padding oracle to incrementally recover the encrypted Content Encryption Key (CEK). The fix generates a deterministic pseudo-random fake CEK on padding failure (via HMAC-SHA256) and proceeds with decryption identically, using constant-time operations throughout, so that all failure paths produce the same error regardless of padding validity.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | wolfSSL is a small, portable, embedded SSL/TLS library targeted for use by embedded systems developers | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00152, EPSS Percentile is 0.04923 |
debian: CVE-2026-6291 was patched at 2026-07-14
1774.
Unknown Vulnerability Type - Envoy (CVE-2026-47692) - Low [164]
Description: {'nvd_cve_data_all': 'Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, PROXY Protocol v2 header generator emits TLVs beyond the maximum length of 65535 bytes, causing a mismatch between bytes written and the length field in the header. This can result in smuggled bytes on the upstream request. This vulnerability is fixed in 1.35.13, 1.36.9, 1.37.5, and 1.38.3.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, PROXY Protocol v2 header generator emits TLVs beyond the maximum length of 65535 bytes, causing a mismatch between bytes written and the length field in the header. This can result in smuggled bytes on the upstream request. This vulnerability is fixed in 1.35.13, 1.36.9, 1.37.5, and 1.38.3.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.7 | 14 | Envoy is a cloud-native, open-source edge and service proxy | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00138, EPSS Percentile is 0.03668 |
altlinux: CVE-2026-47692 was patched at 2026-06-25, 2026-07-02
1775.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-23473) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: io_uring/poll: fix multishot recv missing EOF on wakeup race When a socket send and shutdown() happen back-to-back, both fire wake-ups before the receiver's task_work has a chance to run. The first wake gets poll ownership (poll_refs=1), and the second bumps it to 2. When io_poll_check_events() runs, it calls io_poll_issue() which does a recv that reads the data and returns IOU_RETRY. The loop then drains all accumulated refs (atomic_sub_return(2) -> 0) and exits, even though only the first event was consumed. Since the shutdown is a persistent state change, no further wakeups will happen, and the multishot recv can hang forever. Check specifically for HUP in the poll loop, and ensure that another loop is done to check for status if more than a single poll activation is pending. This ensures we don't lose the shutdown event.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nio_uring/poll: fix multishot recv missing EOF on wakeup race\n\nWhen a socket send and shutdown() happen back-to-back, both fire\nwake-ups before the receiver's task_work has a chance to run. The first\nwake gets poll ownership (poll_refs=1), and the second bumps it to 2.\nWhen io_poll_check_events() runs, it calls io_poll_issue() which does a\nrecv that reads the data and returns IOU_RETRY. The loop then drains all\naccumulated refs (atomic_sub_return(2) -> 0) and exits, even though only\nthe first event was consumed. Since the shutdown is a persistent state\nchange, no further wakeups will happen, and the multishot recv can hang\nforever.\n\nCheck specifically for HUP in the poll loop, and ensure that another\nloop is done to check for status if more than a single poll activation\nis pending. This ensures we don't lose the shutdown event.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00022, EPSS Percentile is 0.06029 |
oraclelinux: CVE-2026-23473 was patched at 2026-07-02
1776.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63822) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: ath11k: fix warning when unbinding If there is an error during some initialization related to firmware, the buffers dp->tx_ring[i].tx_status are released. However this is released again when the device is unbinded (ath11k_pci), and we get: WARNING: CPU: 0 PID: 6231 at mm/slub.c:4368 free_large_kmalloc+0x57/0x90 Call Trace: free_large_kmalloc ath11k_dp_free ath11k_core_deinit ath11k_pci_remove ... The issue is always reproducible from a VM because the MSI addressing initialization is failing. In order to fix the issue, just set the buffers to NULL after releasing in order to avoid the double free.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: ath11k: fix warning when unbinding\n\nIf there is an error during some initialization related to firmware,\nthe buffers dp->tx_ring[i].tx_status are released.\nHowever this is released again when the device is unbinded (ath11k_pci),\nand we get:\nWARNING: CPU: 0 PID: 6231 at mm/slub.c:4368 free_large_kmalloc+0x57/0x90\nCall Trace:\nfree_large_kmalloc\nath11k_dp_free\nath11k_core_deinit\nath11k_pci_remove\n...\n\nThe issue is always reproducible from a VM because the MSI addressing\ninitialization is failing.\n\nIn order to fix the issue, just set the buffers to NULL after releasing in\norder to avoid the double free.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00174, EPSS Percentile is 0.07065 |
debian: CVE-2026-63822 was patched at 2026-07-14, 2026-07-30
1777.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63834) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: restrict number of unacked list entries When the unacked_list is unbound, an attacker could send messages with small lengths and appropriated seqno + gaps to force the receiver to allocate more and more unacked_list entries. And the end either causing an out-of-memory situation or increase the management overhead for the (large) list that significant portions of CPU cycles are wasted in searching through the list. When limiting the list to a specific number, it is important to still correctly add a new entry to the list. But if the list became larger than the limit, the last entry of the list (with the highest seqno) must be dropped to still allow the earlier seqnos to finish and therefore to continue the process. Otherwise, the process might get stuck with too high seqnos which are not handled by batadv_tp_ack_unordered().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tp_meter: restrict number of unacked list entries\n\nWhen the unacked_list is unbound, an attacker could send messages with\nsmall lengths and appropriated seqno + gaps to force the receiver to\nallocate more and more unacked_list entries. And the end either causing an\nout-of-memory situation or increase the management overhead for the (large)\nlist that significant portions of CPU cycles are wasted in searching\nthrough the list.\n\nWhen limiting the list to a specific number, it is important to still\ncorrectly add a new entry to the list. But if the list became larger than\nthe limit, the last entry of the list (with the highest seqno) must be\ndropped to still allow the earlier seqnos to finish and therefore to\ncontinue the process. Otherwise, the process might get stuck with too high\nseqnos which are not handled by batadv_tp_ack_unordered().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00174, EPSS Percentile is 0.07122 |
debian: CVE-2026-63834 was patched at 2026-07-14, 2026-07-30
1778.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63835) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: batman-adv: v: prevent OGM aggregation on disabled hardif When an interface gets disabled, the worker is correctly disabled by batadv_hardif_disable_interface() -> ... -> batadv_v_ogm_iface_disable(). In this process, the skb aggr_list is also freed. But batadv_v_ogm_send_meshif() can still queue new skbs (via batadv_v_ogm_queue_on_if()) to the aggr_list. This will only stop after all cores can no longer find the RCU protected list of hard interfaces. These queued skbs will never be freed or consumed by batadv_v_ogm_aggr_work. The batadv_v_ogm_iface_disable() function must block batadv_v_ogm_queue_on_if() to avoid leak of skbs.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: v: prevent OGM aggregation on disabled hardif\n\nWhen an interface gets disabled, the worker is correctly disabled by\nbatadv_hardif_disable_interface() -> ... -> batadv_v_ogm_iface_disable().\nIn this process, the skb aggr_list is also freed.\n\nBut batadv_v_ogm_send_meshif() can still queue new skbs (via\nbatadv_v_ogm_queue_on_if()) to the aggr_list. This will only stop after all\ncores can no longer find the RCU protected list of hard interfaces. These\nqueued skbs will never be freed or consumed by batadv_v_ogm_aggr_work.\n\nThe batadv_v_ogm_iface_disable() function must block\nbatadv_v_ogm_queue_on_if() to avoid leak of skbs.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00174, EPSS Percentile is 0.07122 |
debian: CVE-2026-63835 was patched at 2026-07-14, 2026-07-30
1779.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63836) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: avoid divide-by-zero for dec_cwnd The cwnd is always MSS <= cwnd <= 0x20000000. But the calculation in batadv_tp_update_cwnd() assumes unsigned 32 bit arithmetics. ((mss * 8) ** 2) / (cwnd * 8) In case cwnd is actually 0x20000000, it will be shifted by 3 bit to the left end up at 0x100000000 or U32_MAX + 1. It will therefore wrap around and be 0 - resulting in: ((mss * 8) ** 2) / 0 This is of course invalid and cannot be calculated. The calculation should must be simplified to avoid this overflow: (mss ** 2) * 8 / cwnd It will keep the precision enhancement from the scaling (by 8) but avoid the overflow in the divisor. In theory, there could still be an overflow in the dividend. It is at the moment fixed to BATADV_TP_PLEN in batadv_tp_recv_ack() - so it is not an imminent problem. But allowing it to use the whole u32 bit range, would mean that it can still use up to 67 bits. To keep this calculation safe for 32 bit arithmetic, mss must never use more than floor((32 - 3) / 2) bits - or in other words: must never be larger than 16383.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tp_meter: avoid divide-by-zero for dec_cwnd\n\nThe cwnd is always MSS <= cwnd <= 0x20000000. But the calculation in\nbatadv_tp_update_cwnd() assumes unsigned 32 bit arithmetics.\n\n ((mss * 8) ** 2) / (cwnd * 8)\n\nIn case cwnd is actually 0x20000000, it will be shifted by 3 bit to the\nleft end up at 0x100000000 or U32_MAX + 1. It will therefore wrap around\nand be 0 - resulting in:\n\n ((mss * 8) ** 2) / 0\n\nThis is of course invalid and cannot be calculated. The calculation should\nmust be simplified to avoid this overflow:\n\n (mss ** 2) * 8 / cwnd\n\nIt will keep the precision enhancement from the scaling (by 8) but avoid\nthe overflow in the divisor.\n\nIn theory, there could still be an overflow in the dividend. It is at the\nmoment fixed to BATADV_TP_PLEN in batadv_tp_recv_ack() - so it is not an\nimminent problem. But allowing it to use the whole u32 bit range, would\nmean that it can still use up to 67 bits. To keep this calculation safe for\n32 bit arithmetic, mss must never use more than floor((32 - 3) / 2) bits -\nor in other words: must never be larger than 16383.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00174, EPSS Percentile is 0.07122 |
debian: CVE-2026-63836 was patched at 2026-07-14, 2026-07-30
1780.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63838) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ASoC: rsnd: Fix potential out-of-bounds access of component_dais[] component_dais[RSND_MAX_COMPONENT] is initially zero-initialized and later populated in rsnd_dai_of_node(). However, the existing boundary check: if (i >= RSND_MAX_COMPONENT) does not guarantee that the last valid element remains zero. As a result, the loop can rely on component_dais[RSND_MAX_COMPONENT] being zero, which may lead to an out-of-bounds access. Found by Linux Verification Center (linuxtesting.org) with SVACE.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nASoC: rsnd: Fix potential out-of-bounds access of component_dais[]\n\ncomponent_dais[RSND_MAX_COMPONENT] is initially zero-initialized\nand later populated in rsnd_dai_of_node(). However, the existing boundary check:\n if (i >= RSND_MAX_COMPONENT)\n\ndoes not guarantee that the last valid element remains zero. As a result,\nthe loop can rely on component_dais[RSND_MAX_COMPONENT] being zero,\nwhich may lead to an out-of-bounds access.\n\nFound by Linux Verification Center (linuxtesting.org) with SVACE.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06521 |
debian: CVE-2026-63838 was patched at 2026-07-14
ubuntu: CVE-2026-63838 was patched at 2026-07-30
1781.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63859) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: airoha: Add missing bits in airoha_qdma_cleanup_tx_queue() Similar to airoha_qdma_cleanup_rx_queue(), reset DMA TX descriptors in airoha_qdma_cleanup_tx_queue routine. Moreover, reset TX_DMA_IDX to TX_CPU_IDX to notify the NIC the QDMA TX ring is empty.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: airoha: Add missing bits in airoha_qdma_cleanup_tx_queue()\n\nSimilar to airoha_qdma_cleanup_rx_queue(), reset DMA TX descriptors in\nairoha_qdma_cleanup_tx_queue routine. Moreover, reset TX_DMA_IDX to\nTX_CPU_IDX to notify the NIC the QDMA TX ring is empty.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05143 |
debian: CVE-2026-63859 was patched at 2026-07-14
ubuntu: CVE-2026-63859 was patched at 2026-07-30
1782.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63861) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: spi: mtk-snfi: unregister ECC engine on probe failure and remove() callback mtk_snand_probe() registers the on-host NAND ECC engine, but teardown was missing from both probe unwind and remove-time cleanup. Add a devm cleanup action after successful registration so nand_ecc_unregister_on_host_hw_engine() runs automatically on probe failures and during device removal.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nspi: mtk-snfi: unregister ECC engine on probe failure and remove() callback\n\nmtk_snand_probe() registers the on-host NAND ECC engine, but teardown was\nmissing from both probe unwind and remove-time cleanup. Add a devm cleanup\naction after successful registration so\nnand_ecc_unregister_on_host_hw_engine() runs automatically on probe\nfailures and during device removal.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05774 |
debian: CVE-2026-63861 was patched at 2026-07-14
ubuntu: CVE-2026-63861 was patched at 2026-07-30
1783.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63862) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: PCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found In mtk_pcie_setup_irq(), the IRQ domains are allocated before the controller's IRQ is fetched. If the latter fails, the function directly returns an error, without cleaning up the allocated domains. Hence, reverse the order so that the IRQ domains are allocated after the controller's IRQ is found. This was flagged by Sashiko during a review of "[PATCH v6 0/7] PCI: mediatek-gen3: add power control support".', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nPCI: mediatek-gen3: Prevent leaking IRQ domains when IRQ not found\n\nIn mtk_pcie_setup_irq(), the IRQ domains are allocated before the\ncontroller's IRQ is fetched. If the latter fails, the function\ndirectly returns an error, without cleaning up the allocated domains.\n\nHence, reverse the order so that the IRQ domains are allocated after the\ncontroller's IRQ is found.\n\nThis was flagged by Sashiko during a review of "[PATCH v6 0/7] PCI:\nmediatek-gen3: add power control support".', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.0572 |
debian: CVE-2026-63862 was patched at 2026-07-14
ubuntu: CVE-2026-63862 was patched at 2026-07-30
1784.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63868) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr The receive-side GARP attribute parser computes dlen with reversed operands: dlen = sizeof(*ga) - ga->len; ga->len is the on-wire attribute length and includes the GARP attribute header. For normal attributes with data, ga->len is larger than sizeof(*ga), so the subtraction underflows in unsigned arithmetic. The resulting value is later passed to garp_attr_lookup(), whose length argument is u8. After truncation, the parsed data length usually no longer matches the length stored for locally registered attributes, so received Join/Leave events are ignored. This breaks the GARP receive path for common attributes, such as GVRP VLAN registration attributes. Compute the data length as the attribute length minus the header length.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: garp: fix unsigned integer underflow in garp_pdu_parse_attr\n\nThe receive-side GARP attribute parser computes dlen with reversed\noperands:\n\n dlen = sizeof(*ga) - ga->len;\n\nga->len is the on-wire attribute length and includes the GARP attribute\nheader. For normal attributes with data, ga->len is larger than\nsizeof(*ga), so the subtraction underflows in unsigned arithmetic.\n\nThe resulting value is later passed to garp_attr_lookup(), whose length\nargument is u8. After truncation, the parsed data length usually no\nlonger matches the length stored for locally registered attributes, so\nreceived Join/Leave events are ignored. This breaks the GARP receive path\nfor common attributes, such as GVRP VLAN registration attributes.\n\nCompute the data length as the attribute length minus the header length.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06151 |
debian: CVE-2026-63868 was patched at 2026-07-14
1785.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63871) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls iso_connect_bis(), iso_connect_cis(), iso_listen_bis(), and iso_conn_big_sync() call hci_get_route() using iso_pi(sk)->dst, iso_pi(sk)->src, and iso_pi(sk)->src_type without holding lock_sock(). These fields may be modified concurrently by connect() or setsockopt() on the same socket, resulting in data-races reported by KCSAN. Fix this by snapshotting the required fields under lock_sock() before calling hci_get_route(). BUG: KCSAN: data-race in memcmp+0x45/0xb0 race at unknown origin, with read to 0xffff8880122135cf of 1 bytes by task 333 on cpu 1: memcmp+0x45/0xb0 hci_get_route+0x27e/0x490 iso_connect_cis+0x4c/0xa10 iso_sock_connect+0x60e/0xb30 __sys_connect_file+0xbd/0xe0 __sys_connect+0xe0/0x110 __x64_sys_connect+0x40/0x50 x64_sys_call+0xcad/0x1c60 do_syscall_64+0x133/0x590 entry_SYSCALL_64_after_hwframe+0x77/0x7f', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: Fix data-race on iso_pi fields in hci_get_route calls\n\niso_connect_bis(), iso_connect_cis(), iso_listen_bis(), and\niso_conn_big_sync() call hci_get_route() using iso_pi(sk)->dst,\niso_pi(sk)->src, and iso_pi(sk)->src_type without holding lock_sock().\n\nThese fields may be modified concurrently by connect() or setsockopt()\non the same socket, resulting in data-races reported by KCSAN.\n\nFix this by snapshotting the required fields under lock_sock() before\ncalling hci_get_route().\n\nBUG: KCSAN: data-race in memcmp+0x45/0xb0\n\nrace at unknown origin, with read to 0xffff8880122135cf of 1 bytes\nby task 333 on cpu 1:\n memcmp+0x45/0xb0\n hci_get_route+0x27e/0x490\n iso_connect_cis+0x4c/0xa10\n iso_sock_connect+0x60e/0xb30\n __sys_connect_file+0xbd/0xe0\n __sys_connect+0xe0/0x110\n __x64_sys_connect+0x40/0x50\n x64_sys_call+0xcad/0x1c60\n do_syscall_64+0x133/0x590\n entry_SYSCALL_64_after_hwframe+0x77/0x7f', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.05328 |
debian: CVE-2026-63871 was patched at 2026-07-14
1786.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63890) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker drivers/scsi/fcoe/fcoe_ctlr.c::fcoe_ctlr_recv_clr_vlink() advanced the descriptor cursor by an attacker-supplied fip_dlen without ever requiring dlen >= sizeof(struct fip_desc) in the default branch. The named descriptor cases (FIP_DT_MAC, FIP_DT_NAME, FIP_DT_VN_ID) checked their per-type minimum lengths, but a FIP_DT_NON_CRITICAL descriptor (fip_dtype >= 128, which the standard requires receivers to silently ignore) skipped that check entirely. An unauthenticated L2 peer on the FCoE control VLAN could hang fcoe_ctlr_recv_work on an fcoe, qedf, or bnx2fc initiator indefinitely by emitting one FIP CVL frame whose single descriptor had fip_dtype == FIP_DT_NON_CRITICAL and fip_dlen == 0: the cursor advanced zero bytes per iteration and the loop condition rlen >= sizeof(*desc) stayed true forever, blocking every subsequent FIP frame on that controller. Tighten the outer dlen guard to also reject dlen < sizeof(struct fip_desc), so a malformed descriptor whose length cannot even cover the descriptor header is rejected before the switch. This is the same lower-bound the named cases already apply and is the minimum scope that closes the loop.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nscsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker\n\ndrivers/scsi/fcoe/fcoe_ctlr.c::fcoe_ctlr_recv_clr_vlink() advanced the\ndescriptor cursor by an attacker-supplied fip_dlen without ever\nrequiring dlen >= sizeof(struct fip_desc) in the default branch. The\nnamed descriptor cases (FIP_DT_MAC, FIP_DT_NAME, FIP_DT_VN_ID) checked\ntheir per-type minimum lengths, but a FIP_DT_NON_CRITICAL descriptor\n(fip_dtype >= 128, which the standard requires receivers to silently\nignore) skipped that check entirely.\n\nAn unauthenticated L2 peer on the FCoE control VLAN could hang\nfcoe_ctlr_recv_work on an fcoe, qedf, or bnx2fc initiator indefinitely\nby emitting one FIP CVL frame whose single descriptor had fip_dtype ==\nFIP_DT_NON_CRITICAL and fip_dlen == 0: the cursor advanced zero bytes\nper iteration and the loop condition rlen >= sizeof(*desc) stayed true\nforever, blocking every subsequent FIP frame on that controller.\n\nTighten the outer dlen guard to also reject dlen < sizeof(struct\nfip_desc), so a malformed descriptor whose length cannot even cover the\ndescriptor header is rejected before the switch. This is the same\nlower-bound the named cases already apply and is the minimum scope that\ncloses the loop.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11448 |
debian: CVE-2026-63890 was patched at 2026-07-14
ubuntu: CVE-2026-63890 was patched at 2026-07-30
1787.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63892) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow On the non-root path, __tb_property_parse_dir() takes dir_len from entry->length (u16 widened to size_t). Two distinct OOB conditions follow when entry->length < 4: 1. The non-root path begins with kmemdup(&block[dir_offset], sizeof(*dir->uuid), ...) which always reads 4 dwords from dir_offset. tb_property_entry_valid() only enforces dir_offset + entry->length <= block_len, so a crafted entry with dir_offset close to the end of the property block and entry->length in 0..3 passes that gate but lets the UUID copy run off the block (e.g. dir_offset = 497, dir_len = 3 in a 500-dword block reads block[497..501]). 2. After the kmemdup, content_len = dir_len - 4 underflows size_t to ~SIZE_MAX, nentries becomes SIZE_MAX / 4, and the entry walk runs OOB on each iteration until an entry fails validation or the kernel oopses on an unmapped page. Reject dir_len < 4 on the non-root path *before* the UUID kmemdup, which closes both holes. Also move INIT_LIST_HEAD(&dir->properties) up to immediately after the dir allocation so the new error-return path (and the existing uuid-alloc failure path) calling tb_property_free_dir() sees a walkable list rather than the zero-initialized NULL next/prev that list_for_each_entry_safe() would oops on.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nthunderbolt: property: Reject dir_len < 4 to prevent size_t underflow\n\nOn the non-root path, __tb_property_parse_dir() takes dir_len from\nentry->length (u16 widened to size_t). Two distinct OOB conditions\nfollow when entry->length < 4:\n\n1. The non-root path begins with kmemdup(&block[dir_offset],\n sizeof(*dir->uuid), ...) which always reads 4 dwords from\n dir_offset. tb_property_entry_valid() only enforces\n dir_offset + entry->length <= block_len, so a crafted entry\n with dir_offset close to the end of the property block and\n entry->length in 0..3 passes that gate but lets the UUID copy\n run off the block (e.g. dir_offset = 497, dir_len = 3 in a\n 500-dword block reads block[497..501]).\n\n2. After the kmemdup, content_len = dir_len - 4 underflows size_t\n to ~SIZE_MAX, nentries becomes SIZE_MAX / 4, and the entry\n walk runs OOB on each iteration until an entry fails\n validation or the kernel oopses on an unmapped page.\n\nReject dir_len < 4 on the non-root path *before* the UUID kmemdup,\nwhich closes both holes.\n\nAlso move INIT_LIST_HEAD(&dir->properties) up to immediately after\nthe dir allocation so the new error-return path (and the existing\nuuid-alloc failure path) calling tb_property_free_dir() sees a\nwalkable list rather than the zero-initialized NULL next/prev that\nlist_for_each_entry_safe() would oops on.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12627 |
debian: CVE-2026-63892 was patched at 2026-07-14
ubuntu: CVE-2026-63892 was patched at 2026-07-30
1788.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63896) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: gadget: composite: fix integer underflow in WebUSB GET_URL handling The WebUSB GET_URL handler in composite_setup() narrows landing_page_length to fit the host-supplied wLength using \tlanding_page_length = w_length \t\t- WEBUSB_URL_DESCRIPTOR_HEADER_LENGTH + landing_page_offset; If wLength is smaller than WEBUSB_URL_DESCRIPTOR_HEADER_LENGTH the unsigned subtraction wraps, and the subsequent \tmemcpy(url_descriptor->URL, \t cdev->landing_page + landing_page_offset, \t landing_page_length - landing_page_offset); ends up copying close to UINT_MAX bytes from cdev->landing_page into cdev->req->buf. KASAN reports a slab-out-of-bounds in composite_setup on the kmalloc-2k gadget_info allocation, and FORTIFY_SOURCE traps the memcpy as a 4294967293-byte field-spanning write into url_descriptor->URL (size 252). A USB host can reach this from a single SETUP packet against any gadget that has webusb/use=1 and a landingPage configured. Handle the small-wLength case before the math: when the host requested fewer bytes than the URL descriptor header, only the header is meaningful and no URL bytes need to be copied. Setting landing_page_length to landing_page_offset makes the existing memcpy a no-op and leaves the descriptor returned to the host unchanged for all larger wLength values.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: gadget: composite: fix integer underflow in WebUSB GET_URL handling\n\nThe WebUSB GET_URL handler in composite_setup() narrows\nlanding_page_length to fit the host-supplied wLength using\n\n\tlanding_page_length = w_length\n\t\t- WEBUSB_URL_DESCRIPTOR_HEADER_LENGTH + landing_page_offset;\n\nIf wLength is smaller than WEBUSB_URL_DESCRIPTOR_HEADER_LENGTH the\nunsigned subtraction wraps, and the subsequent\n\n\tmemcpy(url_descriptor->URL,\n\t cdev->landing_page + landing_page_offset,\n\t landing_page_length - landing_page_offset);\n\nends up copying close to UINT_MAX bytes from cdev->landing_page into\ncdev->req->buf. KASAN reports a slab-out-of-bounds in composite_setup\non the kmalloc-2k gadget_info allocation, and FORTIFY_SOURCE traps the\nmemcpy as a 4294967293-byte field-spanning write into\nurl_descriptor->URL (size 252).\n\nA USB host can reach this from a single SETUP packet against any\ngadget that has webusb/use=1 and a landingPage configured.\n\nHandle the small-wLength case before the math: when the host requested\nfewer bytes than the URL descriptor header, only the header is\nmeaningful and no URL bytes need to be copied. Setting\nlanding_page_length to landing_page_offset makes the existing memcpy a\nno-op and leaves the descriptor returned to the host unchanged for all\nlarger wLength values.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10109 |
debian: CVE-2026-63896 was patched at 2026-07-14
ubuntu: CVE-2026-63896 was patched at 2026-07-30
1789.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63897) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: USB: serial: mct_u232: fix missing interrupt-in transfer sanity check Add the missing sanity check on the size of interrupt-in transfers to avoid parsing stale or uninitialised slab data (and leaking it to user space).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: mct_u232: fix missing interrupt-in transfer sanity check\n\nAdd the missing sanity check on the size of interrupt-in transfers to\navoid parsing stale or uninitialised slab data (and leaking it to user\nspace).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11454 |
debian: CVE-2026-63897 was patched at 2026-07-14
ubuntu: CVE-2026-63897 was patched at 2026-07-30
1790.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63900) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: USB: serial: keyspan: fix missing indat transfer sanity check Add the missing sanity check on the size of usa49wg indat transfers to avoid parsing stale or uninitialised slab data.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: keyspan: fix missing indat transfer sanity check\n\nAdd the missing sanity check on the size of usa49wg indat transfers to\navoid parsing stale or uninitialised slab data.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11454 |
debian: CVE-2026-63900 was patched at 2026-07-14
ubuntu: CVE-2026-63900 was patched at 2026-07-30
1791.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63902) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: USB: serial: cypress_m8: validate interrupt packet headers cypress_read_int_callback() parses the interrupt-in buffer according to the selected Cypress packet format. Format 1 has a two-byte status/count header and format 2 has a one-byte combined status/count header. The usb-serial core sizes the interrupt-in buffer from the endpoint descriptor's wMaxPacketSize, and successful interrupt transfers can complete short when URB_SHORT_NOT_OK is not set. Check that the completed packet contains the selected header before reading it. Malformed short reports are ignored and the interrupt URB is resubmitted through the existing retry path, preventing out-of-bounds header-byte reads. KASAN report as below: KASAN slab-out-of-bounds in cypress_read_int_callback+0x240/0x7f0 Read of size 1 Call trace: cypress_read_int_callback() (drivers/usb/serial/cypress_m8.c:1009) __usb_hcd_giveback_urb() dummy_timer() [ johan: use constants in header length sanity checks ]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: cypress_m8: validate interrupt packet headers\n\ncypress_read_int_callback() parses the interrupt-in buffer according to\nthe selected Cypress packet format. Format 1 has a two-byte status/count\nheader and format 2 has a one-byte combined status/count header. The\nusb-serial core sizes the interrupt-in buffer from the endpoint\ndescriptor's wMaxPacketSize, and successful interrupt transfers can\ncomplete short when URB_SHORT_NOT_OK is not set.\n\nCheck that the completed packet contains the selected header before\nreading it. Malformed short reports are ignored and the interrupt URB is\nresubmitted through the existing retry path, preventing out-of-bounds\nheader-byte reads.\n\nKASAN report as below:\nKASAN slab-out-of-bounds in cypress_read_int_callback+0x240/0x7f0\nRead of size 1\nCall trace:\n cypress_read_int_callback() (drivers/usb/serial/cypress_m8.c:1009)\n __usb_hcd_giveback_urb()\n dummy_timer()\n\n[ johan: use constants in header length sanity checks ]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11448 |
debian: CVE-2026-63902 was patched at 2026-07-14
ubuntu: CVE-2026-63902 was patched at 2026-07-30
1792.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63903) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: USB: serial: belkin_sa: validate interrupt status length The Belkin interrupt callback treats interrupt data as a four-byte status report and reads LSR/MSR fields at offsets 2 and 3. The interrupt-in buffer length is derived from endpoint wMaxPacketSize, and short interrupt transfers may complete successfully with a smaller actual_length. Check the completed interrupt packet length before parsing status fields so short interrupt endpoints and short successful packets are ignored instead of causing out-of-bounds or stale status-byte reads. KASAN report as below: BUG: KASAN: slab-out-of-bounds in belkin_sa_read_int_callback() Read of size 1 Call trace: belkin_sa_read_int_callback() (drivers/usb/serial/belkin_sa.c:202) __usb_hcd_giveback_urb() (drivers/usb/core/hcd.c:1630) dummy_timer() (?:?)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nUSB: serial: belkin_sa: validate interrupt status length\n\nThe Belkin interrupt callback treats interrupt data as a four-byte\nstatus report and reads LSR/MSR fields at offsets 2 and 3. The\ninterrupt-in buffer length is derived from endpoint wMaxPacketSize, and\nshort interrupt transfers may complete successfully with a smaller\nactual_length.\n\nCheck the completed interrupt packet length before parsing status\nfields so short interrupt endpoints and short successful packets are\nignored instead of causing out-of-bounds or stale status-byte reads.\n\nKASAN report as below:\n\nBUG: KASAN: slab-out-of-bounds in belkin_sa_read_int_callback()\nRead of size 1\nCall trace:\n belkin_sa_read_int_callback() (drivers/usb/serial/belkin_sa.c:202)\n __usb_hcd_giveback_urb() (drivers/usb/core/hcd.c:1630)\n dummy_timer() (?:?)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.1145 |
debian: CVE-2026-63903 was patched at 2026-07-14
ubuntu: CVE-2026-63903 was patched at 2026-07-30
1793.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63908) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem When a configuration file provides an object size that is larger than the driver's known mxt_obj_size(object), the driver intends to discard the extra bytes. The loop iterates using for (i = 0; i < size; i++). Inside the loop, the condition to skip processing extra bytes is: if (i > mxt_obj_size(object)) continue; Since i is a 0-based index, the valid indices for the object are 0 through mxt_obj_size(object) - 1. When i == mxt_obj_size(object), the condition evaluates to false, and the code processes the byte instead of discarding it. This causes the code to calculate byte_offset = reg + i - cfg->start_ofs and writes the byte there, overwriting exactly one byte of the adjacent instance or object. Update the boundary check to skip extra bytes correctly by using >=.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: atmel_mxt_ts - fix boundary check in mxt_prepare_cfg_mem\n\nWhen a configuration file provides an object size that is larger than the\ndriver's known mxt_obj_size(object), the driver intends to discard the\nextra bytes.\n\nThe loop iterates using for (i = 0; i < size; i++). Inside the loop, the\ncondition to skip processing extra bytes is:\n\n if (i > mxt_obj_size(object))\n continue;\n\nSince i is a 0-based index, the valid indices for the object are 0 through\nmxt_obj_size(object) - 1.\n\nWhen i == mxt_obj_size(object), the condition evaluates to false, and the\ncode processes the byte instead of discarding it.\n\nThis causes the code to calculate byte_offset = reg + i - cfg->start_ofs\nand writes the byte there, overwriting exactly one byte of the adjacent\ninstance or object.\n\nUpdate the boundary check to skip extra bytes correctly by using >=.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11449 |
debian: CVE-2026-63908 was patched at 2026-07-14
ubuntu: CVE-2026-63908 was patched at 2026-07-30
1794.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63929) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf() iio_buffer_enqueue_dmabuf() allocates a struct iio_dma_fence (104 bytes, kmalloc-128) via kmalloc_obj()+dma_fence_init(), which sets the initial kref to 1. It then calls dma_resv_add_fence() which takes a second reference (kref=2), and stores a raw pointer in block->fence. On the success path the function returns without calling dma_fence_put() to release the initial reference, so every buffer enqueue permanently leaks one kmalloc-128 allocation. The iio_buffer_cleanup() work item only releases the temporary reference taken during completion signalling by iio_buffer_signal_dmabuf_done(); the initial reference from dma_fence_init() is never released. With four iio_rwdev instances at 240kHz and 512 samples per buffer, this produces ~1875 kmalloc-128 allocations per second matching the observed slab growth exactly. A test with ftrace confirmed that the dma_fence_destroy event was never triggered. Fix by calling dma_fence_put() after dma_resv_add_fence(), transferring ownership of the fence to the DMA reservation object. The DMA fence then gets properly discarded after being signalled.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niio: buffer: Fix DMA fence leak in iio_buffer_enqueue_dmabuf()\n\niio_buffer_enqueue_dmabuf() allocates a struct iio_dma_fence (104 bytes,\nkmalloc-128) via kmalloc_obj()+dma_fence_init(), which sets the initial\nkref to 1. It then calls dma_resv_add_fence() which takes a second\nreference (kref=2), and stores a raw pointer in block->fence.\n\nOn the success path the function returns without calling dma_fence_put()\nto release the initial reference, so every buffer enqueue permanently\nleaks one kmalloc-128 allocation.\n\nThe iio_buffer_cleanup() work item only releases the temporary reference\ntaken during completion signalling by iio_buffer_signal_dmabuf_done();\nthe initial reference from dma_fence_init() is never released.\n\nWith four iio_rwdev instances at 240kHz and 512 samples per buffer,\nthis produces ~1875 kmalloc-128 allocations per second matching the\nobserved slab growth exactly. A test with ftrace confirmed that the\ndma_fence_destroy event was never triggered.\n\nFix by calling dma_fence_put() after dma_resv_add_fence(), transferring\nownership of the fence to the DMA reservation object. The DMA fence then\ngets properly discarded after being signalled.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10108 |
debian: CVE-2026-63929 was patched at 2026-07-14
ubuntu: CVE-2026-63929 was patched at 2026-07-30
1795.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63931) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iio: chemical: scd30: fix division by zero in write_raw Add a zero check for val2 before using it as a divisor when setting the sampling frequency. A user writing a zero fractional part to the sampling_frequency sysfs attribute triggers a division by zero in the kernel.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niio: chemical: scd30: fix division by zero in write_raw\n\nAdd a zero check for val2 before using it as a divisor when setting the\nsampling frequency. A user writing a zero fractional part to the\nsampling_frequency sysfs attribute triggers a division by zero in the\nkernel.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11448 |
debian: CVE-2026-63931 was patched at 2026-07-14
ubuntu: CVE-2026-63931 was patched at 2026-07-30
1796.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63933) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iio: gyro: adis16260: fix division by zero in write_raw Add a validation check for the sampling frequency value before using it as a divisor. A user writing zero to the sampling_frequency sysfs attribute triggers a division by zero in the kernel.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niio: gyro: adis16260: fix division by zero in write_raw\n\nAdd a validation check for the sampling frequency value before using it\nas a divisor. A user writing zero to the sampling_frequency sysfs\nattribute triggers a division by zero in the kernel.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11449 |
debian: CVE-2026-63933 was patched at 2026-07-14
ubuntu: CVE-2026-63933 was patched at 2026-07-30
1797.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63934) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iio: gyro: itg3200: fix i2c read into the wrong stack location itg3200_read_all_channels() takes `__be16 *buf' as a parameter and fills the i2c_msg destination as `(char *)&buf'. Since `buf' is the parameter (a pointer), `&buf' is the address of the local pointer slot on the stack of itg3200_read_all_channels(), not the address of the caller's scan buffer. The (char *) cast hides the type mismatch. i2c_transfer() therefore writes ITG3200_SCAN_ELEMENTS * sizeof(s16) = 8 bytes into the parameter's stack slot, which is discarded when the function returns. The caller's scan buffer in itg3200_trigger_handler() is never written to, so iio_push_to_buffers_with_timestamp() pushes uninitialised stack contents to userspace via /dev/iio:deviceX every scan -- both a functional bug (no actual gyroscope or temperature data is delivered through the triggered buffer) and an information leak. The non-buffered read_raw() path is unaffected: it goes through itg3200_read_reg_s16() which uses `&out' on a local s16 value, where that is correct. Drop the spurious `&' so the i2c read writes into the caller's buffer.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niio: gyro: itg3200: fix i2c read into the wrong stack location\n\nitg3200_read_all_channels() takes `__be16 *buf' as a parameter and\nfills the i2c_msg destination as `(char *)&buf'. Since `buf' is the\nparameter (a pointer), `&buf' is the address of the local pointer\nslot on the stack of itg3200_read_all_channels(), not the address\nof the caller's scan buffer. The (char *) cast hides the type\nmismatch.\n\ni2c_transfer() therefore writes ITG3200_SCAN_ELEMENTS * sizeof(s16)\n= 8 bytes into the parameter's stack slot, which is discarded when\nthe function returns. The caller's scan buffer in\nitg3200_trigger_handler() is never written to, so\niio_push_to_buffers_with_timestamp() pushes uninitialised stack\ncontents to userspace via /dev/iio:deviceX every scan -- both a\nfunctional bug (no actual gyroscope or temperature data is\ndelivered through the triggered buffer) and an information leak.\n\nThe non-buffered read_raw() path is unaffected: it goes through\nitg3200_read_reg_s16() which uses `&out' on a local s16 value,\nwhere that is correct.\n\nDrop the spurious `&' so the i2c read writes into the caller's\nbuffer.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11416 |
debian: CVE-2026-63934 was patched at 2026-07-14
ubuntu: CVE-2026-63934 was patched at 2026-07-30
1798.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63936) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iio: adc: mt6359: fix unchecked return value in mt6358_read_imp In mt6358_read_imp(), the variable val_v is passed to regmap_read() but the return value is not checked. If the read fails, val_v remains uninitialized and its random stack content is subsequently reported as a measurement result. Initialize val_v to zero to ensure a predictable value is reported in case of bus failure and to prevent potential stack data leakage. This also satisfies static analyzers that might otherwise flag the variable as used uninitialized.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niio: adc: mt6359: fix unchecked return value in mt6358_read_imp\n\nIn mt6358_read_imp(), the variable val_v is passed to regmap_read()\nbut the return value is not checked. If the read fails, val_v remains\nuninitialized and its random stack content is subsequently reported\nas a measurement result.\n\nInitialize val_v to zero to ensure a predictable value is reported\nin case of bus failure and to prevent potential stack data leakage.\nThis also satisfies static analyzers that might otherwise flag the\nvariable as used uninitialized.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.1011 |
debian: CVE-2026-63936 was patched at 2026-07-14
ubuntu: CVE-2026-63936 was patched at 2026-07-30
1799.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63943) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Input: xpad - fix out-of-bounds access for Share button xpadone_process_packet() receives len directly from urb->actual_length and uses it to index the share-button byte at data[len - 18] or data[len - 26]. Since both len and data[0] are under the device's control, a broken controller can send a GIP_CMD_INPUT packet with actual_length < 18 (e.g. 5 bytes) and reach this code path, causing accesses beyond the actual array. Fix this by calculating the offset and checking bounds against the packet length.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nInput: xpad - fix out-of-bounds access for Share button\n\nxpadone_process_packet() receives len directly from urb->actual_length\nand uses it to index the share-button byte at data[len - 18] or\ndata[len - 26]. Since both len and data[0] are under the device's\ncontrol, a broken controller can send a GIP_CMD_INPUT packet with\nactual_length < 18 (e.g. 5 bytes) and reach this code path, causing\naccesses beyond the actual array.\n\nFix this by calculating the offset and checking bounds against the\npacket length.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10111 |
debian: CVE-2026-63943 was patched at 2026-07-14
ubuntu: CVE-2026-63943 was patched at 2026-07-30
1800.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63948) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn __set_chan_timer() takes a l2cap_chan reference via l2cap_chan_hold() before scheduling the delayed work. The normal path in l2cap_chan_timeout() drops this reference with l2cap_chan_put() at the end, but the early return when chan->conn is NULL skips the put, leaking the reference. Add the missing l2cap_chan_put() before the early return.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: fix chan ref leak in l2cap_chan_timeout() on !conn\n\n__set_chan_timer() takes a l2cap_chan reference via l2cap_chan_hold()\nbefore scheduling the delayed work. The normal path in\nl2cap_chan_timeout() drops this reference with l2cap_chan_put() at the\nend, but the early return when chan->conn is NULL skips the put,\nleaking the reference.\n\nAdd the missing l2cap_chan_put() before the early return.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11447 |
debian: CVE-2026-63948 was patched at 2026-07-14
ubuntu: CVE-2026-63948 was patched at 2026-07-30
1801.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63949) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: auxdisplay: line-display: fix OOB read on zero-length message_store() linedisp_display() unconditionally reads msg[count - 1] before checking whether count is zero, so a write of zero bytes to the message sysfs attribute hits msg[-1]: \twrite(fd, "", 0); \t-> message_store(..., buf, count=0) \t -> linedisp_display(linedisp, buf, count=0) \t -> msg[count - 1] == '\\n' ; OOB read The kernfs write buffer for that store is a 1-byte allocation (kernfs_fop_write_iter() does kmalloc(len + 1) with len == 0), so msg[-1] is a 1-byte read before the slab object. On a KASAN-enabled kernel this trips an out-of-bounds report and panics; on stock kernels it silently reads adjacent slab data and, if that byte happens to be '\\n', the following count-- wraps ssize_t 0 to -1 and is then passed to kmemdup_nul(). linedisp_display() is reached from the message_store() sysfs callback (drivers/auxdisplay/line-display.c message attribute, mode 0644) and from the in-tree initial-message setup with count == -1, so the OOB path is only userspace-triggerable via zero-byte writes; vfs_write() does not short-circuit on count == 0 and kernfs_fop_write_iter() dispatches the store callback regardless. Guard the trailing-newline trim with a count check. The existing if (!count) block then takes the clear-display path unchanged. Affects every auxdisplay driver that registers via linedisp_register() / linedisp_attach(): ht16k33, max6959, img-ascii-lcd, seg-led-gpio.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nauxdisplay: line-display: fix OOB read on zero-length message_store()\n\nlinedisp_display() unconditionally reads msg[count - 1] before\nchecking whether count is zero, so a write of zero bytes to the\nmessage sysfs attribute hits msg[-1]:\n\n\twrite(fd, "", 0);\n\n\t-> message_store(..., buf, count=0)\n\t -> linedisp_display(linedisp, buf, count=0)\n\t -> msg[count - 1] == '\\n' ; OOB read\n\nThe kernfs write buffer for that store is a 1-byte allocation\n(kernfs_fop_write_iter() does kmalloc(len + 1) with len == 0),\nso msg[-1] is a 1-byte read before the slab object. On a\nKASAN-enabled kernel this trips an out-of-bounds report and\npanics; on stock kernels it silently reads adjacent slab data\nand, if that byte happens to be '\\n', the following count--\nwraps ssize_t 0 to -1 and is then passed to kmemdup_nul().\n\nlinedisp_display() is reached from the message_store() sysfs\ncallback (drivers/auxdisplay/line-display.c message attribute,\nmode 0644) and from the in-tree initial-message setup with\ncount == -1, so the OOB path is only userspace-triggerable via\nzero-byte writes; vfs_write() does not short-circuit on\ncount == 0 and kernfs_fop_write_iter() dispatches the store\ncallback regardless.\n\nGuard the trailing-newline trim with a count check. The\nexisting if (!count) block then takes the clear-display path\nunchanged.\n\nAffects every auxdisplay driver that registers via\nlinedisp_register() / linedisp_attach(): ht16k33, max6959,\nimg-ascii-lcd, seg-led-gpio.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06898 |
debian: CVE-2026-63949 was patched at 2026-07-14
ubuntu: CVE-2026-63949 was patched at 2026-07-30
1802.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63958) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: validate connector number in ucsi_connector_change() The connector number in a UCSI CCI notification is a 7-bit field supplied by the PPM. ucsi_connector_change() uses it to index the ucsi->connector[] array without checking it against the number of connectors the PPM reported at init time, so a buggy or malicious PPM (EC firmware, or an I2C-attached UCSI controller on the ccg / stm32g0 / glink transports) can drive schedule_work() on memory past the end of the array. Reject connector numbers that are zero or exceed cap.num_connectors before dereferencing the array.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: validate connector number in ucsi_connector_change()\n\nThe connector number in a UCSI CCI notification is a 7-bit field\nsupplied by the PPM. ucsi_connector_change() uses it to index the\nucsi->connector[] array without checking it against the number of\nconnectors the PPM reported at init time, so a buggy or malicious PPM\n(EC firmware, or an I2C-attached UCSI controller on the ccg / stm32g0 /\nglink transports) can drive schedule_work() on memory past the end of\nthe array.\n\nReject connector numbers that are zero or exceed cap.num_connectors\nbefore dereferencing the array.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.10802 |
debian: CVE-2026-63958 was patched at 2026-07-14
ubuntu: CVE-2026-63958 was patched at 2026-07-30
1803.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63959) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT A broken/malicious port can transmit a CRC-valid frame whose header advertises up to seven data objects but whose body carries fewer than that. Check for this, and rightfully reject the message, instead of reading from uninitialized stack memory.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpm/tcpci_maxim: validate header NDO against RX_BYTE_CNT\n\nA broken/malicious port can transmit a CRC-valid frame whose header\nadvertises up to seven data objects but whose body carries fewer than\nthat. Check for this, and rightfully reject the message, instead of\nreading from uninitialized stack memory.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.1011 |
debian: CVE-2026-63959 was patched at 2026-07-14
ubuntu: CVE-2026-63959 was patched at 2026-07-30
1804.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63960) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer() wcove_read_rx_buffer() copies the PD RX FIFO into the caller's struct pd_message with \tfor (i = 0; i < USBC_RXINFO_RXBYTES(info); i++) \t\tregmap_read(wcove->regmap, USBC_RX_DATA + i, msg + i); which has two problems: USBC_RXINFO_RXBYTES() is a 5-bit field (max 31) while struct pd_message is 30 bytes (__le16 header + __le32 payload[PD_MAX_PAYLOAD], packed). The byte count latched in RXINFO is the number of bytes the port partner put on the wire, so a malicious partner that transmits a 31-byte frame can drive the loop one byte past the destination if the WCOVE BMC receiver does not enforce the PD object-count limit in hardware. The existing FIXME flagged this as unverified. Independently, regmap_read() takes an unsigned int * and stores a full unsigned int at the destination. Passing the byte pointer msg + i means each iteration writes four bytes; the high three are zero (val_bits is 8) and are normally overwritten by the next iteration, but the final iteration's high bytes are not. With RXBYTES == 30 the i == 29 iteration already writes three zero bytes past msg, which sits on the IRQ thread's stack in wcove_typec_irq(). Clamp the loop to sizeof(struct pd_message) and read each register into a local before storing only its low byte, so the copy can never exceed the destination regardless of what RXINFO reports.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: wcove: don't write past struct pd_message in wcove_read_rx_buffer()\n\nwcove_read_rx_buffer() copies the PD RX FIFO into the caller's\nstruct pd_message with\n\n\tfor (i = 0; i < USBC_RXINFO_RXBYTES(info); i++)\n\t\tregmap_read(wcove->regmap, USBC_RX_DATA + i, msg + i);\n\nwhich has two problems:\n\nUSBC_RXINFO_RXBYTES() is a 5-bit field (max 31) while struct pd_message\nis 30 bytes (__le16 header + __le32 payload[PD_MAX_PAYLOAD], packed).\nThe byte count latched in RXINFO is the number of bytes the port partner\nput on the wire, so a malicious partner that transmits a 31-byte frame\ncan drive the loop one byte past the destination if the WCOVE BMC\nreceiver does not enforce the PD object-count limit in hardware. The\nexisting FIXME flagged this as unverified.\n\nIndependently, regmap_read() takes an unsigned int * and stores a full\nunsigned int at the destination. Passing the byte pointer msg + i means\neach iteration writes four bytes; the high three are zero (val_bits is\n8) and are normally overwritten by the next iteration, but the final\niteration's high bytes are not. With RXBYTES == 30 the i == 29 iteration\nalready writes three zero bytes past msg, which sits on the IRQ thread's\nstack in wcove_typec_irq().\n\nClamp the loop to sizeof(struct pd_message) and read each register into\na local before storing only its low byte, so the copy can never exceed\nthe destination regardless of what RXINFO reports.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11454 |
debian: CVE-2026-63960 was patched at 2026-07-14
ubuntu: CVE-2026-63960 was patched at 2026-07-30
1805.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63961) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: typec: altmodes/displayport: validate count before reading Status Update VDO A broken/malicious device can send the incorrect count for a status update VDO, which will cause the kernel to read uninitialized stack data and send it off elsewhere. Fix this up by correctly verifying the count for the update object.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: altmodes/displayport: validate count before reading Status Update VDO\n\nA broken/malicious device can send the incorrect count for a status\nupdate VDO, which will cause the kernel to read uninitialized stack data\nand send it off elsewhere.\n\nFix this up by correctly verifying the count for the update object.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11452 |
debian: CVE-2026-63961 was patched at 2026-07-14
ubuntu: CVE-2026-63961 was patched at 2026-07-30
1806.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63962) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() svdm_consume_modes() checks pmdata->altmodes against the array size once before the loop over the count, but forgot to check the bound at every point in the loop. In the well-behaved SVDM discovery flow this is harmless because each of at most SVID_DISCOVERY_MAX SVIDs contributes at most MODE_DISCOVERY_MAX modes, exactly filling altmode_desc[ALTMODE_DISCOVERY_MAX]. But the CMDT_RSP_ACK handler in tcpm_pd_svdm() does not correlate an incoming ACK with any request the port actually sent. Once port->partner is set, an unsolicited Discover Modes ACK is consumed unconditionally. A broken or malicious port partner can therefore drive altmodes to ALTMODE_DISCOVERY_MAX - 1 via the normal flow, and then send one extra Discover Modes ACK with seven VDOs. Because the pre-loop check passes, the loop could then writes up to five entries past altmode_desc[]. For mode_data_prime the next field in struct tcpm_port is the partner_altmode[] pointer array, which then receives partner-chosen SVID/VDO bytes. Move the bound check inside the loop so the array can never be indexed past ALTMODE_DISCOVERY_MAX regardless of how many VDOs the partner supplies or how the function was reached.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes()\n\nsvdm_consume_modes() checks pmdata->altmodes against the array size once\nbefore the loop over the count, but forgot to check the bound at every\npoint in the loop.\n\nIn the well-behaved SVDM discovery flow this is harmless because each of\nat most SVID_DISCOVERY_MAX SVIDs contributes at most MODE_DISCOVERY_MAX\nmodes, exactly filling altmode_desc[ALTMODE_DISCOVERY_MAX]. But the\nCMDT_RSP_ACK handler in tcpm_pd_svdm() does not correlate an incoming\nACK with any request the port actually sent. Once port->partner is set,\nan unsolicited Discover Modes ACK is consumed unconditionally. A broken\nor malicious port partner can therefore drive altmodes to\nALTMODE_DISCOVERY_MAX - 1 via the normal flow, and then send one extra\nDiscover Modes ACK with seven VDOs. Because the pre-loop check passes,\nthe loop could then writes up to five entries past altmode_desc[]. For\nmode_data_prime the next field in struct tcpm_port is the\npartner_altmode[] pointer array, which then receives partner-chosen\nSVID/VDO bytes.\n\nMove the bound check inside the loop so the array can never be indexed\npast ALTMODE_DISCOVERY_MAX regardless of how many VDOs the partner\nsupplies or how the function was reached.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10111 |
debian: CVE-2026-63962 was patched at 2026-07-14
ubuntu: CVE-2026-63962 was patched at 2026-07-30
1807.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63963) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: validate VDO count in Discover Identity ACK handlers Properly validate the count passed from a device when calling svdm_consume_identity() or svdm_consume_identity_sop_prime() as the device-controlled value could index off of the static arrays, which could leak data.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: tcpm: validate VDO count in Discover Identity ACK handlers\n\nProperly validate the count passed from a device when calling\nsvdm_consume_identity() or svdm_consume_identity_sop_prime() as the\ndevice-controlled value could index off of the static arrays, which\ncould leak data.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.002, EPSS Percentile is 0.10111 |
debian: CVE-2026-63963 was patched at 2026-07-14
ubuntu: CVE-2026-63963 was patched at 2026-07-30
1808.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63964) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: usb: typec: ucsi: ccg: reject firmware images without a ':' record header do_flash() locates the first .cyacd record with \tp = strnchr(fw->data, fw->size, ':'); \twhile (p < eof) { \t\ts = strnchr(p + 1, eof - p - 1, ':'); \t\t... \t} If the firmware image contains no ':' byte, strnchr() returns NULL. NULL compares less than the valid kernel pointer eof, so the loop body runs and strnchr() is called with p + 1 == (void *)1 and a length of roughly (unsigned long)eof, causing a wonderful crash. The not_signed_fw fallthrough earlier in do_flash() and the chip-state branches in ccg_fw_update_needed() allow an unsigned blob to reach this loop, so a root user who can place a crafted file under /lib/firmware and write the do_flash sysfs attribute can trigger the oops. Bail out with -EINVAL when the initial strnchr() returns NULL.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nusb: typec: ucsi: ccg: reject firmware images without a ':' record header\n\ndo_flash() locates the first .cyacd record with\n\n\tp = strnchr(fw->data, fw->size, ':');\n\twhile (p < eof) {\n\t\ts = strnchr(p + 1, eof - p - 1, ':');\n\t\t...\n\t}\n\nIf the firmware image contains no ':' byte, strnchr() returns NULL.\nNULL compares less than the valid kernel pointer eof, so the loop body\nruns and strnchr() is called with p + 1 == (void *)1 and a length of\nroughly (unsigned long)eof, causing a wonderful crash.\n\nThe not_signed_fw fallthrough earlier in do_flash() and the chip-state\nbranches in ccg_fw_update_needed() allow an unsigned blob to reach this\nloop, so a root user who can place a crafted file under /lib/firmware\nand write the do_flash sysfs attribute can trigger the oops.\n\nBail out with -EINVAL when the initial strnchr() returns NULL.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11454 |
debian: CVE-2026-63964 was patched at 2026-07-14
ubuntu: CVE-2026-63964 was patched at 2026-07-30
1809.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63967) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: iio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer The tagged FIFO path declares iio_buff on the stack with __aligned(8) but no initializer, but there is a hole in the structure, which will then leak to userspace as ST_LSM6DSX_SAMPLE_SIZE bytes (6) will be copied, but the space between that and the timestamp are not initialized. Commit c14edb4d0bdc ("iio:imu:st_lsm6dsx Fix alignment and data leak issues") moved the untagged FIFO path to a kzalloc'd buffer in hw->scan, but for the tagged path it only added the alignment qualifier and not the initializer :( Fix this by just zero-initializing the structure on the stack.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\niio: imu: st_lsm6dsx: fix stack leak in tagged FIFO buffer\n\nThe tagged FIFO path declares iio_buff on the stack with __aligned(8)\nbut no initializer, but there is a hole in the structure, which will\nthen leak to userspace as ST_LSM6DSX_SAMPLE_SIZE bytes (6) will be\ncopied, but the space between that and the timestamp are not\ninitialized.\n\nCommit c14edb4d0bdc ("iio:imu:st_lsm6dsx Fix alignment and data leak\nissues") moved the untagged FIFO path to a kzalloc'd buffer in hw->scan,\nbut for the tagged path it only added the alignment qualifier and not\nthe initializer :(\n\nFix this by just zero-initializing the structure on the stack.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00211, EPSS Percentile is 0.11453 |
debian: CVE-2026-63967 was patched at 2026-07-14
ubuntu: CVE-2026-63967 was patched at 2026-07-30
1810.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63969) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ipv6: fix possible infinite loop in rt6_fill_node() Sashiko reported this issue [1]. Apply the same fix as commit f8d8ce1b515a ("ipv6: fix possible infinite loop in fib6_info_uses_dev()"). Writers holding tb6_lock can list_del_rcu(&rt->fib6_siblings) without waiting for RCU readers; rt->fib6_siblings.next then still points into the old ring and this softirq-side walker never reaches &rt->fib6_siblings, causing a CPU stall. fib6_del_route() always WRITE_ONCE()s rt->fib6_nsiblings to 0 before list_del_rcu(), so an inside-loop check is a reliable detach signal. [1] https://sashiko.dev/#/patchset/20260526020227.4857-1-jiayuan.chen%40linux.dev', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nipv6: fix possible infinite loop in rt6_fill_node()\n\nSashiko reported this issue [1]. Apply the same fix as\ncommit f8d8ce1b515a ("ipv6: fix possible infinite loop in fib6_info_uses_dev()").\n\nWriters holding tb6_lock can list_del_rcu(&rt->fib6_siblings)\nwithout waiting for RCU readers; rt->fib6_siblings.next then still\npoints into the old ring and this softirq-side walker never reaches\n&rt->fib6_siblings, causing a CPU stall. fib6_del_route() always\nWRITE_ONCE()s rt->fib6_nsiblings to 0 before list_del_rcu(), so an\ninside-loop check is a reliable detach signal.\n\n[1] https://sashiko.dev/#/patchset/20260526020227.4857-1-jiayuan.chen%40linux.dev', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00206, EPSS Percentile is 0.10804 |
debian: CVE-2026-63969 was patched at 2026-07-14
ubuntu: CVE-2026-63969 was patched at 2026-07-30
1811.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63983) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/sched: fix packet loop on netem when duplicate is on When netem duplicates a packet it re-enqueues the copy at the root qdisc. If another netem sits in the tree the copy can be duplicated again, recursing until the stack or memory is exhausted. The original duplication guard temporarily zeroed q->duplicate around the re-enqueue, but that does not cover all cases because it is per-qdisc state shared across all concurrent enqueue paths and is not safe without additional locking. Use the skb tc_depth field introduced in an earlier patch: - increment it on the duplicate before re-enqueue - skip duplication for any skb whose tc_depth is already non-zero. This marks the packet itself rather than mutating qdisc state, therefore it is safe regardless of tree topology or concurrency.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: fix packet loop on netem when duplicate is on\n\nWhen netem duplicates a packet it re-enqueues the copy at the root qdisc.\nIf another netem sits in the tree the copy can be duplicated\nagain, recursing until the stack or memory is exhausted.\n\nThe original duplication guard temporarily zeroed q->duplicate around\nthe re-enqueue, but that does not cover all cases because it is\nper-qdisc state shared across all concurrent enqueue paths\nand is not safe without additional locking.\n\nUse the skb tc_depth field introduced in an earlier patch:\n - increment it on the duplicate before re-enqueue\n - skip duplication for any skb whose tc_depth is already non-zero.\n\nThis marks the packet itself rather than mutating qdisc state,\ntherefore it is safe regardless of tree topology or concurrency.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06247 |
debian: CVE-2026-63983 was patched at 2026-07-14
ubuntu: CVE-2026-63983 was patched at 2026-07-30
1812.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63990) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: bonding: refuse to enslave CAN devices syzbot reported a kernel paging request crash in can_rx_unregister() inside net/can/af_can.c. The crash occurs because a virtual CAN device (vxcan) is being enslaved to a bonding master. During the enslavement process, the bonding driver mutates and modifies the network device states to fit an Ethernet-like aggregation model. However, CAN devices operate on a completely different Layer 2 architecture, relying on the CAN mid-layer private data structure (can_ml_priv) instead of standard Ethernet structures. Since bonding does not initialize or maintain these CAN structures, subsequent operations on the half-enslaved interface (such as closing associated sockets via isotp_release) lead to a null-pointer dereference when accessing the CAN receiver lists. Bonding CAN interfaces is architecturally invalid as CAN lacks MAC addresses, ARP capabilities, and standard Ethernet link-layer mechanisms. While generic loopback devices are blocked globally in net/core/dev.c, virtual CAN devices bypass this check because they do not carry the IFF_LOOPBACK flag, despite acting as local software-loopbacks. Fix this by explicitly blocking network devices of type ARPHRD_CAN from being enslaved at the very beginning of bond_enslave(). This prevents illegal state mutations, eliminates the resulting KASAN crashes, and avoids potential memory leaks from incomplete socket cleanups. As the CAN support has been added a long time after bonding the Fixes-tag points to the introduction of ARPHRD_CAN that would have needed a specific handling in bonding_main.c.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbonding: refuse to enslave CAN devices\n\nsyzbot reported a kernel paging request crash in\ncan_rx_unregister() inside net/can/af_can.c. The crash occurs\nbecause a virtual CAN device (vxcan) is being enslaved to a\nbonding master.\n\nDuring the enslavement process, the bonding driver mutates\nand modifies the network device states to fit an Ethernet-like\naggregation model. However, CAN devices operate on a completely\ndifferent Layer 2 architecture, relying on the CAN mid-layer\nprivate data structure (can_ml_priv) instead of standard\nEthernet structures. Since bonding does not initialize or\nmaintain these CAN structures, subsequent operations on the\nhalf-enslaved interface (such as closing associated sockets\nvia isotp_release) lead to a null-pointer dereference when\naccessing the CAN receiver lists.\n\nBonding CAN interfaces is architecturally invalid as CAN lacks\nMAC addresses, ARP capabilities, and standard Ethernet\nlink-layer mechanisms. While generic loopback devices are\nblocked globally in net/core/dev.c, virtual CAN devices\nbypass this check because they do not carry the IFF_LOOPBACK\nflag, despite acting as local software-loopbacks.\n\nFix this by explicitly blocking network devices of type\nARPHRD_CAN from being enslaved at the very beginning of\nbond_enslave(). This prevents illegal state mutations,\neliminates the resulting KASAN crashes, and avoids potential\nmemory leaks from incomplete socket cleanups.\n\nAs the CAN support has been added a long time after bonding\nthe Fixes-tag points to the introduction of ARPHRD_CAN that\nwould have needed a specific handling in bonding_main.c.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00181, EPSS Percentile is 0.07956 |
debian: CVE-2026-63990 was patched at 2026-07-14
ubuntu: CVE-2026-63990 was patched at 2026-07-30
1813.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63997) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ethtool: module: avoid leaking a netdev ref on module flash errors module_flash_fw_schedule() is missing undo for setting the "in_progress" flag and taking the netdev reference. Delay taking these, the device can't disappear while we are holding rtnl_lock.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: module: avoid leaking a netdev ref on module flash errors\n\nmodule_flash_fw_schedule() is missing undo for setting\nthe "in_progress" flag and taking the netdev reference.\nDelay taking these, the device can't disappear while\nwe are holding rtnl_lock.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06444 |
debian: CVE-2026-63997 was patched at 2026-07-14
ubuntu: CVE-2026-63997 was patched at 2026-07-30
1814.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63998) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ethtool: module: call ethnl_ops_complete() on module flash errors When validate() fails we are skipping over ethnl_ops_complete() even tho we already called ethnl_ops_begin().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: module: call ethnl_ops_complete() on module flash errors\n\nWhen validate() fails we are skipping over ethnl_ops_complete()\neven tho we already called ethnl_ops_begin().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06249 |
debian: CVE-2026-63998 was patched at 2026-07-14
ubuntu: CVE-2026-63998 was patched at 2026-07-30
1815.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63999) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ethtool: rss: fix indir_table and hkey leak on get_rxfh failure rss_prepare_get() allocates the indirection table and hash key buffer via rss_get_data_alloc(), then calls ops->get_rxfh() to populate them. If get_rxfh() fails, the function returns an error without freeing the allocation.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nethtool: rss: fix indir_table and hkey leak on get_rxfh failure\n\nrss_prepare_get() allocates the indirection table and hash key buffer\nvia rss_get_data_alloc(), then calls ops->get_rxfh() to populate them.\nIf get_rxfh() fails, the function returns an error without freeing\nthe allocation.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06248 |
debian: CVE-2026-63999 was patched at 2026-07-14
ubuntu: CVE-2026-63999 was patched at 2026-07-30
1816.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64001) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix setup list UAF on proc write error snd_pcm_oss_proc_write() links a newly allocated setup entry into the OSS setup list before duplicating the task name. If the task-name allocation fails, the error path frees the already linked entry and leaves setup_list pointing at freed memory. A later OSS device open can then walk the stale list entry in snd_pcm_oss_look_for_setup() and dereference freed memory. Allocate the task name and initialize the setup entry before publishing the entry on setup_list. Also fetch the initial proc read iterator only after taking setup_mutex, so all setup_list traversal follows the same list lifetime rules.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nALSA: pcm: oss: Fix setup list UAF on proc write error\n\nsnd_pcm_oss_proc_write() links a newly allocated setup entry into the\nOSS setup list before duplicating the task name. If the task-name\nallocation fails, the error path frees the already linked entry and\nleaves setup_list pointing at freed memory.\n\nA later OSS device open can then walk the stale list entry in\nsnd_pcm_oss_look_for_setup() and dereference freed memory.\n\nAllocate the task name and initialize the setup entry before publishing\nthe entry on setup_list. Also fetch the initial proc read iterator only\nafter taking setup_mutex, so all setup_list traversal follows the same\nlist lifetime rules.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06443 |
debian: CVE-2026-64001 was patched at 2026-07-14
ubuntu: CVE-2026-64001 was patched at 2026-07-30
1817.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64006) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_tables: fix dst corruption in same register operation For lshift and rshift, the shift operations are performed in a loop over 32-bit words. The loop calculates the shifted value and write it to dst, and then immediately reads from src to calculate the carry for the next iteration. Because src and dst could point to the same memory location, the carry is incorrectly calculated using the newly modified dst value instead of the original src value. Adding a temporary local variable to cache the original value before writing to dst and using it for the carry calculation solves the problem. In addition, partial overlap is rejected from control plane for all kind of operations including byteorder. This was tested with the following bytecode: table test_table ip flags 0 use 1 handle 1 ip test_table test_chain use 3 type filter hook input prio 0 policy accept packets 0 bytes 0 flags 1 ip test_table test_chain 2 [ immediate reg 1 0x44332211 0x88776655 ] [ bitwise reg 1 = ( reg 1 << 0x08000000 ) ] [ cmp eq reg 1 0x66443322 0x00887766 ] [ counter pkts 0 bytes 0 ] ip test_table test_chain 4 3 [ immediate reg 1 0x44332211 0x88776655 ] [ bitwise reg 1 = ( reg 1 << 0x08000000 ) ] [ cmp eq reg 1 0x55443322 0x00887766 ] [ counter pkts 21794 bytes 1917798 ]', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: nf_tables: fix dst corruption in same register operation\n\nFor lshift and rshift, the shift operations are performed in a loop over\n32-bit words. The loop calculates the shifted value and write it to dst,\nand then immediately reads from src to calculate the carry for the next\niteration. Because src and dst could point to the same memory location,\nthe carry is incorrectly calculated using the newly modified dst value\ninstead of the original src value.\n\nAdding a temporary local variable to cache the original value before\nwriting to dst and using it for the carry calculation solves the\nproblem. In addition, partial overlap is rejected from control plane for\nall kind of operations including byteorder. This was tested with the\nfollowing bytecode:\n\ntable test_table ip flags 0 use 1 handle 1\nip test_table test_chain use 3 type filter hook input prio 0 policy accept packets 0 bytes 0 flags 1\nip test_table test_chain 2\n [ immediate reg 1 0x44332211 0x88776655 ]\n [ bitwise reg 1 = ( reg 1 << 0x08000000 ) ]\n [ cmp eq reg 1 0x66443322 0x00887766 ]\n [ counter pkts 0 bytes 0 ]\nip test_table test_chain 4 3\n [ immediate reg 1 0x44332211 0x88776655 ]\n [ bitwise reg 1 = ( reg 1 << 0x08000000 ) ]\n [ cmp eq reg 1 0x55443322 0x00887766 ]\n [ counter pkts 21794 bytes 1917798 ]', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00171, EPSS Percentile is 0.06799 |
debian: CVE-2026-64006 was patched at 2026-07-14
ubuntu: CVE-2026-64006 was patched at 2026-07-30
1818.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64012) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked When sfb has children (eg qfq qdisc) whose peek() callback is qdisc_peek_dequeued(), we could get a kernel panic. When the parent of such qdiscs (eg illustrated in patch #3 as tbf) wants to retrieve an skb from its child (sfb in this case), it will do the following: 1a. do a peek() - and when sensing there's an skb the child can offer, then - the child in this case(sfb) calls its child's (qfq) peek. qfq does the right thing and will return the gso_skb queue packet. Note: if there wasnt a gso_skb entry then qfq will store it there. 1b. invoke a dequeue() on the child (sfb). And herein lies the problem. - sfb will call the child's dequeue() which will essentially just try to grab something of qfq's queue. [ 127.594489][ T453] KASAN: null-ptr-deref in range [0x0000000000000048-0x000000000000004f] [ 127.594741][ T453] CPU: 2 UID: 0 PID: 453 Comm: ping Not tainted 7.1.0-rc1-00035-gac961974495b-dirty #793 PREEMPT(full) [ 127.595059][ T453] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011 [ 127.595254][ T453] RIP: 0010:qfq_dequeue+0x35c/0x1650 [sch_qfq] [ 127.595461][ T453] Code: 00 fc ff df 80 3c 02 00 0f 85 17 0e 00 00 4c 8d 73 48 48 89 9d b8 02 00 00 48 b8 00 00 00 00 00 fc ff df 4c 89 f2 48 c1 ea 03 <80> 3c 02 00 0f 85 76 0c 00 00 48 b8 00 00 00 00 00 fc ff df 4c 8b [ 127.596081][ T453] RSP: 0018:ffff88810e5af440 EFLAGS: 00010216 [ 127.596337][ T453] RAX: dffffc0000000000 RBX: 0000000000000000 RCX: dffffc0000000000 [ 127.596623][ T453] RDX: 0000000000000009 RSI: 0000001880000000 RDI: ffff888104fd82b0 [ 127.596917][ T453] RBP: ffff888104fd8000 R08: ffff888104fd8280 R09: 1ffff110211893a3 [ 127.597165][ T453] R10: 1ffff110211893a6 R11: 1ffff110211893a7 R12: 0000001880000000 [ 127.597404][ T453] R13: ffff888104fd82b8 R14: 0000000000000048 R15: 0000000040000000 [ 127.597644][ T453] FS: 00007fc380cbfc40(0000) GS:ffff88816f2a8000(0000) knlGS:0000000000000000 [ 127.597956][ T453] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 127.598160][ T453] CR2: 00005610aa9890a8 CR3: 000000010369e000 CR4: 0000000000750ef0 [ 127.598390][ T453] PKRU: 55555554 [ 127.598509][ T453] Call Trace: [ 127.598629][ T453] <TASK> [ 127.598718][ T453] ? mark_held_locks+0x40/0x70 [ 127.598890][ T453] ? srso_alias_return_thunk+0x5/0xfbef5 [ 127.599053][ T453] sfb_dequeue+0x88/0x4d0 [ 127.599174][ T453] ? ktime_get+0x137/0x230 [ 127.599328][ T453] ? srso_alias_return_thunk+0x5/0xfbef5 [ 127.599480][ T453] ? qdisc_peek_dequeued+0x7b/0x350 [sch_qfq] [ 127.599670][ T453] ? srso_alias_return_thunk+0x5/0xfbef5 [ 127.599831][ T453] tbf_dequeue+0x6b1/0x1098 [sch_tbf] [ 127.599988][ T453] __qdisc_run+0x169/0x1900 The right thing to do in #1b is to grab the skb off gso_skb queue. This patchset fixes that issue by changing #1b to use qdisc_dequeue_peeked() method instead.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet/sched: sch_sfb: Replace direct dequeue call with peek and qdisc_dequeue_peeked\n\nWhen sfb has children (eg qfq qdisc) whose peek() callback is\nqdisc_peek_dequeued(), we could get a kernel panic. When the parent of such\nqdiscs (eg illustrated in patch #3 as tbf) wants to retrieve an skb from\nits child (sfb in this case), it will do the following:\n 1a. do a peek() - and when sensing there's an skb the child can offer, then\n - the child in this case(sfb) calls its child's (qfq) peek.\n qfq does the right thing and will return the gso_skb queue packet.\n Note: if there wasnt a gso_skb entry then qfq will store it there.\n 1b. invoke a dequeue() on the child (sfb). And herein lies the problem.\n - sfb will call the child's dequeue() which will essentially just\n try to grab something of qfq's queue.\n\n[ 127.594489][ T453] KASAN: null-ptr-deref in range [0x0000000000000048-0x000000000000004f]\n[ 127.594741][ T453] CPU: 2 UID: 0 PID: 453 Comm: ping Not tainted 7.1.0-rc1-00035-gac961974495b-dirty #793 PREEMPT(full)\n[ 127.595059][ T453] Hardware name: Bochs Bochs, BIOS Bochs 01/01/2011\n[ 127.595254][ T453] RIP: 0010:qfq_dequeue+0x35c/0x1650 [sch_qfq]\n[ 127.595461][ T453] Code: 00 fc ff df 80 3c 02 00 0f 85 17 0e 00 00 4c 8d 73 48 48 89 9d b8 02 00 00 48 b8 00 00 00 00 00 fc ff df 4c 89 f2 48 c1 ea 03 <80> 3c 02 00 0f 85 76 0c 00 00 48 b8 00 00 00 00 00 fc ff df 4c 8b\n[ 127.596081][ T453] RSP: 0018:ffff88810e5af440 EFLAGS: 00010216\n[ 127.596337][ T453] RAX: dffffc0000000000 RBX: 0000000000000000 RCX: dffffc0000000000\n[ 127.596623][ T453] RDX: 0000000000000009 RSI: 0000001880000000 RDI: ffff888104fd82b0\n[ 127.596917][ T453] RBP: ffff888104fd8000 R08: ffff888104fd8280 R09: 1ffff110211893a3\n[ 127.597165][ T453] R10: 1ffff110211893a6 R11: 1ffff110211893a7 R12: 0000001880000000\n[ 127.597404][ T453] R13: ffff888104fd82b8 R14: 0000000000000048 R15: 0000000040000000\n[ 127.597644][ T453] FS: 00007fc380cbfc40(0000) GS:ffff88816f2a8000(0000) knlGS:0000000000000000\n[ 127.597956][ T453] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 127.598160][ T453] CR2: 00005610aa9890a8 CR3: 000000010369e000 CR4: 0000000000750ef0\n[ 127.598390][ T453] PKRU: 55555554\n[ 127.598509][ T453] Call Trace:\n[ 127.598629][ T453] <TASK>\n[ 127.598718][ T453] ? mark_held_locks+0x40/0x70\n[ 127.598890][ T453] ? srso_alias_return_thunk+0x5/0xfbef5\n[ 127.599053][ T453] sfb_dequeue+0x88/0x4d0\n[ 127.599174][ T453] ? ktime_get+0x137/0x230\n[ 127.599328][ T453] ? srso_alias_return_thunk+0x5/0xfbef5\n[ 127.599480][ T453] ? qdisc_peek_dequeued+0x7b/0x350 [sch_qfq]\n[ 127.599670][ T453] ? srso_alias_return_thunk+0x5/0xfbef5\n[ 127.599831][ T453] tbf_dequeue+0x6b1/0x1098 [sch_tbf]\n[ 127.599988][ T453] __qdisc_run+0x169/0x1900\n\nThe right thing to do in #1b is to grab the skb off gso_skb queue.\nThis patchset fixes that issue by changing #1b to use qdisc_dequeue_peeked()\nmethod instead.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07455 |
debian: CVE-2026-64012 was patched at 2026-07-14
ubuntu: CVE-2026-64012 was patched at 2026-07-30
1819.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64038) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hwmon: (lm90) Stop work before releasing hwmon device Sashiko reports: In lm90_probe(), the devm action to cancel the alert_work and report_work (lm90_restore_conf) is registered in lm90_init_client() before devm_hwmon_device_register_with_info() is called. Because devm executes cleanup actions in reverse order during module unbind or probe failure, the hwmon device is unregistered and freed first. If lm90_alert_work() or lm90_report_alarms() runs in the window between the hwmon device being freed and the delayed works being cancelled, lm90_update_alarms() will dereference the freed data->hwmon_dev here. Fix the problem by canceling the workers separately after registering the hwmon device and before registering the interrupt handler. This ensures that the workers are canceled after interrupts are disabled and before the hwmon device is released. Add "shutdown" flag to indicate that device shutdown is in progress to prevent workers from being re-armed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (lm90) Stop work before releasing hwmon device\n\nSashiko reports:\n\nIn lm90_probe(), the devm action to cancel the alert_work and report_work\n(lm90_restore_conf) is registered in lm90_init_client() before\ndevm_hwmon_device_register_with_info() is called.\n\nBecause devm executes cleanup actions in reverse order during module\nunbind or probe failure, the hwmon device is unregistered and freed first.\n\nIf lm90_alert_work() or lm90_report_alarms() runs in the window between\nthe hwmon device being freed and the delayed works being cancelled,\nlm90_update_alarms() will dereference the freed data->hwmon_dev here.\n\nFix the problem by canceling the workers separately after registering\nthe hwmon device and before registering the interrupt handler. This ensures\nthat the workers are canceled after interrupts are disabled and before\nthe hwmon device is released. Add "shutdown" flag to indicate that device\nshutdown is in progress to prevent workers from being re-armed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06251 |
debian: CVE-2026-64038 was patched at 2026-07-14
ubuntu: CVE-2026-64038 was patched at 2026-07-30
1820.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64052) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: block: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user() pin_user_pages_fast() can partially succeed and return the number of pages that were actually pinned. However, the bio_integrity_map_user() does not handle this partial pinning. This leads to a general protection fault since bvec_from_pages() dereferences an unpinned page address, which is 0. To fix this, add a check to verify that all requested memory is pinned. If partial pinning occurs, unpin the memory and return -EFAULT. Kernel Oops: Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] CPU: 0 UID: 0 PID: 1061 Comm: nvme-passthroug Not tainted 7.0.0-11783-g90957f9314e8-dirty #16 PREEMPT(lazy) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 RIP: 0010:bio_integrity_map_user.cold+0x1b0/0x9d6', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nblock: bio-integrity: Fix null-ptr-deref in bio_integrity_map_user()\n\npin_user_pages_fast() can partially succeed and return the number of\npages that were actually pinned. However, the bio_integrity_map_user()\ndoes not handle this partial pinning. This leads to a general protection\nfault since bvec_from_pages() dereferences an unpinned page address,\nwhich is 0.\n\nTo fix this, add a check to verify that all requested memory is pinned.\nIf partial pinning occurs, unpin the memory and return -EFAULT.\n\nKernel Oops:\n\nOops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI\nKASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\nCPU: 0 UID: 0 PID: 1061 Comm: nvme-passthroug Not tainted 7.0.0-11783-g90957f9314e8-dirty #16 PREEMPT(lazy)\nHardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\nRIP: 0010:bio_integrity_map_user.cold+0x1b0/0x9d6', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06444 |
debian: CVE-2026-64052 was patched at 2026-07-14
ubuntu: CVE-2026-64052 was patched at 2026-07-30
1821.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64059) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfs: Fix folio->private handling in netfs_perform_write() Under some circumstances, netfs_perform_write() doesn't correctly manipulate folio->private between NULL, NETFS_FOLIO_COPY_TO_CACHE, pointing to a group and pointing to a netfs_folio struct, leading to potential multiple attachments of private data with associated folio ref leaks and also leaks of netfs_folio structs or netfs_group refs. Fix this by consolidating the place at which a folio is marked uptodate in one place and having that look at what's attached to folio->private and decide how to clean it up and then set the new group. Also, the content shouldn't be flushed if group is NULL, even if a group is specified in the netfs_group parameter, as that would be the case for a new folio. A filesystem should always specify netfs_group or never specify netfs_group. The Sashiko auto-review tool noted that it was theoretically possible that the fpos >= ctx->zero_point section might leak if it modified a streaming write folio. This is unlikely, but with a network filesystem, third party changes can happen. It also pointed out that __netfs_set_group() would leak if called multiple times on the same folio from the "whole folio modify section".', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix folio->private handling in netfs_perform_write()\n\nUnder some circumstances, netfs_perform_write() doesn't correctly\nmanipulate folio->private between NULL, NETFS_FOLIO_COPY_TO_CACHE, pointing\nto a group and pointing to a netfs_folio struct, leading to potential\nmultiple attachments of private data with associated folio ref leaks and\nalso leaks of netfs_folio structs or netfs_group refs.\n\nFix this by consolidating the place at which a folio is marked uptodate in\none place and having that look at what's attached to folio->private and\ndecide how to clean it up and then set the new group. Also, the content\nshouldn't be flushed if group is NULL, even if a group is specified in the\nnetfs_group parameter, as that would be the case for a new folio. A\nfilesystem should always specify netfs_group or never specify netfs_group.\n\nThe Sashiko auto-review tool noted that it was theoretically possible that\nthe fpos >= ctx->zero_point section might leak if it modified a streaming\nwrite folio. This is unlikely, but with a network filesystem, third party\nchanges can happen. It also pointed out that __netfs_set_group() would\nleak if called multiple times on the same folio from the "whole folio\nmodify section".', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06444 |
debian: CVE-2026-64059 was patched at 2026-07-14
ubuntu: CVE-2026-64059 was patched at 2026-07-30
1822.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64060) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfs: Fix leak of request in netfs_write_begin() error handling Fix netfs_write_begin() to not leak our ref on the request in the event that we get an error from netfs_wait_for_read().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix leak of request in netfs_write_begin() error handling\n\nFix netfs_write_begin() to not leak our ref on the request in the event\nthat we get an error from netfs_wait_for_read().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00166, EPSS Percentile is 0.06247 |
debian: CVE-2026-64060 was patched at 2026-07-14
ubuntu: CVE-2026-64060 was patched at 2026-07-30
1823.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64062) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfs: Fix potential deadlock in write-through mode Fix netfs_advance_writethrough() to always unlock the supplied folio and to mark it dirty if it isn't yet written to the end. Unfortunately, it can't be marked for writeback until the folio is done with as that may cause a deadlock against mmapped reads and writes. Even though it has been marked dirty, premature writeback can't occur as the caller is holding both inode->i_rwsem (which will prevent concurrent truncation, fallocation, DIO and other writes) and ictx->wb_lock (which will cause flushing to wait and writeback to skip or wait). Note that this may be easier to deal with once the queuing of folios is split from the generation of subrequests.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix potential deadlock in write-through mode\n\nFix netfs_advance_writethrough() to always unlock the supplied folio and to\nmark it dirty if it isn't yet written to the end. Unfortunately, it can't\nbe marked for writeback until the folio is done with as that may cause a\ndeadlock against mmapped reads and writes.\n\nEven though it has been marked dirty, premature writeback can't occur as\nthe caller is holding both inode->i_rwsem (which will prevent concurrent\ntruncation, fallocation, DIO and other writes) and ictx->wb_lock (which\nwill cause flushing to wait and writeback to skip or wait).\n\nNote that this may be easier to deal with once the queuing of folios is\nsplit from the generation of subrequests.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06445 |
debian: CVE-2026-64062 was patched at 2026-07-14
ubuntu: CVE-2026-64062 was patched at 2026-07-30
1824.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64063) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfs: Fix streaming write being overwritten In order to avoid reading whilst writing, netfslib will allow "streaming writes" in which dirty data is stored directly into folios without reading them first. Such folios are marked dirty but may not be marked uptodate. If a folio is entirely written by a streaming write, uptodate will be set, otherwise it will have a netfs_folio struct attached to ->private recording the dirty region. In the event that a partially written streaming write page is to be overwritten entirely by a single write(), netfs_perform_write() will try to copy over it, but doesn't discard the netfs_folio if it succeeds; further, it doesn't correctly handle a partial copy that overwrites some of the dirty data. Fix this by the following: (1) If the folio is successfully overwritten, free the netfs_folio struct before marking the page uptodate. (2) If the copy to the folio partially fails, but short of the dirty data, just ignore the copy. (3) If the copy partially fails and overwrites some of the dirty data, accept the copy, update the netfs_folio struct to record the new data. If the folio is now filled, free the netfs_folio and set uptodate, otherwise return a partial write. Found with: \tfsx -q -N 1000000 -p 10000 -o 128000 -l 600000 \\ \t /xfstest.test/junk --replay-ops=junk.fsxops using the following as junk.fsxops: \ttruncate 0x0 0 0x927c0 \twrite 0x63fb8 0x53c8 0 \tcopy_range 0xb704 0x19b9 0x24429 0x79380 \twrite 0x2402b 0x144a2 0x90660 * \twrite 0x204d5 0x140a0 0x927c0 * \tcopy_range 0x1f72c 0x137d0 0x7a906 0x927c0 * \tread 0x00000 0x20000 0x9157c \tread 0x20000 0x20000 0x9157c \tread 0x40000 0x20000 0x9157c \tread 0x60000 0x20000 0x9157c \tread 0x7e1a0 0xcfb9 0x9157c on cifs with the default cache option. It shows folio 0x24 misbehaving if the FMODE_READ check is commented out in netfs_perform_write(): \t\tif (//(file->f_mode & FMODE_READ) || \t\t netfs_is_cache_enabled(ctx)) { and no fscache. This was initially found with the generic/522 xfstest.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix streaming write being overwritten\n\nIn order to avoid reading whilst writing, netfslib will allow "streaming\nwrites" in which dirty data is stored directly into folios without reading\nthem first. Such folios are marked dirty but may not be marked uptodate.\nIf a folio is entirely written by a streaming write, uptodate will be set,\notherwise it will have a netfs_folio struct attached to ->private recording\nthe dirty region.\n\nIn the event that a partially written streaming write page is to be\noverwritten entirely by a single write(), netfs_perform_write() will try to\ncopy over it, but doesn't discard the netfs_folio if it succeeds; further,\nit doesn't correctly handle a partial copy that overwrites some of the\ndirty data.\n\nFix this by the following:\n\n (1) If the folio is successfully overwritten, free the netfs_folio struct\n before marking the page uptodate.\n\n (2) If the copy to the folio partially fails, but short of the dirty data,\n just ignore the copy.\n\n (3) If the copy partially fails and overwrites some of the dirty data,\n accept the copy, update the netfs_folio struct to record the new data.\n If the folio is now filled, free the netfs_folio and set uptodate,\n otherwise return a partial write.\n\nFound with:\n\n\tfsx -q -N 1000000 -p 10000 -o 128000 -l 600000 \\\n\t /xfstest.test/junk --replay-ops=junk.fsxops\n\nusing the following as junk.fsxops:\n\n\ttruncate 0x0 0 0x927c0\n\twrite 0x63fb8 0x53c8 0\n\tcopy_range 0xb704 0x19b9 0x24429 0x79380\n\twrite 0x2402b 0x144a2 0x90660 *\n\twrite 0x204d5 0x140a0 0x927c0 *\n\tcopy_range 0x1f72c 0x137d0 0x7a906 0x927c0 *\n\tread 0x00000 0x20000 0x9157c\n\tread 0x20000 0x20000 0x9157c\n\tread 0x40000 0x20000 0x9157c\n\tread 0x60000 0x20000 0x9157c\n\tread 0x7e1a0 0xcfb9 0x9157c\n\non cifs with the default cache option.\n\nIt shows folio 0x24 misbehaving if the FMODE_READ check is commented out in\nnetfs_perform_write():\n\n\t\tif (//(file->f_mode & FMODE_READ) ||\n\t\t netfs_is_cache_enabled(ctx)) {\n\nand no fscache. This was initially found with the generic/522 xfstest.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06445 |
debian: CVE-2026-64063 was patched at 2026-07-14
ubuntu: CVE-2026-64063 was patched at 2026-07-30
1825.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64064) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone If a streaming write is made, this will leave the relevant modified folio in a not-uptodate, but dirty state with a netfs_folio struct hung off of folio->private indicating the dirty range. Subsequently truncating the file such that the dirty data in the folio is removed, but the first part of the folio theoretically remains will cause the netfs_folio struct to be discarded... but will leave the dirty flag set. If the folio is then read via mmap(), netfs_read_folio() will see that the page is dirty and jump to netfs_read_gaps() to fill in the missing bits. netfs_read_gaps(), however, expects there to be a netfs_folio struct present and can oops because truncate removed it. Fix this by calling folio_cancel_dirty() in netfs_invalidate_folio() in the event that all the dirty data in the folio is erased (as nfs does). Also add some tracepoints to log modifications to a dirty page. This can be reproduced with something like: dd if=/dev/zero of=/xfstest.test/foo bs=1M count=1 umount /xfstest.test mount /xfstest.test xfs_io -c "w 0xbbbf 0xf96c" \\ -c "truncate 0xbbbf" \\ -c "mmap -r 0xb000 0x11000" \\ -c "mr 0xb000 0x11000" \\ /xfstest.test/foo with fscaching disabled (otherwise streaming writes are suppressed) and a change to netfs_perform_write() to disallow streaming writes if the fd is open O_RDWR: \tif (//(file->f_mode & FMODE_READ) || <--- comment this out \t netfs_is_cache_enabled(ctx)) { It should be reproducible even without this change, but if prevents the above trivial xfs_io command from reproducing it. Note that the initial dd is important: the file must start out sufficiently large that the zero-point logic doesn't just clear the gaps because it knows there's nothing in the file to read yet. Unmounting and mounting is needed to clear the pagecache (there are other ways to do that that may also work). This was initially reproduced with the generic/522 xfstest on some patches that remove the FMODE_READ restriction.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix netfs_invalidate_folio() to clear dirty bit if all changes gone\n\nIf a streaming write is made, this will leave the relevant modified folio\nin a not-uptodate, but dirty state with a netfs_folio struct hung off of\nfolio->private indicating the dirty range. Subsequently truncating the\nfile such that the dirty data in the folio is removed, but the first part\nof the folio theoretically remains will cause the netfs_folio struct to be\ndiscarded... but will leave the dirty flag set.\n\nIf the folio is then read via mmap(), netfs_read_folio() will see that the\npage is dirty and jump to netfs_read_gaps() to fill in the missing bits.\nnetfs_read_gaps(), however, expects there to be a netfs_folio struct\npresent and can oops because truncate removed it.\n\nFix this by calling folio_cancel_dirty() in netfs_invalidate_folio() in the\nevent that all the dirty data in the folio is erased (as nfs does).\n\nAlso add some tracepoints to log modifications to a dirty page.\n\nThis can be reproduced with something like:\n\n dd if=/dev/zero of=/xfstest.test/foo bs=1M count=1\n umount /xfstest.test\n mount /xfstest.test\n xfs_io -c "w 0xbbbf 0xf96c" \\\n -c "truncate 0xbbbf" \\\n -c "mmap -r 0xb000 0x11000" \\\n -c "mr 0xb000 0x11000" \\\n /xfstest.test/foo\n\nwith fscaching disabled (otherwise streaming writes are suppressed) and a\nchange to netfs_perform_write() to disallow streaming writes if the fd is\nopen O_RDWR:\n\n\tif (//(file->f_mode & FMODE_READ) || <--- comment this out\n\t netfs_is_cache_enabled(ctx)) {\n\nIt should be reproducible even without this change, but if prevents the\nabove trivial xfs_io command from reproducing it.\n\nNote that the initial dd is important: the file must start out sufficiently\nlarge that the zero-point logic doesn't just clear the gaps because it\nknows there's nothing in the file to read yet. Unmounting and mounting is\nneeded to clear the pagecache (there are other ways to do that that may\nalso work).\n\nThis was initially reproduced with the generic/522 xfstest on some patches\nthat remove the FMODE_READ restriction.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06441 |
debian: CVE-2026-64064 was patched at 2026-07-14
ubuntu: CVE-2026-64064 was patched at 2026-07-30
1826.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64065) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call The multiple runs of generic/013 test-case is capable to reproduce a kernel BUG at mm/filemap.c:1504 with probability of 30%. while true; do sudo ./check generic/013 done [ 9849.452376] page: refcount:3 mapcount:0 mapping:00000000e58ff252 index:0x10781 pfn:0x1c322 [ 9849.452412] memcg:ffff8881a1915800 [ 9849.452417] aops:ceph_aops ino:1000058db9e dentry name(?):"f9XXXXXX" [ 9849.452432] flags: 0x17ffffc0000000(node=0|zone=2|lastcpupid=0x1fffff) [ 9849.452441] raw: 0017ffffc0000000 0000000000000000 dead000000000122 ffff88816110d248 [ 9849.452445] raw: 0000000000010781 0000000000000000 00000003ffffffff ffff8881a1915800 [ 9849.452447] page dumped because: VM_BUG_ON_FOLIO(!folio_test_locked(folio)) [ 9849.452474] ------------[ cut here ]------------ [ 9849.452476] kernel BUG at mm/filemap.c:1504! [ 9849.478635] Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI [ 9849.481772] CPU: 2 UID: 0 PID: 84223 Comm: fsstress Not tainted 7.0.0-rc1+ #18 PREEMPT(full) [ 9849.482881] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-9.fc43 06/1 0/2025 [ 9849.484539] RIP: 0010:folio_unlock+0x85/0xa0 [ 9849.485076] Code: 89 df 31 f6 e8 1c f3 ff ff 48 8b 5d f8 c9 31 c0 31 d2 31 f6 31 ff c3 cc cc cc cc 48 c7 c6 80 6c d9 a7 48 89 df e8 4b b3 10 00 <0f> 0b 48 89 df e8 21 e6 2c 00 eb 9d 0f 1f 40 00 66 66 2e 0f 1f 84 [ 9849.493818] RSP: 0018:ffff8881bb8076b0 EFLAGS: 00010246 [ 9849.495740] RAX: 0000000000000000 RBX: ffffea00070c8980 RCX: 0000000000000000 [ 9849.498678] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000 [ 9849.500559] RBP: ffff8881bb8076b8 R08: 0000000000000000 R09: 0000000000000000 [ 9849.501097] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000010782000 [ 9849.502108] R13: ffff8881935de738 R14: ffff88816110d010 R15: 0000000000001000 [ 9849.502516] FS: 00007e36cbe94740(0000) GS:ffff88824a899000(0000) knlGS:0000000000000000 [ 9849.502996] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 9849.503810] CR2: 000000c0002b0000 CR3: 000000011bbf6004 CR4: 0000000000772ef0 [ 9849.504459] PKRU: 55555554 [ 9849.504626] Call Trace: [ 9849.505242] <TASK> [ 9849.505379] netfs_write_begin+0x7c8/0x10a0 [ 9849.505877] ? __kasan_check_read+0x11/0x20 [ 9849.506384] ? __pfx_netfs_write_begin+0x10/0x10 [ 9849.507178] ceph_write_begin+0x8c/0x1c0 [ 9849.507934] generic_perform_write+0x391/0x8f0 [ 9849.508503] ? __pfx_generic_perform_write+0x10/0x10 [ 9849.509062] ? file_update_time_flags+0x19a/0x4b0 [ 9849.509581] ? ceph_get_caps+0x63/0xf0 [ 9849.510259] ? ceph_get_caps+0x63/0xf0 [ 9849.510530] ceph_write_iter+0xe79/0x1ae0 [ 9849.511282] ? __pfx_ceph_write_iter+0x10/0x10 [ 9849.511839] ? lock_acquire+0x1ad/0x310 [ 9849.512334] ? ksys_write+0xf9/0x230 [ 9849.512582] ? lock_is_held_type+0xaa/0x140 [ 9849.513128] vfs_write+0x512/0x1110 [ 9849.513634] ? __fget_files+0x33/0x350 [ 9849.513893] ? __pfx_vfs_write+0x10/0x10 [ 9849.514143] ? mutex_lock_nested+0x1b/0x30 [ 9849.514394] ksys_write+0xf9/0x230 [ 9849.514621] ? __pfx_ksys_write+0x10/0x10 [ 9849.514887] ? do_syscall_64+0x25e/0x1520 [ 9849.515122] ? __kasan_check_read+0x11/0x20 [ 9849.515366] ? trace_hardirqs_on_prepare+0x178/0x1c0 [ 9849.515655] __x64_sys_write+0x72/0xd0 [ 9849.515885] ? trace_hardirqs_on+0x24/0x1c0 [ 9849.516130] x64_sys_call+0x22f/0x2390 [ 9849.516341] do_syscall_64+0x12b/0x1520 [ 9849.516545] ? do_syscall_64+0x27c/0x1520 [ 9849.516783] ? do_syscall_64+0x27c/0x1520 [ 9849.517003] ? lock_release+0x318/0x480 [ 9849.517220] ? __x64_sys_io_getevents+0x143/0x2d0 [ 9849.517479] ? percpu_ref_put_many.constprop.0+0x8f/0x210 [ 9849.517779] ? entry_SYSCALL_64_after_hwframe+0x76/0x7e [ 9849.518073] ? do_syscall_64+0x25e/0x1520 [ 9849.518291] ? __kasan_check_read+0x11/0x20 [ 9849.518519] ? trace_hardirqs_on_prepare+0x178/0x1c0 [ 9849.518799] ? do_syscall_64+0x27c/0x1520 [ 9 ---truncated---', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: fix VM_BUG_ON_FOLIO() issue in netfs_write_begin() call\n\nThe multiple runs of generic/013 test-case is capable\nto reproduce a kernel BUG at mm/filemap.c:1504 with\nprobability of 30%.\n\nwhile true; do\n sudo ./check generic/013\ndone\n\n[ 9849.452376] page: refcount:3 mapcount:0 mapping:00000000e58ff252 index:0x10781 pfn:0x1c322\n[ 9849.452412] memcg:ffff8881a1915800\n[ 9849.452417] aops:ceph_aops ino:1000058db9e dentry name(?):"f9XXXXXX"\n[ 9849.452432] flags: 0x17ffffc0000000(node=0|zone=2|lastcpupid=0x1fffff)\n[ 9849.452441] raw: 0017ffffc0000000 0000000000000000 dead000000000122 ffff88816110d248\n[ 9849.452445] raw: 0000000000010781 0000000000000000 00000003ffffffff ffff8881a1915800\n[ 9849.452447] page dumped because: VM_BUG_ON_FOLIO(!folio_test_locked(folio))\n[ 9849.452474] ------------[ cut here ]------------\n[ 9849.452476] kernel BUG at mm/filemap.c:1504!\n[ 9849.478635] Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI\n[ 9849.481772] CPU: 2 UID: 0 PID: 84223 Comm: fsstress Not tainted 7.0.0-rc1+ #18 PREEMPT(full)\n[ 9849.482881] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.17.0-9.fc43 06/1\n0/2025\n[ 9849.484539] RIP: 0010:folio_unlock+0x85/0xa0\n[ 9849.485076] Code: 89 df 31 f6 e8 1c f3 ff ff 48 8b 5d f8 c9 31 c0 31 d2 31 f6 31 ff c3 cc\ncc cc cc 48 c7 c6 80 6c d9 a7 48 89 df e8 4b b3 10 00 <0f> 0b 48 89 df e8 21 e6 2c 00 eb 9d 0f 1f 40 00 66 66 2e 0f 1f 84\n[ 9849.493818] RSP: 0018:ffff8881bb8076b0 EFLAGS: 00010246\n[ 9849.495740] RAX: 0000000000000000 RBX: ffffea00070c8980 RCX: 0000000000000000\n[ 9849.498678] RDX: 0000000000000000 RSI: 0000000000000000 RDI: 0000000000000000\n[ 9849.500559] RBP: ffff8881bb8076b8 R08: 0000000000000000 R09: 0000000000000000\n[ 9849.501097] R10: 0000000000000000 R11: 0000000000000000 R12: 0000000010782000\n[ 9849.502108] R13: ffff8881935de738 R14: ffff88816110d010 R15: 0000000000001000\n[ 9849.502516] FS: 00007e36cbe94740(0000) GS:ffff88824a899000(0000) knlGS:0000000000000000\n[ 9849.502996] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 9849.503810] CR2: 000000c0002b0000 CR3: 000000011bbf6004 CR4: 0000000000772ef0\n[ 9849.504459] PKRU: 55555554\n[ 9849.504626] Call Trace:\n[ 9849.505242] <TASK>\n[ 9849.505379] netfs_write_begin+0x7c8/0x10a0\n[ 9849.505877] ? __kasan_check_read+0x11/0x20\n[ 9849.506384] ? __pfx_netfs_write_begin+0x10/0x10\n[ 9849.507178] ceph_write_begin+0x8c/0x1c0\n[ 9849.507934] generic_perform_write+0x391/0x8f0\n[ 9849.508503] ? __pfx_generic_perform_write+0x10/0x10\n[ 9849.509062] ? file_update_time_flags+0x19a/0x4b0\n[ 9849.509581] ? ceph_get_caps+0x63/0xf0\n[ 9849.510259] ? ceph_get_caps+0x63/0xf0\n[ 9849.510530] ceph_write_iter+0xe79/0x1ae0\n[ 9849.511282] ? __pfx_ceph_write_iter+0x10/0x10\n[ 9849.511839] ? lock_acquire+0x1ad/0x310\n[ 9849.512334] ? ksys_write+0xf9/0x230\n[ 9849.512582] ? lock_is_held_type+0xaa/0x140\n[ 9849.513128] vfs_write+0x512/0x1110\n[ 9849.513634] ? __fget_files+0x33/0x350\n[ 9849.513893] ? __pfx_vfs_write+0x10/0x10\n[ 9849.514143] ? mutex_lock_nested+0x1b/0x30\n[ 9849.514394] ksys_write+0xf9/0x230\n[ 9849.514621] ? __pfx_ksys_write+0x10/0x10\n[ 9849.514887] ? do_syscall_64+0x25e/0x1520\n[ 9849.515122] ? __kasan_check_read+0x11/0x20\n[ 9849.515366] ? trace_hardirqs_on_prepare+0x178/0x1c0\n[ 9849.515655] __x64_sys_write+0x72/0xd0\n[ 9849.515885] ? trace_hardirqs_on+0x24/0x1c0\n[ 9849.516130] x64_sys_call+0x22f/0x2390\n[ 9849.516341] do_syscall_64+0x12b/0x1520\n[ 9849.516545] ? do_syscall_64+0x27c/0x1520\n[ 9849.516783] ? do_syscall_64+0x27c/0x1520\n[ 9849.517003] ? lock_release+0x318/0x480\n[ 9849.517220] ? __x64_sys_io_getevents+0x143/0x2d0\n[ 9849.517479] ? percpu_ref_put_many.constprop.0+0x8f/0x210\n[ 9849.517779] ? entry_SYSCALL_64_after_hwframe+0x76/0x7e\n[ 9849.518073] ? do_syscall_64+0x25e/0x1520\n[ 9849.518291] ? __kasan_check_read+0x11/0x20\n[ 9849.518519] ? trace_hardirqs_on_prepare+0x178/0x1c0\n[ 9849.518799] ? do_syscall_64+0x27c/0x1520\n[ 9\n---truncated---', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06442 |
debian: CVE-2026-64065 was patched at 2026-07-14
ubuntu: CVE-2026-64065 was patched at 2026-07-30
1827.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64070) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: powerpc/hv-gpci: fix preempt count leak in sysfs show paths Four sysfs show() callbacks in hv-gpci take get_cpu_var(hv_gpci_reqb) (which calls preempt_disable()) but only call the matching put_cpu_var() on the error path under the 'out:' label. Every successful read leaks one preempt_disable(): processor_bus_topology_show() processor_config_show() affinity_domain_via_virtual_processor_show() affinity_domain_via_domain_show() (affinity_domain_via_partition_show() was already correct.) On a CONFIG_PREEMPT=y kernel, repeated reads raise preempt_count and eventually return to userspace with preemption still disabled. The next user-mode page fault then hits faulthandler_disabled() == 1, gets forced to SIGSEGV, and the resulting coredump trips 'BUG: scheduling while atomic' in call_usermodehelper_exec -> wait_for_completion_state -> schedule: BUG: scheduling while atomic: <task>/<pid>/0x00000004 ... __schedule_bug+0x6c/0x90 __schedule+0x58c/0x13a0 schedule+0x48/0x1a0 schedule_timeout+0x104/0x170 wait_for_completion_state+0x16c/0x330 call_usermodehelper_exec+0x254/0x2d0 vfs_coredump+0x1050/0x2590 get_signal+0xb9c/0xc80 do_notify_resume+0xf8/0x470 Add an out_success label that calls put_cpu_var() before returning the byte count, mirroring affinity_domain_via_partition_show().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\npowerpc/hv-gpci: fix preempt count leak in sysfs show paths\n\nFour sysfs show() callbacks in hv-gpci take get_cpu_var(hv_gpci_reqb)\n(which calls preempt_disable()) but only call the matching put_cpu_var()\non the error path under the 'out:' label. Every successful read leaks\none preempt_disable():\n\n processor_bus_topology_show()\n processor_config_show()\n affinity_domain_via_virtual_processor_show()\n affinity_domain_via_domain_show()\n\n(affinity_domain_via_partition_show() was already correct.)\n\nOn a CONFIG_PREEMPT=y kernel, repeated reads raise preempt_count and\neventually return to userspace with preemption still disabled. The\nnext user-mode page fault then hits faulthandler_disabled() == 1,\ngets forced to SIGSEGV, and the resulting coredump trips\n'BUG: scheduling while atomic' in call_usermodehelper_exec ->\nwait_for_completion_state -> schedule:\n\n BUG: scheduling while atomic: <task>/<pid>/0x00000004\n ...\n __schedule_bug+0x6c/0x90\n __schedule+0x58c/0x13a0\n schedule+0x48/0x1a0\n schedule_timeout+0x104/0x170\n wait_for_completion_state+0x16c/0x330\n call_usermodehelper_exec+0x254/0x2d0\n vfs_coredump+0x1050/0x2590\n get_signal+0xb9c/0xc80\n do_notify_resume+0xf8/0x470\n\nAdd an out_success label that calls put_cpu_var() before returning\nthe byte count, mirroring affinity_domain_via_partition_show().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05212 |
debian: CVE-2026-64070 was patched at 2026-07-14
ubuntu: CVE-2026-64070 was patched at 2026-07-30
1828.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64079) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: allocate hook ops while under mutex arp/ip(6)t_register_table() add the table to the per-netns list via xt_register_table() before allocating the per-netns hook ops copy via kmemdup_array(). This leaves a window where the table is visible in the list with ops=NULL. If the pernet exit happens runs concurrently the pre_exit callback finds the table via xt_find_table() and passes the NULL ops pointer to nf_unregister_net_hooks(), causing a NULL dereference: general protection fault in nf_unregister_net_hooks+0xbc/0x150 RIP: nf_unregister_net_hooks (net/netfilter/core.c:613) Call Trace: ipt_unregister_table_pre_exit iptable_mangle_net_pre_exit ops_pre_exit_list cleanup_net Fix by moving the ops allocation into the xtables core so the table is never in the list without valid ops. Also ensure the table is no longer processing packets before its torn down on error unwind. nf_register_net_hooks might have published at least one hook; call synchronize_rcu() if there was an error. audit log register message gets deferred until all operations have passed, this avoids need to emit another ureg message in case of error unwinding. Based on earlier patch by Tristan Madani.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfilter: x_tables: allocate hook ops while under mutex\n\narp/ip(6)t_register_table() add the table to the per-netns list via\nxt_register_table() before allocating the per-netns hook ops copy\nvia kmemdup_array(). This leaves a window where the table is\nvisible in the list with ops=NULL.\n\nIf the pernet exit happens runs concurrently the pre_exit callback finds\nthe table via xt_find_table() and passes the NULL ops pointer to\nnf_unregister_net_hooks(), causing a NULL dereference:\n\n general protection fault in nf_unregister_net_hooks+0xbc/0x150\n RIP: nf_unregister_net_hooks (net/netfilter/core.c:613)\n Call Trace:\n ipt_unregister_table_pre_exit\n iptable_mangle_net_pre_exit\n ops_pre_exit_list\n cleanup_net\n\nFix by moving the ops allocation into the xtables core so the table is\nnever in the list without valid ops. Also ensure the table is no longer\nprocessing packets before its torn down on error unwind.\nnf_register_net_hooks might have published at least one hook; call\nsynchronize_rcu() if there was an error.\n\naudit log register message gets deferred until all operations have\npassed, this avoids need to emit another ureg message in case of\nerror unwinding.\n\nBased on earlier patch by Tristan Madani.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05213 |
debian: CVE-2026-64079 was patched at 2026-07-14
ubuntu: CVE-2026-64079 was patched at 2026-07-30
1829.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64083) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors adm1266_gpio_get() and adm1266_gpio_get_multiple() both compose the pin-status word as \tpins_status = read_buf[0] + (read_buf[1] << 8); right after i2c_smbus_read_block_data(), guarding only against an error return. A well-behaved device returns 2 bytes for GPIO_STATUS/PDIO_STATUS, but the helper happily reports a 0- or 1-byte response too. If the device returns 0 bytes, both read_buf slots are uninitialized stack memory; if it returns 1 byte, read_buf[1] is. The composed value then flows through set_bit() into the caller's *bits in adm1266_gpio_get_multiple(), or into the return value of adm1266_gpio_get(), and ends up in userspace via gpiolib (sysfs and the char-dev ioctls). That leaks a few bits of kernel stack per request on any device whose firmware glitch, bus error, or hostile slave produces a short block-read response. Add the missing length check to both call sites and surface a short response as -EIO.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) reject short block-read responses in the GPIO accessors\n\nadm1266_gpio_get() and adm1266_gpio_get_multiple() both compose the\npin-status word as\n\n\tpins_status = read_buf[0] + (read_buf[1] << 8);\n\nright after i2c_smbus_read_block_data(), guarding only against an\nerror return. A well-behaved device returns 2 bytes for\nGPIO_STATUS/PDIO_STATUS, but the helper happily reports a 0- or\n1-byte response too. If the device returns 0 bytes, both read_buf\nslots are uninitialized stack memory; if it returns 1 byte, read_buf[1]\nis.\n\nThe composed value then flows through set_bit() into the caller's\n*bits in adm1266_gpio_get_multiple(), or into the return value of\nadm1266_gpio_get(), and ends up in userspace via gpiolib (sysfs and\nthe char-dev ioctls). That leaks a few bits of kernel stack per\nrequest on any device whose firmware glitch, bus error, or hostile\nslave produces a short block-read response.\n\nAdd the missing length check to both call sites and surface a short\nresponse as -EIO.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.08327 |
debian: CVE-2026-64083 was patched at 2026-07-14
ubuntu: CVE-2026-64083 was patched at 2026-07-30
1830.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64085) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer adm1266_pmbus_block_xfer() copies the device-supplied block payload into the caller-provided buffer using the device-supplied length: \tmemcpy(data_r, &msgs[1].buf[1], msgs[1].buf[0]); The helper does not know how large data_r is and trusts the device to return at most one record's worth of bytes. adm1266_nvmem_read_blackbox() violates that contract: it advances read_buff inside data->dev_mem in ADM1266_BLACKBOX_SIZE (64-byte) strides while the helper is willing to write up to ADM1266_PMBUS_BLOCK_MAX (255) bytes. A device that returns more than 64 bytes on the trailing record (read_buff offset 1984 in the 2048-byte dev_mem allocation) overflows dev_mem by up to 191 bytes before the post-call \tif (ret != ADM1266_BLACKBOX_SIZE) \t\treturn -EIO; can reject the response. Contain the fix in the caller without changing the helper signature: read each record into a 255-byte local bounce buffer that matches the helper's maximum output, validate the returned length, and only then copy exactly ADM1266_BLACKBOX_SIZE bytes into the dev_mem slot.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) bounce blackbox records through a protocol-sized buffer\n\nadm1266_pmbus_block_xfer() copies the device-supplied block payload\ninto the caller-provided buffer using the device-supplied length:\n\n\tmemcpy(data_r, &msgs[1].buf[1], msgs[1].buf[0]);\n\nThe helper does not know how large data_r is and trusts the device to\nreturn at most one record's worth of bytes. adm1266_nvmem_read_blackbox()\nviolates that contract: it advances read_buff inside data->dev_mem in\nADM1266_BLACKBOX_SIZE (64-byte) strides while the helper is willing to\nwrite up to ADM1266_PMBUS_BLOCK_MAX (255) bytes. A device that returns\nmore than 64 bytes on the trailing record (read_buff offset 1984 in\nthe 2048-byte dev_mem allocation) overflows dev_mem by up to 191 bytes\nbefore the post-call\n\n\tif (ret != ADM1266_BLACKBOX_SIZE)\n\t\treturn -EIO;\n\ncan reject the response.\n\nContain the fix in the caller without changing the helper signature:\nread each record into a 255-byte local bounce buffer that matches the\nhelper's maximum output, validate the returned length, and only then\ncopy exactly ADM1266_BLACKBOX_SIZE bytes into the dev_mem slot.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.08326 |
debian: CVE-2026-64085 was patched at 2026-07-14
ubuntu: CVE-2026-64085 was patched at 2026-07-30
1831.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64087) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) reject implausible blackbox record_count adm1266_nvmem_read_blackbox() loops over a record_count that comes straight from byte 3 of the BLACKBOX_INFO response. The destination buffer is data->dev_mem, sized for the nvmem cell's declared 2048 bytes (ADM1266_BLACKBOX_MAX_RECORDS * ADM1266_BLACKBOX_SIZE = 32 * 64). A device that reports a record_count greater than 32 -- whether due to firmware bugs, bus corruption, or a non-responsive slave returning 0xff -- would walk read_buff past the end of the dev_mem allocation on the trailing iterations. Cap record_count at ADM1266_BLACKBOX_MAX_RECORDS (introduced here) before entering the loop and return -EIO on any larger value, so a malformed BLACKBOX_INFO response cannot drive the loop out of bounds.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) reject implausible blackbox record_count\n\nadm1266_nvmem_read_blackbox() loops over a record_count that comes\nstraight from byte 3 of the BLACKBOX_INFO response. The destination\nbuffer is data->dev_mem, sized for the nvmem cell's declared 2048\nbytes (ADM1266_BLACKBOX_MAX_RECORDS * ADM1266_BLACKBOX_SIZE = 32 * 64).\nA device that reports a record_count greater than 32 -- whether due\nto firmware bugs, bus corruption, or a non-responsive slave returning\n0xff -- would walk read_buff past the end of the dev_mem allocation\non the trailing iterations.\n\nCap record_count at ADM1266_BLACKBOX_MAX_RECORDS (introduced here)\nbefore entering the loop and return -EIO on any larger value, so a\nmalformed BLACKBOX_INFO response cannot drive the loop out of bounds.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.08329 |
debian: CVE-2026-64087 was patched at 2026-07-14
ubuntu: CVE-2026-64087 was patched at 2026-07-30
1832.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64090) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: avoid empty VLAN responses The commit 16116dac2339 ("batman-adv: prevent TT request storms by not sending inconsistent TT TLVLs") added checks to the local (direct) TT response code. But the response can also be done indirectly by another node using the global TT state. To avoid such inconsistency states reported in the original fix, also avoid sending empty VLANs for replies from the global TT state.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tt: avoid empty VLAN responses\n\nThe commit 16116dac2339 ("batman-adv: prevent TT request storms by not\nsending inconsistent TT TLVLs") added checks to the local (direct) TT\nresponse code. But the response can also be done indirectly by another node\nusing the global TT state. To avoid such inconsistency states reported in\nthe original fix, also avoid sending empty VLANs for replies from the\nglobal TT state.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00184, EPSS Percentile is 0.08328 |
debian: CVE-2026-64090 was patched at 2026-07-14
ubuntu: CVE-2026-64090 was patched at 2026-07-30
1833.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64092) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: batman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown The receiver shutdown timer handler, batadv_tp_receiver_shutdown(), is responsible for releasing the tp_vars reference it holds. However, the existing logic for coordinating this release with batadv_tp_stop_all() was flawed. timer_shutdown_sync() guarantees the timer will not fire again after it returns, but it returns non-zero only when the timer was pending at the time of the call. If the timer had already expired (and batadv_tp_stop_all() would unsucessfully try to rearm itself), batadv_tp_stop_all() skips its batadv_tp_vars_put(), and batadv_tp_receiver_shutdown() fails to put its own reference as well. Fix this by introducing a new atomic variable receiving that is set to 1 when the receiver is initialized and cleared atomically with atomic_xchg() by whichever side claims it first. Only the side that observes the transition from 1 to 0 is responsible for releasing the tp_vars timer reference, eliminating the uncertainty.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: tp_meter: fix tp_vars reference leak in receiver shutdown\n\nThe receiver shutdown timer handler, batadv_tp_receiver_shutdown(), is\nresponsible for releasing the tp_vars reference it holds. However, the\nexisting logic for coordinating this release with batadv_tp_stop_all() was\nflawed.\n\ntimer_shutdown_sync() guarantees the timer will not fire again after it\nreturns, but it returns non-zero only when the timer was pending at the\ntime of the call. If the timer had already expired (and\nbatadv_tp_stop_all() would unsucessfully try to rearm itself),\nbatadv_tp_stop_all() skips its batadv_tp_vars_put(), and\nbatadv_tp_receiver_shutdown() fails to put its own reference as well.\n\nFix this by introducing a new atomic variable receiving that is set to 1\nwhen the receiver is initialized and cleared atomically with atomic_xchg()\nby whichever side claims it first. Only the side that observes the\ntransition from 1 to 0 is responsible for releasing the tp_vars timer\nreference, eliminating the uncertainty.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07883 |
debian: CVE-2026-64092 was patched at 2026-07-14
1834.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64094) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: batman-adv: bla: avoid NULL-ptr deref for claim via dropped interface Without rtnl_lock held, a hardif might be retrieved as primary interface of a meshif, but then (while operating on this interface) getting decoupled from the mesh interface. In this case, the meshif still exists but the pointer from the primary hardif to the meshif is set to NULL. The mesh_iface must be checked first to be non-NULL before continuing to send an ARP request using meshif.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbatman-adv: bla: avoid NULL-ptr deref for claim via dropped interface\n\nWithout rtnl_lock held, a hardif might be retrieved as primary interface of\na meshif, but then (while operating on this interface) getting decoupled\nfrom the mesh interface. In this case, the meshif still exists but the\npointer from the primary hardif to the meshif is set to NULL.\n\nThe mesh_iface must be checked first to be non-NULL before continuing to\nsend an ARP request using meshif.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0021, EPSS Percentile is 0.11416 |
debian: CVE-2026-64094 was patched at 2026-07-14
ubuntu: CVE-2026-64094 was patched at 2026-07-30
1835.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64105) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: vgic: Free private_irqs when init fails after allocation Companion to commit 250f25367b58 ("KVM: arm64: Tear down vGIC on failed vCPU creation"), which added the missing kvm_vgic_vcpu_destroy() call to the kvm_share_hyp() failure path in kvm_arch_vcpu_create(). The kvm_vgic_vcpu_init() failure path immediately above it has the same shape and still needs the same cleanup. Call kvm_vgic_vcpu_destroy() when kvm_vgic_vcpu_init() fails so private IRQs allocated before a redistributor iodev registration failure are released before the failed vCPU is freed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nKVM: arm64: vgic: Free private_irqs when init fails after allocation\n\nCompanion to commit 250f25367b58 ("KVM: arm64: Tear down vGIC on\nfailed vCPU creation"), which added the missing kvm_vgic_vcpu_destroy()\ncall to the kvm_share_hyp() failure path in kvm_arch_vcpu_create(). The\nkvm_vgic_vcpu_init() failure path immediately above it has the same\nshape and still needs the same cleanup.\n\nCall kvm_vgic_vcpu_destroy() when kvm_vgic_vcpu_init() fails so private\nIRQs allocated before a redistributor iodev registration failure are\nreleased before the failed vCPU is freed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06437 |
debian: CVE-2026-64105 was patched at 2026-07-14
ubuntu: CVE-2026-64105 was patched at 2026-07-30
1836.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64119) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: l2tp: use list_del_rcu in l2tp_session_unhash An unprivileged local user can pin a host CPU indefinitely in l2tp_session_get_by_ifname() by issuing L2TP_CMD_SESSION_GET on L2TP_ATTR_IFNAME concurrently with L2TP_CMD_SESSION_CREATE and L2TP_CMD_SESSION_DELETE on the same tunnel. All three commands take GENL_UNS_ADMIN_PERM, so CAP_NET_ADMIN in the netns user namespace suffices; on any host that has l2tp_core loaded the trigger is reachable from a standard `unshare -Urn` sandbox. l2tp_session_unhash() removes a session from tunnel->session_list with list_del_init(), but that list is walked by l2tp_session_get_by_ifname() with list_for_each_entry_rcu() under rcu_read_lock_bh(). list_del_init() leaves the deleted entry's next/prev self-pointing; a reader that has loaded the entry and then advances pos->list.next reads &session->list, container_of()s back to the same session, and list_for_each_entry_rcu() never reaches the list head. The CPU stays in strcmp() inside the walker, with BH and preemption disabled, so RCU grace periods on the host stall behind it and the wedged thread cannot be killed (SIGKILL is delivered on syscall return). Use list_del_rcu() to match the existing list_add_rcu() in l2tp_session_register(); the deleted session remains visible to in-flight walkers with consistent next/prev pointers until kfree_rcu() in l2tp_session_free() releases it. tunnel->session_list has exactly one list_del_init() call site; the list_del_init (&session->clist) at l2tp_core.c:533 operates on the per-collision list, which is not walked under RCU. list_empty(&session->list) is not used anywhere in net/l2tp/ after the unhash point, so dropping the post-delete self-init is safe; the fix has no userspace-visible behavior change.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nl2tp: use list_del_rcu in l2tp_session_unhash\n\nAn unprivileged local user can pin a host CPU indefinitely in\nl2tp_session_get_by_ifname() by issuing L2TP_CMD_SESSION_GET on\nL2TP_ATTR_IFNAME concurrently with L2TP_CMD_SESSION_CREATE and\nL2TP_CMD_SESSION_DELETE on the same tunnel. All three commands take\nGENL_UNS_ADMIN_PERM, so CAP_NET_ADMIN in the netns user namespace\nsuffices; on any host that has l2tp_core loaded the trigger is\nreachable from a standard `unshare -Urn` sandbox.\n\nl2tp_session_unhash() removes a session from tunnel->session_list\nwith list_del_init(), but that list is walked by\nl2tp_session_get_by_ifname() with list_for_each_entry_rcu() under\nrcu_read_lock_bh(). list_del_init() leaves the deleted entry's\nnext/prev self-pointing; a reader that has loaded the entry and\nthen advances pos->list.next reads &session->list, container_of()s\nback to the same session, and list_for_each_entry_rcu() never\nreaches the list head. The CPU stays in strcmp() inside the\nwalker, with BH and preemption disabled, so RCU grace periods on\nthe host stall behind it and the wedged thread cannot be killed\n(SIGKILL is delivered on syscall return).\n\nUse list_del_rcu() to match the existing list_add_rcu() in\nl2tp_session_register(); the deleted session remains visible to\nin-flight walkers with consistent next/prev pointers until\nkfree_rcu() in l2tp_session_free() releases it. tunnel->session_list\nhas exactly one list_del_init() call site; the list_del_init\n(&session->clist) at l2tp_core.c:533 operates on the per-collision\nlist, which is not walked under RCU. list_empty(&session->list) is\nnot used anywhere in net/l2tp/ after the unhash point, so dropping\nthe post-delete self-init is safe; the fix has no userspace-visible\nbehavior change.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00167, EPSS Percentile is 0.064 |
debian: CVE-2026-64119 was patched at 2026-07-14
ubuntu: CVE-2026-64119 was patched at 2026-07-30
1837.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64121) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: ifb: report ethtool stats over num_tx_queues ifb_dev_init() allocates dp->tx_private to dev->num_tx_queues entries via kzalloc_objs(*txp, dev->num_tx_queues). Both IFB per-queue RX and TX stats live in those entries: ifb_xmit() updates txp->rx_stats using the skb queue mapping, ifb_ri_tasklet() updates txp->tx_stats, and ifb_stats64() aggregates both over dev->num_tx_queues. The ethtool stats callbacks instead size and walk the per-queue stats with dev->real_num_rx_queues and dev->real_num_tx_queues. With an asymmetric device where the RX queue count exceeds the TX queue count, for example: ip link add name ifb10 numtxqueues 1 numrxqueues 8 type ifb ethtool -S ifb10 ifb_get_ethtool_stats() indexes past the tx_private allocation and copies adjacent slab data through ETHTOOL_GSTATS. Use dev->num_tx_queues consistently for the stats strings, the stats count, and the stats data walks. This reports one RX stats group and one TX stats group for each backing ifb_q_private entry, which is the queue set IFB can actually populate. Reproduced under UML+KASAN at v7.1-rc2: BUG: KASAN: slab-out-of-bounds in ifb_fill_stats_data+0x3c/0xae Read of size 8 at addr 0000000062dbd228 by task ethtool/36 ifb_fill_stats_data+0x3c/0xae ifb_get_ethtool_stats+0xc0/0x129 __dev_ethtool+0x1ca5/0x363c dev_ethtool+0x123/0x1b3 dev_ioctl+0x56c/0x744 sock_do_ioctl+0x15f/0x1b2 sock_ioctl+0x4d5/0x50a sys_ioctl+0xd8b/0xde9 With the patch applied, the same UML+KASAN repro is silent and ethtool -S ifb10 reports only the stats backed by the single allocated tx_private entry.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: ifb: report ethtool stats over num_tx_queues\n\nifb_dev_init() allocates dp->tx_private to dev->num_tx_queues\nentries via kzalloc_objs(*txp, dev->num_tx_queues). Both IFB\nper-queue RX and TX stats live in those entries: ifb_xmit() updates\ntxp->rx_stats using the skb queue mapping, ifb_ri_tasklet() updates\ntxp->tx_stats, and ifb_stats64() aggregates both over\ndev->num_tx_queues.\n\nThe ethtool stats callbacks instead size and walk the per-queue\nstats with dev->real_num_rx_queues and dev->real_num_tx_queues. With\nan asymmetric device where the RX queue count exceeds the TX queue\ncount, for example:\n\n ip link add name ifb10 numtxqueues 1 numrxqueues 8 type ifb\n ethtool -S ifb10\n\nifb_get_ethtool_stats() indexes past the tx_private allocation and\ncopies adjacent slab data through ETHTOOL_GSTATS.\n\nUse dev->num_tx_queues consistently for the stats strings, the\nstats count, and the stats data walks. This reports one RX stats\ngroup and one TX stats group for each backing ifb_q_private entry,\nwhich is the queue set IFB can actually populate.\n\nReproduced under UML+KASAN at v7.1-rc2:\n\n BUG: KASAN: slab-out-of-bounds in ifb_fill_stats_data+0x3c/0xae\n Read of size 8 at addr 0000000062dbd228 by task ethtool/36\n ifb_fill_stats_data+0x3c/0xae\n ifb_get_ethtool_stats+0xc0/0x129\n __dev_ethtool+0x1ca5/0x363c\n dev_ethtool+0x123/0x1b3\n dev_ioctl+0x56c/0x744\n sock_do_ioctl+0x15f/0x1b2\n sock_ioctl+0x4d5/0x50a\n sys_ioctl+0xd8b/0xde9\n\nWith the patch applied, the same UML+KASAN repro is silent and\nethtool -S ifb10 reports only the stats backed by the single\nallocated tx_private entry.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00173, EPSS Percentile is 0.06931 |
debian: CVE-2026-64121 was patched at 2026-07-14
ubuntu: CVE-2026-64121 was patched at 2026-07-30
1838.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64127) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer Commit 1c08108f3014 ("Bluetooth: L2CAP: Avoid -Wflex-array-member-not-at-end warnings") converted the on-stack request PDU in l2cap_ecred_reconfigure() from an explicit packed struct to DEFINE_RAW_FLEX(), but did not adjust the size and source-pointer arguments to l2cap_send_cmd(): - struct { - struct l2cap_ecred_reconf_req req; - __le16 scid; - } pdu; + DEFINE_RAW_FLEX(struct l2cap_ecred_reconf_req, pdu, scid, 1); ... l2cap_send_cmd(conn, chan->ident, L2CAP_ECRED_RECONF_REQ, sizeof(pdu), &pdu); After the conversion, DEFINE_RAW_FLEX() expands to declare an anonymous union pdu_u plus a local pointer "pdu" pointing at it. Therefore: - sizeof(pdu) is now sizeof(struct l2cap_ecred_reconf_req *) = 8 on 64-bit (4 on 32-bit), not the 6 bytes of (mtu, mps, scid[1]). - &pdu is the address of the local pointer's stack storage, not the address of the request payload. l2cap_send_cmd() forwards (data, count) to l2cap_build_cmd(), which calls skb_put_data(skb, data, count). The L2CAP_ECRED_RECONFIGURE_REQ packet body therefore contains 8 bytes copied from the kernel stack starting at &pdu -- the 8 bytes overlap the pdu pointer's value, leaking a kernel stack address to the paired Bluetooth peer. The intended (mtu, mps, scid) fields are not transmitted at all, so the peer rejects the request as malformed and the L2CAP_ECRED_RECONFIGURE feature itself has been broken for the local-side initiator since the introducing commit landed. The sibling site l2cap_ecred_conn_req() in the same commit was converted correctly (sizeof(*pdu) + len, pdu); only this site was missed. Restore the original semantics: pass the full flex-struct size via struct_size(pdu, scid, 1) and the pdu pointer (the struct address) as the source. Validated on a stock 7.0-based host kernel via the real call path: setsockopt(SOL_BLUETOOTH, BT_RCVMTU, ...) on a BT_CONNECTED L2CAP_MODE_EXT_FLOWCTL socket emits an L2CAP_ECRED_RECONFIGURE_REQ whose body is 8 bytes (the on-stack pdu local's value) rather than the expected 6. Three captures from fresh socket / fresh hciemu peer on the same host -- low bytes vary per call, high 0xffff confirms a kernel virtual address (KASLR-randomised stack slot, not a fixed string): RECONF_REQ body (ident=0x02 len=8): 42 fb 54 af 0e ca ff ff RECONF_REQ body (ident=0x02 len=8): 52 3d 2e af 0e ca ff ff RECONF_REQ body (ident=0x02 len=8): b2 fc 5b af 0e ca ff ff After this patch the body is 6 bytes carrying the expected little-endian (mtu, mps, scid).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: L2CAP: ecred_reconfigure: send packed pdu, not stack pointer\n\nCommit 1c08108f3014 ("Bluetooth: L2CAP: Avoid -Wflex-array-member-not-at-end\nwarnings") converted the on-stack request PDU in l2cap_ecred_reconfigure()\nfrom an explicit packed struct to DEFINE_RAW_FLEX(), but did not adjust the\nsize and source-pointer arguments to l2cap_send_cmd():\n\n - struct {\n - struct l2cap_ecred_reconf_req req;\n - __le16 scid;\n - } pdu;\n + DEFINE_RAW_FLEX(struct l2cap_ecred_reconf_req, pdu, scid, 1);\n ...\n l2cap_send_cmd(conn, chan->ident, L2CAP_ECRED_RECONF_REQ,\n sizeof(pdu), &pdu);\n\nAfter the conversion, DEFINE_RAW_FLEX() expands to declare an anonymous\nunion pdu_u plus a local pointer "pdu" pointing at it. Therefore:\n\n - sizeof(pdu) is now sizeof(struct l2cap_ecred_reconf_req *) = 8 on\n 64-bit (4 on 32-bit), not the 6 bytes of (mtu, mps, scid[1]).\n - &pdu is the address of the local pointer's stack storage, not the\n address of the request payload.\n\nl2cap_send_cmd() forwards (data, count) to l2cap_build_cmd(), which calls\nskb_put_data(skb, data, count). The L2CAP_ECRED_RECONFIGURE_REQ packet\nbody therefore contains 8 bytes copied from the kernel stack starting at\n&pdu -- the 8 bytes overlap the pdu pointer's value, leaking a kernel\nstack address to the paired Bluetooth peer. The intended (mtu, mps, scid)\nfields are not transmitted at all, so the peer rejects the request as\nmalformed and the L2CAP_ECRED_RECONFIGURE feature itself has been broken\nfor the local-side initiator since the introducing commit landed.\n\nThe sibling site l2cap_ecred_conn_req() in the same commit was converted\ncorrectly (sizeof(*pdu) + len, pdu); only this site was missed.\n\nRestore the original semantics: pass the full flex-struct size via\nstruct_size(pdu, scid, 1) and the pdu pointer (the struct address) as\nthe source.\n\nValidated on a stock 7.0-based host kernel via the real call path:\nsetsockopt(SOL_BLUETOOTH, BT_RCVMTU, ...) on a BT_CONNECTED\nL2CAP_MODE_EXT_FLOWCTL socket emits an L2CAP_ECRED_RECONFIGURE_REQ\nwhose body is 8 bytes (the on-stack pdu local's value) rather than\nthe expected 6. Three captures from fresh socket / fresh hciemu peer\non the same host -- low bytes vary per call, high 0xffff confirms a\nkernel virtual address (KASLR-randomised stack slot, not a fixed\nstring):\n\n RECONF_REQ body (ident=0x02 len=8): 42 fb 54 af 0e ca ff ff\n RECONF_REQ body (ident=0x02 len=8): 52 3d 2e af 0e ca ff ff\n RECONF_REQ body (ident=0x02 len=8): b2 fc 5b af 0e ca ff ff\n\nAfter this patch the body is 6 bytes carrying the expected\nlittle-endian (mtu, mps, scid).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07301 |
debian: CVE-2026-64127 was patched at 2026-07-14
ubuntu: CVE-2026-64127 was patched at 2026-07-30
1839.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64128) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: drop ISO_END frames received without prior ISO_START ISO data PDUs carry a packet-boundary flag indicating START, CONT, END or SINGLE. The ISO_CONT branch of iso_recv() guards against a missing ISO_START by checking conn->rx_len before touching conn->rx_skb, but ISO_END does not. If a peer sends an ISO_END as the first packet on a fresh ISO connection, conn->rx_skb is still NULL and conn->rx_len is zero, so skb_put(conn->rx_skb, ...) dereferences NULL and oopses. For BIS, where receivers sync to a broadcaster without pairing, any broadcaster on the air can trigger this. Mirror the ISO_CONT check at the top of ISO_END so a stray end fragment is logged and dropped instead of crashing the host.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: ISO: drop ISO_END frames received without prior ISO_START\n\nISO data PDUs carry a packet-boundary flag indicating START, CONT, END\nor SINGLE. The ISO_CONT branch of iso_recv() guards against a missing\nISO_START by checking conn->rx_len before touching conn->rx_skb, but\nISO_END does not.\n\nIf a peer sends an ISO_END as the first packet on a fresh ISO\nconnection, conn->rx_skb is still NULL and conn->rx_len is zero, so\nskb_put(conn->rx_skb, ...) dereferences NULL and oopses. For BIS,\nwhere receivers sync to a broadcaster without pairing, any broadcaster\non the air can trigger this.\n\nMirror the ISO_CONT check at the top of ISO_END so a stray end fragment\nis logged and dropped instead of crashing the host.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0018, EPSS Percentile is 0.07885 |
debian: CVE-2026-64128 was patched at 2026-07-14
ubuntu: CVE-2026-64128 was patched at 2026-07-30
1840.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64131) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/memory: fix spurious warning when unmapping device-private/exclusive pages Device private and exclusive entries are only supported for anonymous folios. This condition is tested in __migrate_device_pages() and make_device_exclusive() using folio_test_anon(). However the unmap path tests this assumption using vma_is_anonymous(). This is wrong because whilst anonymous VMAs can only contain folios where folio_test_anon() is true the opposite relation does not hold. A folio for which folio_test_anon() is true does not imply vma_is_anonymous() is true. Such a condition can occur if for example a folio is part of a private filebacked mapping. In this case vma_is_anonymous() is false as the mapping is filebacked, but folio_test_anon() may be true, thus permitting devices to migrate the folio to device private memory. This can lead to the following spurious warnings during process teardown: [ 772.737706] ------------[ cut here ]------------ [ 772.739201] WARNING: mm/memory.c:1754 at unmap_page_range.cold+0x26/0x18a, CPU#17: hmm-tests/2041 [ 772.742050] Modules linked in: test_hmm nvidia_uvm(O) nvidia(O) [ 772.743959] CPU: 17 UID: 0 PID: 2041 Comm: hmm-tests Tainted: G W O 7.0.0+ #387 PREEMPT(full) [ 772.747104] Tainted: [W]=WARN, [O]=OOT_MODULE [ 772.748509] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014 [ 772.752117] RIP: 0010:unmap_page_range.cold+0x26/0x18a [ 772.753780] Code: 7e fe ff ff 48 89 4c 24 78 4c 89 44 24 38 e8 f2 ff b1 00 48 8b 4c 24 78 4c 8b 44 24 38 48 8b 44 24 18 48 83 78 48 00 74 04 90 <0f> 0b 90 48 89 ca b8 ff ff 37 00 48 c1 ea 03 48 c1 e0 2a 80 3c 02 [ 772.759602] RSP: 0018:ffff888112607550 EFLAGS: 00010286 [ 772.761310] RAX: ffff88811bbf4dc0 RBX: dffffc0000000000 RCX: ffffea03e9bfffd8 [ 772.763583] RDX: 1ffff1102377e9c1 RSI: 0000000000000008 RDI: ffff88811bbf4e08 [ 772.765914] RBP: 0000000000000006 R08: ffff8881059f7448 R09: ffffed10224c0e68 [ 772.768184] R10: ffff888112607347 R11: 0000000000000001 R12: 0000000000000001 [ 772.770461] R13: ffffea03e9bfffc0 R14: ffff888112607908 R15: ffffea03e9bfffc0 [ 772.772782] FS: 00007f327caa2780(0000) GS:ffff888427b7d000(0000) knlGS:0000000000000000 [ 772.775328] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 [ 772.777187] CR2: 00007f327ca89000 CR3: 00000001994d5000 CR4: 00000000000006f0 [ 772.779135] Call Trace: [ 772.779792] <TASK> [ 772.780317] ? dmirror_interval_invalidate+0x1a3/0x290 [test_hmm] [ 772.781873] ? vm_normal_page_pud+0x2b0/0x2b0 [ 772.782992] ? __rwlock_init+0x150/0x150 [ 772.784006] ? lock_release+0x216/0x2b0 [ 772.785008] ? __mmu_notifier_invalidate_range_start+0x505/0x6e0 [ 772.786522] ? lock_release+0x216/0x2b0 [ 772.787498] ? unmap_single_vma+0xb6/0x210 [ 772.788573] unmap_vmas+0x27d/0x520 [ 772.789506] ? unmap_single_vma+0x210/0x210 [ 772.790607] ? mas_update_gap.part.0+0x620/0x620 [ 772.791834] unmap_region+0x19e/0x350 [ 772.792769] ? remove_vma+0x130/0x130 [ 772.793684] ? mas_alloc_nodes+0x1f2/0x300 [ 772.794730] vms_complete_munmap_vmas+0x8c1/0xe20 [ 772.795926] ? unmap_region+0x350/0x350 [ 772.796917] do_vmi_align_munmap+0x36a/0x4e0 [ 772.798018] ? lock_release+0x216/0x2b0 [ 772.799024] ? vma_shrink+0x620/0x620 [ 772.799983] do_vmi_munmap+0x150/0x2c0 [ 772.800939] __vm_munmap+0x161/0x2c0 [ 772.801872] ? expand_downwards+0xd60/0xd60 [ 772.802948] ? clockevents_program_event+0x1ef/0x540 [ 772.804217] ? lock_release+0x216/0x2b0 [ 772.805158] __x64_sys_munmap+0x59/0x80 [ 772.805776] do_syscall_64+0xfc/0x670 [ 772.806336] ? irqentry_exit+0xda/0x580 [ 772.806976] entry_SYSCALL_64_after_hwframe+0x4b/0x53 [ 772.807772] RIP: 0033:0x7f327cbb2717 [ 772.808323] Code: 73 01 c3 48 8b 0d f9 76 0d 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 b8 0b 00 00 00 0f 05 <48> 3d 01 f0 ff ---truncated---', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/memory: fix spurious warning when unmapping device-private/exclusive pages\n\nDevice private and exclusive entries are only supported for anonymous\nfolios. This condition is tested in __migrate_device_pages() and\nmake_device_exclusive() using folio_test_anon(). However the unmap path\ntests this assumption using vma_is_anonymous().\n\nThis is wrong because whilst anonymous VMAs can only contain folios where\nfolio_test_anon() is true the opposite relation does not hold. A folio\nfor which folio_test_anon() is true does not imply vma_is_anonymous() is\ntrue. Such a condition can occur if for example a folio is part of a\nprivate filebacked mapping.\n\nIn this case vma_is_anonymous() is false as the mapping is filebacked, but\nfolio_test_anon() may be true, thus permitting devices to migrate the\nfolio to device private memory. This can lead to the following spurious\nwarnings during process teardown:\n\n[ 772.737706] ------------[ cut here ]------------\n[ 772.739201] WARNING: mm/memory.c:1754 at unmap_page_range.cold+0x26/0x18a, CPU#17: hmm-tests/2041\n[ 772.742050] Modules linked in: test_hmm nvidia_uvm(O) nvidia(O)\n[ 772.743959] CPU: 17 UID: 0 PID: 2041 Comm: hmm-tests Tainted: G W O 7.0.0+ #387 PREEMPT(full)\n[ 772.747104] Tainted: [W]=WARN, [O]=OOT_MODULE\n[ 772.748509] Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS rel-1.17.0-0-gb52ca86e094d-prebuilt.qemu.org 04/01/2014\n[ 772.752117] RIP: 0010:unmap_page_range.cold+0x26/0x18a\n[ 772.753780] Code: 7e fe ff ff 48 89 4c 24 78 4c 89 44 24 38 e8 f2 ff b1 00 48 8b 4c 24 78 4c 8b 44 24 38 48 8b 44 24 18 48 83 78 48 00 74 04 90 <0f> 0b 90 48 89 ca b8 ff ff 37 00 48 c1 ea 03 48 c1 e0 2a 80 3c 02\n[ 772.759602] RSP: 0018:ffff888112607550 EFLAGS: 00010286\n[ 772.761310] RAX: ffff88811bbf4dc0 RBX: dffffc0000000000 RCX: ffffea03e9bfffd8\n[ 772.763583] RDX: 1ffff1102377e9c1 RSI: 0000000000000008 RDI: ffff88811bbf4e08\n[ 772.765914] RBP: 0000000000000006 R08: ffff8881059f7448 R09: ffffed10224c0e68\n[ 772.768184] R10: ffff888112607347 R11: 0000000000000001 R12: 0000000000000001\n[ 772.770461] R13: ffffea03e9bfffc0 R14: ffff888112607908 R15: ffffea03e9bfffc0\n[ 772.772782] FS: 00007f327caa2780(0000) GS:ffff888427b7d000(0000) knlGS:0000000000000000\n[ 772.775328] CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033\n[ 772.777187] CR2: 00007f327ca89000 CR3: 00000001994d5000 CR4: 00000000000006f0\n[ 772.779135] Call Trace:\n[ 772.779792] <TASK>\n[ 772.780317] ? dmirror_interval_invalidate+0x1a3/0x290 [test_hmm]\n[ 772.781873] ? vm_normal_page_pud+0x2b0/0x2b0\n[ 772.782992] ? __rwlock_init+0x150/0x150\n[ 772.784006] ? lock_release+0x216/0x2b0\n[ 772.785008] ? __mmu_notifier_invalidate_range_start+0x505/0x6e0\n[ 772.786522] ? lock_release+0x216/0x2b0\n[ 772.787498] ? unmap_single_vma+0xb6/0x210\n[ 772.788573] unmap_vmas+0x27d/0x520\n[ 772.789506] ? unmap_single_vma+0x210/0x210\n[ 772.790607] ? mas_update_gap.part.0+0x620/0x620\n[ 772.791834] unmap_region+0x19e/0x350\n[ 772.792769] ? remove_vma+0x130/0x130\n[ 772.793684] ? mas_alloc_nodes+0x1f2/0x300\n[ 772.794730] vms_complete_munmap_vmas+0x8c1/0xe20\n[ 772.795926] ? unmap_region+0x350/0x350\n[ 772.796917] do_vmi_align_munmap+0x36a/0x4e0\n[ 772.798018] ? lock_release+0x216/0x2b0\n[ 772.799024] ? vma_shrink+0x620/0x620\n[ 772.799983] do_vmi_munmap+0x150/0x2c0\n[ 772.800939] __vm_munmap+0x161/0x2c0\n[ 772.801872] ? expand_downwards+0xd60/0xd60\n[ 772.802948] ? clockevents_program_event+0x1ef/0x540\n[ 772.804217] ? lock_release+0x216/0x2b0\n[ 772.805158] __x64_sys_munmap+0x59/0x80\n[ 772.805776] do_syscall_64+0xfc/0x670\n[ 772.806336] ? irqentry_exit+0xda/0x580\n[ 772.806976] entry_SYSCALL_64_after_hwframe+0x4b/0x53\n[ 772.807772] RIP: 0033:0x7f327cbb2717\n[ 772.808323] Code: 73 01 c3 48 8b 0d f9 76 0d 00 f7 d8 64 89 01 48 83 c8 ff c3 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 44 00 00 b8 0b 00 00 00 0f 05 <48> 3d 01 f0 ff\n---truncated---', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06898 |
debian: CVE-2026-64131 was patched at 2026-07-14
ubuntu: CVE-2026-64131 was patched at 2026-07-30
1841.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64135) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: hwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX adm1266_nvmem_read_blackbox() declares a 5-byte stack buffer and passes it to i2c_smbus_read_block_data() to retrieve the 4-byte BLACKBOX_INFO response. i2c_smbus_read_block_data() does not honour caller buffer sizes -- it memcpy()s data.block[0] bytes from the SMBus transaction (where data.block[0] is the length byte returned by the slave device, up to I2C_SMBUS_BLOCK_MAX = 32): \tmemcpy(values, &data.block[1], data.block[0]); If the device returns any block length above 5, the call overflows the caller's 5-byte stack buffer before the post-call \tif (ret != 4) \t\treturn -EIO; check has a chance to reject the response. Widen the local buffer to I2C_SMBUS_BLOCK_MAX so the helper has room for any well-formed SMBus block response, matching the convention used by the other i2c_smbus_read_block_data() callers in this driver.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nhwmon: (pmbus/adm1266) widen blackbox-info buffer to I2C_SMBUS_BLOCK_MAX\n\nadm1266_nvmem_read_blackbox() declares a 5-byte stack buffer and\npasses it to i2c_smbus_read_block_data() to retrieve the 4-byte\nBLACKBOX_INFO response. i2c_smbus_read_block_data() does not honour\ncaller buffer sizes -- it memcpy()s data.block[0] bytes from the\nSMBus transaction (where data.block[0] is the length byte returned by\nthe slave device, up to I2C_SMBUS_BLOCK_MAX = 32):\n\n\tmemcpy(values, &data.block[1], data.block[0]);\n\nIf the device returns any block length above 5, the call overflows\nthe caller's 5-byte stack buffer before the post-call\n\n\tif (ret != 4)\n\t\treturn -EIO;\n\ncheck has a chance to reject the response.\n\nWiden the local buffer to I2C_SMBUS_BLOCK_MAX so the helper has room\nfor any well-formed SMBus block response, matching the convention used\nby the other i2c_smbus_read_block_data() callers in this driver.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00177, EPSS Percentile is 0.07455 |
debian: CVE-2026-64135 was patched at 2026-07-14
ubuntu: CVE-2026-64135 was patched at 2026-07-30
1842.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64144) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btmtk: fix urb->setup_packet leak in error paths The setup_packet of control urb is not freed if usb_submit_urb fails or the submitted urb is killed. Add free in these two paths.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nBluetooth: btmtk: fix urb->setup_packet leak in error paths\n\nThe setup_packet of control urb is not freed if usb_submit_urb fails or\nthe submitted urb is killed. Add free in these two paths.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.073 |
debian: CVE-2026-64144 was patched at 2026-07-14
ubuntu: CVE-2026-64144 was patched at 2026-07-30
1843.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64146) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: erofs: fix metabuf leak in inode xattr initialization commit bb88e8da0025 ("erofs: use meta buffers for xattr operations") converted xattr operations to use on-stack erofs_buf instances. erofs_init_inode_xattrs() uses such a metabuf while reading the inline xattr header and shared xattr id array. Some error paths after erofs_read_metabuf() leave through out_unlock without dropping the metabuf, so the folio reference can leak. Consolidate the cleanup at out_unlock. erofs_put_metabuf() is a no-op if no folio has been acquired, and this keeps all paths after taking EROFS_I_BL_XATTR_BIT covered by a single cleanup site.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nerofs: fix metabuf leak in inode xattr initialization\n\ncommit bb88e8da0025 ("erofs: use meta buffers for xattr operations")\nconverted xattr operations to use on-stack erofs_buf instances.\nerofs_init_inode_xattrs() uses such a metabuf while reading the inline\nxattr header and shared xattr id array.\n\nSome error paths after erofs_read_metabuf() leave through out_unlock\nwithout dropping the metabuf, so the folio reference can leak.\n\nConsolidate the cleanup at out_unlock. erofs_put_metabuf() is a\nno-op if no folio has been acquired, and this keeps all paths after\ntaking EROFS_I_BL_XATTR_BIT covered by a single cleanup site.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00162, EPSS Percentile is 0.05901 |
debian: CVE-2026-64146 was patched at 2026-07-14
ubuntu: CVE-2026-64146 was patched at 2026-07-30
1844.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64147) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: pds_core: fix debugfs_lookup dentry leak and error handling debugfs_lookup() returns a dentry with an elevated reference count that must be released with dput(). The current code discards the returned dentry without calling dput(), causing a reference leak on every firmware reset recovery. Additionally, when CONFIG_DEBUG_FS is disabled, debugfs_lookup() returns ERR_PTR(-ENODEV), not NULL. The current check passes for error pointers and would call dput() on an invalid pointer, causing a crash.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\npds_core: fix debugfs_lookup dentry leak and error handling\n\ndebugfs_lookup() returns a dentry with an elevated reference count that\nmust be released with dput(). The current code discards the returned\ndentry without calling dput(), causing a reference leak on every\nfirmware reset recovery.\n\nAdditionally, when CONFIG_DEBUG_FS is disabled, debugfs_lookup()\nreturns ERR_PTR(-ENODEV), not NULL. The current check passes for error\npointers and would call dput() on an invalid pointer, causing a crash.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00175, EPSS Percentile is 0.07301 |
debian: CVE-2026-64147 was patched at 2026-07-14
ubuntu: CVE-2026-64147 was patched at 2026-07-30
1845.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64154) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drm/msm/adreno: Fix a reference leak in a6xx_gpu_init() In a6xx_gpu_init(), node is obtained via of_parse_phandle(). While there was a manual of_node_put() at the end of the common path, several early error returns would bypass this call, resulting in a reference leak. Fix this by using the __free(device_node) cleanup handler to release the reference when the variable goes out of scope. Patchwork: https://patchwork.freedesktop.org/patch/700661/', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrm/msm/adreno: Fix a reference leak in a6xx_gpu_init()\n\nIn a6xx_gpu_init(), node is obtained via of_parse_phandle().\nWhile there was a manual of_node_put() at the end of the\ncommon path, several early error returns would bypass this call,\nresulting in a reference leak.\nFix this by using the __free(device_node) cleanup handler to\nrelease the reference when the variable goes out of scope.\n\nPatchwork: https://patchwork.freedesktop.org/patch/700661/', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06145 |
debian: CVE-2026-64154 was patched at 2026-07-14
ubuntu: CVE-2026-64154 was patched at 2026-07-30
1846.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64157) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfs: Fix partial invalidation of streaming-write folio In netfs_invalidate_folio(), if the region of a partial invalidation overlaps the front (but not all) of a dirty write cached in a streaming write page (dirty, but not uptodate, with the dirty region tracked by a netfs_folio struct), the function modifies the dirty region - but incorrectly as it moves the region forward by setting the start to the start, not the end, of the invalidation region. Fix this by setting finfo->dirty_offset to the end of the invalidation region (iend).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix partial invalidation of streaming-write folio\n\nIn netfs_invalidate_folio(), if the region of a partial invalidation\noverlaps the front (but not all) of a dirty write cached in a streaming\nwrite page (dirty, but not uptodate, with the dirty region tracked by a\nnetfs_folio struct), the function modifies the dirty region - but\nincorrectly as it moves the region forward by setting the start to the\nstart, not the end, of the invalidation region.\n\nFix this by setting finfo->dirty_offset to the end of the invalidation\nregion (iend).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06436 |
debian: CVE-2026-64157 was patched at 2026-07-14
ubuntu: CVE-2026-64157 was patched at 2026-07-30
1847.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64159) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: netfs: Fix zeropoint update where i_size > remote_i_size Fix the update of the zero point[*] by netfs_release_folio() when there is uncommitted data in the pagecache beyond the folio being released but the on-server EOF is in this folio (ie. i_size > remote_i_size). The update needs to limit zero_point to remote_i_size, not i_size as i_size is a local phenomenon reflecting updates made locally to the pagecache, not stuff written to the server. remote_i_size tracks the server's i_size. [*] The zero point is the file position from which we can assume that the server will just return zeros, so we can avoid generating reads. Note that netfs_invalidate_folio() probably doesn't need fixing as zero_point should be updated by setattr after truncation or fallocate. Found with: fsx -q -N 1000000 -p 10000 -o 128000 -l 600000 \\ /xfstest.test/junk --replay-ops=junk.fsxops using the following as junk.fsxops: truncate 0x0 0x1bbae 0x82864 write 0x3ef2e 0xf9c8 0x1bbae write 0x67e05 0xcb5a 0x4e8f6 mapread 0x57781 0x85b6 0x7495f copy_range 0x5d3d 0x10329 0x54fac 0x7495f write 0x64710 0x1c2b 0x7495f mapread 0x64000 0x1000 0x7495f on cifs with the default cache option. It shows read-gaps on folio 0x64 failing with a short read (ie. it hits EOF) if the FMODE_READ check is commented out in netfs_perform_write(): if (//(file->f_mode & FMODE_READ) || netfs_is_cache_enabled(ctx)) { and no fscache. This was initially found with the generic/522 xfstest.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnetfs: Fix zeropoint update where i_size > remote_i_size\n\nFix the update of the zero point[*] by netfs_release_folio() when there is\nuncommitted data in the pagecache beyond the folio being released but the\non-server EOF is in this folio (ie. i_size > remote_i_size). The update\nneeds to limit zero_point to remote_i_size, not i_size as i_size is a local\nphenomenon reflecting updates made locally to the pagecache, not stuff\nwritten to the server. remote_i_size tracks the server's i_size.\n\n[*] The zero point is the file position from which we can assume that the\n server will just return zeros, so we can avoid generating reads.\n\nNote that netfs_invalidate_folio() probably doesn't need fixing as\nzero_point should be updated by setattr after truncation or fallocate.\n\nFound with:\n\n fsx -q -N 1000000 -p 10000 -o 128000 -l 600000 \\\n /xfstest.test/junk --replay-ops=junk.fsxops\n\nusing the following as junk.fsxops:\n\n truncate 0x0 0x1bbae 0x82864\n write 0x3ef2e 0xf9c8 0x1bbae\n write 0x67e05 0xcb5a 0x4e8f6\n mapread 0x57781 0x85b6 0x7495f\n copy_range 0x5d3d 0x10329 0x54fac 0x7495f\n write 0x64710 0x1c2b 0x7495f\n mapread 0x64000 0x1000 0x7495f\n\non cifs with the default cache option.\n\nIt shows read-gaps on folio 0x64 failing with a short read (ie. it hits\nEOF) if the FMODE_READ check is commented out in netfs_perform_write():\n\n if (//(file->f_mode & FMODE_READ) ||\n netfs_is_cache_enabled(ctx)) {\n\nand no fscache. This was initially found with the generic/522 xfstest.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00155, EPSS Percentile is 0.05215 |
debian: CVE-2026-64159 was patched at 2026-07-14
ubuntu: CVE-2026-64159 was patched at 2026-07-30
1848.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64163) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: test_kprobes: clear kprobes between test runs Running the kprobes sanity tests twice makes all tests fail and eventually crashes the kernel. [root@martin-riscv-1 ~]# echo 1 > /sys/kernel/debug/kunit/kprobes_test/run ... # Totals: pass:5 fail:0 skip:0 total:5 ok 1 kprobes_test [root@martin-riscv-1 ~]# echo 1 > /sys/kernel/debug/kunit/kprobes_test/run ... # test_kprobe: EXPECTATION FAILED at lib/tests/test_kprobes.c:64 Expected 0 == register_kprobe(&kp), but register_kprobe(&kp) == -22 (0xffffffffffffffea) ... Unable to handle kernel paging request ... The testsuite defines several kprobes and kretprobes as static variables that are preserved across test runs. After register_kprobe and unregister_kprobe, a kprobe contains some leftover data that must be cleared before the kprobe can be registered again. The tests are setting symbol_name to define the probe location. Address and flags must be cleared. The existing code clears some of the probes between subsequent tests, but not between two test runs. The leftover data from a previous test run makes the registrations fail in the next run. Move the cleanups for all kprobes into kprobes_test_init, this function is called before each single test (including the first test of a test run).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntest_kprobes: clear kprobes between test runs\n\nRunning the kprobes sanity tests twice makes all tests fail and\neventually crashes the kernel.\n\n[root@martin-riscv-1 ~]# echo 1 > /sys/kernel/debug/kunit/kprobes_test/run\n...\n # Totals: pass:5 fail:0 skip:0 total:5\n ok 1 kprobes_test\n[root@martin-riscv-1 ~]# echo 1 > /sys/kernel/debug/kunit/kprobes_test/run\n...\n # test_kprobe: EXPECTATION FAILED at lib/tests/test_kprobes.c:64\n Expected 0 == register_kprobe(&kp), but\n register_kprobe(&kp) == -22 (0xffffffffffffffea)\n...\n Unable to handle kernel paging request ...\n\nThe testsuite defines several kprobes and kretprobes as static variables\nthat are preserved across test runs.\n\nAfter register_kprobe and unregister_kprobe, a kprobe contains some\nleftover data that must be cleared before the kprobe can be registered\nagain. The tests are setting symbol_name to define the probe location.\nAddress and flags must be cleared.\n\nThe existing code clears some of the probes between subsequent tests, but\nnot between two test runs. The leftover data from a previous test run\nmakes the registrations fail in the next run.\n\nMove the cleanups for all kprobes into kprobes_test_init, this function\nis called before each single test (including the first test of a test\nrun).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00164, EPSS Percentile is 0.06027 |
debian: CVE-2026-64163 was patched at 2026-07-14
ubuntu: CVE-2026-64163 was patched at 2026-07-30
1849.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64164) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() The trace event btrfs_sync_file() is called in an atomic context (all trace events are) and its call to dput(), which is needed due to the call to dget_parent(), can sleep, triggering a kernel splat. This can be reproduced by enabling the trace event and running btrfs/056 from fstests for example. The splat shown in dmesg is the following: [53.919] BUG: sleeping function called from invalid context at fs/dcache.c:970 [53.947] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 32773, name: xfs_io [53.988] preempt_count: 2, expected: 0 [53.967] RCU nest depth: 0, expected: 0 [53.943] Preemption disabled at: [53.944] [<0000000000000000>] 0x0 [54.078] CPU: 0 UID: 0 PID: 32773 Comm: xfs_io Tainted: G W 7.1.0-rc1-btrfs-next-232+ #1 PREEMPT(full) [54.070] Tainted: [W]=WARN [54.071] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014 [54.072] Call Trace: [54.074] <TASK> [54.076] dump_stack_lvl+0x56/0x80 [54.079] __might_resched.cold+0xd6/0x10f [54.072] dput.part.0+0x24/0x110 [54.078] trace_event_raw_event_btrfs_sync_file+0x75/0x140 [btrfs] [54.089] btrfs_sync_file+0x1ed/0x530 [btrfs] [54.087] ? __handle_mm_fault+0x8ae/0xed0 [54.089] btrfs_do_write_iter+0x172/0x210 [btrfs] [54.091] vfs_write+0x21f/0x450 [54.094] __x64_sys_pwrite64+0x8d/0xc0 [54.096] ? do_user_addr_fault+0x20c/0x670 [54.099] do_syscall_64+0x60/0xf20 [54.092] ? clear_bhb_loop+0x60/0xb0 [54.094] entry_SYSCALL_64_after_hwframe+0x76/0x7e So stop using dget_parent() and dput() and access the parent dentry directly as dentry->d_parent. This is also what ext4 is doing in its equivalent trace event ext4_sync_file_enter().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbtrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file()\n\nThe trace event btrfs_sync_file() is called in an atomic context (all trace\nevents are) and its call to dput(), which is needed due to the call to\ndget_parent(), can sleep, triggering a kernel splat.\n\nThis can be reproduced by enabling the trace event and running btrfs/056\nfrom fstests for example. The splat shown in dmesg is the following:\n\n [53.919] BUG: sleeping function called from invalid context at fs/dcache.c:970\n [53.947] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 32773, name: xfs_io\n [53.988] preempt_count: 2, expected: 0\n [53.967] RCU nest depth: 0, expected: 0\n [53.943] Preemption disabled at:\n [53.944] [<0000000000000000>] 0x0\n [54.078] CPU: 0 UID: 0 PID: 32773 Comm: xfs_io Tainted: G W 7.1.0-rc1-btrfs-next-232+ #1 PREEMPT(full)\n [54.070] Tainted: [W]=WARN\n [54.071] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014\n [54.072] Call Trace:\n [54.074] <TASK>\n [54.076] dump_stack_lvl+0x56/0x80\n [54.079] __might_resched.cold+0xd6/0x10f\n [54.072] dput.part.0+0x24/0x110\n [54.078] trace_event_raw_event_btrfs_sync_file+0x75/0x140 [btrfs]\n [54.089] btrfs_sync_file+0x1ed/0x530 [btrfs]\n [54.087] ? __handle_mm_fault+0x8ae/0xed0\n [54.089] btrfs_do_write_iter+0x172/0x210 [btrfs]\n [54.091] vfs_write+0x21f/0x450\n [54.094] __x64_sys_pwrite64+0x8d/0xc0\n [54.096] ? do_user_addr_fault+0x20c/0x670\n [54.099] do_syscall_64+0x60/0xf20\n [54.092] ? clear_bhb_loop+0x60/0xb0\n [54.094] entry_SYSCALL_64_after_hwframe+0x76/0x7e\n\nSo stop using dget_parent() and dput() and access the parent dentry\ndirectly as dentry->d_parent. This is also what ext4 is doing in\nits equivalent trace event ext4_sync_file_enter().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06099 |
debian: CVE-2026-64164 was patched at 2026-07-14
ubuntu: CVE-2026-64164 was patched at 2026-07-30
1850.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64166) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: firmware: arm_ffa: Check for NULL FF-A ID table while driver registration The bus match callback assumes that every FF-A driver provides an id_table and dereferences it unconditionally. Enforce that contract at registration time so a buggy client driver cannot crash the bus during match.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nfirmware: arm_ffa: Check for NULL FF-A ID table while driver registration\n\nThe bus match callback assumes that every FF-A driver provides an\nid_table and dereferences it unconditionally. Enforce that contract at\nregistration time so a buggy client driver cannot crash the bus during\nmatch.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.0653 |
debian: CVE-2026-64166 was patched at 2026-07-14
ubuntu: CVE-2026-64166 was patched at 2026-07-30
1851.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64168) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: spi: sprd: fix error pointer deref after DMA setup failure The driver falls back to PIO mode if DMA setup fails during probe. Make sure to check the dma.enabled flag before trying to release the DMA channels also on late probe errors to avoid dereferencing an error pointer (or attempting to release a channel a second time). This issue was flagged by Sashiko when reviewing a devres allocation conversion patch.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nspi: sprd: fix error pointer deref after DMA setup failure\n\nThe driver falls back to PIO mode if DMA setup fails during probe.\n\nMake sure to check the dma.enabled flag before trying to release the DMA\nchannels also on late probe errors to avoid dereferencing an error\npointer (or attempting to release a channel a second time).\n\nThis issue was flagged by Sashiko when reviewing a devres allocation\nconversion patch.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.0613 |
debian: CVE-2026-64168 was patched at 2026-07-14
ubuntu: CVE-2026-64168 was patched at 2026-07-30
1852.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64169) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: spi: ep93xx: fix error pointer deref after DMA setup failure The driver falls back to PIO mode if DMA setup fails during probe. Make sure to the clear the DMA channel pointers on setup failure to avoid dereferencing an error pointer on later probe errors or driver unbind. This issue was flagged by Sashiko when reviewing a devres allocation conversion patch.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nspi: ep93xx: fix error pointer deref after DMA setup failure\n\nThe driver falls back to PIO mode if DMA setup fails during probe.\n\nMake sure to the clear the DMA channel pointers on setup failure to\navoid dereferencing an error pointer on later probe errors or driver\nunbind.\n\nThis issue was flagged by Sashiko when reviewing a devres allocation\nconversion patch.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05287 |
debian: CVE-2026-64169 was patched at 2026-07-14
ubuntu: CVE-2026-64169 was patched at 2026-07-30
1853.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64170) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: spi: qup: fix error pointer deref after DMA setup failure The driver falls back to PIO mode if DMA setup fails during probe. Make sure to the clear the DMA channel pointers on setup failure to avoid dereferencing an error pointer (or attempting to release a channel a second time) on later probe errors or driver unbind. This issue was flagged by Sashiko when reviewing a devres allocation conversion patch.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nspi: qup: fix error pointer deref after DMA setup failure\n\nThe driver falls back to PIO mode if DMA setup fails during probe.\n\nMake sure to the clear the DMA channel pointers on setup failure to\navoid dereferencing an error pointer (or attempting to release a channel\na second time) on later probe errors or driver unbind.\n\nThis issue was flagged by Sashiko when reviewing a devres allocation\nconversion patch.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06099 |
debian: CVE-2026-64170 was patched at 2026-07-14
ubuntu: CVE-2026-64170 was patched at 2026-07-30
1854.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64173) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: tracing: Do not call map->ops->elt_free() if elt_alloc() fails In paths where tracing_map_elt_alloc() failed to allocate objects, the map->ops->elt_alloc() call was never successful. In this case, map->ops->elt_free() should not be called.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ntracing: Do not call map->ops->elt_free() if elt_alloc() fails\n\nIn paths where tracing_map_elt_alloc() failed to allocate objects,\nthe map->ops->elt_alloc() call was never successful. In this case,\nmap->ops->elt_free() should not be called.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06099 |
debian: CVE-2026-64173 was patched at 2026-07-14
ubuntu: CVE-2026-64173 was patched at 2026-07-30
1855.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64174) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: wifi: cfg80211: advance loop vars in cfg80211_merge_profile() cfg80211_merge_profile() reassembles a Multi-BSSID non-transmitted BSS profile that has been split across multiple consecutive MBSSID elements. Its while-loop calls \tcfg80211_get_profile_continuation(ie, ielen, mbssid_elem, sub_elem) but never advances mbssid_elem or sub_elem inside the body. Each iteration therefore searches for a continuation that follows the same fixed pair; the helper returns the same next_mbssid; and the same next_sub bytes are memcpy()'d into merged_ie at a growing offset until the buffer fills. Advance both mbssid_elem and sub_elem to the just-consumed continuation so the next call to cfg80211_get_profile_continuation() searches for a further continuation beyond it (or returns NULL when none exists). A specially-crafted malicious beacon can take advantage of this bug to cause the kernel to spend an excessive amount of time in cfg80211_merge_profile (up to as much as 2ms per beacon received), which could theoretically be abused in some way.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nwifi: cfg80211: advance loop vars in cfg80211_merge_profile()\n\ncfg80211_merge_profile() reassembles a Multi-BSSID non-transmitted BSS\nprofile that has been split across multiple consecutive MBSSID elements.\nIts while-loop calls\n\n\tcfg80211_get_profile_continuation(ie, ielen, mbssid_elem, sub_elem)\n\nbut never advances mbssid_elem or sub_elem inside the body. Each\niteration therefore searches for a continuation that follows the same\nfixed pair; the helper returns the same next_mbssid; and the same\nnext_sub bytes are memcpy()'d into merged_ie at a growing offset until\nthe buffer fills.\n\nAdvance both mbssid_elem and sub_elem to the just-consumed continuation\nso the next call to cfg80211_get_profile_continuation() searches for a\nfurther continuation beyond it (or returns NULL when none exists).\n\nA specially-crafted malicious beacon can take advantage of this bug\nto cause the kernel to spend an excessive amount of time in\ncfg80211_merge_profile (up to as much as 2ms per beacon received),\nwhich could theoretically be abused in some way.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00172, EPSS Percentile is 0.06904 |
debian: CVE-2026-64174 was patched at 2026-07-14
ubuntu: CVE-2026-64174 was patched at 2026-07-30
1856.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64177) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: phonet/pep: disable BH around forwarded sk_receive_skb() The networking receive path is usually run from softirq context, but protocols that take the socket lock may have packets stored in the backlog and processed later from process context. In that case release_sock() -> __release_sock() drops the slock with spin_unlock_bh() and then calls sk->sk_backlog_rcv() with bottom halves enabled. Typical sk_backlog_rcv handlers process the socket whose backlog is being drained, so the BH state at entry is irrelevant for the slocks they touch. pep_do_rcv() is different: when the inbound skb targets an existing PEP pipe, it forwards the skb to a different *child* socket via sk_receive_skb(). That helper takes the child slock with bh_lock_sock_nested(), which is just spin_lock_nested() and assumes BH is already off. The same child slock therefore ends up acquired with BH on (process path) and with BH off (softirq path): process context softirq context --------------- --------------- release_sock(listener) __netif_receive_skb() __release_sock() phonet_rcv() spin_unlock_bh() __sk_receive_skb(listener) [BH now ENABLED] [BH already disabled] sk_backlog_rcv: sk_backlog_rcv: pep_do_rcv() pep_do_rcv() sk_receive_skb(child) sk_receive_skb(child) bh_lock_sock_nested(child) bh_lock_sock_nested(child) => SOFTIRQ-ON-W => IN-SOFTIRQ-W Lockdep flags this as inconsistent lock state, and it can become a real self-deadlock if a softirq on the same CPU tries to receive to the same child socket while its slock is held in the BH-enabled path: WARNING: inconsistent lock state inconsistent {SOFTIRQ-ON-W} -> {IN-SOFTIRQ-W} usage. (slock-AF_PHONET/1){+.?.}-{3:3}, at: __sk_receive_skb+0x1cf/0x900 __sk_receive_skb net/core/sock.c:563 sk_receive_skb include/net/sock.h:2022 [inline] pep_do_rcv net/phonet/pep.c:675 sk_backlog_rcv include/net/sock.h:1190 __release_sock net/core/sock.c:3216 release_sock net/core/sock.c:3815 pep_sock_accept net/phonet/pep.c:879 Wrap the forwarded sk_receive_skb() in local_bh_disable() / local_bh_enable() so the child slock is always acquired with BH off. local_bh_disable() nests safely on the softirq path. Discovered via in-house syzkaller fuzzing; the same root cause also on the linux-6.1.y syzbot dashboard as extid 44f0626dd6284f02663c. Reproduced under KASAN + LOCKDEP + PROVE_LOCKING, reproducer: https://pastebin.com/A3t8xzCR', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nphonet/pep: disable BH around forwarded sk_receive_skb()\n\nThe networking receive path is usually run from softirq context, but\nprotocols that take the socket lock may have packets stored in the\nbacklog and processed later from process context. In that case\nrelease_sock() -> __release_sock() drops the slock with spin_unlock_bh()\nand then calls sk->sk_backlog_rcv() with bottom halves enabled.\n\nTypical sk_backlog_rcv handlers process the socket whose backlog is\nbeing drained, so the BH state at entry is irrelevant for the slocks\nthey touch. pep_do_rcv() is different: when the inbound skb targets an\nexisting PEP pipe, it forwards the skb to a different *child* socket\nvia sk_receive_skb(). That helper takes the child slock with\nbh_lock_sock_nested(), which is just spin_lock_nested() and assumes BH\nis already off. The same child slock therefore ends up acquired with\nBH on (process path) and with BH off (softirq path):\n\n process context softirq context\n --------------- ---------------\n release_sock(listener) __netif_receive_skb()\n __release_sock() phonet_rcv()\n spin_unlock_bh() __sk_receive_skb(listener)\n [BH now ENABLED] [BH already disabled]\n sk_backlog_rcv: sk_backlog_rcv:\n pep_do_rcv() pep_do_rcv()\n sk_receive_skb(child) sk_receive_skb(child)\n bh_lock_sock_nested(child) bh_lock_sock_nested(child)\n => SOFTIRQ-ON-W => IN-SOFTIRQ-W\n\nLockdep flags this as inconsistent lock state, and it can become a real\nself-deadlock if a softirq on the same CPU tries to receive to the same\nchild socket while its slock is held in the BH-enabled path:\n\n WARNING: inconsistent lock state\n inconsistent {SOFTIRQ-ON-W} -> {IN-SOFTIRQ-W} usage.\n (slock-AF_PHONET/1){+.?.}-{3:3}, at: __sk_receive_skb+0x1cf/0x900\n __sk_receive_skb net/core/sock.c:563\n sk_receive_skb include/net/sock.h:2022 [inline]\n pep_do_rcv net/phonet/pep.c:675\n sk_backlog_rcv include/net/sock.h:1190\n __release_sock net/core/sock.c:3216\n release_sock net/core/sock.c:3815\n pep_sock_accept net/phonet/pep.c:879\n\nWrap the forwarded sk_receive_skb() in local_bh_disable() /\nlocal_bh_enable() so the child slock is always acquired with BH off.\nlocal_bh_disable() nests safely on the softirq path.\n\nDiscovered via in-house syzkaller fuzzing; the same root cause also\non the linux-6.1.y syzbot dashboard as extid 44f0626dd6284f02663c.\nReproduced under KASAN + LOCKDEP + PROVE_LOCKING, reproducer:\nhttps://pastebin.com/A3t8xzCR', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00165, EPSS Percentile is 0.06098 |
debian: CVE-2026-64177 was patched at 2026-07-14
ubuntu: CVE-2026-64177 was patched at 2026-07-30
1857.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64179) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: net: wwan: iosm: fix potential memory leaks in ipc_imem_init() The memory allocated in ipc_protocol_init() is not freed on the error paths that follow in ipc_imem_init(). Fix that by calling the corresponding release function ipc_protocol_deinit() in the error path.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nnet: wwan: iosm: fix potential memory leaks in ipc_imem_init()\n\nThe memory allocated in ipc_protocol_init() is not freed on the error\npaths that follow in ipc_imem_init(). Fix that by calling the\ncorresponding release function ipc_protocol_deinit() in the error path.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.05773 |
debian: CVE-2026-64179 was patched at 2026-07-14
ubuntu: CVE-2026-64179 was patched at 2026-07-30
1858.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64180) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/memory_hotplug: fix memory block reference leak on remove Patch series "mm: Fix memory block leaks and locking", v2. This series fixes two memory block device reference leaks and one locking issue around the per-memory_block hwpoison counter. This patch (of 2): remove_memory_blocks_and_altmaps() looks up each memory block with find_memory_block(), which acquires a reference to the memory block device. That reference is never dropped on this path, resulting in a leaked device reference when removing memory blocks and their altmaps. Drop the reference after retrieving mem->altmap and clearing mem->altmap, before removing the memory block device.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/memory_hotplug: fix memory block reference leak on remove\n\nPatch series "mm: Fix memory block leaks and locking", v2.\n\nThis series fixes two memory block device reference leaks and one locking\nissue around the per-memory_block hwpoison counter.\n\n\nThis patch (of 2):\n\nremove_memory_blocks_and_altmaps() looks up each memory block with\nfind_memory_block(), which acquires a reference to the memory block\ndevice.\n\nThat reference is never dropped on this path, resulting in a leaked device\nreference when removing memory blocks and their altmaps. Drop the\nreference after retrieving mem->altmap and clearing mem->altmap, before\nremoving the memory block device.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.05331 |
debian: CVE-2026-64180 was patched at 2026-07-14
ubuntu: CVE-2026-64180 was patched at 2026-07-30
1859.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64182) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: drivers/base/memory: fix memory block reference leak in poison accounting memblk_nr_poison_inc() and memblk_nr_poison_sub() look up a memory block via find_memory_block_by_id(), which acquires a reference to the memory block device. Both helpers use the returned memory block without dropping that reference, leaking the device reference on each successful lookup. Drop the reference after updating nr_hwpoison.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ndrivers/base/memory: fix memory block reference leak in poison accounting\n\nmemblk_nr_poison_inc() and memblk_nr_poison_sub() look up a memory block\nvia find_memory_block_by_id(), which acquires a reference to the memory\nblock device.\n\nBoth helpers use the returned memory block without dropping that\nreference, leaking the device reference on each successful lookup. Drop\nthe reference after updating nr_hwpoison.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.05328 |
debian: CVE-2026-64182 was patched at 2026-07-14
ubuntu: CVE-2026-64182 was patched at 2026-07-30
1860.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64184) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: call missing mem_cgroup_iter_break() damon_sysfs_memcg_path_to_id() breaks mem_cgroup_iter() loop without calling mem_cgroup_iter_break(). This leaks the cgroup reference. Fix the issue by calling mem_cgroup_iter_break() before the break. The issue was discovered [1] by Sashiko.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nmm/damon/sysfs-schemes: call missing mem_cgroup_iter_break()\n\ndamon_sysfs_memcg_path_to_id() breaks mem_cgroup_iter() loop without\ncalling mem_cgroup_iter_break(). This leaks the cgroup reference. Fix\nthe issue by calling mem_cgroup_iter_break() before the break.\n\nThe issue was discovered [1] by Sashiko.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00157, EPSS Percentile is 0.05328 |
debian: CVE-2026-64184 was patched at 2026-07-14
ubuntu: CVE-2026-64184 was patched at 2026-07-30
1861.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64185) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: sysfs: don't remove existing directory on update failure When sysfs_update_group() is called for a named group and create_files() fails (e.g. -ENOMEM), internal_create_group() calls kernfs_remove(kn) on the group directory. In the update path, kn was obtained via kernfs_find_and_get() and refers to a directory that already existed before this call. Removing it silently destroys a sysfs group that the caller did not create. Only remove the directory if we created it ourselves. On update failure the directory remains as it is left empty by remove_files() inside create_files(), but can be repopulated by a retry.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nsysfs: don't remove existing directory on update failure\n\nWhen sysfs_update_group() is called for a named group and create_files()\nfails (e.g. -ENOMEM), internal_create_group() calls kernfs_remove(kn) on\nthe group directory. In the update path, kn was obtained via\nkernfs_find_and_get() and refers to a directory that already existed\nbefore this call. Removing it silently destroys a sysfs group that the\ncaller did not create.\n\nOnly remove the directory if we created it ourselves. On update failure\nthe directory remains as it is left empty by remove_files() inside\ncreate_files(), but can be repopulated by a retry.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00168, EPSS Percentile is 0.06465 |
debian: CVE-2026-64185 was patched at 2026-07-14
ubuntu: CVE-2026-64185 was patched at 2026-07-30
1862.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64187) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: xfs: fail recovery on a committed log item with no regions If the first op of a transaction is a bare transaction header (len == sizeof(struct xfs_trans_header)), xlog_recover_add_to_trans() adds an item but no region, leaving it on r_itemq with ri_cnt == 0 and ri_buf == NULL. The header can be split across op records, so later ops may still add regions; the item is only invalid if the transaction commits with none. The runtime commit path never emits such a transaction, so this only happens on a crafted log. It came from an AI-assisted code audit of the recovery parser. xlog_recover_reorder_trans() calls ITEM_TYPE() on the item, which reads *(unsigned short *)item->ri_buf[0].iov_base and faults on the NULL ri_buf. Reject it there, before the commit handlers that also read ri_buf[0]. KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007] RIP: 0010:xlog_recover_reorder_trans (fs/xfs/xfs_log_recover.c:1836) xlog_recover_commit_trans (fs/xfs/xfs_log_recover.c:2043) xlog_recover_process_data (fs/xfs/xfs_log_recover.c:2501) xlog_do_recovery_pass (fs/xfs/xfs_log_recover.c:3244) xlog_recover (fs/xfs/xfs_log_recover.c:3493) xfs_log_mount (fs/xfs/xfs_log.c:618) xfs_mountfs (fs/xfs/xfs_mount.c:1034) xfs_fs_fill_super (fs/xfs/xfs_super.c:1938) vfs_get_tree (fs/super.c:1695) path_mount (fs/namespace.c:4161) __x64_sys_mount (fs/namespace.c:4367)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nxfs: fail recovery on a committed log item with no regions\n\nIf the first op of a transaction is a bare transaction header\n(len == sizeof(struct xfs_trans_header)), xlog_recover_add_to_trans()\nadds an item but no region, leaving it on r_itemq with ri_cnt == 0 and\nri_buf == NULL.\n\nThe header can be split across op records, so later ops may still add\nregions; the item is only invalid if the transaction commits with none.\nThe runtime commit path never emits such a transaction, so this only\nhappens on a crafted log. It came from an AI-assisted code audit of the\nrecovery parser.\n\nxlog_recover_reorder_trans() calls ITEM_TYPE() on the item, which reads\n*(unsigned short *)item->ri_buf[0].iov_base and faults on the NULL\nri_buf. Reject it there, before the commit handlers that also read\nri_buf[0].\n\n KASAN: null-ptr-deref in range [0x0000000000000000-0x0000000000000007]\n RIP: 0010:xlog_recover_reorder_trans (fs/xfs/xfs_log_recover.c:1836)\n xlog_recover_commit_trans (fs/xfs/xfs_log_recover.c:2043)\n xlog_recover_process_data (fs/xfs/xfs_log_recover.c:2501)\n xlog_do_recovery_pass (fs/xfs/xfs_log_recover.c:3244)\n xlog_recover (fs/xfs/xfs_log_recover.c:3493)\n xfs_log_mount (fs/xfs/xfs_log.c:618)\n xfs_mountfs (fs/xfs/xfs_mount.c:1034)\n xfs_fs_fill_super (fs/xfs/xfs_super.c:1938)\n vfs_get_tree (fs/super.c:1695)\n path_mount (fs/namespace.c:4161)\n __x64_sys_mount (fs/namespace.c:4367)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00161, EPSS Percentile is 0.0572 |
debian: CVE-2026-64187 was patched at 2026-07-14, 2026-07-21
1863.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64192) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: bpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized When CONFIG_BPF_LSM=y is set, BPF inode storage maps (BPF_MAP_TYPE_INODE_STORAGE) are compiled into the kernel. However, if the BPF LSM is not explicitly enabled at boot time (e.g. omitted from the "lsm=" boot parameter), lsm_prepare() is never executed for the BPF LSM. Consequently, the BPF inode security blob offset (bpf_lsm_blob_sizes.lbs_inode) is never initialized and remains at its default compiled size of 8 bytes instead of being updated to a valid offset past the reserved struct rcu_head (typically 16 bytes or more). When a privileged user creates and updates a BPF_MAP_TYPE_INODE_STORAGE map, bpf_inode() evaluates inode->i_security + 8. This erroneously aliases the struct rcu_head.func callback pointer at the beginning of the inode->i_security blob. During subsequent map element cleanup or inode destruction, writing NULL to owner_storage clears the queued RCU callback pointer. When rcu_do_batch() later executes the queued callback, it attempts an instruction fetch at address 0x0, triggering an immediate kernel panic. Fix this by introducing a global bpf_lsm_initialized boolean flag marked with __ro_after_init. Set this flag to true inside bpf_lsm_init() when the LSM framework successfully registers the BPF LSM. Gate map allocation in inode_storage_map_alloc() on this flag, returning -EOPNOTSUPP if the BPF LSM is in turn uninitialized. This fail-fast approach prevents userspace from allocating inode storage maps when the supporting BPF LSM infrastructure is absent, avoiding zombie map states.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nbpf: Reject BPF_MAP_TYPE_INODE_STORAGE creation if BPF LSM is uninitialized\n\nWhen CONFIG_BPF_LSM=y is set, BPF inode storage maps\n(BPF_MAP_TYPE_INODE_STORAGE) are compiled into the kernel. However,\nif the BPF LSM is not explicitly enabled at boot time (e.g. omitted\nfrom the "lsm=" boot parameter), lsm_prepare() is never executed for\nthe BPF LSM.\n\nConsequently, the BPF inode security blob offset\n(bpf_lsm_blob_sizes.lbs_inode) is never initialized and remains at\nits default compiled size of 8 bytes instead of being updated to a\nvalid offset past the reserved struct rcu_head (typically 16 bytes\nor more).\n\nWhen a privileged user creates and updates a BPF_MAP_TYPE_INODE_STORAGE\nmap, bpf_inode() evaluates inode->i_security + 8. This erroneously\naliases the struct rcu_head.func callback pointer at the beginning\nof the inode->i_security blob. During subsequent map element cleanup\nor inode destruction, writing NULL to owner_storage clears the queued\nRCU callback pointer. When rcu_do_batch() later executes the queued\ncallback, it attempts an instruction fetch at address 0x0, triggering\nan immediate kernel panic.\n\nFix this by introducing a global bpf_lsm_initialized boolean flag\nmarked with __ro_after_init. Set this flag to true inside bpf_lsm_init()\nwhen the LSM framework successfully registers the BPF LSM. Gate map\nallocation in inode_storage_map_alloc() on this flag, returning\n-EOPNOTSUPP if the BPF LSM is in turn uninitialized.\n\nThis fail-fast approach prevents userspace from allocating inode\nstorage maps when the supporting BPF LSM infrastructure is absent,\navoiding zombie map states.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.00162, EPSS Percentile is 0.05866 |
debian: CVE-2026-64192 was patched at 2026-07-14
1864.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-64205) - Low [161]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: i2c: i801: fix hardware state machine corruption in error path A severe livelock and subsequent Hung Task panic were observed in the i2c-i801 driver during concurrent Fuzzing. The crash is caused by an unconditional hardware register cleanup in the error handling path of i801_access(). When i801_check_pre() fails (e.g., returning -EBUSY because the SMBus controller is actively used by BIOS/ACPI), the kernel does not actually acquire the hardware ownership. However, the code jumps to the 'out' label and executes: iowrite8(SMBHSTSTS_INUSE_STS | STATUS_FLAGS, SMBHSTSTS(priv)); This forcefully clears the INUSE_STS lock and resets the hardware status flags without owning the controller. Doing so interrupts ongoing BIOS/ACPI transactions and totally corrupts the SMBus hardware state machine. Consequently, all subsequent i801_access() calls fail at the pre-check stage, triggering an endless stream of "SMBus is busy, can't use it!" error logs. Over a slow serial console, this printk flood monopolizes the CPU (Console Livelock), starving other processes trying to acquire the mmap_lock down_read semaphore, ultimately triggering the hung task watchdog. Fix this by moving the 'out' label below the hardware register cleanup. If i801_check_pre() fails, we safely bypass the iowrite8() and only release the software locks (pm_runtime and mutex), strictly adhering to the rule of not releasing resources that were never acquired.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\ni2c: i801: fix hardware state machine corruption in error path\n\nA severe livelock and subsequent Hung Task panic were observed in the\ni2c-i801 driver during concurrent Fuzzing. The crash is caused by an\nunconditional hardware register cleanup in the error handling path of\ni801_access().\n\nWhen i801_check_pre() fails (e.g., returning -EBUSY because the SMBus\ncontroller is actively used by BIOS/ACPI), the kernel does not actually\nacquire the hardware ownership. However, the code jumps to the 'out'\nlabel and executes:\n\n iowrite8(SMBHSTSTS_INUSE_STS | STATUS_FLAGS, SMBHSTSTS(priv));\n\nThis forcefully clears the INUSE_STS lock and resets the hardware status\nflags without owning the controller. Doing so interrupts ongoing BIOS/ACPI\ntransactions and totally corrupts the SMBus hardware state machine.\n\nConsequently, all subsequent i801_access() calls fail at the pre-check\nstage, triggering an endless stream of "SMBus is busy, can't use it!"\nerror logs. Over a slow serial console, this printk flood monopolizes\nthe CPU (Console Livelock), starving other processes trying to acquire\nthe mmap_lock down_read semaphore, ultimately triggering the hung task\nwatchdog.\n\nFix this by moving the 'out' label below the hardware register cleanup.\nIf i801_check_pre() fails, we safely bypass the iowrite8() and only\nrelease the software locks (pm_runtime and mutex), strictly adhering to\nthe rule of not releasing resources that were never acquired.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.1 | 10 | EPSS Probability is 0.0017, EPSS Percentile is 0.06697 |
debian: CVE-2026-64205 was patched at 2026-07-14
1865.
Denial of Service - Unknown Product (CVE-2026-14683) - Low [160]
Description: {'nvd_cve_data_all': 'A vulnerability was detected in HdrHistogram up to 2.2.2. Affected by this issue is the function org.HdrHistogram.AbstractHistogram.decodeFromCompressedByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. The manipulation of the argument lengthOfCompressedContents results in uncontrolled memory allocation. The attack needs to be approached locally. The exploit is now public and may be used. It is still unclear if this vulnerability genuinely exists. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability was detected in HdrHistogram up to 2.2.2. Affected by this issue is the function org.HdrHistogram.AbstractHistogram.decodeFromCompressedByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. The manipulation of the argument lengthOfCompressedContents results in uncontrolled memory allocation. The attack needs to be approached locally. The exploit is now public and may be used. It is still unclear if this vulnerability genuinely exists. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.01983 |
debian: CVE-2026-14683 was patched at 2026-07-14
1866.
Denial of Service - Unknown Product (CVE-2026-14684) - Low [160]
Description: {'nvd_cve_data_all': 'A flaw has been found in HdrHistogram up to 2.2.2. This affects the function org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. This manipulation of the argument numberOfSignificantValueDigits causes uncontrolled memory allocation. The attack can only be executed locally. The exploit has been published and may be used. The actual existence of this vulnerability is currently in question. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw has been found in HdrHistogram up to 2.2.2. This affects the function org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. This manipulation of the argument numberOfSignificantValueDigits causes uncontrolled memory allocation. The attack can only be executed locally. The exploit has been published and may be used. The actual existence of this vulnerability is currently in question. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0012, EPSS Percentile is 0.02133 |
debian: CVE-2026-14684 was patched at 2026-07-14
1867.
Denial of Service - Unknown Product (CVE-2026-39199) - Low [160]
Description: {'nvd_cve_data_all': 'snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.7 | 15 | Denial of Service | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 2.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00125, EPSS Percentile is 0.02574 |
debian: CVE-2026-39199 was patched at 2026-06-24
1868.
Incorrect Calculation - Unknown Product (CVE-2026-15551) - Low [160]
Description: {'nvd_cve_data_all': 'Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Overflow Buffers. This issue affects .', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Integer overflow or wraparound vulnerability in Samsung Open Source rlottie allows Overflow Buffers.\n\nThis issue affects .', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Incorrect Calculation | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00081, EPSS Percentile is 0.00256 |
debian: CVE-2026-15551 was patched at 2026-07-14
1869.
Memory Corruption - Unknown Product (CVE-2026-14647) - Low [160]
Description: {'nvd_cve_data_all': 'A weakness has been identified in onnx up to 1.21.x. This vulnerability affects the function convPoolShapeInference_opset19 of the file onnx/defs/nn/old.cc of the component onnxruntime. This manipulation causes out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Patch name: a7bf3a0f1d18bb62575236ef6e4944980c40e045. It is recommended to apply a patch to fix this issue.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A weakness has been identified in onnx up to 1.21.x. This vulnerability affects the function convPoolShapeInference_opset19 of the file onnx/defs/nn/old.cc of the component onnxruntime. This manipulation causes out-of-bounds read. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks. Patch name: a7bf3a0f1d18bb62575236ef6e4944980c40e045. It is recommended to apply a patch to fix this issue.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00253, EPSS Percentile is 0.16833 |
debian: CVE-2026-14647 was patched at 2026-07-14
1870.
Memory Corruption - Unknown Product (CVE-2026-54696) - Low [160]
Description: {'nvd_cve_data_all': 'Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when the JSON generator is provided with an oversized streamed object. When streaming to an IO JSON.dump(obj, io) and JSON::State#generate(obj, io) can write past the internal JSON generator buffer when a streamed object contains an attacker-controlled string near 16 KB. Exploitation would result in a reliable process crash/denial of service. This issue has been fixed in version 2.19.9.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 through 2.19.8 are vulnerable to heap buffer overflow when the JSON generator is provided with an oversized streamed object. When streaming to an IO JSON.dump(obj, io) and JSON::State#generate(obj, io) can write past the internal JSON generator buffer when a streamed object contains an\nattacker-controlled string near 16 KB. Exploitation would result in a reliable process crash/denial of service. This issue has been fixed in version 2.19.9.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00301, EPSS Percentile is 0.22461 |
debian: CVE-2026-54696 was patched at 2026-07-14
1871.
Memory Corruption - Unknown Product (CVE-2026-60103) - Low [160]
Description: {'nvd_cve_data_all': 'Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or read adjacent heap memory by supplying a crafted .blend file with a malicious signed short member_index value in the SDNA block. The member_index field is used as an array index into the sdna->members[] array in sdna_expand_names() without bounds validation, allowing any value outside the allocated range to produce an invalid pointer subsequently passed to strlen(), resulting in a SIGSEGV crash or unintended heap memory disclosure.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerability that allows attackers to trigger a crash or read adjacent heap memory by supplying a crafted .blend file with a malicious signed short member_index value in the SDNA block. The member_index field is used as an array index into the sdna->members[] array in sdna_expand_names() without bounds validation, allowing any value outside the allocated range to produce an invalid pointer subsequently passed to strlen(), resulting in a SIGSEGV crash or unintended heap memory disclosure.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.1. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01937 |
debian: CVE-2026-60103 was patched at 2026-07-14
1872.
Unknown Vulnerability Type - Gogs (CVE-2026-26196) - Low [158]
Description: {'nvd_cve_data_all': 'Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params like token and access_token, which can leak through logs, browser history, and referrers. This issue has been patched in version 0.14.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params like token and access_token, which can leak through logs, browser history, and referrers. This issue has been patched in version 0.14.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.45 | 14 | Gogs is a lightweight self-hosted Git service that provides repository hosting, user management, issue tracking, and collaboration features through a web interface. | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00254, EPSS Percentile is 0.16978 |
altlinux: CVE-2026-26196 was patched at 2026-06-25
1873.
Unknown Vulnerability Type - 389 Directory Server (CVE-2026-15041) - Low [154]
Description: {'nvd_cve_data_all': 'A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though practical exploitation is extremely difficult due to PBKDF2 computational overhead.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in 389 Directory Server. The PBKDF2-SHA256 password verification function uses standard memcmp() for comparing password hashes instead of a constant-time comparison function. A remote attacker could potentially use timing measurements of LDAP bind attempts to infer partial hash information, though practical exploitation is extremely difficult due to PBKDF2 computational overhead.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | 389 Directory Server is a highly usable, fully featured, reliable and secure LDAP server implementation | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.003, EPSS Percentile is 0.22306 |
debian: CVE-2026-15041 was patched at 2026-07-14
1874.
Unknown Vulnerability Type - Kafka (CVE-2026-41115) - Low [154]
Description: {'nvd_cve_data_all': 'An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead of the READ operation that documented in the official kafka documentation and the KIP-848. This discrepancy can result in misconfigured Access Control Lists (ACLs) and unintended security postures, like granting READ permission to users who should not be able to join/sync groups, or allowing users without READ permission (but with DESCRIBE permission) to access sensitive group metadata. The correct permission for CONSUMER_GROUP_DESCRIBE API is DESCRIBE GROUP so the current implementation is correct. However, the kafka documentation as well as the KIP-848 will be updated to reflect the correct permission. We advise the Kafka users to review existing group ACLs to ensure the principle of least privilege.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An improper authorization vulnerability has been identified in Apache Kafka.\n\nThe implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead of the READ operation that documented in the official kafka documentation and the KIP-848. This discrepancy can result in misconfigured Access Control Lists (ACLs) and unintended security postures, like granting READ permission to users who should not be able to join/sync groups, or allowing users without READ permission (but with DESCRIBE permission) to access sensitive group metadata.\n\nThe correct permission for CONSUMER_GROUP_DESCRIBE API is DESCRIBE GROUP so the current implementation is correct. However, the kafka documentation as well as the KIP-848 will be updated to reflect the correct permission. We advise the Kafka users to review existing group ACLs to ensure the principle of least privilege.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:apache:kafka (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00288, EPSS Percentile is 0.21011 |
altlinux: CVE-2026-41115 was patched at 2026-06-24, 2026-07-03
redos: CVE-2026-41115 was patched at 2026-07-07
1875.
Unknown Vulnerability Type - Psr-7 (CVE-2026-55766) - Low [154]
Description: {'nvd_cve_data_all': 'guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and response reason phrase. If an application placed attacker-controlled data into one of those fields and later serialized the PSR-7 message as raw HTTP/1.x, for example with Message::toString() or an equivalent serializer, the serialized message could contain attacker-controlled header lines. The issue can also be reached through Message::parseRequest() or Message::parseResponse() when malformed raw messages are parsed into first-party PSR-7 objects and then serialized again. Creating or modifying a Request, Response, or other PSR-7 object alone is not sufficient. The issue requires the malformed message to be serialized and written to the network, forwarded, replayed, or otherwise processed by software that does not independently reject the malformed start line. This vulnerability is fixed in 2.12.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Prior to 2.12.1, guzzlehttp/psr7 did not reject CR/LF characters in certain first-party HTTP start-line fields: the request method, protocol version, and response reason phrase. If an application placed attacker-controlled data into one of those fields and later serialized the PSR-7 message as raw HTTP/1.x, for example with Message::toString() or an equivalent serializer, the serialized message could contain attacker-controlled header lines. The issue can also be reached through Message::parseRequest() or Message::parseResponse() when malformed raw messages are parsed into first-party PSR-7 objects and then serialized again. Creating or modifying a Request, Response, or other PSR-7 object alone is not sufficient. The issue requires the malformed message to be serialized and written to the network, forwarded, replayed, or otherwise processed by software that does not independently reject the malformed start line. This vulnerability is fixed in 2.12.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:guzzlephp:psr-7 (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 4.8. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00158, EPSS Percentile is 0.054 |
debian: CVE-2026-55766 was patched at 2026-06-24
1876.
Unknown Vulnerability Type - Starlette (CVE-2026-48817) - Low [154]
Description: {'nvd_cve_data_all': 'Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lowercased name matches an attribute on the endpoint subclass reaches the endpoint, that attribute is invoked as if it were a request handler. An attacker can use this to reach methods that were never meant to be HTTP handlers, such as internal helpers, without the authorization checks applied by the intended public handler. An application (including Starlette-based frameworks like FastAPI) is affected if it registers an HTTPEndpoint subclass via Route(...) without explicitly setting methods=, and that subclass includes extra methods named like non-standard HTTP verbs that take one request argument and return a response. This issue has been fixed in version 1.1.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Starlette is a lightweight ASGI framework/toolkit. In versions 1.0.1 and below, when dispatching a request, HTTPEndpoint selects the handler by lowercasing the HTTP method and looking it up as an attribute with getattr, without restricting the lookup to a known set of HTTP verbs. When an HTTPEndpoint subclass is registered through Route(...) without an explicit methods= argument, the route does not constrain the method and every method reaches the endpoint. If a non-standard HTTP method whose lowercased name matches an attribute on the endpoint subclass reaches the endpoint, that attribute is invoked as if it were a request handler. An attacker can use this to reach methods that were never meant to be HTTP handlers, such as internal helpers, without the authorization checks applied by the intended public handler. An application (including Starlette-based frameworks like FastAPI) is affected if it registers an HTTPEndpoint subclass via Route(...) without explicitly setting methods=, and that subclass includes extra methods named like non-standard HTTP verbs that take one request argument and return a response. This issue has been fixed in version 1.1.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00213, EPSS Percentile is 0.11745 |
debian: CVE-2026-48817 was patched at 2026-06-24
1877.
Unknown Vulnerability Type - Starlette (CVE-2026-54282) - Low [154]
Description: {'nvd_cve_data_all': 'Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header or scope) can therefore be misled into trusting an attacker-supplied host. This vulnerability is fixed in 1.3.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Starlette is a lightweight ASGI framework/toolkit. Prior to 1.3.0, the HTTP request path is not validated before being used to reconstruct request.url. Because request.url is rebuilt by concatenating {scheme}://{host}{path} and re-parsing the result, a path that does not begin with / (for example @google.com) moves the authority boundary during re-parsing, so request.url.hostname and request.url.netloc become attacker-controlled. Code that reads request.url.hostname (rather than the Host header or scope) can therefore be misled into trusting an attacker-supplied host. This vulnerability is fixed in 1.3.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Starlette is an Asynchronous Server Gateway Interface (ASGI) framework/toolkit | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00187, EPSS Percentile is 0.08606 |
debian: CVE-2026-54282 was patched at 2026-06-24
1878.
Unknown Vulnerability Type - erlang\\/otp (CVE-2026-53422) - Low [154]
Description: {'nvd_cve_data_all': 'Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enumerate the existence of files and directories outside the configured root directory. The SSH_FXP_REALPATH handler in ssh_sftpd calls relate_file_name/3 with Canonicalize=false, unlike every other SFTP operation handler. This allows .. components in the requested path to bypass the is_within_root/2 check without being resolved. The un-canonicalized path then enters resolve_symlinks/2, which walks up the directory tree above the configured root and issues read_link() syscalls on arbitrary filesystem paths. An authenticated SFTP client can exploit this by sending a REALPATH request with a crafted traversal path. The server response differs depending on whether the target path exists on the host filesystem (SSH_FXP_NAME when the path resolves successfully, SSH_FX_NO_SUCH_FILE when it does not). This creates a path-existence oracle that an attacker can use to enumerate the filesystem structure outside the configured root, including the existence of sensitive files, directories, and mount points. The vulnerability leaks only the existence of paths. No file contents, credentials, or write access are obtainable through this issue alone. The information gained may assist further attacks when combined with other vulnerabilities. This vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and program routine ssh_sftpd:handle_op/4. This issue affects OTP from OTP 17.0 before OTP 29.0.3, OTP 28.5.0.3 and OTP 27.3.4.14, corresponding to ssh from 3.0.1 before 6.0.2, 5.5.2.2 and 5.2.11.9.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Observable Response Discrepancy vulnerability in Erlang OTP ssh (ssh_sftpd module) allows an authenticated SFTP user to enumerate the existence of files and directories outside the configured root directory.\n\nThe SSH_FXP_REALPATH handler in ssh_sftpd calls relate_file_name/3 with Canonicalize=false, unlike every other SFTP operation handler. This allows .. components in the requested path to bypass the is_within_root/2 check without being resolved. The un-canonicalized path then enters resolve_symlinks/2, which walks up the directory tree above the configured root and issues read_link() syscalls on arbitrary filesystem paths.\n\nAn authenticated SFTP client can exploit this by sending a REALPATH request with a crafted traversal path. The server response differs depending on whether the target path exists on the host filesystem (SSH_FXP_NAME when the path resolves successfully, SSH_FX_NO_SUCH_FILE when it does not). This creates a path-existence oracle that an attacker can use to enumerate the filesystem structure outside the configured root, including the existence of sensitive files, directories, and mount points.\n\nThe vulnerability leaks only the existence of paths. No file contents, credentials, or write access are obtainable through this issue alone. The information gained may assist further attacks when combined with other vulnerabilities.\n\nThis vulnerability is associated with program files lib/ssh/src/ssh_sftpd.erl and program routine ssh_sftpd:handle_op/4.\n\nThis issue affects OTP from OTP 17.0 before OTP\xa029.0.3, OTP\xa028.5.0.3 and OTP\xa027.3.4.14, corresponding to ssh from 3.0.1 before 6.0.2, 5.5.2.2 and 5.2.11.9.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:erlang:erlang\\/otp (does NOT exist in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00262, EPSS Percentile is 0.17926 |
debian: CVE-2026-53422 was patched at 2026-07-14
1879.
Unknown Vulnerability Type - freeswitch (CVE-2026-49472) - Low [154]
Description: {'nvd_cve_data_all': 'FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH includes a vulnerable function, PREFIX(prologTok)(), in libs/xmlrpc-c/lib/expat/xmltok/xmltok_impl.c, which was cloned from an outdated and vulnerable version in libexpat/libexpat. The function did not receive the corresponding security patch. This issue has been patched in version 1.11.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'FreeSWITCH is a Software Defined Telecom Stack enabling the digital transformation from proprietary telecom switches to a software implementation that runs on any commodity hardware. Prior to version 1.11.0, FreeSWITCH includes a vulnerable function, PREFIX(prologTok)(), in libs/xmlrpc-c/lib/expat/xmltok/xmltok_impl.c, which was cloned from an outdated and vulnerable version in libexpat/libexpat. The function did not receive the corresponding security patch. This issue has been patched in version 1.11.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:freeswitch:freeswitch (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00223, EPSS Percentile is 0.13066 |
altlinux: CVE-2026-49472 was patched at 2026-06-24, 2026-06-26, 2026-07-16
1880.
Unknown Vulnerability Type - hardened_images (CVE-2026-13757) - Low [154]
Description: {'nvd_cve_data_all': 'A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. An unauthenticated attacker with local access to the p11-kit RPC Unix domain socket can send a specially crafted request with deeply nested template attributes, causing stack exhaustion and crashing the p11-kit server process and its dependent services.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:redhat:hardened_images (does NOT exist in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00136, EPSS Percentile is 0.03491 |
altlinux: CVE-2026-13757 was patched at 2026-07-08, 2026-07-13
debian: CVE-2026-13757 was patched at 2026-07-14
1881.
Unknown Vulnerability Type - nats-server (CVE-2026-58209) - Low [154]
Description: {'nvd_cve_data_all': 'NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose original topics matched a subscriber configured subscribe deny rule because these delivery paths did not consistently recheck the concrete original topic before sending the MQTT PUBLISH to the subscriber. This issue is fixed in versions 2.14.3 and 2.12.12.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, MQTT retained message delivery and QoS1+ durable replay could deliver messages whose original topics matched a subscriber configured subscribe deny rule because these delivery paths did not consistently recheck the concrete original topic before sending the MQTT PUBLISH to the subscriber. This issue is fixed in versions 2.14.3 and 2.12.12.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:linuxfoundation:nats-server (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00251, EPSS Percentile is 0.16576 |
altlinux: CVE-2026-58209 was patched at 2026-07-10, 2026-07-13, 2026-07-14
debian: CVE-2026-58209 was patched at 2026-07-14
1882.
Unknown Vulnerability Type - nats-server (CVE-2026-58211) - Low [154]
Description: {'nvd_cve_data_all': 'NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be registered as the configured no_auth_user through a parser path used when the first client operation was not CONNECT, bypassing user-level connection restrictions such as allowed_connection_types or proxy_required that normal authentication would apply. This issue is fixed in versions 2.14.3 and 2.12.12.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, a client could be registered as the configured no_auth_user through a parser path used when the first client operation was not CONNECT, bypassing user-level connection restrictions such as allowed_connection_types or proxy_required that normal authentication would apply. This issue is fixed in versions 2.14.3 and 2.12.12.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:linuxfoundation:nats-server (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00207, EPSS Percentile is 0.10976 |
altlinux: CVE-2026-58211 was patched at 2026-07-10, 2026-07-13, 2026-07-14
debian: CVE-2026-58211 was patched at 2026-07-14
1883.
Unknown Vulnerability Type - nats-server (CVE-2026-58214) - Low [154]
Description: {'nvd_cve_data_all': 'NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an authenticated MQTT client could subscribe to the internal $MQTT.deliver.pubrel subject family, bypassing configured subscribe permissions and exposing MQTT QoS2 protocol metadata for sessions in the account. This issue is fixed in versions 2.14.3 and 2.12.12.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'NATS Server is a high-performance server for NATS.io, the cloud and edge native messaging system. Prior to 2.14.3 and 2.12.12, an authenticated MQTT client could subscribe to the internal $MQTT.deliver.pubrel subject family, bypassing configured subscribe permissions and exposing MQTT QoS2 protocol metadata for sessions in the account. This issue is fixed in versions 2.14.3 and 2.12.12.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:linuxfoundation:nats-server (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00256, EPSS Percentile is 0.17213 |
altlinux: CVE-2026-58214 was patched at 2026-07-10, 2026-07-13, 2026-07-14
debian: CVE-2026-58214 was patched at 2026-07-14
1884.
Unknown Vulnerability Type - op-tee (CVE-2026-44362) - Low [154]
Description: {'nvd_cve_data_all': 'OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.20.0 and prior to version 4.11.0, a vulnerability in OP-TEE’s subkey rollback protection allows the use of revoked or older subkey versions because the system fails to propagate versioning data during the Trusted Application (TA) loading process. In `core/crypto/signed_hdr.c`, the function `shdr_load_pub_key()` parses subkey headers but does not assign the `subkey_version` to the runtime `shdr_pub_key` structure. As a result, the `key->version` field remains at zero regardless of the version specified in the header. When `ree_fs_ta_open()` in `core/kernel/ree_fs_ta.c` calls `check_update_version()`, it passes this zeroed version to the rollback database. Because the database never receives a non-zero version to record, it never advances, effectively bypassing the rollback check and allowing TAs signed with downgraded subkey chains to load successfully. This impacts OP-TEE mainline configurations that utilize subkey-based signing chains for Trusted Application (TA) authentication. Version 4.11.0 contains a patch. No known workarounds are available.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.20.0 and prior to version 4.11.0, a vulnerability in OP-TEE’s subkey rollback protection allows the use of revoked or older subkey versions because the system fails to propagate versioning data during the Trusted Application (TA) loading process. In `core/crypto/signed_hdr.c`, the function `shdr_load_pub_key()` parses subkey headers but does not assign the `subkey_version` to the runtime `shdr_pub_key` structure. As a result, the `key->version` field remains at zero regardless of the version specified in the header. When `ree_fs_ta_open()` in `core/kernel/ree_fs_ta.c` calls `check_update_version()`, it passes this zeroed version to the rollback database. Because the database never receives a non-zero version to record, it never advances, effectively bypassing the rollback check and allowing TAs signed with downgraded subkey chains to load successfully. This impacts OP-TEE mainline configurations that utilize subkey-based signing chains for Trusted Application (TA) authentication. Version 4.11.0 contains a patch. No known workarounds are available.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by o:trustedfirmware:op-tee (does NOT exist in CPE dict) | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00122, EPSS Percentile is 0.02363 |
debian: CVE-2026-44362 was patched at 2026-07-14
1885.
Unknown Vulnerability Type - undici (CVE-2026-11525) - Low [154]
Description: {'nvd_cve_data_all': 'Impact: When undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example, SameSite=NoneOfYourBusiness is parsed as None (the most permissive setting), and SameSite=StrictLax is parsed as Lax (a downgrade from Strict). Affected applications are those that consume Set-Cookie headers from server responses (for example via undici's fetch or proxy code paths) and then forward or rely on the parsed sameSite attribute. A malicious or non-compliant server can coerce the consumer's view of a cookie's SameSite policy to a weaker value, silently degrading the SameSite enforcement the cookie is supposed to provide. This was introduced in undici 5.15.0 when the cookies feature was added. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: After parsing a Set-Cookie header, validate that the resulting sameSite attribute is one of 'Strict', 'Lax', or 'None' (exact, case-insensitive) before forwarding or relying on it.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Impact:\nWhen undici parses a Set-Cookie header, it accepts any SameSite attribute value that contains Strict, Lax, or None as a substring, rather than the case-insensitive exact match specified by RFC 6265. Non-spec values are silently mapped to one of the three standard tokens. For example, SameSite=NoneOfYourBusiness is parsed as None (the most permissive setting), and SameSite=StrictLax is parsed as Lax (a downgrade from Strict).\n\nAffected applications are those that consume Set-Cookie headers from server responses (for example via undici's fetch or proxy code paths) and then forward or rely on the parsed sameSite attribute. A malicious or non-compliant server can coerce the consumer's view of a cookie's SameSite policy to a weaker value, silently degrading the SameSite enforcement the cookie is supposed to provide.\n\nThis was introduced in undici 5.15.0 when the cookies feature was added.\n\nPatches:\nUpgrade to undici v6.26.0, v7.28.0 or v8.5.0.\n\nWorkarounds:\nAfter parsing a Set-Cookie header, validate that the resulting sameSite attribute is one of 'Strict', 'Lax', or 'None' (exact, case-insensitive) before forwarding or relying on it.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00238, EPSS Percentile is 0.15045 |
almalinux: CVE-2026-11525 was patched at 2026-07-06, 2026-07-15, 2026-07-20
debian: CVE-2026-11525 was patched at 2026-06-24
oraclelinux: CVE-2026-11525 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-11525 was patched at 2026-07-06, 2026-07-15, 2026-07-20
1886.
Unknown Vulnerability Type - Linux Kernel (CVE-2026-63811) - Low [150]
Description: {'nvd_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved: f2fs: read COW data with the original inode during atomic write When updating an atomic-write file, f2fs_write_begin() may read the previously written data back from the COW inode: prepare_atomic_write_begin() locates the block in the COW inode and sets use_cow, and the read bio is then built with the COW inode: \tf2fs_submit_page_read(use_cow ? F2FS_I(inode)->cow_inode : inode, \t\t\t ...); and f2fs_grab_read_bio() decides whether to schedule fs-layer decryption (STEP_DECRYPT) for the bio based on that inode via fscrypt_inode_uses_fs_layer_crypto(). However, the folio being filled belongs to the original inode (folio->mapping->host == inode), and the data stored in the COW block was encrypted (or left as plaintext) using the original inode's context, not the COW inode's -- see f2fs_encrypt_one_page(), which keys off fio->page->mapping->host. fscrypt_decrypt_pagecache_blocks() likewise operates on folio->mapping->host. The COW inode is created as a tmpfile in the parent directory and inherits its encryption policy from there. With test_dummy_encryption the newly created COW inode gets the dummy policy and becomes encrypted, while a pre-existing regular file -- created before the policy applied, e.g. already present in the on-disk image -- stays unencrypted. The read path then sets STEP_DECRYPT based on the encrypted COW inode and calls fscrypt_decrypt_pagecache_blocks() on a folio whose host (the unencrypted original inode) has a NULL ->i_crypt_info, dereferencing it: Oops: general protection fault, probably for non-canonical address ... KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] RIP: 0010:fscrypt_decrypt_pagecache_blocks+0xa0/0x310 Workqueue: f2fs_post_read_wq f2fs_post_read_work Call Trace: fscrypt_decrypt_bio+0x1eb/0x340 f2fs_post_read_work+0xba/0x140 process_one_work+0x91c/0x1a40 worker_thread+0x677/0xe90 kthread+0x2bc/0x3a0 The COW inode is only needed to locate the on-disk block, and that block address is already resolved into @blkaddr by prepare_atomic_write_begin() via __find_data_block(cow_inode, ...); f2fs_submit_page_read() then reads from that physical @blkaddr directly, so the inode argument only selects the post-read crypto context, not which block is fetched. Reading with @inode therefore returns the same (latest, not-yet-committed) COW data, while making both the fs-layer decryption decision and the inline crypto path use the correct (original inode's) key. With the COW inode no longer used at the read site, the use_cow flag has no remaining consumer; drop it from f2fs_write_begin() and prepare_atomic_write_begin().', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'In the Linux kernel, the following vulnerability has been resolved:\n\nf2fs: read COW data with the original inode during atomic write\n\nWhen updating an atomic-write file, f2fs_write_begin() may read the\npreviously written data back from the COW inode:\nprepare_atomic_write_begin() locates the block in the COW inode and sets\nuse_cow, and the read bio is then built with the COW inode:\n\n\tf2fs_submit_page_read(use_cow ? F2FS_I(inode)->cow_inode : inode,\n\t\t\t ...);\n\nand f2fs_grab_read_bio() decides whether to schedule fs-layer decryption\n(STEP_DECRYPT) for the bio based on that inode via\nfscrypt_inode_uses_fs_layer_crypto().\n\nHowever, the folio being filled belongs to the original inode\n(folio->mapping->host == inode), and the data stored in the COW block was\nencrypted (or left as plaintext) using the original inode's context, not\nthe COW inode's -- see f2fs_encrypt_one_page(), which keys off\nfio->page->mapping->host. fscrypt_decrypt_pagecache_blocks() likewise\noperates on folio->mapping->host.\n\nThe COW inode is created as a tmpfile in the parent directory and inherits\nits encryption policy from there. With test_dummy_encryption the newly\ncreated COW inode gets the dummy policy and becomes encrypted, while a\npre-existing regular file -- created before the policy applied, e.g.\nalready present in the on-disk image -- stays unencrypted. The read\npath then sets STEP_DECRYPT based on the encrypted COW inode and calls\nfscrypt_decrypt_pagecache_blocks() on a folio whose host (the unencrypted\noriginal inode) has a NULL ->i_crypt_info, dereferencing it:\n\n Oops: general protection fault, probably for non-canonical address ...\n KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f]\n RIP: 0010:fscrypt_decrypt_pagecache_blocks+0xa0/0x310\n Workqueue: f2fs_post_read_wq f2fs_post_read_work\n Call Trace:\n fscrypt_decrypt_bio+0x1eb/0x340\n f2fs_post_read_work+0xba/0x140\n process_one_work+0x91c/0x1a40\n worker_thread+0x677/0xe90\n kthread+0x2bc/0x3a0\n\nThe COW inode is only needed to locate the on-disk block, and that block\naddress is already resolved into @blkaddr by prepare_atomic_write_begin()\nvia __find_data_block(cow_inode, ...); f2fs_submit_page_read() then reads\nfrom that physical @blkaddr directly, so the inode argument only selects\nthe post-read crypto context, not which block is fetched. Reading with\n@inode therefore returns the same (latest, not-yet-committed) COW data,\nwhile making both the fs-layer decryption decision and the inline crypto\npath use the correct (original inode's) key.\n\nWith the COW inode no longer used at the read site, the use_cow flag has no\nremaining consumer; drop it from f2fs_write_begin() and\nprepare_atomic_write_begin().', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.9 | 14 | The Linux kernel is a free and open-source, monolithic, modular, multitasking, Unix-like operating system kernel | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0.0 | 10 | EPSS Probability is 0.00106, EPSS Percentile is 0.01265 |
debian: CVE-2026-63811 was patched at 2026-07-14
1887.
Unknown Vulnerability Type - Gzip (CVE-2026-41991) - Low [142]
Description: {'nvd_cve_data_all': 'GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite. This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks.\nA local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.\n\nThis issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:gnu:gzip (exists in CPE dict) | |
| 0.5 | 10 | CVSS Base Score is 4.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01955 |
debian: CVE-2026-41991 was patched at 2026-07-14
ubuntu: CVE-2026-41991 was patched at 2026-07-30
1888.
Unknown Vulnerability Type - Unknown Product (CVE-2026-11972) - Low [142]
Description: {'nvd_cve_data_all': 'When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take exponentially longer.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 8.2. According to Vulners data source | |
| 0.4 | 10 | EPSS Probability is 0.00433, EPSS Percentile is 0.35603 |
debian: CVE-2026-11972 was patched at 2026-07-14
1889.
Unknown Vulnerability Type - python-multipart (CVE-2026-53540) - Low [142]
Description: {'nvd_cve_data_all': 'Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a single read instead of in fixed-size chunks. This vulnerability is fixed in 0.0.31.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.31, parse_form() did not validate the Content-Length header before using it to bound its chunked read of the request body. A negative Content-Length turned the bounded read into a read-until-EOF, so the entire body was loaded into memory in a single read instead of in fixed-size chunks. This vulnerability is fixed in 0.0.31.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:fastapiexpert:python-multipart (does NOT exist in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00218, EPSS Percentile is 0.1232 |
altlinux: CVE-2026-53540 was patched at 2026-07-01
debian: CVE-2026-53540 was patched at 2026-06-24
1890.
Unknown Vulnerability Type - undici (CVE-2026-6733) - Low [142]
Description: {'nvd_cve_data_all': 'Impact: Undici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests. This requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse. Patches: Upgrade to undici v6.26.0, v7.28.0 or v8.5.0. Workarounds: Disable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Impact:\nUndici's HTTP/1.1 client is vulnerable to response queue poisoning on reused keep-alive sockets. An attacker-controlled upstream server can inject an unsolicited HTTP/1.1 response onto an idle socket after a request completes. When the client dispatches the next request on that socket, it associates the injected response with the new request, causing responses to be delivered to the wrong requests.\n\nThis requires an attacker-controlled or compromised upstream HTTP/1.1 server and keep-alive connection reuse.\n\nPatches:\nUpgrade to undici v6.26.0, v7.28.0 or v8.5.0.\n\nWorkarounds:\nDisable keep-alive connection reuse by setting keepAliveTimeout: 0 on the Client or Pool.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by a:nodejs:undici (exists in CPE dict) | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0022, EPSS Percentile is 0.12603 |
almalinux: CVE-2026-6733 was patched at 2026-07-06, 2026-07-15, 2026-07-20
debian: CVE-2026-6733 was patched at 2026-06-24
oraclelinux: CVE-2026-6733 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-6733 was patched at 2026-07-06, 2026-07-15, 2026-07-20
1891.
Unknown Vulnerability Type - ImageMagick (CVE-2026-61859) - Low [135]
Description: {'nvd_cve_data_all': 'ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a policy bypass vulnerability in the -script operation due to missing security policy checks. This allows reading files from paths that are otherwise disallowed by the configured security policy.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.6 | 14 | ImageMagick, invoked from the command line as magick, is a free and open-source cross-platform software suite for displaying, creating, converting, modifying, and editing raster images | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.0255 |
altlinux: CVE-2026-61859 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-61859 was patched at 2026-07-14
1892.
Unknown Vulnerability Type - 389 Directory Server (CVE-2026-14969) - Low [130]
Description: {'nvd_cve_data_all': 'A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw was found in 389-ds-base where the LDBM backend attribute encryption uses a hardcoded static initialization vector for AES-CBC and 3DES-CBC operations, allowing an attacker with privileged filesystem access to detect plaintext equality across encrypted entries by comparing ciphertext blocks.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | 389 Directory Server is a highly usable, fully featured, reliable and secure LDAP server implementation | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00077, EPSS Percentile is 0.00147 |
debian: CVE-2026-14969 was patched at 2026-07-14
1893.
Unknown Vulnerability Type - Unknown Product (CVE-2026-35505) - Low [130]
Description: {'nvd_cve_data_all': 'An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process deployments the memory grows until the service is killed and the port stops responding until restart.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An unauthenticated remote attacker can repeatedly send crafted connection requests to leak memory. In single-process deployments the memory grows until the service is killed and the port stops responding until restart.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00416, EPSS Percentile is 0.34257 |
debian: CVE-2026-35505 was patched at 2026-07-14
1894.
Unknown Vulnerability Type - Unknown Product (CVE-2026-46601) - Low [130]
Description: {'nvd_cve_data_all': 'The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00335, EPSS Percentile is 0.26045 |
debian: CVE-2026-46601 was patched at 2026-07-14
1895.
Unknown Vulnerability Type - Unknown Product (CVE-2026-50254) - Low [130]
Description: {'nvd_cve_data_all': 'An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator restarts it.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An unauthenticated remote attacker can repeatedly send a single crafted connection request to leak memory. Against storescp in its default single-process mode, memory grows quickly and the service is eventually killed, after which it stops accepting connections until an operator restarts it.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.8 | 10 | CVSS Base Score is 7.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00416, EPSS Percentile is 0.34216 |
debian: CVE-2026-50254 was patched at 2026-07-14
1896.
Unknown Vulnerability Type - Unknown Product (CVE-2026-54466) - Low [130]
Description: {'nvd_cve_data_all': 'websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values 0x80 or above, a client can make the server parse these bytes into an ever-growing integer in lib/websocket/driver/draft75.js; because JavaScript numbers are 64-bit floating point values, this number will eventually lose precision and lead to the subsequent payload being parsed incorrectly. This issue is fixed in version 0.7.5.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.7.5, the frame format in draft versions of the WebSocket protocol includes a length header that allows an arbitrarily large integer to be encoded as a sequence of bytes with the high bit set. By sending an indefinite sequence of bytes with values 0x80 or above, a client can make the server parse these bytes into an ever-growing integer in lib/websocket/driver/draft75.js; because JavaScript numbers are 64-bit floating point values, this number will eventually lose precision and lead to the subsequent payload being parsed incorrectly. This issue is fixed in version 0.7.5.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.9 | 10 | CVSS Base Score is 9.2. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00263, EPSS Percentile is 0.18024 |
debian: CVE-2026-54466 was patched at 2026-07-14
1897.
Memory Corruption - Unknown Product (CVE-2026-13573) - Low [125]
Description: {'nvd_cve_data_all': 'A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component ValueSymbolTable Module. The manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The presence of this vulnerability remains uncertain at this time. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component ValueSymbolTable Module. The manipulation results in stack-based buffer overflow. Attacking locally is a requirement. The exploit has been made public and could be used. The presence of this vulnerability remains uncertain at this time. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02536 |
debian: CVE-2026-13573 was patched at 2026-07-14
1898.
Memory Corruption - Unknown Product (CVE-2026-13574) - Low [125]
Description: {'nvd_cve_data_all': 'A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. There are still doubts about whether this vulnerability truly exists. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. This manipulation causes heap-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been publicly disclosed and may be utilized. There are still doubts about whether this vulnerability truly exists. The LLVM project explains, that the reported behavior is outside its documented security scope and therefore not considered a security vulnerability.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0.5 | 15 | Memory Corruption | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00124, EPSS Percentile is 0.02535 |
debian: CVE-2026-13574 was patched at 2026-07-14
1899.
Unknown Vulnerability Type - Pypdf (CVE-2026-49460) - Low [119]
Description: {'nvd_cve_data_all': 'pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /FlateDecode filter with a PNG predictor. This vulnerability is fixed in 6.12.2.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'pypdf is a free and open-source pure-python PDF library. Prior to 6.12.2, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires accessing a stream which uses the /FlateDecode filter with a PNG predictor. This vulnerability is fixed in 6.12.2.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | PyPDF is a Python library for reading, manipulating, and writing PDF files, including extraction, splitting, merging, and encryption features. | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00117, EPSS Percentile is 0.01947 |
debian: CVE-2026-49460 was patched at 2026-06-24
redos: CVE-2026-49460 was patched at 2026-07-29
1900.
Unknown Vulnerability Type - Unknown Product (CVE-2026-50162) - Low [119]
Description: {'nvd_cve_data_all': 'oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a lexical filepath.Rel check for workingDir and does not account for symlink traversal, so when AllowPathTraversalOnWrite=false an attacker-controlled blob title through ocispec.AnnotationTitle such as out/pwn.txt can follow a workingDir symlink out -> /some/outside/dir and cause pushFile() to create /some/outside/dir/pwn.txt outside workingDir. This issue is fixed in version 2.6.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, resolveWritePath() in content/file/file.go uses a lexical filepath.Rel check for workingDir and does not account for symlink traversal, so when AllowPathTraversalOnWrite=false an attacker-controlled blob title through ocispec.AnnotationTitle such as out/pwn.txt can follow a workingDir symlink out -> /some/outside/dir and cause pushFile() to create /some/outside/dir/pwn.txt outside workingDir. This issue is fixed in version 2.6.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.9. According to Vulners data source | |
| 0.3 | 10 | EPSS Probability is 0.00365, EPSS Percentile is 0.29233 |
debian: CVE-2026-50162 was patched at 2026-07-14
1901.
Unknown Vulnerability Type - op-tee (CVE-2026-41514) - Low [119]
Description: {'nvd_cve_data_all': 'OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.5.0 and prior to version 4.11.0, the RSA-OAEP decryption implementation in the Hisilicon HPRE crypto driver uses non-constant-time `memcmp()` for label hash verification and has multiple distinguishable error paths. This creates a Manger-style padding oracle that allows an attacker to recover RSA-OAEP plaintext with approximately 1000-2000 adaptive chosen ciphertext queries. Only affects plat-d06 with `CFG_HISILICON_ACC_V3=y`, which seems to be disabled by default. Version 4.11.0 contains a patch. As a workaround, disable Hisilicon HPRE RSA driver with `CFG_HISILICON_ACC_V3=n`.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 4.5.0 and prior to version 4.11.0, the RSA-OAEP decryption implementation in the Hisilicon HPRE crypto driver uses non-constant-time `memcmp()` for label hash verification and has multiple distinguishable error paths. This creates a Manger-style padding oracle that allows an attacker to recover RSA-OAEP plaintext with approximately 1000-2000 adaptive chosen ciphertext queries. Only affects plat-d06 with `CFG_HISILICON_ACC_V3=y`, which seems to be disabled by default. Version 4.11.0 contains a patch. As a workaround, disable Hisilicon HPRE RSA driver with `CFG_HISILICON_ACC_V3=n`.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by o:trustedfirmware:op-tee (does NOT exist in CPE dict) | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00095, EPSS Percentile is 0.00799 |
debian: CVE-2026-41514 was patched at 2026-07-14
1902.
Unknown Vulnerability Type - op-tee (CVE-2026-41515) - Low [119]
Description: {'nvd_cve_data_all': 'OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.9.0 and prior to version 4.11.0, the RSA-OAEP decryption implementation in the NXP CAAM crypto driver uses non-constant-time `memcmp()` for label hash verification and has multiple distinguishable error paths. This creates a Manger-style padding oracle that allows an attacker to recover RSA-OAEP plaintext with approximately 1000-2000 adaptive chosen ciphertext queries. Version 4.11.0 contains a patch. As a workaround, disable the NXP CAAM RSA driver with `CFG_CRYPTO_DRV_RSA=n`.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.9.0 and prior to version 4.11.0, the RSA-OAEP decryption implementation in the NXP CAAM crypto driver uses non-constant-time `memcmp()` for label hash verification and has multiple distinguishable error paths. This creates a Manger-style padding oracle that allows an attacker to recover RSA-OAEP plaintext with approximately 1000-2000 adaptive chosen ciphertext queries. Version 4.11.0 contains a patch. As a workaround, disable the NXP CAAM RSA driver with `CFG_CRYPTO_DRV_RSA=n`.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Product detected by o:trustedfirmware:op-tee (does NOT exist in CPE dict) | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00094, EPSS Percentile is 0.00704 |
debian: CVE-2026-41515 was patched at 2026-07-14
1903.
Unknown Vulnerability Type - Cacti (CVE-2026-39894) - Low [107]
Description: {'nvd_cve_data_all': 'Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can corrupt RRDtool metric values. The rrdtool_function_update() function checks metric values with is_numeric() and concatenates them into the RRDtool update command via PHP string interpolation. PHP's string cast of floats is locale-sensitive: if LC_NUMERIC uses comma as decimal separator (e.g., de_DE), a value of 1.5 becomes "1,5". RRDtool expects . as decimal separator, causing metric data to shift into wrong columns or be silently dropped. No setlocale() reset is present in the update path. This causes a data integrity issue, but is not remotely exploitable; it requires server locale misconfiguration. The issue has been fixed in version 1.2.31.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Cacti is an open source performance and fault management framework. In versions 1.2.30 and below, the locale-dependent decimal formatting in rrdtool_function_update() can corrupt RRDtool metric values. The rrdtool_function_update() function checks metric values with is_numeric() and concatenates them into the RRDtool update command via PHP string interpolation. PHP's string cast of floats is locale-sensitive: if LC_NUMERIC uses comma as decimal separator (e.g., de_DE), a value of 1.5 becomes "1,5". RRDtool expects . as decimal separator, causing metric data to shift into wrong columns or be silently dropped. No setlocale() reset is present in the update path. This causes a data integrity issue, but is not remotely exploitable; it requires server locale misconfiguration. The issue has been fixed in version 1.2.31.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.5 | 14 | Cacti is an open source operational monitoring and fault management framework | |
| 0.2 | 10 | CVSS Base Score is 2.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00147, EPSS Percentile is 0.04409 |
altlinux: CVE-2026-39894 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-39894 was patched at 2026-07-14
1904.
Unknown Vulnerability Type - Unknown Product (CVE-2026-44918) - Low [107]
Description: {'nvd_cve_data_all': 'OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'OpenStack Ironic through before 37.0.1 allows creation or modification of nodes cross-project without authorization.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.3 | 10 | EPSS Probability is 0.00329, EPSS Percentile is 0.25409 |
debian: CVE-2026-44918 was patched at 2026-07-14
1905.
Unknown Vulnerability Type - GitHub (CVE-2026-59831) - Low [104]
Description: {'nvd_cve_data_all': 'GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without validating that it is a loopback HTTP or HTTPS address, allowing a crafted vscode:// or vscode-insiders:// URL to be handed to VS Code. This issue is fixed in version 2.96.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'GitHub CLI (gh) is GitHub’s official command line tool. From 2.10.0 through 2.95.0, connecting to a malicious Codespace with gh codespace jupyter can allow command execution because the command opens a JupyterLab URL supplied by a process inside the Codespace without validating that it is a loopback HTTP or HTTPS address, allowing a crafted vscode:// or vscode-insiders:// URL to be handed to VS Code. This issue is fixed in version 2.96.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.2 | 14 | GitHub, Inc. is an Internet hosting service for software development and version control using Git | |
| 0.4 | 10 | CVSS Base Score is 4.4. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00259, EPSS Percentile is 0.17574 |
debian: CVE-2026-59831 was patched at 2026-07-14
1906.
Unknown Vulnerability Type - GPAC (CVE-2026-13523) - Low [102]
Description: {'nvd_cve_data_all': 'A weakness has been identified in GPAC up to 26.02.0. This affects an unknown part of the file src/utils/base_encoding.c of the component ISOBMFF Parser. Executing a manipulation can lead to highly compressed data. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. This patch is called 297f2d8d1f493d8b241330533cd47f7da758aeb3. A patch should be applied to remediate this issue. The vendor confirms: "We added a check on inflate output size, if it surpasses 32 times the input size we stop in error. This value could be adjusted later."', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A weakness has been identified in GPAC up to 26.02.0. This affects an unknown part of the file src/utils/base_encoding.c of the component ISOBMFF Parser. Executing a manipulation can lead to highly compressed data. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks. This patch is called 297f2d8d1f493d8b241330533cd47f7da758aeb3. A patch should be applied to remediate this issue. The vendor confirms: "We added a check on inflate output size, if it surpasses 32 times the input size we stop in error. This value could be adjusted later."', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0.4 | 14 | GPAC is an Open Source multimedia framework for research and academic purposes; the project covers different aspects of multimedia, with a focus on presentation technologies (graphics, animation and interactivity) | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00112, EPSS Percentile is 0.01616 |
debian: CVE-2026-13523 was patched at 2026-07-14
1907.
Unknown Vulnerability Type - Unknown Product (CVE-2026-47084) - Low [95]
Description: {'nvd_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the admin-only LOCALDELETE IMAP command and delete mailboxes for which they had no permissions.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The LOCALDELETE command bypassed ACL checks. An authenticated but non-admin user could invoke the admin-only LOCALDELETE IMAP command and delete mailboxes for which they had no permissions.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 6.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00214, EPSS Percentile is 0.11919 |
debian: CVE-2026-47084 was patched at 2026-07-14
1908.
Unknown Vulnerability Type - Unknown Product (CVE-2026-24791) - Low [83]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.7 | 10 | CVSS Base Score is 7.3. According to BDU data source | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
redos: CVE-2026-24791 was patched at 2026-07-14
1909.
Unknown Vulnerability Type - Unknown Product (CVE-2026-40012) - Low [83]
Description: {'nvd_cve_data_all': 'ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'ECS zero scoped answers are stored in the packet cache while they should not. This impacts only configurations that have ECS enabled;', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.00318, EPSS Percentile is 0.24276 |
debian: CVE-2026-40012 was patched at 2026-06-25, 2026-07-14
1910.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55748) - Low [83]
Description: {'nvd_cve_data_all': 'OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file downloading that may have a crafted project name with shell metacharacters. NOTE: some parties consider this a security hardening opportunity to address certain types of user error, not a vulnerability.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.0019, EPSS Percentile is 0.08946 |
debian: CVE-2026-55748 was patched at 2026-06-24
1911.
Unknown Vulnerability Type - Unknown Product (CVE-2026-46377) - Low [71]
Description: {'nvd_cve_data_all': 'Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the escape sequence handler in (*Tokenizer).parseCurRune in selector/lexer/tokenize.go increments past a trailing backslash in a quoted string such as "\\ or '\\ and then reads p.src[pos] without a bounds check, allowing attacker-controlled selector strings to trigger a Go index-out-of-range panic. This issue is fixed in version 3.10.1.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Dasel is a command-line tool and library for querying, modifying, and transforming data structures. From 3.0.0 until 3.10.1, the escape sequence handler in (*Tokenizer).parseCurRune in selector/lexer/tokenize.go increments past a trailing backslash in a quoted string such as "\\ or '\\ and then reads p.src[pos] without a bounds check, allowing attacker-controlled selector strings to trigger a Go index-out-of-range panic. This issue is fixed in version 3.10.1.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 6.2. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02826 |
debian: CVE-2026-46377 was patched at 2026-07-14
1912.
Unknown Vulnerability Type - Unknown Product (CVE-2026-47082) - Low [71]
Description: {'nvd_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacation Sieve script used :fcc (to save a copy of the sent message) could deliver vacation auto-reply copies into any mailbox the script could name, regardless of whether the script owner had insert permissions on the destination mailbox.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. The vacation "fcc" feature skips the destination-mailbox ACL. A user whose vacation Sieve script used :fcc (to save a copy of the sent message) could deliver vacation auto-reply copies into any mailbox the script could name, regardless of whether the script owner had insert permissions on the destination mailbox.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.4. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00196, EPSS Percentile is 0.09651 |
debian: CVE-2026-47082 was patched at 2026-07-14
1913.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55392) - Low [71]
Description: {'nvd_cve_data_all': 'NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'NILFS utilities through 2.3.0, fixed in commit 26efb5d, nilfs_sb_is_valid() function fails to validate s_log_block_size field in NILFS2 superblock before bit-shift operations. Attackers supplying crafted NILFS2 images trigger undefined behavior through oversized shifts or out-of-memory conditions, crashing tools like nilfs-tune and dumpseg.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.6 | 10 | CVSS Base Score is 5.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00151, EPSS Percentile is 0.04769 |
debian: CVE-2026-55392 was patched at 2026-06-24
1914.
Unknown Vulnerability Type - Unknown Product (CVE-2026-13502) - Low [59]
Description: {'nvd_cve_data_all': 'A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java of the component Maven Plugin. This manipulation causes time-of-check time-of-use. The attack is restricted to local execution. A high degree of complexity is needed for the attack. It is indicated that the exploitability is difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java of the component Maven Plugin. This manipulation causes time-of-check time-of-use. The attack is restricted to local execution. A high degree of complexity is needed for the attack. It is indicated that the exploitability is difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 4.5. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00091, EPSS Percentile is 0.00608 |
debian: CVE-2026-13502 was patched at 2026-07-14
1915.
Unknown Vulnerability Type - Unknown Product (CVE-2026-14686) - Low [59]
Description: {'nvd_cve_data_all': 'A vulnerability was found in HdrHistogram up to 2.2.2. This issue affects the function org.HdrHistogram.DoubleHistogram.recordValue of the file src/main/java/org/HdrHistogram/DoubleHistogram.java of the component Range Check. Performing a manipulation results in incorrect comparison. The attack is only possible with local access. The exploit has been made public and could be used. The presence of this vulnerability remains uncertain at this time. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability was found in HdrHistogram up to 2.2.2. This issue affects the function org.HdrHistogram.DoubleHistogram.recordValue of the file src/main/java/org/HdrHistogram/DoubleHistogram.java of the component Range Check. Performing a manipulation results in incorrect comparison. The attack is only possible with local access. The exploit has been made public and could be used. The presence of this vulnerability remains uncertain at this time. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.2 | 10 | EPSS Probability is 0.0024, EPSS Percentile is 0.15293 |
debian: CVE-2026-14686 was patched at 2026-07-14
1916.
Unknown Vulnerability Type - Unknown Product (CVE-2026-40208) - Low [59]
Description: {'nvd_cve_data_all': 'An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker might be able to delay the processing of DoH3 queries by sending DoH3 GET queries with an invalid DATA frame.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00205, EPSS Percentile is 0.10651 |
altlinux: CVE-2026-40208 was patched at 2026-06-29, 2026-06-30
debian: CVE-2026-40208 was patched at 2026-06-25, 2026-07-14
1917.
Unknown Vulnerability Type - Unknown Product (CVE-2026-42004) - Low [59]
Description: {'nvd_cve_data_all': 'An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend to see the EDNS option(s) that DNSdist did not filter.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00156, EPSS Percentile is 0.05233 |
altlinux: CVE-2026-42004 was patched at 2026-06-29, 2026-06-30
debian: CVE-2026-42004 was patched at 2026-06-25, 2026-07-14
1918.
Unknown Vulnerability Type - Unknown Product (CVE-2026-47083) - Low [59]
Description: {'nvd_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could name. Search would return UIDs of messages matching the search, creating a content oracle (without allowing arbitrary reads of the target's content).', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an ESEARCH cross-user content oracle. By using the ESEARCH command, an authenticated IMAP user could enumerate folder names under any account they could name. Search would return UIDs of messages matching the search, creating a content oracle (without allowing arbitrary reads of the target's content).', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00194, EPSS Percentile is 0.09354 |
debian: CVE-2026-47083 was patched at 2026-07-14
1919.
Unknown Vulnerability Type - Unknown Product (CVE-2026-47089) - Low [59]
Description: {'nvd_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access to it. (This action should have been restricted to users with admin access on the target mailbox.)', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. LISTRIGHTS os not limited to users with admin access. An authenticated user could call IMAP LISTRIGHTS against any mailbox they could name and learn what principals had what access to it. (This action should have been restricted to users with admin access on the target mailbox.)', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.3. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00178, EPSS Percentile is 0.07552 |
debian: CVE-2026-47089 was patched at 2026-07-14
1920.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55688) - Low [59]
Description: {'nvd_cve_data_all': 'The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0 and from 3.0.0.Beta1 prior to 3.0.11, ThreadSafeCookieStore stored a cookie under the value of its Domain attribute without verifying that the responding host is allowed to set a cookie for that domain, leading to a cookie tossing / cookie injection issue. A host the client connects to can therefore plant a cookie scoped to an unrelated domain, and the client will then send that cookie on later requests to that domain. Applications that use a single AsyncHttpClient instance - and thus the default, shared CookieStore - to reach both an attacker-influenced host and a trusted host are impacted. This issue has been fixed in versions 2.16.0 and 3.0.11.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. In versions from 2.0.0 prior to 2.16.0 and from 3.0.0.Beta1 prior to 3.0.11, ThreadSafeCookieStore stored a cookie under the value of its Domain attribute without verifying that the responding host is allowed to set a cookie for that domain, leading to a cookie tossing / cookie injection issue. A host the client connects to can therefore plant a cookie scoped to an unrelated domain, and the client will then send that cookie on later requests to that domain. Applications that use a single AsyncHttpClient instance - and thus the default, shared CookieStore - to reach both an attacker-influenced host and a trusted host are impacted. This issue has been fixed in versions 2.16.0 and 3.0.11.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.0. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.0775 |
debian: CVE-2026-55688 was patched at 2026-07-14
1921.
Unknown Vulnerability Type - Unknown Product (CVE-2026-62294) - Low [59]
Description: {'nvd_cve_data_all': 'Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a predictable temporary path and followed symlinks, creating a time-of-check to time-of-use race that allowed a local unprivileged attacker on the same machine to pre-plant a symlink and cause Flameshot to write PNG data through it, overwriting any file the victim user could write. This issue is fixed in version 14.0.0.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.5 | 10 | CVSS Base Score is 5.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00101, EPSS Percentile is 0.01058 |
debian: CVE-2026-62294 was patched at 2026-07-14
1922.
Unknown Vulnerability Type - Unknown Product (CVE-2026-0864) - Low [47]
Description: {'nvd_cve_data_all': 'When using the "configparser" module to write configuration files containing multi-line text values with carriage return characters (\\r) the resulting file could be injected with unexpected keys and values if the attacker controls the written value.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'When using the "configparser" module to write configuration files\ncontaining multi-line text values with carriage return characters (\\r) the\nresulting file could be injected with unexpected keys and values if the\nattacker controls the written value.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 4.1. According to Vulners data source | |
| 0.0 | 10 | EPSS Probability is 0.00128, EPSS Percentile is 0.02819 |
debian: CVE-2026-0864 was patched at 2026-07-14
1923.
Unknown Vulnerability Type - Unknown Product (CVE-2026-14935) - Low [47]
Description: {'nvd_cve_data_all': 'A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attribute, while incorrectly rejecting those that include it. An attacker with the ability to intercept and modify WebRTC signaling messages could exploit this to bypass the SDP-level DTLS certificate fingerprint binding, weakening defenses against man-in-the-middle attacks on media streams.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A logic vulnerability was found in GStreamer's webrtcbin component. The _check_sdp_crypto() function contains an inverted boolean condition that causes it to accept remote SDP offers or answers that lack the required a=fingerprint attribute, while incorrectly rejecting those that include it. An attacker with the ability to intercept and modify WebRTC signaling messages could exploit this to bypass the SDP-level DTLS certificate fingerprint binding, weakening defenses against man-in-the-middle attacks on media streams.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.0015, EPSS Percentile is 0.04748 |
altlinux: CVE-2026-14935 was patched at 2026-07-09
debian: CVE-2026-14935 was patched at 2026-07-14
1924.
Unknown Vulnerability Type - Unknown Product (CVE-2026-40011) - Low [47]
Description: {'nvd_cve_data_all': 'An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An attacker sending a large number of crafted DNS queries might be able to trigger a dynamic block being inserted with a value causing invalid output to be produced in the prometheus endpoint. The prometheus endpoint will then be rejected by the scraper until the dynamic block expires.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.4 | 10 | CVSS Base Score is 3.7. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00153, EPSS Percentile is 0.04949 |
altlinux: CVE-2026-40011 was patched at 2026-06-29, 2026-06-30
debian: CVE-2026-40011 was patched at 2026-06-25, 2026-07-14
1925.
Unknown Vulnerability Type - Unknown Product (CVE-2026-47081) - Low [47]
Description: {'nvd_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and then create Apple Push Notification Service notifications for new mail in those mailboxes to their own APNS device. This did not leak any data about the content of mailboxes. Instead, a "mailbox has changed" notice would be pushed when the mailbox modseq changed.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is an XAPPLEPUSHSERVICE folder existence oracle and push hijack. An authenticated IMAP user could probe for the existence of arbitrary mailboxes on other users' accounts via the XAPPLEPUSHSERVICE command and then create Apple Push Notification Service notifications for new mail in those mailboxes to their own APNS device. This did not leak any data about the content of mailboxes. Instead, a "mailbox has changed" notice would be pushed when the mailbox modseq changed.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00163, EPSS Percentile is 0.05957 |
debian: CVE-2026-47081 was patched at 2026-07-14
1926.
Unknown Vulnerability Type - Unknown Product (CVE-2026-47086) - Low [47]
Description: {'nvd_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading mail from mailboxes despite having no granted permissions.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. GENURLAUTH-issued tokens can bypass ACLs. Any authenticated user could mint a URLAUTH token (via the GENURLAUTH command) for any mailbox they could name, even without read access on it. This would allow reading mail from mailboxes despite having no granted permissions.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00179, EPSS Percentile is 0.07711 |
debian: CVE-2026-47086 was patched at 2026-07-14
1927.
Unknown Vulnerability Type - Unknown Product (CVE-2026-47087) - Low [47]
Description: {'nvd_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. URLAUTH does not honor revoked authorizer access. A URLAUTH URL minted while the authorizer had access continued to work after that access was revoked.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.5. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00192, EPSS Percentile is 0.09164 |
debian: CVE-2026-47087 was patched at 2026-07-14
1928.
Unknown Vulnerability Type - Unknown Product (CVE-2026-47088) - Low [47]
Description: {'nvd_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash. When parsing the message, the server would read past the message's end in memory, and read into the heap, returning the read content to the user.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. There is heap exposure in nested MIME comment parsing. An authenticated IMAP user could craft an email message containing an RFC 822 comment ending with a backslash. When parsing the message, the server would read past the message's end in memory, and read into the heap, returning the read content to the user.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.1. According to NVD data source | |
| 0.1 | 10 | EPSS Probability is 0.00178, EPSS Percentile is 0.07574 |
debian: CVE-2026-47088 was patched at 2026-07-14
1929.
Unknown Vulnerability Type - Unknown Product (CVE-2026-47241) - Low [47]
Description: {'nvd_cve_data_all': 'Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a raw string argument which is only validated to prevent CRLF injection and then sent verbatim. If this string is derived from user-controlled input, an attacker can force the next command to be absorbed as a continuation of the first command. This will cause the first command to eventually fail, but also prevents it from returning until another command is sent (from another thread). That other command will not return until the connection is closed. This vulnerability is fixed in 0.6.5 and 0.5.15.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a raw string argument which is only validated to prevent CRLF injection and then sent verbatim. If this string is derived from user-controlled input, an attacker can force the next command to be absorbed as a continuation of the first command. This will cause the first command to eventually fail, but also prevents it from returning until another command is sent (from another thread). That other command will not return until the connection is closed. This vulnerability is fixed in 0.6.5 and 0.5.15.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.2 | 10 | CVSS Base Score is 2.1. According to Vulners data source | |
| 0.2 | 10 | EPSS Probability is 0.00239, EPSS Percentile is 0.15112 |
debian: CVE-2026-47241 was patched at 2026-07-14
1930.
Unknown Vulnerability Type - Unknown Product (CVE-2026-14685) - Low [35]
Description: {'nvd_cve_data_all': 'A vulnerability has been found in HdrHistogram up to 2.2.2. This vulnerability affects the function recordValueWithCount of the file src/main/java/org/HdrHistogram/AbstractHistogram.java of the component AbstractHistogram. Such manipulation of the argument Count leads to state issue. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The existence of this vulnerability is still disputed at present. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'A vulnerability has been found in HdrHistogram up to 2.2.2. This vulnerability affects the function recordValueWithCount of the file src/main/java/org/HdrHistogram/AbstractHistogram.java of the component AbstractHistogram. Such manipulation of the argument Count leads to state issue. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The existence of this vulnerability is still disputed at present. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 3.3. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00118, EPSS Percentile is 0.01993 |
debian: CVE-2026-14685 was patched at 2026-07-14
1931.
Unknown Vulnerability Type - Unknown Product (CVE-2026-57062) - Low [35]
Description: {'nvd_cve_data_all': 'CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG through 2.5.20 mishandles the CMS format for AES-GCM because aes-ICVlen is supposed to be 12 bytes but 4 bytes is accepted. NOTE: this is related to CVE-2026-34182.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.3 | 10 | CVSS Base Score is 2.9. According to NVD data source | |
| 0.0 | 10 | EPSS Probability is 0.00142, EPSS Percentile is 0.04016 |
debian: CVE-2026-57062 was patched at 2026-06-24
1932.
Unknown Vulnerability Type - Unknown Product (CVE-2023-53502) - Low [0]
Description: {'nvd_cve_data_all': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
redos: CVE-2023-53502 was patched at 2026-06-29
1933.
Unknown Vulnerability Type - Unknown Product (CVE-2023-53805) - Low [0]
Description: {'nvd_cve_data_all': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
redos: CVE-2023-53805 was patched at 2026-07-01
1934.
Unknown Vulnerability Type - Unknown Product (CVE-2023-54054) - Low [0]
Description: {'nvd_cve_data_all': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
redos: CVE-2023-54054 was patched at 2026-07-02
1935.
Unknown Vulnerability Type - Unknown Product (CVE-2023-54103) - Low [0]
Description: {'nvd_cve_data_all': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
redos: CVE-2023-54103 was patched at 2026-07-02
1936.
Unknown Vulnerability Type - Unknown Product (CVE-2025-8263) - Low [0]
Description: {'nvd_cve_data_all': 'Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2025-8263 was patched at 2026-06-26
1937.
Unknown Vulnerability Type - Unknown Product (CVE-2026-12893) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-12893 was patched at 2026-07-14
1938.
Unknown Vulnerability Type - Unknown Product (CVE-2026-13324) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-13324 was patched at 2026-07-14
1939.
Unknown Vulnerability Type - Unknown Product (CVE-2026-13606) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-13606 was patched at 2026-07-14
1940.
Unknown Vulnerability Type - Unknown Product (CVE-2026-33630) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
almalinux: CVE-2026-33630 was patched at 2026-07-20
altlinux: CVE-2026-33630 was patched at 2026-07-11, 2026-07-15
debian: CVE-2026-33630 was patched at 2026-07-14
oraclelinux: CVE-2026-33630 was patched at 2026-07-21
1941.
Unknown Vulnerability Type - Unknown Product (CVE-2026-3886) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-3886 was patched at 2026-07-14
1942.
Unknown Vulnerability Type - Unknown Product (CVE-2026-42616) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-42616 was patched at 2026-07-14, 2026-07-15
ubuntu: CVE-2026-42616 was patched at 2026-07-30
1943.
Unknown Vulnerability Type - Unknown Product (CVE-2026-42617) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-42617 was patched at 2026-07-14, 2026-07-15
ubuntu: CVE-2026-42617 was patched at 2026-07-30
1944.
Unknown Vulnerability Type - Unknown Product (CVE-2026-42618) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-42618 was patched at 2026-07-14, 2026-07-15
ubuntu: CVE-2026-42618 was patched at 2026-07-30
1945.
Unknown Vulnerability Type - Unknown Product (CVE-2026-44517) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-44517 was patched at 2026-06-24
1946.
Unknown Vulnerability Type - Unknown Product (CVE-2026-44605) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-44605 was patched at 2026-07-14
1947.
Unknown Vulnerability Type - Unknown Product (CVE-2026-45092) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-45092 was patched at 2026-07-14
1948.
Unknown Vulnerability Type - Unknown Product (CVE-2026-45093) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-45093 was patched at 2026-07-14
1949.
Unknown Vulnerability Type - Unknown Product (CVE-2026-45094) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-45094 was patched at 2026-07-14
1950.
Unknown Vulnerability Type - Unknown Product (CVE-2026-45095) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-45095 was patched at 2026-07-14
1951.
Unknown Vulnerability Type - Unknown Product (CVE-2026-45096) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-45096 was patched at 2026-07-14
1952.
Unknown Vulnerability Type - Unknown Product (CVE-2026-45097) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-45097 was patched at 2026-07-14
1953.
Unknown Vulnerability Type - Unknown Product (CVE-2026-45098) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-45098 was patched at 2026-07-14
1954.
Unknown Vulnerability Type - Unknown Product (CVE-2026-45992) - Low [0]
Description: {'nvd_cve_data_all': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
oraclelinux: CVE-2026-45992 was patched at 2026-07-02
1955.
Unknown Vulnerability Type - Unknown Product (CVE-2026-46569) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-46569 was patched at 2026-07-14, 2026-07-15
ubuntu: CVE-2026-46569 was patched at 2026-07-30
1956.
Unknown Vulnerability Type - Unknown Product (CVE-2026-46570) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-46570 was patched at 2026-07-14, 2026-07-15
ubuntu: CVE-2026-46570 was patched at 2026-07-30
1957.
Unknown Vulnerability Type - Unknown Product (CVE-2026-46571) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-46571 was patched at 2026-07-14, 2026-07-15
ubuntu: CVE-2026-46571 was patched at 2026-07-30
1958.
Unknown Vulnerability Type - Unknown Product (CVE-2026-46572) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-46572 was patched at 2026-07-14, 2026-07-15
ubuntu: CVE-2026-46572 was patched at 2026-07-30
1959.
Unknown Vulnerability Type - Unknown Product (CVE-2026-48002) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-48002 was patched at 2026-07-14
oraclelinux: CVE-2026-48002 was patched at 2026-06-23
1960.
Unknown Vulnerability Type - Unknown Product (CVE-2026-48003) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-48003 was patched at 2026-07-14
oraclelinux: CVE-2026-48003 was patched at 2026-06-23
1961.
Unknown Vulnerability Type - Unknown Product (CVE-2026-48004) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-48004 was patched at 2026-07-14
1962.
Unknown Vulnerability Type - Unknown Product (CVE-2026-48749) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-48749 was patched at 2026-06-26, 2026-06-28, 2026-07-14
1963.
Unknown Vulnerability Type - Unknown Product (CVE-2026-48750) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-48750 was patched at 2026-06-26, 2026-06-28, 2026-07-14
1964.
Unknown Vulnerability Type - Unknown Product (CVE-2026-48751) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-48751 was patched at 2026-06-26, 2026-06-28, 2026-07-14
1965.
Unknown Vulnerability Type - Unknown Product (CVE-2026-48752) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-48752 was patched at 2026-06-26, 2026-06-28, 2026-07-14
1966.
Unknown Vulnerability Type - Unknown Product (CVE-2026-48755) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-48755 was patched at 2026-06-26, 2026-06-28, 2026-07-14
1967.
Unknown Vulnerability Type - Unknown Product (CVE-2026-48769) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-48769 was patched at 2026-06-26, 2026-06-28, 2026-07-14
1968.
Unknown Vulnerability Type - Unknown Product (CVE-2026-48915) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-48915 was patched at 2026-07-14
1969.
Unknown Vulnerability Type - Unknown Product (CVE-2026-49838) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-49838 was patched at 2026-07-14
1970.
Unknown Vulnerability Type - Unknown Product (CVE-2026-49861) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-49861 was patched at 2026-07-14
1971.
Unknown Vulnerability Type - Unknown Product (CVE-2026-49862) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-49862 was patched at 2026-07-14
1972.
Unknown Vulnerability Type - Unknown Product (CVE-2026-49863) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-49863 was patched at 2026-07-14
1973.
Unknown Vulnerability Type - Unknown Product (CVE-2026-50142) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-50142 was patched at 2026-07-14
ubuntu: CVE-2026-50142 was patched at 2026-07-30
1974.
Unknown Vulnerability Type - Unknown Product (CVE-2026-50190) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-50190 was patched at 2026-06-24
1975.
Unknown Vulnerability Type - Unknown Product (CVE-2026-53166) - Low [0]
Description: {'nvd_cve_data_all': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
almalinux: CVE-2026-53166 was patched at 2026-07-13, 2026-07-14
oraclelinux: CVE-2026-53166 was patched at 2026-07-14, 2026-07-15
redhat: CVE-2026-53166 was patched at 2026-07-13, 2026-07-14, 2026-07-15, 2026-07-16, 2026-07-17
1976.
Unknown Vulnerability Type - Unknown Product (CVE-2026-53533) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-53533 was patched at 2026-07-06
1977.
Unknown Vulnerability Type - Unknown Product (CVE-2026-53588) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-53588 was patched at 2026-07-14
1978.
Unknown Vulnerability Type - Unknown Product (CVE-2026-53589) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-53589 was patched at 2026-07-14
1979.
Unknown Vulnerability Type - Unknown Product (CVE-2026-53590) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-53590 was patched at 2026-07-14
1980.
Unknown Vulnerability Type - Unknown Product (CVE-2026-54161) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-54161 was patched at 2026-07-14
1981.
Unknown Vulnerability Type - Unknown Product (CVE-2026-54240) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-54240 was patched at 2026-07-14
ubuntu: CVE-2026-54240 was patched at 2026-07-30
1982.
Unknown Vulnerability Type - Unknown Product (CVE-2026-54241) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-54241 was patched at 2026-07-14
ubuntu: CVE-2026-54241 was patched at 2026-07-30
1983.
Unknown Vulnerability Type - Unknown Product (CVE-2026-54548) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-54548 was patched at 2026-07-14
1984.
Unknown Vulnerability Type - Unknown Product (CVE-2026-54604) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-54604 was patched at 2026-06-24
1985.
Unknown Vulnerability Type - Unknown Product (CVE-2026-54706) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-54706 was patched at 2026-07-14
1986.
Unknown Vulnerability Type - Unknown Product (CVE-2026-54707) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-54707 was patched at 2026-07-14
1987.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55063) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-55063 was patched at 2026-07-14
1988.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55191) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-55191 was patched at 2026-06-20, 2026-06-22, 2026-06-24
debian: CVE-2026-55191 was patched at 2026-07-14
ubuntu: CVE-2026-55191 was patched at 2026-07-30
1989.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55192) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-55192 was patched at 2026-06-20, 2026-06-22, 2026-06-24
debian: CVE-2026-55192 was patched at 2026-07-14
ubuntu: CVE-2026-55192 was patched at 2026-07-30
1990.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55193) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-55193 was patched at 2026-06-20, 2026-06-22, 2026-06-24
debian: CVE-2026-55193 was patched at 2026-07-14
ubuntu: CVE-2026-55193 was patched at 2026-07-30
1991.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55194) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-55194 was patched at 2026-06-20, 2026-06-22, 2026-06-24
debian: CVE-2026-55194 was patched at 2026-07-14
ubuntu: CVE-2026-55194 was patched at 2026-07-30
1992.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55520) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-55520 was patched at 2026-07-14
1993.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55556) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-55556 was patched at 2026-06-24
1994.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55564) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-55564 was patched at 2026-07-14
ubuntu: CVE-2026-55564 was patched at 2026-07-30
1995.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55621) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-55621 was patched at 2026-06-26, 2026-06-28, 2026-07-14
1996.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55622) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-55622 was patched at 2026-06-26, 2026-06-28, 2026-07-14
1997.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55648) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-55648 was patched at 2026-06-20, 2026-06-22, 2026-06-24
debian: CVE-2026-55648 was patched at 2026-07-14
ubuntu: CVE-2026-55648 was patched at 2026-07-30
1998.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55770) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-55770 was patched at 2026-07-08, 2026-07-14, 2026-07-15
1999.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55774) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-55774 was patched at 2026-07-08, 2026-07-14, 2026-07-15
2000.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55775) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-55775 was patched at 2026-07-08, 2026-07-14, 2026-07-15
2001.
Unknown Vulnerability Type - Unknown Product (CVE-2026-55776) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
altlinux: CVE-2026-55776 was patched at 2026-07-08, 2026-07-14, 2026-07-15
2002.
Unknown Vulnerability Type - Unknown Product (CVE-2026-56135) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-56135 was patched at 2026-07-14, 2026-07-15
ubuntu: CVE-2026-56135 was patched at 2026-07-30
2003.
Unknown Vulnerability Type - Unknown Product (CVE-2026-56136) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-56136 was patched at 2026-07-14, 2026-07-15
ubuntu: CVE-2026-56136 was patched at 2026-07-30
2004.
Unknown Vulnerability Type - Unknown Product (CVE-2026-57825) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-57825 was patched at 2026-07-10, 2026-07-14
2005.
Unknown Vulnerability Type - Unknown Product (CVE-2026-58382) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-58382 was patched at 2026-07-14
2006.
Unknown Vulnerability Type - Unknown Product (CVE-2026-58383) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-58383 was patched at 2026-07-14
2007.
Unknown Vulnerability Type - Unknown Product (CVE-2026-58385) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-58385 was patched at 2026-07-14
2008.
Unknown Vulnerability Type - Unknown Product (CVE-2026-58386) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-58386 was patched at 2026-07-14
2009.
Unknown Vulnerability Type - Unknown Product (CVE-2026-58387) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-58387 was patched at 2026-07-14
2010.
Unknown Vulnerability Type - Unknown Product (CVE-2026-58388) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-58388 was patched at 2026-07-14
2011.
Unknown Vulnerability Type - Unknown Product (CVE-2026-61627) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-61627 was patched at 2026-07-14
2012.
Unknown Vulnerability Type - Unknown Product (CVE-2026-62318) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-62318 was patched at 2026-07-14
2013.
Unknown Vulnerability Type - Unknown Product (CVE-2026-62319) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-62319 was patched at 2026-07-14
2014.
Unknown Vulnerability Type - Unknown Product (CVE-2026-62320) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-62320 was patched at 2026-07-14
2015.
Unknown Vulnerability Type - Unknown Product (CVE-2026-62321) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-62321 was patched at 2026-07-14
2016.
Unknown Vulnerability Type - Unknown Product (CVE-2026-6425) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-6425 was patched at 2026-07-14
2017.
Unknown Vulnerability Type - Unknown Product (CVE-2026-8343) - Low [0]
Description: {'nvd_cve_data_all': '', 'epss_cve_data_all': '', 'attackerkb_cve_data_all': '', 'vulners_cve_data_all': 'This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.', 'bdu_cve_data_all': '', 'custom_cve_data_all': '', 'combined_cve_data_all': ''}
| Component | Value | Weight | Comment |
|---|---|---|---|
| 0 | 18 | Exploitation in the wild is NOT mentioned in available Data Sources | |
| 0 | 17 | The existence of publicly available or private exploit is NOT mentioned in available Data Sources | |
| 0 | 15 | Unknown Vulnerability Type | |
| 0 | 14 | Unknown Product | |
| 0.0 | 10 | CVSS Base Score is NA. No data. | |
| 0 | 10 | EPSS Probability is 0, EPSS Percentile is 0 |
debian: CVE-2026-8343 was patched at 2026-07-14
oraclelinux: CVE-2026-8343 was patched at 2026-06-23
altlinux: CVE-2025-8110 was patched at 2026-06-25
redos: CVE-2025-27607 was patched at 2026-07-13
debian: CVE-2026-8461 was patched at 2026-06-22, 2026-06-24
altlinux: CVE-2026-42533 was patched at 2026-07-17, 2026-07-21, 2026-07-22
debian: CVE-2026-42533 was patched at 2026-07-14
altlinux: CVE-2025-64111 was patched at 2026-06-25
altlinux: CVE-2026-55200 was patched at 2026-07-09, 2026-07-13, 2026-07-14, 2026-07-15, 2026-07-17
debian: CVE-2026-55200 was patched at 2026-06-24, 2026-06-25
ubuntu: CVE-2026-55200 was patched at 2026-07-30
altlinux: CVE-2026-14431 was patched at 2026-07-03
debian: CVE-2026-13036 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-14431 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-56786 was patched at 2026-07-14
debian: CVE-2026-14266 was patched at 2026-07-14
altlinux: CVE-2026-48090 was patched at 2026-06-25, 2026-07-02
debian: CVE-2026-12481 was patched at 2026-07-14
almalinux: CVE-2026-58380 was patched at 2026-07-16
almalinux: CVE-2026-58384 was patched at 2026-07-16
debian: CVE-2026-58380 was patched at 2026-07-14
debian: CVE-2026-58384 was patched at 2026-07-14
oraclelinux: CVE-2026-58380 was patched at 2026-07-16
oraclelinux: CVE-2026-58384 was patched at 2026-07-16
redhat: CVE-2026-58380 was patched at 2026-07-16
redhat: CVE-2026-58384 was patched at 2026-07-16
debian: CVE-2026-12252 was patched at 2026-07-14
debian: CVE-2026-58459 was patched at 2026-07-14
altlinux: CVE-2026-26194 was patched at 2026-06-25
debian: CVE-2026-64600 was patched at 2026-07-30
oraclelinux: CVE-2026-64600 was patched at 2026-07-16
redhat: CVE-2026-64600 was patched at 2026-07-14, 2026-07-15, 2026-07-16, 2026-07-17, 2026-07-29
altlinux: CVE-2026-25232 was patched at 2026-06-25
debian: CVE-2026-9640 was patched at 2026-06-28, 2026-07-14
redos: CVE-2026-28699 was patched at 2026-07-14
altlinux: CVE-2026-11856 was patched at 2026-06-24, 2026-06-30
altlinux: CVE-2026-8926 was patched at 2026-06-24, 2026-06-30
altlinux: CVE-2026-8927 was patched at 2026-06-24, 2026-06-30
altlinux: CVE-2026-9079 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-11856 was patched at 2026-06-24
debian: CVE-2026-8926 was patched at 2026-07-14
debian: CVE-2026-8927 was patched at 2026-07-14
debian: CVE-2026-9079 was patched at 2026-07-14
ubuntu: CVE-2026-8926 was patched at 2026-07-30
ubuntu: CVE-2026-8927 was patched at 2026-07-30
ubuntu: CVE-2026-9079 was patched at 2026-07-30
debian: CVE-2026-57216 was patched at 2026-07-14
altlinux: CVE-2026-55761 was patched at 2026-06-25, 2026-07-02
altlinux: CVE-2026-52845 was patched at 2026-07-02, 2026-07-03
debian: CVE-2026-52845 was patched at 2026-07-14
altlinux: CVE-2026-25229 was patched at 2026-06-25
altlinux: CVE-2026-59856 was patched at 2026-06-30, 2026-07-06
debian: CVE-2026-59856 was patched at 2026-07-14
redhat: CVE-2026-59856 was patched at 2026-07-29
ubuntu: CVE-2026-59856 was patched at 2026-07-30
debian: CVE-2026-58025 was patched at 2026-07-05, 2026-07-14
altlinux: CVE-2026-40083 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-40083 was patched at 2026-07-14
altlinux: CVE-2026-50023 was patched at 2026-07-27
debian: CVE-2026-50023 was patched at 2026-07-14
altlinux: CVE-2026-25242 was patched at 2026-06-25
debian: CVE-2026-44941 was patched at 2026-07-14
almalinux: CVE-2026-53359 was patched at 2026-07-09, 2026-07-14
almalinux: CVE-2026-53362 was patched at 2026-07-02
altlinux: CVE-2026-52910 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53264 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53359 was patched at 2026-07-04, 2026-07-06, 2026-07-07, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53362 was patched at 2026-07-04, 2026-07-06, 2026-07-07, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-52910 was patched at 2026-06-21, 2026-06-24, 2026-07-14
debian: CVE-2026-53264 was patched at 2026-07-14
debian: CVE-2026-53359 was patched at 2026-07-05, 2026-07-14, 2026-07-30
debian: CVE-2026-53362 was patched at 2026-07-05, 2026-07-14, 2026-07-30
oraclelinux: CVE-2026-53359 was patched at 2026-07-02, 2026-07-03, 2026-07-04, 2026-07-10, 2026-07-14
oraclelinux: CVE-2026-53362 was patched at 2026-07-15
redhat: CVE-2026-53359 was patched at 2026-07-09, 2026-07-10, 2026-07-13, 2026-07-14, 2026-07-15, 2026-07-17, 2026-07-22, 2026-07-23
altlinux: CVE-2026-57157 was patched at 2026-07-28
altlinux: CVE-2026-57158 was patched at 2026-07-28
debian: CVE-2026-57157 was patched at 2026-07-14
debian: CVE-2026-57158 was patched at 2026-07-14
ubuntu: CVE-2026-57157 was patched at 2026-07-30
ubuntu: CVE-2026-57158 was patched at 2026-07-30
altlinux: CVE-2026-10536 was patched at 2026-06-24, 2026-06-30
altlinux: CVE-2026-8925 was patched at 2026-06-24, 2026-06-30
altlinux: CVE-2026-9080 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-10536 was patched at 2026-06-24
debian: CVE-2026-9080 was patched at 2026-07-14
ubuntu: CVE-2026-10536 was patched at 2026-07-30
ubuntu: CVE-2026-8925 was patched at 2026-07-30
ubuntu: CVE-2026-9080 was patched at 2026-07-30
altlinux: CVE-2026-47204 was patched at 2026-06-25, 2026-07-02
altlinux: CVE-2026-47205 was patched at 2026-06-25, 2026-07-02
altlinux: CVE-2026-47207 was patched at 2026-06-25, 2026-07-02
debian: CVE-2026-58049 was patched at 2026-07-14
altlinux: CVE-2026-59198 was patched at 2026-07-27
altlinux: CVE-2026-59199 was patched at 2026-07-27
altlinux: CVE-2026-59205 was patched at 2026-07-27
debian: CVE-2026-54058 was patched at 2026-07-14
debian: CVE-2026-59198 was patched at 2026-07-14
debian: CVE-2026-59199 was patched at 2026-07-14
debian: CVE-2026-59205 was patched at 2026-07-14
redhat: CVE-2026-54058 was patched at 2026-07-29
debian: CVE-2026-58051 was patched at 2026-07-14
ubuntu: CVE-2026-58051 was patched at 2026-07-30
debian: CVE-2026-56789 was patched at 2026-07-14
debian: CVE-2026-12549 was patched at 2026-07-14
debian: CVE-2025-70102 was patched at 2026-06-24, 2026-07-14, 2026-07-15
debian: CVE-2026-54902 was patched at 2026-07-14
debian: CVE-2026-15185 was patched at 2026-07-14
redos: CVE-2026-28744 was patched at 2026-06-26
altlinux: CVE-2026-11564 was patched at 2026-06-24, 2026-06-30
altlinux: CVE-2026-12064 was patched at 2026-06-24, 2026-06-30
altlinux: CVE-2026-8286 was patched at 2026-06-24, 2026-06-30
altlinux: CVE-2026-8924 was patched at 2026-06-24, 2026-06-30
altlinux: CVE-2026-8932 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-12064 was patched at 2026-06-24
debian: CVE-2026-8286 was patched at 2026-07-14
debian: CVE-2026-8924 was patched at 2026-07-14
debian: CVE-2026-8932 was patched at 2026-07-14
ubuntu: CVE-2026-11564 was patched at 2026-07-30
ubuntu: CVE-2026-12064 was patched at 2026-07-30
ubuntu: CVE-2026-8286 was patched at 2026-07-30
ubuntu: CVE-2026-8924 was patched at 2026-07-30
almalinux: CVE-2026-54512 was patched at 2026-07-16, 2026-07-22
debian: CVE-2026-54512 was patched at 2026-07-14
oraclelinux: CVE-2026-54512 was patched at 2026-07-20, 2026-07-23
redhat: CVE-2026-54512 was patched at 2026-07-16, 2026-07-23
debian: CVE-2026-52747 was patched at 2026-07-14
debian: CVE-2026-57215 was patched at 2026-07-14
debian: CVE-2026-57217 was patched at 2026-07-14
debian: CVE-2026-57218 was patched at 2026-07-14
altlinux: CVE-2026-47778 was patched at 2026-06-25, 2026-07-02
altlinux: CVE-2026-48743 was patched at 2026-06-25, 2026-07-02
debian: CVE-2026-58055 was patched at 2026-07-14
ubuntu: CVE-2026-58055 was patched at 2026-07-30
altlinux: CVE-2026-25120 was patched at 2026-06-25
altlinux: CVE-2026-25921 was patched at 2026-06-25
altlinux: CVE-2026-59890 was patched at 2026-07-07
altlinux: CVE-2026-40941 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-40941 was patched at 2026-07-14
debian: CVE-2026-59930 was patched at 2026-07-14
debian: CVE-2026-58052 was patched at 2026-07-14
altlinux: CVE-2026-39938 was patched at 2026-07-25, 2026-07-29
altlinux: CVE-2026-40084 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-39938 was patched at 2026-07-14
debian: CVE-2026-40084 was patched at 2026-07-14
debian: CVE-2026-45309 was patched at 2026-07-14
redos: CVE-2026-44307 was patched at 2026-07-13
debian: CVE-2023-32309 was patched at 2026-07-14
debian: CVE-2026-46338 was patched at 2026-07-14
altlinux: CVE-2026-54572 was patched at 2026-07-13, 2026-07-16
altlinux: CVE-2026-59732 was patched at 2026-07-13, 2026-07-16
altlinux: CVE-2026-59733 was patched at 2026-07-13, 2026-07-16
debian: CVE-2026-54572 was patched at 2026-07-14
debian: CVE-2026-59732 was patched at 2026-07-14
debian: CVE-2026-59733 was patched at 2026-07-14
altlinux: CVE-2026-23633 was patched at 2026-06-25
altlinux: CVE-2026-24135 was patched at 2026-06-25
altlinux: CVE-2026-52844 was patched at 2026-07-02, 2026-07-03
debian: CVE-2026-52844 was patched at 2026-07-14
debian: CVE-2026-56876 was patched at 2026-07-14
debian: CVE-2026-59924 was patched at 2026-07-14
debian: CVE-2026-8384 was patched at 2026-07-14
debian: CVE-2026-44891 was patched at 2026-07-14
altlinux: CVE-2026-55199 was patched at 2026-07-09, 2026-07-13, 2026-07-14, 2026-07-15, 2026-07-17
debian: CVE-2026-55199 was patched at 2026-06-24, 2026-06-25
ubuntu: CVE-2026-55199 was patched at 2026-07-30
debian: CVE-2026-59925 was patched at 2026-07-14
altlinux: CVE-2026-47220 was patched at 2026-06-25, 2026-07-02
altlinux: CVE-2026-47221 was patched at 2026-06-25, 2026-07-02
altlinux: CVE-2026-48042 was patched at 2026-06-25, 2026-07-02
altlinux: CVE-2026-48044 was patched at 2026-06-25, 2026-07-02
debian: CVE-2026-48779 was patched at 2026-06-24
almalinux: CVE-2026-55654 was patched at 2026-07-29
debian: CVE-2026-55654 was patched at 2026-06-24
oraclelinux: CVE-2026-55654 was patched at 2026-07-30
redhat: CVE-2026-55654 was patched at 2026-07-29
altlinux: CVE-2026-11352 was patched at 2026-06-24, 2026-06-30
altlinux: CVE-2026-11586 was patched at 2026-06-24, 2026-06-30
ubuntu: CVE-2026-11352 was patched at 2026-07-30
ubuntu: CVE-2026-11586 was patched at 2026-07-30
debian: CVE-2026-54297 was patched at 2026-07-14
altlinux: CVE-2026-29181 was patched at 2026-07-10, 2026-07-13
debian: CVE-2026-59880 was patched at 2026-07-14
debian: CVE-2026-57212 was patched at 2026-07-14
debian: CVE-2026-49476 was patched at 2026-07-14
debian: CVE-2026-49477 was patched at 2026-07-14
debian: CVE-2026-59922 was patched at 2026-07-14
debian: CVE-2026-59927 was patched at 2026-07-14
debian: CVE-2026-59928 was patched at 2026-07-14
almalinux: CVE-2026-54059 was patched at 2026-07-14
almalinux: CVE-2026-54060 was patched at 2026-07-14
almalinux: CVE-2026-55379 was patched at 2026-07-14
almalinux: CVE-2026-55380 was patched at 2026-07-14
altlinux: CVE-2026-54059 was patched at 2026-07-27
altlinux: CVE-2026-54060 was patched at 2026-07-27
altlinux: CVE-2026-55379 was patched at 2026-07-27
altlinux: CVE-2026-55380 was patched at 2026-07-27
altlinux: CVE-2026-59200 was patched at 2026-07-27
altlinux: CVE-2026-59204 was patched at 2026-07-27
debian: CVE-2026-54059 was patched at 2026-07-14
debian: CVE-2026-54060 was patched at 2026-07-14
debian: CVE-2026-55379 was patched at 2026-07-14
debian: CVE-2026-55380 was patched at 2026-07-14
debian: CVE-2026-59200 was patched at 2026-07-14
debian: CVE-2026-59204 was patched at 2026-07-14
oraclelinux: CVE-2026-54059 was patched at 2026-07-14
oraclelinux: CVE-2026-54060 was patched at 2026-07-14
oraclelinux: CVE-2026-55379 was patched at 2026-07-14
oraclelinux: CVE-2026-55380 was patched at 2026-07-14
redhat: CVE-2026-54059 was patched at 2026-07-14
redhat: CVE-2026-54060 was patched at 2026-07-14
redhat: CVE-2026-55379 was patched at 2026-07-14
redhat: CVE-2026-55380 was patched at 2026-07-14
debian: CVE-2026-59939 was patched at 2026-07-14
redhat: CVE-2026-59939 was patched at 2026-07-30
ubuntu: CVE-2026-59939 was patched at 2026-07-30
debian: CVE-2026-53550 was patched at 2026-07-14
debian: CVE-2026-59869 was patched at 2026-07-14
debian: CVE-2026-56787 was patched at 2026-07-14
debian: CVE-2026-56788 was patched at 2026-07-14
debian: CVE-2026-59871 was patched at 2026-07-14
debian: CVE-2026-59873 was patched at 2026-07-14
debian: CVE-2026-59874 was patched at 2026-07-14
redhat: CVE-2026-59873 was patched at 2026-07-28
redhat: CVE-2026-59874 was patched at 2026-07-28
altlinux: CVE-2026-15165 was patched at 2026-07-12, 2026-07-14, 2026-07-15
altlinux: CVE-2026-15166 was patched at 2026-07-12, 2026-07-14, 2026-07-15
altlinux: CVE-2026-15167 was patched at 2026-07-12, 2026-07-14, 2026-07-15
altlinux: CVE-2026-15169 was patched at 2026-07-12, 2026-07-14, 2026-07-15
altlinux: CVE-2026-15170 was patched at 2026-07-12, 2026-07-14, 2026-07-15
altlinux: CVE-2026-15171 was patched at 2026-07-12, 2026-07-14, 2026-07-15
altlinux: CVE-2026-15172 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15165 was patched at 2026-07-14
debian: CVE-2026-15166 was patched at 2026-07-14
debian: CVE-2026-15167 was patched at 2026-07-14
debian: CVE-2026-15169 was patched at 2026-07-14
debian: CVE-2026-15170 was patched at 2026-07-14
debian: CVE-2026-15171 was patched at 2026-07-14
debian: CVE-2026-15172 was patched at 2026-07-14
debian: CVE-2026-9639 was patched at 2026-06-28, 2026-07-14
debian: CVE-2026-54904 was patched at 2026-07-14
altlinux: CVE-2026-22592 was patched at 2026-06-25
debian: CVE-2026-48988 was patched at 2026-06-24
altlinux: CVE-2026-44512 was patched at 2026-07-06
debian: CVE-2026-44512 was patched at 2026-07-14
debian: CVE-2026-13117 was patched at 2026-07-03, 2026-07-14
ubuntu: CVE-2026-13117 was patched at 2026-07-30
altlinux: CVE-2026-15164 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15164 was patched at 2026-07-14
almalinux: CVE-2026-42055 was patched at 2026-07-07, 2026-07-08, 2026-07-13
altlinux: CVE-2026-42055 was patched at 2026-06-23, 2026-06-25, 2026-06-26
debian: CVE-2026-42055 was patched at 2026-06-24, 2026-06-30
oraclelinux: CVE-2026-42055 was patched at 2026-07-09, 2026-07-13, 2026-07-14, 2026-07-16
redhat: CVE-2026-42055 was patched at 2026-07-07, 2026-07-08, 2026-07-13
redos: CVE-2026-42055 was patched at 2026-07-14
ubuntu: CVE-2026-42055 was patched at 2026-07-30
altlinux: CVE-2026-55827 was patched at 2026-06-20, 2026-06-22, 2026-06-24
altlinux: CVE-2026-57156 was patched at 2026-07-28
debian: CVE-2026-55827 was patched at 2026-07-14
debian: CVE-2026-57156 was patched at 2026-07-14
ubuntu: CVE-2026-55827 was patched at 2026-07-30
ubuntu: CVE-2026-57156 was patched at 2026-07-30
altlinux: CVE-2026-59197 was patched at 2026-07-27
debian: CVE-2026-59197 was patched at 2026-07-14
redhat: CVE-2026-59197 was patched at 2026-07-29
debian: CVE-2026-59879 was patched at 2026-07-14
debian: CVE-2026-58050 was patched at 2026-07-14
ubuntu: CVE-2026-58050 was patched at 2026-07-30
debian: CVE-2026-58058 was patched at 2026-07-14
debian: CVE-2026-54900 was patched at 2026-07-14
debian: CVE-2026-12243 was patched at 2026-07-14
debian: CVE-2026-54293 was patched at 2026-06-24
altlinux: CVE-2026-9545 was patched at 2026-06-24, 2026-06-30
altlinux: CVE-2026-9546 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-9545 was patched at 2026-07-14
ubuntu: CVE-2026-9545 was patched at 2026-07-30
altlinux: CVE-2026-47775 was patched at 2026-06-25, 2026-07-02
debian: CVE-2026-57221 was patched at 2026-07-14
altlinux: CVE-2026-15168 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15168 was patched at 2026-07-14
altlinux: CVE-2026-57053 was patched at 2026-07-14, 2026-07-17, 2026-07-20
debian: CVE-2026-57053 was patched at 2026-06-24
ubuntu: CVE-2026-57053 was patched at 2026-07-30
debian: CVE-2026-41516 was patched at 2026-07-14
debian: CVE-2026-47423 was patched at 2026-07-14
debian: CVE-2026-49458 was patched at 2026-07-14
debian: CVE-2026-49459 was patched at 2026-07-14
debian: CVE-2026-49978 was patched at 2026-07-14
debian: CVE-2026-58037 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-59923 was patched at 2026-07-14
debian: CVE-2026-44587 was patched at 2026-06-24
debian: CVE-2026-59929 was patched at 2026-07-14
debian: CVE-2026-57213 was patched at 2026-07-14
altlinux: CVE-2026-26022 was patched at 2026-06-25
altlinux: CVE-2026-52846 was patched at 2026-07-02, 2026-07-03
debian: CVE-2026-52846 was patched at 2026-07-14
debian: CVE-2026-55599 was patched at 2026-06-24
debian: CVE-2026-28385 was patched at 2026-07-14
redos: CVE-2026-35527 was patched at 2026-06-22
debian: CVE-2026-50221 was patched at 2026-06-24
altlinux: CVE-2026-40080 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-40080 was patched at 2026-07-14
debian: CVE-2026-41479 was patched at 2026-06-24
altlinux: CVE-2026-9547 was patched at 2026-06-24, 2026-06-30
debian: CVE-2026-9547 was patched at 2026-07-14
ubuntu: CVE-2026-9547 was patched at 2026-07-30
altlinux: CVE-2026-48931 was patched at 2026-07-23
debian: CVE-2026-48931 was patched at 2026-06-24
altlinux: CVE-2026-40082 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-40082 was patched at 2026-07-14
debian: CVE-2026-53655 was patched at 2026-06-24
redos: CVE-2026-7474 was patched at 2026-07-09
altlinux: CVE-2026-13283 was patched at 2026-06-29
altlinux: CVE-2026-13774 was patched at 2026-07-03
altlinux: CVE-2026-13778 was patched at 2026-07-03
altlinux: CVE-2026-13779 was patched at 2026-07-03
altlinux: CVE-2026-13786 was patched at 2026-07-03
altlinux: CVE-2026-13787 was patched at 2026-07-03
altlinux: CVE-2026-13788 was patched at 2026-07-03
altlinux: CVE-2026-13791 was patched at 2026-07-03
altlinux: CVE-2026-13794 was patched at 2026-07-03
altlinux: CVE-2026-13802 was patched at 2026-07-03
altlinux: CVE-2026-13805 was patched at 2026-07-03
altlinux: CVE-2026-13807 was patched at 2026-07-03
altlinux: CVE-2026-13811 was patched at 2026-07-03
altlinux: CVE-2026-13815 was patched at 2026-07-03
altlinux: CVE-2026-13821 was patched at 2026-07-03
altlinux: CVE-2026-13830 was patched at 2026-07-03
altlinux: CVE-2026-13831 was patched at 2026-07-03
altlinux: CVE-2026-13845 was patched at 2026-07-03
altlinux: CVE-2026-13848 was patched at 2026-07-03
altlinux: CVE-2026-13850 was patched at 2026-07-03
altlinux: CVE-2026-13855 was patched at 2026-07-03
altlinux: CVE-2026-13870 was patched at 2026-07-03
altlinux: CVE-2026-13884 was patched at 2026-07-03
altlinux: CVE-2026-13885 was patched at 2026-07-03
altlinux: CVE-2026-13888 was patched at 2026-07-03
altlinux: CVE-2026-13898 was patched at 2026-07-03
altlinux: CVE-2026-13899 was patched at 2026-07-03
altlinux: CVE-2026-13925 was patched at 2026-07-03
altlinux: CVE-2026-13965 was patched at 2026-07-03
altlinux: CVE-2026-13967 was patched at 2026-07-03
altlinux: CVE-2026-13968 was patched at 2026-07-03
altlinux: CVE-2026-14006 was patched at 2026-07-03
altlinux: CVE-2026-14032 was patched at 2026-07-03
altlinux: CVE-2026-14064 was patched at 2026-07-03
altlinux: CVE-2026-14067 was patched at 2026-07-03
altlinux: CVE-2026-14086 was patched at 2026-07-03
altlinux: CVE-2026-14091 was patched at 2026-07-03
altlinux: CVE-2026-14104 was patched at 2026-07-03
altlinux: CVE-2026-14107 was patched at 2026-07-03
altlinux: CVE-2026-14108 was patched at 2026-07-03
altlinux: CVE-2026-14111 was patched at 2026-07-03
altlinux: CVE-2026-14121 was patched at 2026-07-03
altlinux: CVE-2026-14149 was patched at 2026-07-03
altlinux: CVE-2026-14383 was patched at 2026-07-03
altlinux: CVE-2026-14392 was patched at 2026-07-03
altlinux: CVE-2026-14393 was patched at 2026-07-03
altlinux: CVE-2026-14395 was patched at 2026-07-03
altlinux: CVE-2026-14397 was patched at 2026-07-03
altlinux: CVE-2026-14400 was patched at 2026-07-03
altlinux: CVE-2026-14403 was patched at 2026-07-03
altlinux: CVE-2026-14405 was patched at 2026-07-03
altlinux: CVE-2026-14407 was patched at 2026-07-03
altlinux: CVE-2026-14409 was patched at 2026-07-03
altlinux: CVE-2026-14426 was patched at 2026-07-03
altlinux: CVE-2026-14430 was patched at 2026-07-03
altlinux: CVE-2026-14432 was patched at 2026-07-03
altlinux: CVE-2026-15107 was patched at 2026-07-09
altlinux: CVE-2026-15116 was patched at 2026-07-09
altlinux: CVE-2026-15118 was patched at 2026-07-09
altlinux: CVE-2026-15121 was patched at 2026-07-09
altlinux: CVE-2026-15125 was patched at 2026-07-09
altlinux: CVE-2026-15126 was patched at 2026-07-09
altlinux: CVE-2026-15132 was patched at 2026-07-09
altlinux: CVE-2026-15133 was patched at 2026-07-09
altlinux: CVE-2026-15767 was patched at 2026-07-15
altlinux: CVE-2026-15776 was patched at 2026-07-15
altlinux: CVE-2026-15902 was patched at 2026-07-18
altlinux: CVE-2026-15903 was patched at 2026-07-18
debian: CVE-2026-13031 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13033 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13035 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13037 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13038 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13283 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13774 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13778 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13779 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13786 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13787 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13788 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13791 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13794 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13802 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13805 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13807 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13811 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13815 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13821 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13830 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13831 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13845 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13848 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13850 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13855 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13870 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13884 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13885 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13888 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13898 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13899 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13925 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13965 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13967 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13968 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14006 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14032 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14064 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14067 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14086 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14091 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14104 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14107 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14108 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14111 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14121 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14149 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14383 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14392 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14393 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14395 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14397 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14400 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14403 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14405 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14407 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14409 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14426 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14430 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14432 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-15107 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15116 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15118 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15121 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15125 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15126 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15132 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15133 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15767 was patched at 2026-07-14, 2026-07-16
debian: CVE-2026-15776 was patched at 2026-07-14, 2026-07-16
debian: CVE-2026-15902 was patched at 2026-07-14, 2026-07-22
debian: CVE-2026-15903 was patched at 2026-07-14, 2026-07-22
debian: CVE-2011-10043 was patched at 2026-07-14
altlinux: CVE-2026-41252 was patched at 2026-07-08
altlinux: CVE-2026-44178 was patched at 2026-07-08
debian: CVE-2026-41252 was patched at 2026-07-14
debian: CVE-2026-44178 was patched at 2026-07-14
altlinux: CVE-2026-9086 was patched at 2026-06-28, 2026-07-01, 2026-07-02
altlinux: CVE-2026-14241 was patched at 2026-07-02, 2026-07-07
altlinux: CVE-2026-48706 was patched at 2026-06-25, 2026-07-02
altlinux: CVE-2026-57453 was patched at 2026-06-30, 2026-07-06
ubuntu: CVE-2026-57453 was patched at 2026-07-30
altlinux: CVE-2026-14380 was patched at 2026-07-21
debian: CVE-2026-14380 was patched at 2026-07-14
altlinux: CVE-2026-56001 was patched at 2026-07-08, 2026-07-09, 2026-07-14
altlinux: CVE-2026-56002 was patched at 2026-07-08, 2026-07-09, 2026-07-14
altlinux: CVE-2026-56003 was patched at 2026-07-08, 2026-07-09, 2026-07-14
debian: CVE-2026-56001 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-56002 was patched at 2026-07-14, 2026-07-15
debian: CVE-2026-56003 was patched at 2026-07-14, 2026-07-15
oraclelinux: CVE-2026-56001 was patched at 2026-07-28
oraclelinux: CVE-2026-56002 was patched at 2026-07-28
oraclelinux: CVE-2026-56003 was patched at 2026-07-28
redhat: CVE-2026-56001 was patched at 2026-07-28
redhat: CVE-2026-56002 was patched at 2026-07-28
redhat: CVE-2026-56003 was patched at 2026-07-28
ubuntu: CVE-2026-56001 was patched at 2026-07-30
ubuntu: CVE-2026-56002 was patched at 2026-07-30
ubuntu: CVE-2026-56003 was patched at 2026-07-30
debian: CVE-2026-63090 was patched at 2026-07-14
altlinux: CVE-2026-50195 was patched at 2026-06-19, 2026-07-14, 2026-07-15
ubuntu: CVE-2026-50195 was patched at 2026-07-30
almalinux: CVE-2026-12413 was patched at 2026-07-27
almalinux: CVE-2026-50721 was patched at 2026-07-27
almalinux: CVE-2026-50722 was patched at 2026-07-27
debian: CVE-2026-12413 was patched at 2026-07-14
debian: CVE-2026-50721 was patched at 2026-07-14
debian: CVE-2026-50722 was patched at 2026-07-14
oraclelinux: CVE-2026-12413 was patched at 2026-07-27
oraclelinux: CVE-2026-50721 was patched at 2026-07-27
oraclelinux: CVE-2026-50722 was patched at 2026-07-27
redhat: CVE-2026-12413 was patched at 2026-07-27
redhat: CVE-2026-50721 was patched at 2026-07-27
redhat: CVE-2026-50722 was patched at 2026-07-27
altlinux: CVE-2026-50574 was patched at 2026-07-27
debian: CVE-2026-50574 was patched at 2026-07-14
debian: CVE-2026-23879 was patched at 2026-07-14
debian: CVE-2026-9323 was patched at 2026-07-14
altlinux: CVE-2026-12244 was patched at 2026-06-26, 2026-06-29
ubuntu: CVE-2026-12244 was patched at 2026-07-30
debian: CVE-2026-13311 was patched at 2026-07-14
altlinux: CVE-2026-53334 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53335 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-61861 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-61861 was patched at 2026-07-14
altlinux: CVE-2026-53914 was patched at 2026-06-26, 2026-07-06
altlinux: CVE-2026-44727 was patched at 2026-06-18
debian: CVE-2026-44727 was patched at 2026-07-14
debian: CVE-2026-40553 was patched at 2026-07-14
ubuntu: CVE-2026-40553 was patched at 2026-07-30
debian: CVE-2026-11979 was patched at 2026-07-14
almalinux: CVE-2026-12505 was patched at 2026-07-15
almalinux: CVE-2026-14544 was patched at 2026-07-15, 2026-07-16
altlinux: CVE-2026-12505 was patched at 2026-07-29
debian: CVE-2026-12505 was patched at 2026-06-24
debian: CVE-2026-13006 was patched at 2026-07-14
debian: CVE-2026-46606 was patched at 2026-07-14
debian: CVE-2026-46607 was patched at 2026-07-14
debian: CVE-2026-56208 was patched at 2026-06-24
debian: CVE-2026-56209 was patched at 2026-06-24
debian: CVE-2026-56211 was patched at 2026-06-24
oraclelinux: CVE-2026-12505 was patched at 2026-07-15, 2026-07-21
oraclelinux: CVE-2026-14544 was patched at 2026-07-16
oraclelinux: CVE-2026-56208 was patched at 2026-07-28
redhat: CVE-2026-12505 was patched at 2026-07-15
redhat: CVE-2026-14544 was patched at 2026-07-16
redhat: CVE-2026-56208 was patched at 2026-07-28
ubuntu: CVE-2026-12505 was patched at 2026-07-30
debian: CVE-2026-40034 was patched at 2026-07-14
almalinux: CVE-2026-58379 was patched at 2026-07-13
debian: CVE-2026-58379 was patched at 2026-07-14
debian: CVE-2026-58381 was patched at 2026-07-14
oraclelinux: CVE-2026-58379 was patched at 2026-07-13
redhat: CVE-2026-58379 was patched at 2026-07-13
debian: CVE-2026-5674 was patched at 2026-07-14
debian: CVE-2026-56740 was patched at 2026-07-14
debian: CVE-2026-56741 was patched at 2026-07-14
oraclelinux: CVE-2026-5674 was patched at 2026-07-28
debian: CVE-2025-11226 was patched at 2026-07-14
debian: CVE-2026-15028 was patched at 2026-07-14
ubuntu: CVE-2026-15028 was patched at 2026-07-30
almalinux: CVE-2026-12912 was patched at 2026-07-20, 2026-07-21
debian: CVE-2026-12912 was patched at 2026-07-14, 2026-07-19
oraclelinux: CVE-2026-12912 was patched at 2026-07-20, 2026-07-21, 2026-07-28
redhat: CVE-2026-12912 was patched at 2026-07-21
almalinux: CVE-2026-48618 was patched at 2026-07-06, 2026-07-15, 2026-07-20
almalinux: CVE-2026-48928 was patched at 2026-07-06, 2026-07-15, 2026-07-20
almalinux: CVE-2026-48930 was patched at 2026-07-06, 2026-07-15, 2026-07-20
almalinux: CVE-2026-48935 was patched at 2026-07-06, 2026-07-15, 2026-07-20
altlinux: CVE-2026-48617 was patched at 2026-07-23
altlinux: CVE-2026-48618 was patched at 2026-07-23
altlinux: CVE-2026-48928 was patched at 2026-07-23
altlinux: CVE-2026-48930 was patched at 2026-07-23
altlinux: CVE-2026-48935 was patched at 2026-07-23
debian: CVE-2026-48617 was patched at 2026-06-24
debian: CVE-2026-48618 was patched at 2026-06-24
debian: CVE-2026-48928 was patched at 2026-06-24
debian: CVE-2026-48930 was patched at 2026-06-24
debian: CVE-2026-48935 was patched at 2026-06-24
oraclelinux: CVE-2026-48618 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
oraclelinux: CVE-2026-48928 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
oraclelinux: CVE-2026-48930 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
oraclelinux: CVE-2026-48935 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-48618 was patched at 2026-07-06, 2026-07-15, 2026-07-20
redhat: CVE-2026-48928 was patched at 2026-07-06, 2026-07-15, 2026-07-20
redhat: CVE-2026-48930 was patched at 2026-07-06, 2026-07-15, 2026-07-20
redhat: CVE-2026-48935 was patched at 2026-07-06, 2026-07-15, 2026-07-20
altlinux: CVE-2026-55955 was patched at 2026-06-24, 2026-07-10, 2026-07-20
altlinux: CVE-2026-55956 was patched at 2026-06-24, 2026-07-10, 2026-07-20
debian: CVE-2026-55955 was patched at 2026-07-14
debian: CVE-2026-55956 was patched at 2026-07-14
redhat: CVE-2026-55956 was patched at 2026-07-22
redos: CVE-2026-20706 was patched at 2026-07-14
redos: CVE-2026-22555 was patched at 2026-07-14
redos: CVE-2026-33322 was patched at 2026-07-14
altlinux: CVE-2026-13800 was patched at 2026-07-03
altlinux: CVE-2026-13818 was patched at 2026-07-03
altlinux: CVE-2026-13828 was patched at 2026-07-03
altlinux: CVE-2026-13864 was patched at 2026-07-03
altlinux: CVE-2026-13897 was patched at 2026-07-03
altlinux: CVE-2026-13914 was patched at 2026-07-03
altlinux: CVE-2026-13931 was patched at 2026-07-03
altlinux: CVE-2026-13932 was patched at 2026-07-03
altlinux: CVE-2026-13933 was patched at 2026-07-03
altlinux: CVE-2026-13936 was patched at 2026-07-03
altlinux: CVE-2026-13937 was patched at 2026-07-03
altlinux: CVE-2026-13949 was patched at 2026-07-03
altlinux: CVE-2026-13953 was patched at 2026-07-03
altlinux: CVE-2026-13954 was patched at 2026-07-03
altlinux: CVE-2026-13964 was patched at 2026-07-03
altlinux: CVE-2026-13984 was patched at 2026-07-03
altlinux: CVE-2026-13985 was patched at 2026-07-03
altlinux: CVE-2026-14003 was patched at 2026-07-03
altlinux: CVE-2026-14019 was patched at 2026-07-03
altlinux: CVE-2026-14034 was patched at 2026-07-03
altlinux: CVE-2026-14035 was patched at 2026-07-03
altlinux: CVE-2026-14052 was patched at 2026-07-03
altlinux: CVE-2026-14061 was patched at 2026-07-03
altlinux: CVE-2026-14118 was patched at 2026-07-03
altlinux: CVE-2026-14155 was patched at 2026-07-03
altlinux: CVE-2026-14156 was patched at 2026-07-03
altlinux: CVE-2026-14381 was patched at 2026-07-03
debian: CVE-2026-13800 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13818 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13828 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13864 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13897 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13914 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13931 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13932 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13933 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13936 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13937 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13949 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13953 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13954 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13964 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13984 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13985 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14003 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14019 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14034 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14035 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14052 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14061 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14118 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14155 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14156 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14381 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-45363 was patched at 2026-07-14
almalinux: CVE-2026-43701 was patched at 2026-07-20
almalinux: CVE-2026-43713 was patched at 2026-07-20
debian: CVE-2026-43701 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43713 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43701 was patched at 2026-07-20
oraclelinux: CVE-2026-43713 was patched at 2026-07-20
redhat: CVE-2026-43701 was patched at 2026-07-20
redhat: CVE-2026-43713 was patched at 2026-07-20
debian: CVE-2026-49877 was patched at 2026-07-14
altlinux: CVE-2026-9689 was patched at 2026-07-11, 2026-07-13, 2026-07-14, 2026-07-16
altlinux: CVE-2026-9798 was patched at 2026-07-11, 2026-07-13, 2026-07-14, 2026-07-16
altlinux: CVE-2026-9799 was patched at 2026-06-28, 2026-07-01, 2026-07-02
altlinux: CVE-2026-9800 was patched at 2026-06-28, 2026-07-01, 2026-07-02
altlinux: CVE-2026-62644 was patched at 2026-07-10, 2026-07-15
debian: CVE-2026-62644 was patched at 2026-07-14, 2026-07-19
debian: CVE-2026-57219 was patched at 2026-07-14
altlinux: CVE-2025-64175 was patched at 2026-06-25
debian: CVE-2026-58029 was patched at 2026-07-05, 2026-07-14
altlinux: CVE-2026-35275 was patched at 2026-06-29
altlinux: CVE-2026-46768 was patched at 2026-06-29
altlinux: CVE-2026-46825 was patched at 2026-06-29
altlinux: CVE-2026-46873 was patched at 2026-06-29
altlinux: CVE-2026-46877 was patched at 2026-06-29
altlinux: CVE-2026-46974 was patched at 2026-06-29
altlinux: CVE-2026-47050 was patched at 2026-06-29
debian: CVE-2026-56016 was patched at 2026-07-14
debian: CVE-2026-7017 was patched at 2026-07-14
debian: CVE-2026-47737 was patched at 2026-07-14
redos: CVE-2026-1707 was patched at 2026-06-23
redos: CVE-2026-34204 was patched at 2026-07-14
debian: CVE-2026-52690 was patched at 2026-06-25, 2026-07-14
altlinux: CVE-2026-12490 was patched at 2026-06-26, 2026-06-29
debian: CVE-2026-12490 was patched at 2026-07-14
ubuntu: CVE-2026-12490 was patched at 2026-07-30
altlinux: CVE-2026-55626 was patched at 2026-07-08
debian: CVE-2026-55626 was patched at 2026-07-14
altlinux: CVE-2026-49843 was patched at 2026-06-24, 2026-06-26, 2026-07-16
altlinux: CVE-2026-49848 was patched at 2026-06-24, 2026-06-26, 2026-07-16
debian: CVE-2026-55962 was patched at 2026-07-14
debian: CVE-2026-49852 was patched at 2026-07-14
almalinux: CVE-2026-14476 was patched at 2026-07-20
debian: CVE-2026-12199 was patched at 2026-06-24
debian: CVE-2026-14476 was patched at 2026-07-14
debian: CVE-2026-55202 was patched at 2026-06-24
debian: CVE-2026-56091 was patched at 2026-07-14
debian: CVE-2026-56130 was patched at 2026-07-14
oraclelinux: CVE-2026-14476 was patched at 2026-07-20, 2026-07-22
redhat: CVE-2026-14476 was patched at 2026-07-20, 2026-07-28
altlinux: CVE-2026-13281 was patched at 2026-06-29
altlinux: CVE-2026-13775 was patched at 2026-07-03
altlinux: CVE-2026-13776 was patched at 2026-07-03
altlinux: CVE-2026-13777 was patched at 2026-07-03
altlinux: CVE-2026-13780 was patched at 2026-07-03
altlinux: CVE-2026-13781 was patched at 2026-07-03
altlinux: CVE-2026-13782 was patched at 2026-07-03
altlinux: CVE-2026-13785 was patched at 2026-07-03
altlinux: CVE-2026-13789 was patched at 2026-07-08
altlinux: CVE-2026-13790 was patched at 2026-07-03
altlinux: CVE-2026-13792 was patched at 2026-07-03
altlinux: CVE-2026-13793 was patched at 2026-07-03
altlinux: CVE-2026-13795 was patched at 2026-07-03
altlinux: CVE-2026-13796 was patched at 2026-07-03
altlinux: CVE-2026-13797 was patched at 2026-07-03
altlinux: CVE-2026-13798 was patched at 2026-07-03
altlinux: CVE-2026-13801 was patched at 2026-07-03
altlinux: CVE-2026-13803 was patched at 2026-07-03
altlinux: CVE-2026-13804 was patched at 2026-07-03
altlinux: CVE-2026-13806 was patched at 2026-07-03
altlinux: CVE-2026-13808 was patched at 2026-07-03
altlinux: CVE-2026-13809 was patched at 2026-07-03
altlinux: CVE-2026-13812 was patched at 2026-07-03
altlinux: CVE-2026-13813 was patched at 2026-07-03
altlinux: CVE-2026-13816 was patched at 2026-07-03
altlinux: CVE-2026-13817 was patched at 2026-07-03
altlinux: CVE-2026-13820 was patched at 2026-07-03
altlinux: CVE-2026-13822 was patched at 2026-07-03
altlinux: CVE-2026-13823 was patched at 2026-07-03
altlinux: CVE-2026-13824 was patched at 2026-07-03
altlinux: CVE-2026-13826 was patched at 2026-07-03
altlinux: CVE-2026-13829 was patched at 2026-07-03
altlinux: CVE-2026-13832 was patched at 2026-07-03
altlinux: CVE-2026-13833 was patched at 2026-07-03
altlinux: CVE-2026-13834 was patched at 2026-07-03
altlinux: CVE-2026-13838 was patched at 2026-07-03
altlinux: CVE-2026-13839 was patched at 2026-07-03
altlinux: CVE-2026-13840 was patched at 2026-07-03
altlinux: CVE-2026-13841 was patched at 2026-07-03
altlinux: CVE-2026-13843 was patched at 2026-07-03
altlinux: CVE-2026-13846 was patched at 2026-07-03
altlinux: CVE-2026-13847 was patched at 2026-07-03
altlinux: CVE-2026-13849 was patched at 2026-07-03
altlinux: CVE-2026-13851 was patched at 2026-07-03
altlinux: CVE-2026-13852 was patched at 2026-07-03
altlinux: CVE-2026-13853 was patched at 2026-07-03
altlinux: CVE-2026-13854 was patched at 2026-07-03
altlinux: CVE-2026-13856 was patched at 2026-07-03
altlinux: CVE-2026-13859 was patched at 2026-07-03
altlinux: CVE-2026-13861 was patched at 2026-07-03
altlinux: CVE-2026-13862 was patched at 2026-07-03
altlinux: CVE-2026-13863 was patched at 2026-07-03
altlinux: CVE-2026-13865 was patched at 2026-07-03
altlinux: CVE-2026-13866 was patched at 2026-07-03
altlinux: CVE-2026-13868 was patched at 2026-07-03
altlinux: CVE-2026-13869 was patched at 2026-07-03
altlinux: CVE-2026-13871 was patched at 2026-07-03
altlinux: CVE-2026-13872 was patched at 2026-07-03
altlinux: CVE-2026-13875 was patched at 2026-07-03
altlinux: CVE-2026-13876 was patched at 2026-07-03
altlinux: CVE-2026-13877 was patched at 2026-07-03
altlinux: CVE-2026-13878 was patched at 2026-07-03
altlinux: CVE-2026-13880 was patched at 2026-07-03
altlinux: CVE-2026-13881 was patched at 2026-07-03
altlinux: CVE-2026-13882 was patched at 2026-07-03
altlinux: CVE-2026-13883 was patched at 2026-07-03
altlinux: CVE-2026-13886 was patched at 2026-07-03
altlinux: CVE-2026-13887 was patched at 2026-07-03
altlinux: CVE-2026-13889 was patched at 2026-07-03
altlinux: CVE-2026-13891 was patched at 2026-07-03
altlinux: CVE-2026-13892 was patched at 2026-07-03
altlinux: CVE-2026-13893 was patched at 2026-07-03
altlinux: CVE-2026-13894 was patched at 2026-07-03
altlinux: CVE-2026-13896 was patched at 2026-07-03
altlinux: CVE-2026-13900 was patched at 2026-07-03
altlinux: CVE-2026-13901 was patched at 2026-07-03
altlinux: CVE-2026-13903 was patched at 2026-07-03
altlinux: CVE-2026-13904 was patched at 2026-07-03
altlinux: CVE-2026-13908 was patched at 2026-07-03
altlinux: CVE-2026-13909 was patched at 2026-07-03
altlinux: CVE-2026-13910 was patched at 2026-07-03
altlinux: CVE-2026-13911 was patched at 2026-07-03
altlinux: CVE-2026-13913 was patched at 2026-07-03
altlinux: CVE-2026-13917 was patched at 2026-07-03
altlinux: CVE-2026-13919 was patched at 2026-07-03
altlinux: CVE-2026-13920 was patched at 2026-07-03
altlinux: CVE-2026-13921 was patched at 2026-07-03
altlinux: CVE-2026-13922 was patched at 2026-07-03
altlinux: CVE-2026-13924 was patched at 2026-07-03
altlinux: CVE-2026-13926 was patched at 2026-07-03
altlinux: CVE-2026-13927 was patched at 2026-07-03
altlinux: CVE-2026-13928 was patched at 2026-07-03
altlinux: CVE-2026-13929 was patched at 2026-07-03
altlinux: CVE-2026-13930 was patched at 2026-07-03
altlinux: CVE-2026-13934 was patched at 2026-07-03
altlinux: CVE-2026-13935 was patched at 2026-07-03
altlinux: CVE-2026-13939 was patched at 2026-07-03
altlinux: CVE-2026-13942 was patched at 2026-07-03
altlinux: CVE-2026-13944 was patched at 2026-07-03
altlinux: CVE-2026-13945 was patched at 2026-07-03
altlinux: CVE-2026-13946 was patched at 2026-07-03
altlinux: CVE-2026-13948 was patched at 2026-07-03
altlinux: CVE-2026-13951 was patched at 2026-07-03
altlinux: CVE-2026-13952 was patched at 2026-07-03
altlinux: CVE-2026-13955 was patched at 2026-07-03
altlinux: CVE-2026-13959 was patched at 2026-07-03
altlinux: CVE-2026-13961 was patched at 2026-07-03
altlinux: CVE-2026-13962 was patched at 2026-07-03
altlinux: CVE-2026-13963 was patched at 2026-07-03
altlinux: CVE-2026-13974 was patched at 2026-07-03
altlinux: CVE-2026-13976 was patched at 2026-07-03
altlinux: CVE-2026-13978 was patched at 2026-07-03
altlinux: CVE-2026-13990 was patched at 2026-07-03
altlinux: CVE-2026-13991 was patched at 2026-07-03
altlinux: CVE-2026-13995 was patched at 2026-07-03
altlinux: CVE-2026-13999 was patched at 2026-07-03
altlinux: CVE-2026-14004 was patched at 2026-07-03
altlinux: CVE-2026-14007 was patched at 2026-07-03
altlinux: CVE-2026-14009 was patched at 2026-07-03
altlinux: CVE-2026-14015 was patched at 2026-07-03
altlinux: CVE-2026-14016 was patched at 2026-07-03
altlinux: CVE-2026-14017 was patched at 2026-07-03
altlinux: CVE-2026-14020 was patched at 2026-07-03
altlinux: CVE-2026-14021 was patched at 2026-07-03
altlinux: CVE-2026-14022 was patched at 2026-07-03
altlinux: CVE-2026-14023 was patched at 2026-07-03
altlinux: CVE-2026-14033 was patched at 2026-07-03
altlinux: CVE-2026-14036 was patched at 2026-07-03
altlinux: CVE-2026-14037 was patched at 2026-07-03
altlinux: CVE-2026-14038 was patched at 2026-07-03
altlinux: CVE-2026-14039 was patched at 2026-07-03
altlinux: CVE-2026-14041 was patched at 2026-07-03
altlinux: CVE-2026-14043 was patched at 2026-07-03
altlinux: CVE-2026-14044 was patched at 2026-07-03
altlinux: CVE-2026-14045 was patched at 2026-07-03
altlinux: CVE-2026-14046 was patched at 2026-07-03
altlinux: CVE-2026-14047 was patched at 2026-07-03
altlinux: CVE-2026-14050 was patched at 2026-07-03
altlinux: CVE-2026-14053 was patched at 2026-07-03
altlinux: CVE-2026-14054 was patched at 2026-07-03
altlinux: CVE-2026-14055 was patched at 2026-07-03
altlinux: CVE-2026-14056 was patched at 2026-07-03
altlinux: CVE-2026-14057 was patched at 2026-07-03
altlinux: CVE-2026-14058 was patched at 2026-07-03
altlinux: CVE-2026-14059 was patched at 2026-07-03
altlinux: CVE-2026-14060 was patched at 2026-07-03
altlinux: CVE-2026-14065 was patched at 2026-07-03
altlinux: CVE-2026-14066 was patched at 2026-07-03
altlinux: CVE-2026-14071 was patched at 2026-07-03
altlinux: CVE-2026-14073 was patched at 2026-07-03
altlinux: CVE-2026-14074 was patched at 2026-07-03
altlinux: CVE-2026-14075 was patched at 2026-07-03
altlinux: CVE-2026-14076 was patched at 2026-07-03
altlinux: CVE-2026-14078 was patched at 2026-07-03
altlinux: CVE-2026-14079 was patched at 2026-07-03
altlinux: CVE-2026-14080 was patched at 2026-07-03
altlinux: CVE-2026-14081 was patched at 2026-07-03
altlinux: CVE-2026-14082 was patched at 2026-07-03
altlinux: CVE-2026-14083 was patched at 2026-07-03
altlinux: CVE-2026-14084 was patched at 2026-07-03
altlinux: CVE-2026-14085 was patched at 2026-07-03
altlinux: CVE-2026-14087 was patched at 2026-07-03
altlinux: CVE-2026-14089 was patched at 2026-07-03
altlinux: CVE-2026-14090 was patched at 2026-07-03
altlinux: CVE-2026-14092 was patched at 2026-07-03
altlinux: CVE-2026-14093 was patched at 2026-07-03
altlinux: CVE-2026-14095 was patched at 2026-07-03
altlinux: CVE-2026-14096 was patched at 2026-07-03
altlinux: CVE-2026-14097 was patched at 2026-07-03
altlinux: CVE-2026-14098 was patched at 2026-07-03
altlinux: CVE-2026-14100 was patched at 2026-07-03
altlinux: CVE-2026-14101 was patched at 2026-07-03
altlinux: CVE-2026-14105 was patched at 2026-07-03
altlinux: CVE-2026-14106 was patched at 2026-07-03
altlinux: CVE-2026-14109 was patched at 2026-07-03
altlinux: CVE-2026-14113 was patched at 2026-07-03
altlinux: CVE-2026-14115 was patched at 2026-07-03
altlinux: CVE-2026-14116 was patched at 2026-07-03
altlinux: CVE-2026-14117 was patched at 2026-07-03
altlinux: CVE-2026-14120 was patched at 2026-07-03
altlinux: CVE-2026-14122 was patched at 2026-07-03
altlinux: CVE-2026-14127 was patched at 2026-07-03
altlinux: CVE-2026-14130 was patched at 2026-07-03
altlinux: CVE-2026-14131 was patched at 2026-07-03
altlinux: CVE-2026-14135 was patched at 2026-07-03
altlinux: CVE-2026-14136 was patched at 2026-07-03
altlinux: CVE-2026-14137 was patched at 2026-07-03
altlinux: CVE-2026-14140 was patched at 2026-07-03
altlinux: CVE-2026-14146 was patched at 2026-07-03
altlinux: CVE-2026-14150 was patched at 2026-07-03
altlinux: CVE-2026-14151 was patched at 2026-07-03
altlinux: CVE-2026-14152 was patched at 2026-07-03
altlinux: CVE-2026-14382 was patched at 2026-07-03
altlinux: CVE-2026-14384 was patched at 2026-07-03
altlinux: CVE-2026-14387 was patched at 2026-07-03
altlinux: CVE-2026-14389 was patched at 2026-07-03
altlinux: CVE-2026-14390 was patched at 2026-07-03
altlinux: CVE-2026-14396 was patched at 2026-07-03
altlinux: CVE-2026-14398 was patched at 2026-07-03
altlinux: CVE-2026-14401 was patched at 2026-07-03
altlinux: CVE-2026-14411 was patched at 2026-07-03
altlinux: CVE-2026-14412 was patched at 2026-07-03
altlinux: CVE-2026-14413 was patched at 2026-07-03
altlinux: CVE-2026-14414 was patched at 2026-07-03
altlinux: CVE-2026-14416 was patched at 2026-07-03
altlinux: CVE-2026-14417 was patched at 2026-07-03
altlinux: CVE-2026-14418 was patched at 2026-07-03
altlinux: CVE-2026-14419 was patched at 2026-07-03
altlinux: CVE-2026-14420 was patched at 2026-07-03
altlinux: CVE-2026-14423 was patched at 2026-07-03
altlinux: CVE-2026-14424 was patched at 2026-07-03
altlinux: CVE-2026-14425 was patched at 2026-07-03
altlinux: CVE-2026-14427 was patched at 2026-07-03
altlinux: CVE-2026-14428 was patched at 2026-07-03
altlinux: CVE-2026-14429 was patched at 2026-07-03
altlinux: CVE-2026-15113 was patched at 2026-07-09
altlinux: CVE-2026-15115 was patched at 2026-07-09
altlinux: CVE-2026-15119 was patched at 2026-07-09
altlinux: CVE-2026-15120 was patched at 2026-07-09
altlinux: CVE-2026-15122 was patched at 2026-07-09
altlinux: CVE-2026-15124 was patched at 2026-07-09
altlinux: CVE-2026-15130 was patched at 2026-07-09
altlinux: CVE-2026-15131 was patched at 2026-07-09
altlinux: CVE-2026-15768 was patched at 2026-07-15
altlinux: CVE-2026-15769 was patched at 2026-07-15
altlinux: CVE-2026-15771 was patched at 2026-07-15
altlinux: CVE-2026-15772 was patched at 2026-07-15
altlinux: CVE-2026-15773 was patched at 2026-07-15
altlinux: CVE-2026-15774 was patched at 2026-07-15
altlinux: CVE-2026-15775 was patched at 2026-07-15
altlinux: CVE-2026-15778 was patched at 2026-07-15
altlinux: CVE-2026-15899 was patched at 2026-07-18
altlinux: CVE-2026-15900 was patched at 2026-07-18
debian: CVE-2026-13021 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13022 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13024 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13025 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13028 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13032 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13034 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13281 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13775 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13776 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13777 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13780 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13781 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13782 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13785 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13789 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13790 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13792 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13793 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13795 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13796 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13797 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13798 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13801 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13803 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13804 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13806 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13808 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13809 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13812 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13813 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13816 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13817 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13820 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13822 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13823 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13824 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13826 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13829 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13832 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13833 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13834 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13838 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13839 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13840 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13841 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13843 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13846 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13847 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13849 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13851 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13852 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13853 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13854 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13856 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13859 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13861 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13862 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13863 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13865 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13866 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13868 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13869 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13871 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13872 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13875 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13876 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13877 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13878 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13880 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13881 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13882 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13883 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13886 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13887 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13889 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13891 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13892 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13893 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13894 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13896 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13900 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13901 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13903 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13904 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13908 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13909 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13910 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13911 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13913 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13917 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13919 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13920 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13921 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13922 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13924 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13926 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13927 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13928 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13929 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13930 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13934 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13935 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13939 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13942 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13944 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13945 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13946 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13948 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13951 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13952 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13955 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13959 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13961 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13962 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13963 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13974 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13976 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13978 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13990 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13991 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13995 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13999 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14004 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14007 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14009 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14015 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14016 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14017 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14020 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14021 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14022 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14023 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14033 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14036 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14037 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14038 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14039 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14041 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14043 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14044 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14045 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14046 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14047 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14050 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14053 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14054 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14055 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14056 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14057 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14058 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14059 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14060 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14065 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14066 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14071 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14073 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14074 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14075 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14076 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14078 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14079 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14080 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14081 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14082 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14083 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14084 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14085 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14087 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14089 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14090 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14092 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14093 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14095 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14096 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14097 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14098 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14100 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14101 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14105 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14106 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14109 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14113 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14115 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14116 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14117 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14120 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14122 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14127 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14130 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14131 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14135 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14136 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14137 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14140 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14146 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14150 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14151 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14152 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14382 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14384 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14387 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14389 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14390 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14396 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14398 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14401 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14411 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14412 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14413 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14414 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14416 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14417 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14418 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14419 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14420 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14423 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14424 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14425 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14427 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14428 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14429 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-15113 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15115 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15119 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15120 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15122 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15124 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15130 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15131 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15768 was patched at 2026-07-14, 2026-07-16
debian: CVE-2026-15769 was patched at 2026-07-14, 2026-07-16
debian: CVE-2026-15771 was patched at 2026-07-14, 2026-07-16
debian: CVE-2026-15772 was patched at 2026-07-14, 2026-07-16
debian: CVE-2026-15773 was patched at 2026-07-14, 2026-07-16
debian: CVE-2026-15774 was patched at 2026-07-14, 2026-07-16
debian: CVE-2026-15775 was patched at 2026-07-14, 2026-07-16
debian: CVE-2026-15778 was patched at 2026-07-14, 2026-07-16
debian: CVE-2026-15899 was patched at 2026-07-14, 2026-07-22
debian: CVE-2026-15900 was patched at 2026-07-14, 2026-07-22
almalinux: CVE-2026-43725 was patched at 2026-07-20
debian: CVE-2026-43725 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43725 was patched at 2026-07-20
redhat: CVE-2026-43725 was patched at 2026-07-20
altlinux: CVE-2026-53492 was patched at 2026-06-19, 2026-07-14, 2026-07-15
ubuntu: CVE-2026-53492 was patched at 2026-07-30
debian: CVE-2026-50168 was patched at 2026-06-24
redos: CVE-2026-26143 was patched at 2026-07-09
redos: CVE-2026-28377 was patched at 2026-06-25
debian: CVE-2026-49432 was patched at 2026-07-14
debian: CVE-2026-49434 was patched at 2026-07-14
altlinux: CVE-2026-11800 was patched at 2026-06-28, 2026-07-01, 2026-07-02
debian: CVE-2026-59999 was patched at 2026-07-14
ubuntu: CVE-2026-59999 was patched at 2026-07-30
almalinux: CVE-2026-54513 was patched at 2026-07-16, 2026-07-22
debian: CVE-2026-54513 was patched at 2026-07-14
oraclelinux: CVE-2026-54513 was patched at 2026-07-20, 2026-07-23
redhat: CVE-2026-54513 was patched at 2026-07-16, 2026-07-22, 2026-07-23
debian: CVE-2026-11625 was patched at 2026-07-14
debian: CVE-2026-13082 was patched at 2026-07-14
debian: CVE-2026-13577 was patched at 2026-07-14
debian: CVE-2026-14570 was patched at 2026-07-14
debian: CVE-2026-55961 was patched at 2026-07-14
debian: CVE-2026-55964 was patched at 2026-07-14
debian: CVE-2026-6091 was patched at 2026-07-14
debian: CVE-2026-6331 was patched at 2026-07-14
altlinux: CVE-2022-29257 was patched at 2026-06-20
altlinux: CVE-2026-49475 was patched at 2026-06-24, 2026-06-26, 2026-07-16
altlinux: CVE-2026-49840 was patched at 2026-06-24, 2026-06-26, 2026-07-16
almalinux: CVE-2026-6734 was patched at 2026-07-06, 2026-07-15
almalinux: CVE-2026-9697 was patched at 2026-07-06, 2026-07-15
debian: CVE-2026-6734 was patched at 2026-06-24
debian: CVE-2026-9697 was patched at 2026-06-24
oraclelinux: CVE-2026-6734 was patched at 2026-07-07, 2026-07-20
oraclelinux: CVE-2026-9697 was patched at 2026-07-07, 2026-07-20
redhat: CVE-2026-6734 was patched at 2026-07-06, 2026-07-15
redhat: CVE-2026-9697 was patched at 2026-07-06, 2026-07-15
debian: CVE-2026-54919 was patched at 2026-07-14
altlinux: CVE-2026-53488 was patched at 2026-06-19, 2026-07-14, 2026-07-15
debian: CVE-2026-53488 was patched at 2026-06-24
ubuntu: CVE-2026-53488 was patched at 2026-07-30
altlinux: CVE-2026-59818 was patched at 2026-07-10, 2026-07-13
debian: CVE-2026-59818 was patched at 2026-07-14
altlinux: CVE-2026-12246 was patched at 2026-06-26, 2026-06-29
ubuntu: CVE-2026-12246 was patched at 2026-07-30
redos: CVE-2025-12765 was patched at 2026-06-23
debian: CVE-2026-46611 was patched at 2026-07-14
debian: CVE-2026-49981 was patched at 2026-07-14
debian: CVE-2026-54911 was patched at 2026-06-24
debian: CVE-2026-55960 was patched at 2026-07-14
debian: CVE-2026-6092 was patched at 2026-07-14
debian: CVE-2026-6329 was patched at 2026-07-14
debian: CVE-2026-6330 was patched at 2026-07-14
debian: CVE-2026-6412 was patched at 2026-07-14
debian: CVE-2026-64121 was patched at 2026-07-14
debian: CVE-2026-64123 was patched at 2026-07-14
debian: CVE-2026-64125 was patched at 2026-07-14
debian: CVE-2026-64126 was patched at 2026-07-14
debian: CVE-2026-64127 was patched at 2026-07-14
debian: CVE-2026-64128 was patched at 2026-07-14
debian: CVE-2026-6450 was patched at 2026-07-14
debian: CVE-2026-6731 was patched at 2026-07-14
debian: CVE-2026-7511 was patched at 2026-07-14
debian: CVE-2026-7532 was patched at 2026-07-14
ubuntu: CVE-2026-64121 was patched at 2026-07-30
ubuntu: CVE-2026-64123 was patched at 2026-07-30
ubuntu: CVE-2026-64125 was patched at 2026-07-30
ubuntu: CVE-2026-64126 was patched at 2026-07-30
ubuntu: CVE-2026-64127 was patched at 2026-07-30
ubuntu: CVE-2026-64128 was patched at 2026-07-30
debian: CVE-2026-4360 was patched at 2026-07-14
debian: CVE-2026-49834 was patched at 2026-07-14
debian: CVE-2026-8720 was patched at 2026-07-14
debian: CVE-2026-6790 was patched at 2026-07-14
altlinux: CVE-2026-44978 was patched at 2026-07-08
debian: CVE-2026-44978 was patched at 2026-07-14
debian: CVE-2026-49284 was patched at 2026-07-14
debian: CVE-2026-64155 was patched at 2026-07-14
ubuntu: CVE-2026-64155 was patched at 2026-07-30
debian: CVE-2026-55568 was patched at 2026-06-24
debian: CVE-2026-55767 was patched at 2026-06-24
debian: CVE-2026-59883 was patched at 2026-07-14
almalinux: CVE-2026-48934 was patched at 2026-07-06, 2026-07-15, 2026-07-20
altlinux: CVE-2026-48934 was patched at 2026-07-23
debian: CVE-2026-48934 was patched at 2026-06-24
oraclelinux: CVE-2026-48934 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-48934 was patched at 2026-07-06, 2026-07-15, 2026-07-20
debian: CVE-2026-33612 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-38974 was patched at 2026-07-14
debian: CVE-2026-42387 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-42388 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-42390 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-47085 was patched at 2026-07-14
debian: CVE-2026-54387 was patched at 2026-06-24
debian: CVE-2026-54388 was patched at 2026-06-24
debian: CVE-2026-54423 was patched at 2026-07-14
debian: CVE-2026-54431 was patched at 2026-07-14
debian: CVE-2026-55223 was patched at 2026-07-14
debian: CVE-2026-58302 was patched at 2026-07-14
debian: CVE-2026-58494 was patched at 2026-07-14
debian: CVE-2026-54891 was patched at 2026-07-14
altlinux: CVE-2026-40079 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-40079 was patched at 2026-07-14
debian: CVE-2026-13501 was patched at 2026-07-14
debian: CVE-2026-47240 was patched at 2026-07-14
debian: CVE-2026-47242 was patched at 2026-07-14
debian: CVE-2026-60102 was patched at 2026-07-14
altlinux: CVE-2026-55895 was patched at 2026-06-30, 2026-07-06
altlinux: CVE-2026-57456 was patched at 2026-06-30, 2026-07-06
altlinux: CVE-2026-59858 was patched at 2026-06-30, 2026-07-06
debian: CVE-2026-55895 was patched at 2026-07-14
debian: CVE-2026-57456 was patched at 2026-07-14
debian: CVE-2026-59858 was patched at 2026-07-14
redhat: CVE-2026-57456 was patched at 2026-07-29
redhat: CVE-2026-59858 was patched at 2026-07-29
ubuntu: CVE-2026-55895 was patched at 2026-07-30
ubuntu: CVE-2026-57456 was patched at 2026-07-30
ubuntu: CVE-2026-59858 was patched at 2026-07-30
altlinux: CVE-2026-39893 was patched at 2026-07-25, 2026-07-29
altlinux: CVE-2026-39948 was patched at 2026-07-25, 2026-07-29
altlinux: CVE-2026-39951 was patched at 2026-07-25, 2026-07-29
altlinux: CVE-2026-39955 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-39893 was patched at 2026-07-14
debian: CVE-2026-39948 was patched at 2026-07-14
debian: CVE-2026-39951 was patched at 2026-07-14
debian: CVE-2026-39955 was patched at 2026-07-14
altlinux: CVE-2026-41889 was patched at 2026-07-08, 2026-07-14, 2026-07-15
redos: CVE-2025-12764 was patched at 2026-06-23
debian: CVE-2026-53511 was patched at 2026-07-14
debian: CVE-2026-39178 was patched at 2026-07-14
debian: CVE-2026-39179 was patched at 2026-07-14
debian: CVE-2025-61018 was patched at 2026-07-14
debian: CVE-2025-61019 was patched at 2026-07-14
debian: CVE-2025-61020 was patched at 2026-07-14
debian: CVE-2025-61021 was patched at 2026-07-14
debian: CVE-2025-61022 was patched at 2026-07-14
debian: CVE-2025-61023 was patched at 2026-07-14
debian: CVE-2025-61024 was patched at 2026-07-14
debian: CVE-2025-61025 was patched at 2026-07-14
debian: CVE-2025-61027 was patched at 2026-07-14
debian: CVE-2025-61028 was patched at 2026-07-14
debian: CVE-2025-61029 was patched at 2026-07-14
debian: CVE-2026-13500 was patched at 2026-07-14
debian: CVE-2026-50169 was patched at 2026-06-24
debian: CVE-2026-50170 was patched at 2026-06-24
debian: CVE-2026-50184 was patched at 2026-06-24
debian: CVE-2026-54264 was patched at 2026-06-24
altlinux: CVE-2022-21718 was patched at 2026-06-20
altlinux: CVE-2022-29247 was patched at 2026-06-20
almalinux: CVE-2026-43732 was patched at 2026-07-20
debian: CVE-2026-43732 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43732 was patched at 2026-07-20
redhat: CVE-2026-43732 was patched at 2026-07-20
altlinux: CVE-2026-13810 was patched at 2026-07-03
altlinux: CVE-2026-14012 was patched at 2026-07-03
altlinux: CVE-2026-14049 was patched at 2026-07-03
altlinux: CVE-2026-14062 was patched at 2026-07-03
altlinux: CVE-2026-14112 was patched at 2026-07-03
debian: CVE-2026-13810 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14012 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14049 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14062 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14112 was patched at 2026-07-05, 2026-07-14
altlinux: CVE-2026-9083 was patched at 2026-06-28, 2026-07-01, 2026-07-02
altlinux: CVE-2026-9705 was patched at 2026-06-28, 2026-07-01, 2026-07-02
almalinux: CVE-2026-57231 was patched at 2026-07-09, 2026-07-13
altlinux: CVE-2026-57231 was patched at 2026-07-28
debian: CVE-2026-57231 was patched at 2026-07-14
oraclelinux: CVE-2026-57231 was patched at 2026-07-10, 2026-07-15, 2026-07-23
redhat: CVE-2026-57231 was patched at 2026-07-09, 2026-07-13
debian: CVE-2026-49853 was patched at 2026-07-14
altlinux: CVE-2026-41521 was patched at 2026-07-08
altlinux: CVE-2026-42218 was patched at 2026-07-08
debian: CVE-2026-41521 was patched at 2026-07-14
debian: CVE-2026-42218 was patched at 2026-07-14
debian: CVE-2026-58024 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-58026 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-58033 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13595 was patched at 2026-07-14
altlinux: CVE-2026-50019 was patched at 2026-07-27
debian: CVE-2026-50019 was patched at 2026-07-14
debian: CVE-2026-50813 was patched at 2026-07-14
ubuntu: CVE-2026-50813 was patched at 2026-07-30
debian: CVE-2026-58027 was patched at 2026-07-05, 2026-07-14
altlinux: CVE-2026-53467 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-53467 was patched at 2026-07-07, 2026-07-14
debian: CVE-2026-61862 was patched at 2026-07-14
altlinux: CVE-2026-46815 was patched at 2026-06-29
altlinux: CVE-2026-46816 was patched at 2026-06-29
altlinux: CVE-2026-46874 was patched at 2026-06-29
altlinux: CVE-2026-46977 was patched at 2026-06-29
debian: CVE-2026-12480 was patched at 2026-07-14
debian: CVE-2026-52584 was patched at 2026-07-14
debian: CVE-2026-56210 was patched at 2026-06-24
debian: CVE-2026-59180 was patched at 2026-07-14
debian: CVE-2026-8804 was patched at 2026-07-14
almalinux: CVE-2026-11610 was patched at 2026-07-07
debian: CVE-2026-11610 was patched at 2026-07-14
debian: CVE-2026-14612 was patched at 2026-07-14
oraclelinux: CVE-2026-11610 was patched at 2026-07-07, 2026-07-08, 2026-07-16
redhat: CVE-2026-11610 was patched at 2026-07-07, 2026-07-08
altlinux: CVE-2026-52946 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-07, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-52948 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53169 was patched at 2026-06-19
altlinux: CVE-2026-53181 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53250 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53274 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53337 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-52946 was patched at 2026-07-14
debian: CVE-2026-52948 was patched at 2026-07-14
debian: CVE-2026-53181 was patched at 2026-07-14
debian: CVE-2026-53250 was patched at 2026-07-14
debian: CVE-2026-53274 was patched at 2026-07-14
debian: CVE-2026-53337 was patched at 2026-07-14
debian: CVE-2026-63806 was patched at 2026-07-14
debian: CVE-2026-50171 was patched at 2026-06-24
debian: CVE-2026-54268 was patched at 2026-06-24
almalinux: CVE-2026-48619 was patched at 2026-07-06, 2026-07-15, 2026-07-20
almalinux: CVE-2026-48933 was patched at 2026-07-06, 2026-07-15, 2026-07-20
altlinux: CVE-2026-48619 was patched at 2026-07-23
altlinux: CVE-2026-48933 was patched at 2026-07-23
altlinux: CVE-2026-48937 was patched at 2026-07-23
debian: CVE-2026-48619 was patched at 2026-06-24
debian: CVE-2026-48933 was patched at 2026-06-24
debian: CVE-2026-48937 was patched at 2026-06-24
oraclelinux: CVE-2026-48619 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
oraclelinux: CVE-2026-48933 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-48619 was patched at 2026-07-06, 2026-07-15, 2026-07-20
redhat: CVE-2026-48933 was patched at 2026-07-06, 2026-07-15, 2026-07-20
debian: CVE-2026-60000 was patched at 2026-07-14
debian: CVE-2026-60001 was patched at 2026-07-14
ubuntu: CVE-2026-60000 was patched at 2026-07-30
ubuntu: CVE-2026-60001 was patched at 2026-07-30
debian: CVE-2026-44452 was patched at 2026-07-14
debian: CVE-2026-54340 was patched at 2026-07-14
debian: CVE-2026-50734 was patched at 2026-07-14
debian: CVE-2026-50750 was patched at 2026-07-14
debian: CVE-2026-53916 was patched at 2026-07-14
debian: CVE-2026-53917 was patched at 2026-07-14
redos: CVE-2026-27878 was patched at 2026-06-26
redos: CVE-2026-28376 was patched at 2026-07-07
debian: CVE-2026-59173 was patched at 2026-07-14
altlinux: CVE-2026-46863 was patched at 2026-06-30
ubuntu: CVE-2026-46863 was patched at 2026-07-30
debian: CVE-2026-12706 was patched at 2026-06-24
debian: CVE-2026-44453 was patched at 2026-07-14
debian: CVE-2026-55213 was patched at 2026-07-14
altlinux: CVE-2026-20213 was patched at 2026-07-03, 2026-07-15
altlinux: CVE-2026-20214 was patched at 2026-07-03, 2026-07-15
altlinux: CVE-2026-20215 was patched at 2026-07-03, 2026-07-15
altlinux: CVE-2026-20216 was patched at 2026-07-03, 2026-07-15
altlinux: CVE-2026-20217 was patched at 2026-07-03, 2026-07-15
altlinux: CVE-2026-20243 was patched at 2026-07-03, 2026-07-15
altlinux: CVE-2026-20244 was patched at 2026-07-03, 2026-07-15
debian: CVE-2026-20213 was patched at 2026-07-14
debian: CVE-2026-20214 was patched at 2026-07-14
debian: CVE-2026-20215 was patched at 2026-07-14
debian: CVE-2026-20216 was patched at 2026-07-14
debian: CVE-2026-20217 was patched at 2026-07-14
debian: CVE-2026-20243 was patched at 2026-07-14
debian: CVE-2026-20244 was patched at 2026-07-14
ubuntu: CVE-2026-20213 was patched at 2026-07-30
ubuntu: CVE-2026-20214 was patched at 2026-07-30
ubuntu: CVE-2026-20215 was patched at 2026-07-30
ubuntu: CVE-2026-20216 was patched at 2026-07-30
ubuntu: CVE-2026-20217 was patched at 2026-07-30
ubuntu: CVE-2026-20243 was patched at 2026-07-30
ubuntu: CVE-2026-20244 was patched at 2026-07-30
debian: CVE-2026-13401 was patched at 2026-07-14
debian: CVE-2026-13705 was patched at 2026-07-14
debian: CVE-2026-13713 was patched at 2026-07-14
debian: CVE-2026-14741 was patched at 2026-07-14
debian: CVE-2026-14803 was patched at 2026-07-14
debian: CVE-2026-14895 was patched at 2026-07-14
debian: CVE-2026-49146 was patched at 2026-07-14
debian: CVE-2026-56017 was patched at 2026-07-14
debian: CVE-2026-56018 was patched at 2026-07-14
debian: CVE-2026-60081 was patched at 2026-07-14
ubuntu: CVE-2026-14741 was patched at 2026-07-30
almalinux: CVE-2026-15308 was patched at 2026-07-14, 2026-07-15, 2026-07-16, 2026-07-20
debian: CVE-2026-15308 was patched at 2026-07-30
debian: CVE-2026-47183 was patched at 2026-07-14
debian: CVE-2026-47184 was patched at 2026-07-14
debian: CVE-2026-48045 was patched at 2026-07-14
debian: CVE-2026-49851 was patched at 2026-07-14
debian: CVE-2026-57585 was patched at 2026-07-14
oraclelinux: CVE-2026-15308 was patched at 2026-07-15, 2026-07-16, 2026-07-21
redhat: CVE-2026-15308 was patched at 2026-07-14, 2026-07-15, 2026-07-20
debian: CVE-2026-58101 was patched at 2026-07-14
altlinux: CVE-2025-15661 was patched at 2026-07-09, 2026-07-14
debian: CVE-2025-15661 was patched at 2026-06-24, 2026-06-25
ubuntu: CVE-2025-15661 was patched at 2026-07-30
redos: CVE-2026-21728 was patched at 2026-06-26
almalinux: CVE-2026-12151 was patched at 2026-07-06, 2026-07-15, 2026-07-20
debian: CVE-2026-12151 was patched at 2026-06-24
oraclelinux: CVE-2026-12151 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-12151 was patched at 2026-07-06, 2026-07-15, 2026-07-20
debian: CVE-2026-47736 was patched at 2026-07-14
altlinux: CVE-2026-57451 was patched at 2026-06-30, 2026-07-06
altlinux: CVE-2026-57454 was patched at 2026-06-30, 2026-07-06
debian: CVE-2026-57451 was patched at 2026-07-14
altlinux: CVE-2026-49842 was patched at 2026-06-24, 2026-06-26, 2026-07-16
debian: CVE-2026-55204 was patched at 2026-06-24
ubuntu: CVE-2026-55204 was patched at 2026-07-30
debian: CVE-2026-54399 was patched at 2026-07-14
debian: CVE-2026-54428 was patched at 2026-07-14
altlinux: CVE-2026-58210 was patched at 2026-07-10, 2026-07-13, 2026-07-14
debian: CVE-2026-58210 was patched at 2026-07-14
debian: CVE-2026-49835 was patched at 2026-07-14
debian: CVE-2026-14164 was patched at 2026-07-14
ubuntu: CVE-2026-14164 was patched at 2026-07-30
debian: CVE-2026-49461 was patched at 2026-06-24
debian: CVE-2026-54530 was patched at 2026-06-24
debian: CVE-2026-54531 was patched at 2026-06-24
debian: CVE-2026-54651 was patched at 2026-06-24
debian: CVE-2026-57204 was patched at 2026-07-14
debian: CVE-2026-59935 was patched at 2026-07-14
debian: CVE-2026-59936 was patched at 2026-07-14
debian: CVE-2026-59937 was patched at 2026-07-14
debian: CVE-2026-59938 was patched at 2026-07-14
redos: CVE-2026-49461 was patched at 2026-07-29
redos: CVE-2026-54530 was patched at 2026-07-29
redos: CVE-2026-54531 was patched at 2026-07-29
debian: CVE-2026-54283 was patched at 2026-06-24
altlinux: CVE-2026-54538 was patched at 2026-07-08
altlinux: CVE-2026-55238 was patched at 2026-07-08
altlinux: CVE-2026-55645 was patched at 2026-07-08
debian: CVE-2026-54538 was patched at 2026-07-14
debian: CVE-2026-55238 was patched at 2026-07-14
debian: CVE-2026-55645 was patched at 2026-07-14
debian: CVE-2026-13708 was patched at 2026-07-14
altlinux: CVE-2026-59884 was patched at 2026-07-10, 2026-07-13
altlinux: CVE-2026-59885 was patched at 2026-07-10, 2026-07-13
altlinux: CVE-2026-59886 was patched at 2026-07-10, 2026-07-13
debian: CVE-2026-59884 was patched at 2026-07-14
debian: CVE-2026-59885 was patched at 2026-07-14
debian: CVE-2026-59886 was patched at 2026-07-14
debian: CVE-2026-55958 was patched at 2026-07-14
altlinux: CVE-2026-47262 was patched at 2026-06-19, 2026-07-14, 2026-07-15
debian: CVE-2026-47262 was patched at 2026-06-24
ubuntu: CVE-2026-47262 was patched at 2026-07-30
altlinux: CVE-2026-55594 was patched at 2026-07-11, 2026-07-15, 2026-07-16
altlinux: CVE-2026-55595 was patched at 2026-07-11, 2026-07-15, 2026-07-16
altlinux: CVE-2026-61465 was patched at 2026-07-11, 2026-07-15, 2026-07-16
altlinux: CVE-2026-61870 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-55594 was patched at 2026-07-07, 2026-07-14
debian: CVE-2026-55595 was patched at 2026-07-07, 2026-07-14
debian: CVE-2026-56375 was patched at 2026-07-14
debian: CVE-2026-61464 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-61465 was patched at 2026-07-14
debian: CVE-2026-61860 was patched at 2026-07-14
debian: CVE-2026-61867 was patched at 2026-07-14
debian: CVE-2026-61868 was patched at 2026-07-14
debian: CVE-2026-61869 was patched at 2026-07-14
debian: CVE-2026-61870 was patched at 2026-07-14
debian: CVE-2026-61871 was patched at 2026-07-14
redos: CVE-2026-56375 was patched at 2026-07-28
altlinux: CVE-2026-62641 was patched at 2026-07-10, 2026-07-15
altlinux: CVE-2026-62642 was patched at 2026-07-10, 2026-07-15
debian: CVE-2026-62641 was patched at 2026-07-14, 2026-07-19
debian: CVE-2026-62642 was patched at 2026-07-14, 2026-07-19
altlinux: CVE-2026-15163 was patched at 2026-07-12, 2026-07-14, 2026-07-15
altlinux: CVE-2026-15173 was patched at 2026-07-12, 2026-07-14, 2026-07-15
altlinux: CVE-2026-15174 was patched at 2026-07-12, 2026-07-14, 2026-07-15
debian: CVE-2026-15163 was patched at 2026-07-14
debian: CVE-2026-15173 was patched at 2026-07-14
debian: CVE-2026-15174 was patched at 2026-07-14
debian: CVE-2026-40469 was patched at 2026-07-14
ubuntu: CVE-2026-40469 was patched at 2026-07-30
debian: CVE-2026-53994 was patched at 2026-07-14
debian: CVE-2026-53432 was patched at 2026-07-14
debian: CVE-2026-53433 was patched at 2026-07-14
redos: CVE-2026-33378 was patched at 2026-07-08
debian: CVE-2026-13122 was patched at 2026-07-03, 2026-07-14
debian: CVE-2026-13698 was patched at 2026-07-03, 2026-07-14
ubuntu: CVE-2026-13122 was patched at 2026-07-30
ubuntu: CVE-2026-13698 was patched at 2026-07-30
altlinux: CVE-2026-14110 was patched at 2026-07-03
altlinux: CVE-2026-14142 was patched at 2026-07-03
debian: CVE-2026-14110 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14142 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-38752 was patched at 2026-07-14
debian: CVE-2026-38753 was patched at 2026-07-14
debian: CVE-2026-38754 was patched at 2026-07-14
debian: CVE-2026-38755 was patched at 2026-07-14
debian: CVE-2026-50812 was patched at 2026-07-14
ubuntu: CVE-2026-50812 was patched at 2026-07-30
debian: CVE-2026-14258 was patched at 2026-07-14
debian: CVE-2026-56113 was patched at 2026-06-24
debian: CVE-2026-56116 was patched at 2026-06-24
debian: CVE-2026-42546 was patched at 2026-07-14
almalinux: CVE-2026-35406 was patched at 2026-07-07, 2026-07-08
oraclelinux: CVE-2026-35406 was patched at 2026-07-07, 2026-07-16
redhat: CVE-2026-35406 was patched at 2026-07-07
debian: CVE-2026-54592 was patched at 2026-07-14
debian: CVE-2026-54886 was patched at 2026-07-14
debian: CVE-2026-54887 was patched at 2026-07-14
debian: CVE-2026-55950 was patched at 2026-07-14
debian: CVE-2026-14940 was patched at 2026-07-14
debian: CVE-2026-12932 was patched at 2026-07-03, 2026-07-14
debian: CVE-2026-12996 was patched at 2026-07-03, 2026-07-14
ubuntu: CVE-2026-12932 was patched at 2026-07-30
ubuntu: CVE-2026-12996 was patched at 2026-07-30
debian: CVE-2026-47714 was patched at 2026-07-14
ubuntu: CVE-2026-47714 was patched at 2026-07-30
debian: CVE-2026-56288 was patched at 2026-07-14
debian: CVE-2026-56289 was patched at 2026-07-14
altlinux: CVE-2026-57962 was patched at 2026-07-02
debian: CVE-2026-57962 was patched at 2026-07-14
debian: CVE-2026-57965 was patched at 2026-07-14, 2026-07-24
altlinux: CVE-2026-40209 was patched at 2026-06-29, 2026-06-30
altlinux: CVE-2026-40211 was patched at 2026-06-29, 2026-06-30
altlinux: CVE-2026-42005 was patched at 2026-06-29, 2026-06-30
altlinux: CVE-2026-59691 was patched at 2026-07-09
altlinux: CVE-2026-59692 was patched at 2026-07-09
debian: CVE-2026-11771 was patched at 2026-07-03, 2026-07-14
debian: CVE-2026-11946 was patched at 2026-07-14
debian: CVE-2026-13149 was patched at 2026-07-14
debian: CVE-2026-14330 was patched at 2026-07-14
debian: CVE-2026-14683 was patched at 2026-07-14
debian: CVE-2026-14684 was patched at 2026-07-14
debian: CVE-2026-33592 was patched at 2026-07-14
debian: CVE-2026-38076 was patched at 2026-07-14
debian: CVE-2026-39199 was patched at 2026-06-24
debian: CVE-2026-40209 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-40211 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-42005 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-44628 was patched at 2026-07-14
debian: CVE-2026-46378 was patched at 2026-07-14
debian: CVE-2026-48125 was patched at 2026-07-14
debian: CVE-2026-49337 was patched at 2026-06-24
debian: CVE-2026-51105 was patched at 2026-07-14
debian: CVE-2026-54463 was patched at 2026-07-14
debian: CVE-2026-54464 was patched at 2026-07-14
debian: CVE-2026-54465 was patched at 2026-07-14
debian: CVE-2026-54490 was patched at 2026-07-14
debian: CVE-2026-54908 was patched at 2026-07-14
debian: CVE-2026-56740 was patched at 2026-07-14
debian: CVE-2026-56741 was patched at 2026-07-14
debian: CVE-2026-56770 was patched at 2026-07-14
debian: CVE-2026-59691 was patched at 2026-07-14
debian: CVE-2026-59692 was patched at 2026-07-14
debian: CVE-2026-8484 was patched at 2026-06-24
debian: CVE-2026-9375 was patched at 2026-06-24
oraclelinux: CVE-2026-59691 was patched at 2026-07-28, 2026-07-29
oraclelinux: CVE-2026-59692 was patched at 2026-07-28, 2026-07-29
redhat: CVE-2026-13149 was patched at 2026-07-28
redhat: CVE-2026-59691 was patched at 2026-07-30
redhat: CVE-2026-59692 was patched at 2026-07-30
redos: CVE-2026-49337 was patched at 2026-07-14
ubuntu: CVE-2026-11771 was patched at 2026-07-30
ubuntu: CVE-2026-14330 was patched at 2026-07-30
ubuntu: CVE-2026-38076 was patched at 2026-07-30
ubuntu: CVE-2026-49337 was patched at 2026-07-30
debian: CVE-2026-50810 was patched at 2026-07-14
debian: CVE-2026-12892 was patched at 2026-07-14
debian: CVE-2026-48990 was patched at 2026-06-24
debian: CVE-2026-41434 was patched at 2026-07-14
debian: CVE-2026-54786 was patched at 2026-07-14
redos: CVE-2026-28737 was patched at 2026-07-14
debian: CVE-2026-50555 was patched at 2026-06-24
debian: CVE-2026-50556 was patched at 2026-06-24
debian: CVE-2026-50557 was patched at 2026-06-24
debian: CVE-2026-52725 was patched at 2026-06-24
debian: CVE-2026-54265 was patched at 2026-06-24
debian: CVE-2026-54267 was patched at 2026-06-24
altlinux: CVE-2026-54432 was patched at 2026-07-10, 2026-07-15
altlinux: CVE-2026-54433 was patched at 2026-07-10, 2026-07-15
debian: CVE-2026-54432 was patched at 2026-07-14, 2026-07-19
debian: CVE-2026-54433 was patched at 2026-07-14, 2026-07-19
debian: CVE-2026-52760 was patched at 2026-07-14
altlinux: CVE-2026-13836 was patched at 2026-07-03
altlinux: CVE-2026-13957 was patched at 2026-07-03
altlinux: CVE-2026-13977 was patched at 2026-07-03
altlinux: CVE-2026-14000 was patched at 2026-07-03
altlinux: CVE-2026-14001 was patched at 2026-07-03
altlinux: CVE-2026-14068 was patched at 2026-07-03
altlinux: CVE-2026-14145 was patched at 2026-07-03
altlinux: CVE-2026-14147 was patched at 2026-07-03
altlinux: CVE-2026-15127 was patched at 2026-07-09
altlinux: CVE-2026-15128 was patched at 2026-07-09
debian: CVE-2026-13836 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13957 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13977 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14000 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14001 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14068 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14145 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14147 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-15127 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15128 was patched at 2026-07-11, 2026-07-14
redhat: CVE-2025-12799 was patched at 2026-07-07
debian: CVE-2026-48822 was patched at 2026-06-24
debian: CVE-2026-58028 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-58032 was patched at 2026-07-05, 2026-07-14
altlinux: CVE-2026-57963 was patched at 2026-07-02
debian: CVE-2026-57963 was patched at 2026-07-14
altlinux: CVE-2026-40179 was patched at 2026-06-29, 2026-07-29
altlinux: CVE-2026-39897 was patched at 2026-07-25, 2026-07-29
altlinux: CVE-2026-39900 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-39897 was patched at 2026-07-14
debian: CVE-2026-39900 was patched at 2026-07-14
debian: CVE-2026-59926 was patched at 2026-07-14
redos: CVE-2026-9029 was patched at 2026-07-14
debian: CVE-2026-58030 was patched at 2026-07-05, 2026-07-14
altlinux: CVE-2026-26195 was patched at 2026-06-25
altlinux: CVE-2026-26276 was patched at 2026-06-25
altlinux: CVE-2026-58402 was patched at 2026-07-01
debian: CVE-2026-58402 was patched at 2026-07-14
debian: CVE-2026-57214 was patched at 2026-07-14
debian: CVE-2026-11998 was patched at 2026-07-14
debian: CVE-2026-48823 was patched at 2026-06-24
debian: CVE-2026-54163 was patched at 2026-07-14
debian: CVE-2026-6658 was patched at 2026-07-14
altlinux: CVE-2026-15718 was patched at 2026-07-15, 2026-07-30
debian: CVE-2026-15718 was patched at 2026-07-22, 2026-07-30
oraclelinux: CVE-2026-15718 was patched at 2026-07-28
redhat: CVE-2026-15718 was patched at 2026-07-28
altlinux: CVE-2026-52917 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-52924 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-52929 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-52935 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-52938 was patched at 2026-06-27
altlinux: CVE-2026-52939 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-52942 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-52947 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53135 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53136 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53137 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53138 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53142 was patched at 2026-06-19, 2026-06-22, 2026-07-04, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53144 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53145 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53147 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53148 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53149 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53152 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53156 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53157 was patched at 2026-06-19, 2026-06-22, 2026-07-04, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53158 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53160 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53161 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53163 was patched at 2026-06-19, 2026-06-22, 2026-07-04, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53165 was patched at 2026-06-19
altlinux: CVE-2026-53172 was patched at 2026-06-19
altlinux: CVE-2026-53173 was patched at 2026-06-19
altlinux: CVE-2026-53175 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53177 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53179 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53185 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53187 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53192 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53193 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53194 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53195 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53196 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53198 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53202 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53203 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53204 was patched at 2026-06-19
altlinux: CVE-2026-53205 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53209 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53212 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53213 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53214 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53216 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53220 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53222 was patched at 2026-06-19
altlinux: CVE-2026-53224 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53226 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53230 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53233 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53234 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53237 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53239 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53240 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53242 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53246 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53247 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53248 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53252 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53253 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53254 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53255 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53256 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53259 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53260 was patched at 2026-06-19
altlinux: CVE-2026-53268 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53271 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53272 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53273 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53275 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53276 was patched at 2026-06-19
altlinux: CVE-2026-53325 was patched at 2026-06-27, 2026-06-28, 2026-07-04, 2026-07-06, 2026-07-07, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53330 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53338 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53339 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53341 was patched at 2026-06-19, 2026-06-22, 2026-07-04, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53344 was patched at 2026-06-19
altlinux: CVE-2026-53345 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53346 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53348 was patched at 2026-06-19
altlinux: CVE-2026-53350 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53352 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53355 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
debian: CVE-2026-52917 was patched at 2026-07-14
debian: CVE-2026-52924 was patched at 2026-07-14
debian: CVE-2026-52929 was patched at 2026-07-14
debian: CVE-2026-52935 was patched at 2026-07-14
debian: CVE-2026-52939 was patched at 2026-07-14
debian: CVE-2026-52942 was patched at 2026-07-14
debian: CVE-2026-52947 was patched at 2026-07-14
debian: CVE-2026-53135 was patched at 2026-07-14
debian: CVE-2026-53136 was patched at 2026-07-14
debian: CVE-2026-53137 was patched at 2026-07-14
debian: CVE-2026-53138 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-53142 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-53144 was patched at 2026-07-14
debian: CVE-2026-53147 was patched at 2026-07-14
debian: CVE-2026-53148 was patched at 2026-07-14
debian: CVE-2026-53149 was patched at 2026-07-14
debian: CVE-2026-53152 was patched at 2026-07-14
debian: CVE-2026-53156 was patched at 2026-07-14
debian: CVE-2026-53157 was patched at 2026-07-05, 2026-07-14, 2026-07-30
debian: CVE-2026-53158 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-53160 was patched at 2026-07-14
debian: CVE-2026-53161 was patched at 2026-07-14
debian: CVE-2026-53163 was patched at 2026-07-05, 2026-07-14, 2026-07-30
debian: CVE-2026-53177 was patched at 2026-07-14
debian: CVE-2026-53179 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-53185 was patched at 2026-07-14
debian: CVE-2026-53192 was patched at 2026-07-14
debian: CVE-2026-53193 was patched at 2026-07-14
debian: CVE-2026-53194 was patched at 2026-07-14
debian: CVE-2026-53195 was patched at 2026-07-14
debian: CVE-2026-53196 was patched at 2026-07-14
debian: CVE-2026-53198 was patched at 2026-07-14
debian: CVE-2026-53202 was patched at 2026-07-14
debian: CVE-2026-53203 was patched at 2026-07-14
debian: CVE-2026-53205 was patched at 2026-07-14
debian: CVE-2026-53209 was patched at 2026-07-14
debian: CVE-2026-53212 was patched at 2026-07-14
debian: CVE-2026-53213 was patched at 2026-07-14
debian: CVE-2026-53214 was patched at 2026-07-14
debian: CVE-2026-53216 was patched at 2026-07-14
debian: CVE-2026-53220 was patched at 2026-07-14
debian: CVE-2026-53224 was patched at 2026-07-14
debian: CVE-2026-53226 was patched at 2026-07-14, 2026-07-21
debian: CVE-2026-53230 was patched at 2026-07-14
debian: CVE-2026-53233 was patched at 2026-07-14
debian: CVE-2026-53234 was patched at 2026-07-14
debian: CVE-2026-53237 was patched at 2026-07-14
debian: CVE-2026-53239 was patched at 2026-07-14
debian: CVE-2026-53242 was patched at 2026-07-14
debian: CVE-2026-53246 was patched at 2026-07-14
debian: CVE-2026-53247 was patched at 2026-07-14
debian: CVE-2026-53252 was patched at 2026-07-14
debian: CVE-2026-53253 was patched at 2026-07-14
debian: CVE-2026-53254 was patched at 2026-07-14
debian: CVE-2026-53255 was patched at 2026-07-14
debian: CVE-2026-53256 was patched at 2026-07-14
debian: CVE-2026-53260 was patched at 2026-07-14
debian: CVE-2026-53268 was patched at 2026-07-14
debian: CVE-2026-53271 was patched at 2026-07-14
debian: CVE-2026-53272 was patched at 2026-07-14
debian: CVE-2026-53273 was patched at 2026-07-14
debian: CVE-2026-53275 was patched at 2026-07-14
debian: CVE-2026-53325 was patched at 2026-07-05, 2026-07-14, 2026-07-30
debian: CVE-2026-53330 was patched at 2026-07-14
debian: CVE-2026-53339 was patched at 2026-07-14
debian: CVE-2026-53341 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-53345 was patched at 2026-07-14
debian: CVE-2026-53346 was patched at 2026-07-14
debian: CVE-2026-53350 was patched at 2026-07-14
debian: CVE-2026-53352 was patched at 2026-07-14
debian: CVE-2026-53355 was patched at 2026-07-14
debian: CVE-2026-53381 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-53382 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-53383 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-53384 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-53385 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-53388 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-53389 was patched at 2026-07-14
debian: CVE-2026-53390 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-53391 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-53392 was patched at 2026-07-14, 2026-07-21
debian: CVE-2026-53399 was patched at 2026-07-14, 2026-07-21
debian: CVE-2026-53400 was patched at 2026-07-14
debian: CVE-2026-53401 was patched at 2026-07-14
debian: CVE-2026-53402 was patched at 2026-07-14, 2026-07-21
debian: CVE-2026-53403 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63794 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63795 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63796 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63797 was patched at 2026-07-14
debian: CVE-2026-63798 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63800 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63801 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63802 was patched at 2026-07-14
debian: CVE-2026-63803 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63804 was patched at 2026-07-14
debian: CVE-2026-63807 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63808 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63810 was patched at 2026-07-14
debian: CVE-2026-63815 was patched at 2026-07-14, 2026-07-21
debian: CVE-2026-63821 was patched at 2026-07-14
debian: CVE-2026-63826 was patched at 2026-07-14
debian: CVE-2026-63827 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63831 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63876 was patched at 2026-07-14
debian: CVE-2026-63877 was patched at 2026-07-14
debian: CVE-2026-63882 was patched at 2026-07-14
debian: CVE-2026-63894 was patched at 2026-07-14
debian: CVE-2026-63898 was patched at 2026-07-14
debian: CVE-2026-63899 was patched at 2026-07-14
debian: CVE-2026-63901 was patched at 2026-07-14
debian: CVE-2026-63904 was patched at 2026-07-14
debian: CVE-2026-63905 was patched at 2026-07-14
debian: CVE-2026-63906 was patched at 2026-07-14
debian: CVE-2026-63915 was patched at 2026-07-14
debian: CVE-2026-63916 was patched at 2026-07-14
debian: CVE-2026-63918 was patched at 2026-07-14
debian: CVE-2026-63920 was patched at 2026-07-14
debian: CVE-2026-63928 was patched at 2026-07-14
debian: CVE-2026-63930 was patched at 2026-07-14
debian: CVE-2026-63942 was patched at 2026-07-14
debian: CVE-2026-63944 was patched at 2026-07-14
debian: CVE-2026-63945 was patched at 2026-07-14
debian: CVE-2026-63946 was patched at 2026-07-14
debian: CVE-2026-63947 was patched at 2026-07-14
debian: CVE-2026-63956 was patched at 2026-07-14
debian: CVE-2026-63957 was patched at 2026-07-14
debian: CVE-2026-63973 was patched at 2026-07-14
debian: CVE-2026-63991 was patched at 2026-07-14
debian: CVE-2026-64004 was patched at 2026-07-14
debian: CVE-2026-64010 was patched at 2026-07-14
debian: CVE-2026-64011 was patched at 2026-07-14
debian: CVE-2026-64014 was patched at 2026-07-14
debian: CVE-2026-64017 was patched at 2026-07-14
debian: CVE-2026-64025 was patched at 2026-07-14
debian: CVE-2026-64029 was patched at 2026-07-14
debian: CVE-2026-64032 was patched at 2026-07-14
debian: CVE-2026-64033 was patched at 2026-07-14
debian: CVE-2026-64061 was patched at 2026-07-14
debian: CVE-2026-64073 was patched at 2026-07-14
debian: CVE-2026-64096 was patched at 2026-07-14
debian: CVE-2026-64097 was patched at 2026-07-14
debian: CVE-2026-64099 was patched at 2026-07-14
debian: CVE-2026-64102 was patched at 2026-07-14
debian: CVE-2026-64103 was patched at 2026-07-14
debian: CVE-2026-64113 was patched at 2026-07-14
debian: CVE-2026-64115 was patched at 2026-07-14
debian: CVE-2026-64116 was patched at 2026-07-14
debian: CVE-2026-64117 was patched at 2026-07-14
debian: CVE-2026-64123 was patched at 2026-07-14
debian: CVE-2026-64126 was patched at 2026-07-14
debian: CVE-2026-64139 was patched at 2026-07-14
debian: CVE-2026-64141 was patched at 2026-07-14
debian: CVE-2026-64165 was patched at 2026-07-14
debian: CVE-2026-64183 was patched at 2026-07-14
debian: CVE-2026-64188 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-64189 was patched at 2026-07-14, 2026-07-21
debian: CVE-2026-64190 was patched at 2026-07-14
oraclelinux: CVE-2026-31688 was patched at 2026-07-02
redhat: CVE-2026-64017 was patched at 2026-07-28
redos: CVE-2023-53779 was patched at 2026-07-01
redos: CVE-2025-40144 was patched at 2026-06-29
ubuntu: CVE-2026-63876 was patched at 2026-07-30
ubuntu: CVE-2026-63877 was patched at 2026-07-30
ubuntu: CVE-2026-63882 was patched at 2026-07-30
ubuntu: CVE-2026-63894 was patched at 2026-07-30
ubuntu: CVE-2026-63898 was patched at 2026-07-30
ubuntu: CVE-2026-63899 was patched at 2026-07-30
ubuntu: CVE-2026-63901 was patched at 2026-07-30
ubuntu: CVE-2026-63904 was patched at 2026-07-30
ubuntu: CVE-2026-63905 was patched at 2026-07-30
ubuntu: CVE-2026-63906 was patched at 2026-07-30
ubuntu: CVE-2026-63915 was patched at 2026-07-30
ubuntu: CVE-2026-63916 was patched at 2026-07-30
ubuntu: CVE-2026-63918 was patched at 2026-07-30
ubuntu: CVE-2026-63920 was patched at 2026-07-30
ubuntu: CVE-2026-63928 was patched at 2026-07-30
ubuntu: CVE-2026-63930 was patched at 2026-07-30
ubuntu: CVE-2026-63942 was patched at 2026-07-30
ubuntu: CVE-2026-63944 was patched at 2026-07-30
ubuntu: CVE-2026-63945 was patched at 2026-07-30
ubuntu: CVE-2026-63946 was patched at 2026-07-30
ubuntu: CVE-2026-63947 was patched at 2026-07-30
ubuntu: CVE-2026-63956 was patched at 2026-07-30
ubuntu: CVE-2026-63957 was patched at 2026-07-30
ubuntu: CVE-2026-63973 was patched at 2026-07-30
ubuntu: CVE-2026-63991 was patched at 2026-07-30
ubuntu: CVE-2026-64004 was patched at 2026-07-30
ubuntu: CVE-2026-64010 was patched at 2026-07-30
ubuntu: CVE-2026-64011 was patched at 2026-07-30
ubuntu: CVE-2026-64014 was patched at 2026-07-30
ubuntu: CVE-2026-64017 was patched at 2026-07-30
ubuntu: CVE-2026-64025 was patched at 2026-07-30
ubuntu: CVE-2026-64029 was patched at 2026-07-30
ubuntu: CVE-2026-64032 was patched at 2026-07-30
ubuntu: CVE-2026-64033 was patched at 2026-07-30
ubuntu: CVE-2026-64061 was patched at 2026-07-30
ubuntu: CVE-2026-64073 was patched at 2026-07-30
ubuntu: CVE-2026-64096 was patched at 2026-07-30
ubuntu: CVE-2026-64097 was patched at 2026-07-30
ubuntu: CVE-2026-64099 was patched at 2026-07-30
ubuntu: CVE-2026-64102 was patched at 2026-07-30
ubuntu: CVE-2026-64103 was patched at 2026-07-30
ubuntu: CVE-2026-64113 was patched at 2026-07-30
ubuntu: CVE-2026-64115 was patched at 2026-07-30
ubuntu: CVE-2026-64116 was patched at 2026-07-30
ubuntu: CVE-2026-64117 was patched at 2026-07-30
ubuntu: CVE-2026-64123 was patched at 2026-07-30
ubuntu: CVE-2026-64126 was patched at 2026-07-30
ubuntu: CVE-2026-64139 was patched at 2026-07-30
ubuntu: CVE-2026-64141 was patched at 2026-07-30
ubuntu: CVE-2026-64165 was patched at 2026-07-30
ubuntu: CVE-2026-64183 was patched at 2026-07-30
almalinux: CVE-2026-39872 was patched at 2026-07-20
almalinux: CVE-2026-43663 was patched at 2026-07-20
almalinux: CVE-2026-43676 was patched at 2026-07-20
almalinux: CVE-2026-43699 was patched at 2026-07-20
almalinux: CVE-2026-43705 was patched at 2026-07-20
almalinux: CVE-2026-43707 was patched at 2026-07-20
almalinux: CVE-2026-43712 was patched at 2026-07-20
almalinux: CVE-2026-43715 was patched at 2026-07-20
almalinux: CVE-2026-43716 was patched at 2026-07-20
almalinux: CVE-2026-43720 was patched at 2026-07-20
almalinux: CVE-2026-43726 was patched at 2026-07-20
almalinux: CVE-2026-43727 was patched at 2026-07-20
almalinux: CVE-2026-43731 was patched at 2026-07-20
almalinux: CVE-2026-43734 was patched at 2026-07-20
almalinux: CVE-2026-43740 was patched at 2026-07-20
almalinux: CVE-2026-43742 was patched at 2026-07-20
almalinux: CVE-2026-43745 was patched at 2026-07-20
debian: CVE-2026-39872 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43663 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43676 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43699 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43705 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43707 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43712 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43715 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43716 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43720 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43726 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43727 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43731 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43734 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43740 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43742 was patched at 2026-07-14, 2026-07-23
debian: CVE-2026-43745 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-39872 was patched at 2026-07-20
oraclelinux: CVE-2026-43663 was patched at 2026-07-20
oraclelinux: CVE-2026-43676 was patched at 2026-07-20
oraclelinux: CVE-2026-43699 was patched at 2026-07-20
oraclelinux: CVE-2026-43705 was patched at 2026-07-20
oraclelinux: CVE-2026-43707 was patched at 2026-07-20
oraclelinux: CVE-2026-43712 was patched at 2026-07-20
oraclelinux: CVE-2026-43715 was patched at 2026-07-20
oraclelinux: CVE-2026-43716 was patched at 2026-07-20
oraclelinux: CVE-2026-43720 was patched at 2026-07-20
oraclelinux: CVE-2026-43726 was patched at 2026-07-20
oraclelinux: CVE-2026-43727 was patched at 2026-07-20
oraclelinux: CVE-2026-43731 was patched at 2026-07-20
oraclelinux: CVE-2026-43734 was patched at 2026-07-20
oraclelinux: CVE-2026-43740 was patched at 2026-07-20
oraclelinux: CVE-2026-43742 was patched at 2026-07-20
oraclelinux: CVE-2026-43745 was patched at 2026-07-20
redhat: CVE-2026-39872 was patched at 2026-07-20
redhat: CVE-2026-43663 was patched at 2026-07-20
redhat: CVE-2026-43676 was patched at 2026-07-20
redhat: CVE-2026-43699 was patched at 2026-07-20
redhat: CVE-2026-43705 was patched at 2026-07-20
redhat: CVE-2026-43707 was patched at 2026-07-20
redhat: CVE-2026-43712 was patched at 2026-07-20
redhat: CVE-2026-43715 was patched at 2026-07-20
redhat: CVE-2026-43716 was patched at 2026-07-20
redhat: CVE-2026-43720 was patched at 2026-07-20
redhat: CVE-2026-43726 was patched at 2026-07-20
redhat: CVE-2026-43727 was patched at 2026-07-20
redhat: CVE-2026-43731 was patched at 2026-07-20
redhat: CVE-2026-43734 was patched at 2026-07-20
redhat: CVE-2026-43740 was patched at 2026-07-20
redhat: CVE-2026-43742 was patched at 2026-07-20
redhat: CVE-2026-43745 was patched at 2026-07-20
debian: CVE-2026-58102 was patched at 2026-07-14
debian: CVE-2026-9265 was patched at 2026-06-24
altlinux: CVE-2026-13282 was patched at 2026-06-29
altlinux: CVE-2026-13783 was patched at 2026-07-03
altlinux: CVE-2026-13784 was patched at 2026-07-03
altlinux: CVE-2026-13799 was patched at 2026-07-03
altlinux: CVE-2026-13814 was patched at 2026-07-03
altlinux: CVE-2026-13819 was patched at 2026-07-03
altlinux: CVE-2026-13825 was patched at 2026-07-03
altlinux: CVE-2026-13835 was patched at 2026-07-03
altlinux: CVE-2026-13858 was patched at 2026-07-03
altlinux: CVE-2026-13873 was patched at 2026-07-03
altlinux: CVE-2026-13879 was patched at 2026-07-03
altlinux: CVE-2026-13890 was patched at 2026-07-03
altlinux: CVE-2026-13906 was patched at 2026-07-03
altlinux: CVE-2026-13915 was patched at 2026-07-03
altlinux: CVE-2026-13918 was patched at 2026-07-03
altlinux: CVE-2026-13975 was patched at 2026-07-03
altlinux: CVE-2026-14005 was patched at 2026-07-03
altlinux: CVE-2026-14011 was patched at 2026-07-03
altlinux: CVE-2026-14024 was patched at 2026-07-03
altlinux: CVE-2026-14025 was patched at 2026-07-03
altlinux: CVE-2026-14027 was patched at 2026-07-03
altlinux: CVE-2026-14040 was patched at 2026-07-03
altlinux: CVE-2026-14048 was patched at 2026-07-03
altlinux: CVE-2026-14063 was patched at 2026-07-03
altlinux: CVE-2026-14099 was patched at 2026-07-03
altlinux: CVE-2026-14102 was patched at 2026-07-03
altlinux: CVE-2026-14103 was patched at 2026-07-03
altlinux: CVE-2026-14119 was patched at 2026-07-03
altlinux: CVE-2026-14148 was patched at 2026-07-03
altlinux: CVE-2026-14385 was patched at 2026-07-03
altlinux: CVE-2026-14386 was patched at 2026-07-03
altlinux: CVE-2026-14388 was patched at 2026-07-03
altlinux: CVE-2026-14394 was patched at 2026-07-03
altlinux: CVE-2026-14406 was patched at 2026-07-03
altlinux: CVE-2026-14415 was patched at 2026-07-03
altlinux: CVE-2026-14422 was patched at 2026-07-03
altlinux: CVE-2026-15110 was patched at 2026-07-09
altlinux: CVE-2026-15111 was patched at 2026-07-09
altlinux: CVE-2026-15112 was patched at 2026-07-09
altlinux: CVE-2026-15114 was patched at 2026-07-09
altlinux: CVE-2026-15117 was patched at 2026-07-09
altlinux: CVE-2026-15123 was patched at 2026-07-09
altlinux: CVE-2026-15129 was patched at 2026-07-09
altlinux: CVE-2026-15764 was patched at 2026-07-15
altlinux: CVE-2026-15765 was patched at 2026-07-15
altlinux: CVE-2026-15777 was patched at 2026-07-15
altlinux: CVE-2026-15901 was patched at 2026-07-18
altlinux: CVE-2026-15904 was patched at 2026-07-18
altlinux: CVE-2026-15905 was patched at 2026-07-18
debian: CVE-2026-13026 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13027 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13029 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13282 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13783 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13784 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13799 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13814 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13819 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13825 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13835 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13858 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13873 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13879 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13890 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13906 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13915 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13918 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13975 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14005 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14011 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14024 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14025 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14027 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14040 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14048 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14063 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14099 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14102 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14103 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14119 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14148 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14385 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14386 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14388 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14394 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14406 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14415 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14422 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-15110 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15111 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15112 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15114 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15117 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15123 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15129 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15764 was patched at 2026-07-14, 2026-07-16
debian: CVE-2026-15765 was patched at 2026-07-14, 2026-07-16
debian: CVE-2026-15777 was patched at 2026-07-14, 2026-07-16
debian: CVE-2026-15901 was patched at 2026-07-14, 2026-07-22
debian: CVE-2026-15904 was patched at 2026-07-14, 2026-07-22
debian: CVE-2026-15905 was patched at 2026-07-14, 2026-07-22
almalinux: CVE-2026-60002 was patched at 2026-07-29
debian: CVE-2026-60002 was patched at 2026-07-14
oraclelinux: CVE-2026-60002 was patched at 2026-07-30
redhat: CVE-2026-60002 was patched at 2026-07-29
ubuntu: CVE-2026-60002 was patched at 2026-07-30
redos: CVE-2026-8711 was patched at 2026-06-26, 2026-06-29
ubuntu: CVE-2026-8711 was patched at 2026-07-30
altlinux: CVE-2026-55693 was patched at 2026-06-30, 2026-07-06
altlinux: CVE-2026-55892 was patched at 2026-06-30, 2026-07-06
altlinux: CVE-2026-57452 was patched at 2026-06-30, 2026-07-06
altlinux: CVE-2026-57455 was patched at 2026-06-30, 2026-07-06
altlinux: CVE-2026-59857 was patched at 2026-06-30, 2026-07-06
debian: CVE-2026-55693 was patched at 2026-07-14
debian: CVE-2026-55892 was patched at 2026-07-14
debian: CVE-2026-57452 was patched at 2026-07-14
debian: CVE-2026-57455 was patched at 2026-07-14
debian: CVE-2026-59857 was patched at 2026-07-14
redhat: CVE-2026-55693 was patched at 2026-07-29
redhat: CVE-2026-57455 was patched at 2026-07-29
ubuntu: CVE-2026-55693 was patched at 2026-07-30
ubuntu: CVE-2026-55892 was patched at 2026-07-30
ubuntu: CVE-2026-57452 was patched at 2026-07-30
ubuntu: CVE-2026-57455 was patched at 2026-07-30
ubuntu: CVE-2026-59857 was patched at 2026-07-30
debian: CVE-2026-42450 was patched at 2026-07-14
debian: CVE-2026-12844 was patched at 2026-07-14
debian: CVE-2026-13593 was patched at 2026-07-14
debian: CVE-2026-57074 was patched at 2026-07-14
debian: CVE-2026-57075 was patched at 2026-07-14
debian: CVE-2026-57076 was patched at 2026-07-14
debian: CVE-2026-57077 was patched at 2026-07-14
debian: CVE-2026-60082 was patched at 2026-07-14
altlinux: CVE-2026-14739 was patched at 2026-07-21
altlinux: CVE-2026-14740 was patched at 2026-07-21
debian: CVE-2026-14739 was patched at 2026-07-14
debian: CVE-2026-14740 was patched at 2026-07-14
debian: CVE-2026-6094 was patched at 2026-07-14
debian: CVE-2026-6325 was patched at 2026-07-14
debian: CVE-2026-7531 was patched at 2026-07-14
altlinux: CVE-2026-53877 was patched at 2026-07-27
debian: CVE-2026-53877 was patched at 2026-07-14
debian: CVE-2025-26240 was patched at 2026-06-24
debian: CVE-2026-57236 was patched at 2026-07-14
debian: CVE-2026-56123 was patched at 2026-07-14
ubuntu: CVE-2026-56123 was patched at 2026-07-30
altlinux: CVE-2026-55510 was patched at 2026-07-11, 2026-07-15, 2026-07-16
altlinux: CVE-2026-55577 was patched at 2026-07-11, 2026-07-15, 2026-07-16
altlinux: CVE-2026-61857 was patched at 2026-07-11, 2026-07-15, 2026-07-16
altlinux: CVE-2026-61863 was patched at 2026-07-11, 2026-07-15, 2026-07-16
altlinux: CVE-2026-61866 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-55577 was patched at 2026-07-07, 2026-07-14
debian: CVE-2026-61857 was patched at 2026-07-14
debian: CVE-2026-61863 was patched at 2026-07-14
debian: CVE-2026-61864 was patched at 2026-07-14
debian: CVE-2026-61865 was patched at 2026-07-14
debian: CVE-2026-61866 was patched at 2026-07-14
debian: CVE-2026-61872 was patched at 2026-07-14
debian: CVE-2026-41992 was patched at 2026-07-14
ubuntu: CVE-2026-41992 was patched at 2026-07-30
altlinux: CVE-2026-56434 was patched at 2026-07-17, 2026-07-21, 2026-07-22
debian: CVE-2026-56434 was patched at 2026-07-14
ubuntu: CVE-2026-56434 was patched at 2026-07-30
debian: CVE-2026-58469 was patched at 2026-07-14
debian: CVE-2026-58471 was patched at 2026-07-14
ubuntu: CVE-2026-58469 was patched at 2026-07-30
ubuntu: CVE-2026-58471 was patched at 2026-07-30
altlinux: CVE-2026-45771 was patched at 2026-06-24, 2026-06-26, 2026-07-16
debian: CVE-2026-57235 was patched at 2026-07-14
debian: CVE-2026-57434 was patched at 2026-07-14
debian: CVE-2026-57435 was patched at 2026-07-14
debian: CVE-2026-57436 was patched at 2026-07-14
debian: CVE-2026-57437 was patched at 2026-07-14
debian: CVE-2026-57438 was patched at 2026-07-14
debian: CVE-2026-46604 was patched at 2026-07-14
debian: CVE-2026-12805 was patched at 2026-06-24
almalinux: CVE-2026-55999 was patched at 2026-07-13
altlinux: CVE-2026-55999 was patched at 2026-07-08, 2026-07-14
altlinux: CVE-2026-56000 was patched at 2026-07-08, 2026-07-14
debian: CVE-2026-55999 was patched at 2026-07-14
debian: CVE-2026-56000 was patched at 2026-07-14
oraclelinux: CVE-2026-55999 was patched at 2026-07-13
redhat: CVE-2026-55999 was patched at 2026-07-13
redhat: CVE-2026-56000 was patched at 2026-07-13
altlinux: CVE-2026-48142 was patched at 2026-06-23, 2026-06-25, 2026-06-26
debian: CVE-2026-48142 was patched at 2026-06-24, 2026-06-30
redos: CVE-2026-48142 was patched at 2026-07-14
ubuntu: CVE-2026-48142 was patched at 2026-07-30
altlinux: CVE-2026-12245 was patched at 2026-06-26, 2026-06-29
ubuntu: CVE-2026-12245 was patched at 2026-07-30
debian: CVE-2025-15666 was patched at 2026-07-14
debian: CVE-2026-14604 was patched at 2026-07-14
debian: CVE-2026-14610 was patched at 2026-07-14
debian: CVE-2026-9539 was patched at 2026-07-14
ubuntu: CVE-2026-9539 was patched at 2026-07-30
debian: CVE-2026-40467 was patched at 2026-07-14
ubuntu: CVE-2026-40467 was patched at 2026-07-30
debian: CVE-2026-57432 was patched at 2026-07-14
debian: CVE-2026-56114 was patched at 2026-06-24, 2026-07-14
debian: CVE-2026-56117 was patched at 2026-06-24
altlinux: CVE-2026-55639 was patched at 2026-07-08
debian: CVE-2026-55639 was patched at 2026-07-14
debian: CVE-2026-56131 was patched at 2026-06-24, 2026-07-30
debian: CVE-2026-56132 was patched at 2026-06-24, 2026-07-30
debian: CVE-2026-56412 was patched at 2026-06-24, 2026-07-30
debian: CVE-2026-12528 was patched at 2026-06-24
debian: CVE-2026-12891 was patched at 2026-07-14
debian: CVE-2026-40257 was patched at 2026-07-14
debian: CVE-2026-54500 was patched at 2026-07-14
debian: CVE-2026-54502 was patched at 2026-07-14
debian: CVE-2026-54896 was patched at 2026-07-14
debian: CVE-2026-54897 was patched at 2026-07-14
debian: CVE-2026-54898 was patched at 2026-07-14
debian: CVE-2026-54899 was patched at 2026-07-14
debian: CVE-2026-54901 was patched at 2026-07-14
altlinux: CVE-2026-40210 was patched at 2026-06-29, 2026-06-30
debian: CVE-2026-13573 was patched at 2026-07-14
debian: CVE-2026-13574 was patched at 2026-07-14
debian: CVE-2026-14324 was patched at 2026-07-14
debian: CVE-2026-14461 was patched at 2026-07-14
debian: CVE-2026-14647 was patched at 2026-07-14
debian: CVE-2026-22879 was patched at 2026-07-14
debian: CVE-2026-40210 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-45382 was patched at 2026-07-14
debian: CVE-2026-45383 was patched at 2026-07-14
debian: CVE-2026-46602 was patched at 2026-07-14
debian: CVE-2026-48029 was patched at 2026-07-14
debian: CVE-2026-54696 was patched at 2026-07-14
debian: CVE-2026-56109 was patched at 2026-06-24
debian: CVE-2026-60103 was patched at 2026-07-14
debian: CVE-2026-7701 was patched at 2026-07-14
ubuntu: CVE-2026-14324 was patched at 2026-07-30
ubuntu: CVE-2026-45382 was patched at 2026-07-30
ubuntu: CVE-2026-45383 was patched at 2026-07-30
ubuntu: CVE-2026-48029 was patched at 2026-07-30
ubuntu: CVE-2026-56109 was patched at 2026-07-30
debian: CVE-2026-14790 was patched at 2026-07-14
altlinux: CVE-2026-9795 was patched at 2026-06-28, 2026-07-01, 2026-07-02
altlinux: CVE-2026-9796 was patched at 2026-07-11, 2026-07-13, 2026-07-14, 2026-07-16
altlinux: CVE-2026-13827 was patched at 2026-07-03
altlinux: CVE-2026-13844 was patched at 2026-07-03
altlinux: CVE-2026-14018 was patched at 2026-07-03
altlinux: CVE-2026-14094 was patched at 2026-07-03
altlinux: CVE-2026-14124 was patched at 2026-07-03
debian: CVE-2026-13827 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13844 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14018 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14094 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14124 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-15779 was patched at 2026-07-14
ubuntu: CVE-2026-15779 was patched at 2026-07-30
redos: CVE-2026-45490 was patched at 2026-07-09
redos: CVE-2023-28737 was patched at 2026-06-29
debian: CVE-2026-12003 was patched at 2026-06-24
debian: CVE-2026-12610 was patched at 2026-07-14
almalinux: CVE-2026-54369 was patched at 2026-07-21, 2026-07-22
almalinux: CVE-2026-54370 was patched at 2026-07-21, 2026-07-22
debian: CVE-2026-48821 was patched at 2026-06-24
debian: CVE-2026-54369 was patched at 2026-07-14
debian: CVE-2026-54370 was patched at 2026-07-14
debian: CVE-2026-54371 was patched at 2026-07-14
oraclelinux: CVE-2026-54369 was patched at 2026-07-21, 2026-07-22
oraclelinux: CVE-2026-54370 was patched at 2026-07-21, 2026-07-22
redhat: CVE-2026-54369 was patched at 2026-07-21, 2026-07-22
redhat: CVE-2026-54370 was patched at 2026-07-21, 2026-07-22
altlinux: CVE-2026-62643 was patched at 2026-07-10, 2026-07-15
debian: CVE-2026-62643 was patched at 2026-07-14, 2026-07-19
debian: CVE-2026-41423 was patched at 2026-06-24
debian: CVE-2026-46417 was patched at 2026-06-24
altlinux: CVE-2026-58404 was patched at 2026-07-01
debian: CVE-2026-58501 was patched at 2026-07-14
debian: CVE-2026-54514 was patched at 2026-07-14
debian: CVE-2026-15146 was patched at 2026-07-14
debian: CVE-2026-16221 was patched at 2026-07-14
debian: CVE-2026-48978 was patched at 2026-07-14
debian: CVE-2026-50151 was patched at 2026-07-14
debian: CVE-2026-53727 was patched at 2026-07-14
ubuntu: CVE-2026-15146 was patched at 2026-07-30
debian: CVE-2026-54430 was patched at 2026-07-14
debian: CVE-2026-25707 was patched at 2026-07-14
altlinux: CVE-2026-53143 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53150 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53176 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53178 was patched at 2026-06-19
altlinux: CVE-2026-53263 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53277 was patched at 2026-06-19, 2026-06-22, 2026-07-06
debian: CVE-2026-53143 was patched at 2026-07-14
debian: CVE-2026-53150 was patched at 2026-07-14
debian: CVE-2026-53176 was patched at 2026-07-14
debian: CVE-2026-53178 was patched at 2026-07-14
debian: CVE-2026-53263 was patched at 2026-07-14
debian: CVE-2026-53277 was patched at 2026-07-14
debian: CVE-2026-63881 was patched at 2026-07-14
ubuntu: CVE-2026-53277 was patched at 2026-07-30
ubuntu: CVE-2026-63881 was patched at 2026-07-30
altlinux: CVE-2026-13938 was patched at 2026-07-03
altlinux: CVE-2026-14069 was patched at 2026-07-03
altlinux: CVE-2026-14070 was patched at 2026-07-03
altlinux: CVE-2026-14391 was patched at 2026-07-03
altlinux: CVE-2026-15108 was patched at 2026-07-09
debian: CVE-2026-13938 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14069 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14070 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14391 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-15108 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-13221 was patched at 2026-07-14
debian: CVE-2026-57433 was patched at 2026-07-14
debian: CVE-2026-45784 was patched at 2026-07-14
debian: CVE-2026-55203 was patched at 2026-06-24
ubuntu: CVE-2026-55203 was patched at 2026-07-30
debian: CVE-2026-40468 was patched at 2026-07-14
ubuntu: CVE-2026-40468 was patched at 2026-07-30
altlinux: CVE-2026-58207 was patched at 2026-07-10, 2026-07-13, 2026-07-14
debian: CVE-2026-58207 was patched at 2026-07-14
altlinux: CVE-2026-53466 was patched at 2026-07-11, 2026-07-15, 2026-07-16
altlinux: CVE-2026-55597 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-53466 was patched at 2026-07-07, 2026-07-14
debian: CVE-2026-55597 was patched at 2026-07-07, 2026-07-14
debian: CVE-2026-63091 was patched at 2026-07-14
debian: CVE-2026-58470 was patched at 2026-07-14
debian: CVE-2026-58472 was patched at 2026-07-14
ubuntu: CVE-2026-58470 was patched at 2026-07-30
ubuntu: CVE-2026-58472 was patched at 2026-07-30
debian: CVE-2026-56403 was patched at 2026-06-24, 2026-07-30
debian: CVE-2026-56404 was patched at 2026-06-24, 2026-07-30
debian: CVE-2026-56405 was patched at 2026-06-24, 2026-07-30
debian: CVE-2026-56406 was patched at 2026-06-24, 2026-07-30
debian: CVE-2026-56407 was patched at 2026-06-24, 2026-07-30
debian: CVE-2026-56408 was patched at 2026-06-24, 2026-07-30
debian: CVE-2026-56409 was patched at 2026-06-24, 2026-07-30
debian: CVE-2026-56410 was patched at 2026-06-24, 2026-07-30
debian: CVE-2026-56411 was patched at 2026-06-24, 2026-07-30
debian: CVE-2026-54905 was patched at 2026-07-14
debian: CVE-2026-6678 was patched at 2026-07-14
debian: CVE-2026-54903 was patched at 2026-07-14
debian: CVE-2026-53763 was patched at 2026-07-14
altlinux: CVE-2026-54679 was patched at 2026-06-22, 2026-06-24, 2026-06-25, 2026-06-29
debian: CVE-2026-54679 was patched at 2026-07-14
debian: CVE-2026-14801 was patched at 2026-07-14
debian: CVE-2026-15551 was patched at 2026-07-14
debian: CVE-2026-50003 was patched at 2026-07-14
redos: CVE-2026-42129 was patched at 2026-07-14
debian: CVE-2026-29509 was patched at 2026-07-14
debian: CVE-2026-54591 was patched at 2026-07-14
debian: CVE-2026-59946 was patched at 2026-07-14
debian: CVE-2026-59948 was patched at 2026-07-14
debian: CVE-2026-15392 was patched at 2026-07-14
debian: CVE-2026-12479 was patched at 2026-07-14
altlinux: CVE-2026-39899 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-39899 was patched at 2026-07-14
debian: CVE-2026-49356 was patched at 2026-07-14
debian: CVE-2026-11940 was patched at 2026-06-24
debian: CVE-2026-13503 was patched at 2026-07-14
debian: CVE-2026-44942 was patched at 2026-06-24
debian: CVE-2026-49342 was patched at 2026-06-24
debian: CVE-2026-50163 was patched at 2026-07-14
debian: CVE-2026-52868 was patched at 2026-07-14
debian: CVE-2026-53925 was patched at 2026-07-14
debian: CVE-2026-55677 was patched at 2026-07-14
redos: CVE-2026-10601 was patched at 2026-07-14
debian: CVE-2026-57966 was patched at 2026-07-14
redos: CVE-2026-25779 was patched at 2026-07-14
debian: CVE-2026-9679 was patched at 2026-06-24
altlinux: CVE-2026-44889 was patched at 2026-07-01
debian: CVE-2026-44889 was patched at 2026-06-24
debian: CVE-2026-12804 was patched at 2026-06-24
debian: CVE-2026-63889 was patched at 2026-07-14
ubuntu: CVE-2026-63889 was patched at 2026-07-30
altlinux: CVE-2026-13837 was patched at 2026-07-03
altlinux: CVE-2026-13842 was patched at 2026-07-03
altlinux: CVE-2026-13857 was patched at 2026-07-03
altlinux: CVE-2026-13860 was patched at 2026-07-03
altlinux: CVE-2026-13867 was patched at 2026-07-03
altlinux: CVE-2026-13895 was patched at 2026-07-03
altlinux: CVE-2026-13902 was patched at 2026-07-03
altlinux: CVE-2026-13907 was patched at 2026-07-03
altlinux: CVE-2026-13912 was patched at 2026-07-03
altlinux: CVE-2026-13916 was patched at 2026-07-03
altlinux: CVE-2026-13941 was patched at 2026-07-03
altlinux: CVE-2026-13956 was patched at 2026-07-03
altlinux: CVE-2026-13960 was patched at 2026-07-03
altlinux: CVE-2026-13966 was patched at 2026-07-03
altlinux: CVE-2026-13972 was patched at 2026-07-03
altlinux: CVE-2026-13973 was patched at 2026-07-03
altlinux: CVE-2026-13979 was patched at 2026-07-03
altlinux: CVE-2026-13980 was patched at 2026-07-03
altlinux: CVE-2026-13981 was patched at 2026-07-03
altlinux: CVE-2026-13982 was patched at 2026-07-03
altlinux: CVE-2026-13983 was patched at 2026-07-03
altlinux: CVE-2026-13986 was patched at 2026-07-03
altlinux: CVE-2026-13987 was patched at 2026-07-03
altlinux: CVE-2026-13988 was patched at 2026-07-03
altlinux: CVE-2026-13989 was patched at 2026-07-03
altlinux: CVE-2026-13992 was patched at 2026-07-03
altlinux: CVE-2026-13993 was patched at 2026-07-03
altlinux: CVE-2026-13994 was patched at 2026-07-03
altlinux: CVE-2026-13996 was patched at 2026-07-03
altlinux: CVE-2026-13997 was patched at 2026-07-03
altlinux: CVE-2026-13998 was patched at 2026-07-03
altlinux: CVE-2026-14002 was patched at 2026-07-03
altlinux: CVE-2026-14013 was patched at 2026-07-03
altlinux: CVE-2026-14014 was patched at 2026-07-03
altlinux: CVE-2026-14026 was patched at 2026-07-03
altlinux: CVE-2026-14028 was patched at 2026-07-03
altlinux: CVE-2026-14030 was patched at 2026-07-03
altlinux: CVE-2026-14031 was patched at 2026-07-03
altlinux: CVE-2026-14042 was patched at 2026-07-03
altlinux: CVE-2026-14072 was patched at 2026-07-03
altlinux: CVE-2026-14077 was patched at 2026-07-03
altlinux: CVE-2026-14114 was patched at 2026-07-03
altlinux: CVE-2026-14123 was patched at 2026-07-03
altlinux: CVE-2026-14126 was patched at 2026-07-03
altlinux: CVE-2026-14128 was patched at 2026-07-03
altlinux: CVE-2026-14129 was patched at 2026-07-03
altlinux: CVE-2026-14132 was patched at 2026-07-03
altlinux: CVE-2026-14133 was patched at 2026-07-03
altlinux: CVE-2026-14134 was patched at 2026-07-03
altlinux: CVE-2026-14138 was patched at 2026-07-03
altlinux: CVE-2026-14139 was patched at 2026-07-03
altlinux: CVE-2026-14141 was patched at 2026-07-03
altlinux: CVE-2026-14143 was patched at 2026-07-03
altlinux: CVE-2026-14144 was patched at 2026-07-03
altlinux: CVE-2026-14153 was patched at 2026-07-03
altlinux: CVE-2026-14154 was patched at 2026-07-03
altlinux: CVE-2026-14404 was patched at 2026-07-03
altlinux: CVE-2026-14410 was patched at 2026-07-03
debian: CVE-2026-13837 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13842 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13857 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13860 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13867 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13895 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13902 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13907 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13912 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13916 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13941 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13956 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13960 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13966 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13972 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13973 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13979 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13980 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13981 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13982 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13983 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13986 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13987 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13988 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13989 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13992 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13993 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13994 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13996 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13997 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13998 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14002 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14013 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14014 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14026 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14028 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14030 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14031 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14042 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14072 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14077 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14114 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14123 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14126 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14128 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14129 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14132 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14133 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14134 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14138 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14139 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14141 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14143 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14144 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14153 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14154 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14404 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14410 was patched at 2026-07-05, 2026-07-14
altlinux: CVE-2026-58403 was patched at 2026-07-01
debian: CVE-2026-58403 was patched at 2026-07-14
debian: CVE-2026-49145 was patched at 2026-07-14
debian: CVE-2026-58451 was patched at 2026-07-14
altlinux: CVE-2026-15719 was patched at 2026-07-15, 2026-07-30
debian: CVE-2026-15719 was patched at 2026-07-22, 2026-07-30
oraclelinux: CVE-2026-15719 was patched at 2026-07-28
redhat: CVE-2026-15719 was patched at 2026-07-28
almalinux: CVE-2026-53266 was patched at 2026-07-08, 2026-07-14
almalinux: CVE-2026-53366 was patched at 2026-07-02
altlinux: CVE-2026-52908 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-52909 was patched at 2026-06-19, 2026-06-22, 2026-07-04, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-52930 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-52940 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53131 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53132 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53133 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53134 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53139 was patched at 2026-06-19, 2026-06-22, 2026-07-04, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53140 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53141 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53146 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53151 was patched at 2026-06-19, 2026-06-22, 2026-07-04, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53153 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53154 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53155 was patched at 2026-06-19
altlinux: CVE-2026-53159 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53162 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53164 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53167 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53168 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53170 was patched at 2026-06-19
altlinux: CVE-2026-53171 was patched at 2026-06-19
altlinux: CVE-2026-53174 was patched at 2026-06-19
altlinux: CVE-2026-53180 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53182 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53183 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53184 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53186 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53188 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53189 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53190 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53191 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53197 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53199 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53200 was patched at 2026-06-19
altlinux: CVE-2026-53201 was patched at 2026-06-19
altlinux: CVE-2026-53206 was patched at 2026-06-19
altlinux: CVE-2026-53207 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53208 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53210 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53211 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53215 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53217 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53218 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53219 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53221 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53223 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53225 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53227 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53228 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53229 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53231 was patched at 2026-06-19
altlinux: CVE-2026-53235 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53236 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53238 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53241 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53243 was patched at 2026-06-19
altlinux: CVE-2026-53244 was patched at 2026-06-19
altlinux: CVE-2026-53245 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53249 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53251 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53257 was patched at 2026-06-19
altlinux: CVE-2026-53258 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53261 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53262 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53265 was patched at 2026-06-19, 2026-06-22, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53266 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53267 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53269 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53270 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53326 was patched at 2026-06-19
altlinux: CVE-2026-53327 was patched at 2026-06-19, 2026-06-27, 2026-06-28, 2026-07-04, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53328 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53329 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53331 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53332 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53333 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53336 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53340 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53342 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53343 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53347 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53349 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53351 was patched at 2026-06-19
altlinux: CVE-2026-53353 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53354 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-07, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53356 was patched at 2026-06-19, 2026-06-22, 2026-06-23, 2026-06-26, 2026-07-06, 2026-07-16, 2026-07-17, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53361 was patched at 2026-07-04, 2026-07-06, 2026-07-24, 2026-07-25
altlinux: CVE-2026-53363 was patched at 2026-06-19, 2026-06-22, 2026-07-06
altlinux: CVE-2026-53366 was patched at 2026-07-04, 2026-07-06, 2026-07-07, 2026-07-24, 2026-07-25
debian: CVE-2026-52908 was patched at 2026-06-21, 2026-06-24
debian: CVE-2026-52909 was patched at 2026-06-21, 2026-06-24, 2026-07-14
debian: CVE-2026-52930 was patched at 2026-07-14
debian: CVE-2026-53131 was patched at 2026-07-14
debian: CVE-2026-53132 was patched at 2026-07-14
debian: CVE-2026-53133 was patched at 2026-07-14
debian: CVE-2026-53134 was patched at 2026-07-14
debian: CVE-2026-53139 was patched at 2026-07-05, 2026-07-14, 2026-07-30
debian: CVE-2026-53140 was patched at 2026-07-14
debian: CVE-2026-53146 was patched at 2026-07-14
debian: CVE-2026-53151 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-53154 was patched at 2026-07-14
debian: CVE-2026-53159 was patched at 2026-07-14
debian: CVE-2026-53167 was patched at 2026-07-05, 2026-07-14, 2026-07-30
debian: CVE-2026-53168 was patched at 2026-07-14
debian: CVE-2026-53180 was patched at 2026-07-14
debian: CVE-2026-53182 was patched at 2026-07-14
debian: CVE-2026-53183 was patched at 2026-07-14
debian: CVE-2026-53184 was patched at 2026-07-14
debian: CVE-2026-53186 was patched at 2026-07-14
debian: CVE-2026-53189 was patched at 2026-07-14
debian: CVE-2026-53190 was patched at 2026-07-14
debian: CVE-2026-53191 was patched at 2026-07-14
debian: CVE-2026-53199 was patched at 2026-07-14
debian: CVE-2026-53207 was patched at 2026-07-14
debian: CVE-2026-53208 was patched at 2026-07-14
debian: CVE-2026-53210 was patched at 2026-07-14
debian: CVE-2026-53215 was patched at 2026-07-14
debian: CVE-2026-53217 was patched at 2026-07-14
debian: CVE-2026-53218 was patched at 2026-07-14
debian: CVE-2026-53219 was patched at 2026-07-14
debian: CVE-2026-53221 was patched at 2026-07-14
debian: CVE-2026-53223 was patched at 2026-07-14
debian: CVE-2026-53225 was patched at 2026-07-14
debian: CVE-2026-53227 was patched at 2026-07-14
debian: CVE-2026-53228 was patched at 2026-07-14
debian: CVE-2026-53229 was patched at 2026-07-14
debian: CVE-2026-53232 was patched at 2026-07-14
debian: CVE-2026-53235 was patched at 2026-07-14
debian: CVE-2026-53236 was patched at 2026-07-14
debian: CVE-2026-53238 was patched at 2026-07-14
debian: CVE-2026-53241 was patched at 2026-07-14
debian: CVE-2026-53245 was patched at 2026-07-14
debian: CVE-2026-53249 was patched at 2026-07-14
debian: CVE-2026-53251 was patched at 2026-07-14
debian: CVE-2026-53258 was patched at 2026-07-14
debian: CVE-2026-53261 was patched at 2026-07-14
debian: CVE-2026-53262 was patched at 2026-07-14
debian: CVE-2026-53265 was patched at 2026-07-14
debian: CVE-2026-53266 was patched at 2026-07-14
debian: CVE-2026-53267 was patched at 2026-07-14
debian: CVE-2026-53269 was patched at 2026-07-14
debian: CVE-2026-53270 was patched at 2026-07-14
debian: CVE-2026-53327 was patched at 2026-07-05, 2026-07-14, 2026-07-30
debian: CVE-2026-53328 was patched at 2026-07-14
debian: CVE-2026-53329 was patched at 2026-07-14
debian: CVE-2026-53331 was patched at 2026-07-14
debian: CVE-2026-53332 was patched at 2026-07-14
debian: CVE-2026-53336 was patched at 2026-07-14
debian: CVE-2026-53343 was patched at 2026-07-14
debian: CVE-2026-53347 was patched at 2026-07-14
debian: CVE-2026-53349 was patched at 2026-07-14
debian: CVE-2026-53353 was patched at 2026-07-14
debian: CVE-2026-53354 was patched at 2026-07-14
debian: CVE-2026-53356 was patched at 2026-07-14
debian: CVE-2026-53361 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-53366 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-53368 was patched at 2026-07-14
debian: CVE-2026-53369 was patched at 2026-07-14
debian: CVE-2026-53374 was patched at 2026-07-14
debian: CVE-2026-53375 was patched at 2026-07-14
debian: CVE-2026-53376 was patched at 2026-07-14
debian: CVE-2026-53377 was patched at 2026-07-14
debian: CVE-2026-53379 was patched at 2026-07-14
debian: CVE-2026-53386 was patched at 2026-07-14
debian: CVE-2026-53387 was patched at 2026-07-14
debian: CVE-2026-53393 was patched at 2026-07-14
debian: CVE-2026-53394 was patched at 2026-07-14
debian: CVE-2026-53397 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-53398 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63805 was patched at 2026-07-14
debian: CVE-2026-63809 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63811 was patched at 2026-07-14
debian: CVE-2026-63812 was patched at 2026-07-14
debian: CVE-2026-63814 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63816 was patched at 2026-07-14, 2026-07-21
debian: CVE-2026-63817 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63818 was patched at 2026-07-14, 2026-07-21
debian: CVE-2026-63819 was patched at 2026-07-14
debian: CVE-2026-63822 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63823 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63824 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63825 was patched at 2026-07-14
debian: CVE-2026-63828 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63829 was patched at 2026-07-14
debian: CVE-2026-63830 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63832 was patched at 2026-07-14
debian: CVE-2026-63833 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63834 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63835 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63836 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-63838 was patched at 2026-07-14
debian: CVE-2026-63842 was patched at 2026-07-14
debian: CVE-2026-63843 was patched at 2026-07-14
debian: CVE-2026-63844 was patched at 2026-07-14
debian: CVE-2026-63845 was patched at 2026-07-14
debian: CVE-2026-63846 was patched at 2026-07-14
debian: CVE-2026-63847 was patched at 2026-07-14
debian: CVE-2026-63848 was patched at 2026-07-14
debian: CVE-2026-63850 was patched at 2026-07-14
debian: CVE-2026-63851 was patched at 2026-07-14
debian: CVE-2026-63852 was patched at 2026-07-14
debian: CVE-2026-63853 was patched at 2026-07-14
debian: CVE-2026-63854 was patched at 2026-07-14
debian: CVE-2026-63855 was patched at 2026-07-14
debian: CVE-2026-63856 was patched at 2026-07-14
debian: CVE-2026-63857 was patched at 2026-07-14
debian: CVE-2026-63858 was patched at 2026-07-14
debian: CVE-2026-63859 was patched at 2026-07-14
debian: CVE-2026-63860 was patched at 2026-07-14
debian: CVE-2026-63861 was patched at 2026-07-14
debian: CVE-2026-63862 was patched at 2026-07-14
debian: CVE-2026-63865 was patched at 2026-07-14
debian: CVE-2026-63867 was patched at 2026-07-14
debian: CVE-2026-63868 was patched at 2026-07-14
debian: CVE-2026-63869 was patched at 2026-07-14
debian: CVE-2026-63870 was patched at 2026-07-14
debian: CVE-2026-63871 was patched at 2026-07-14
debian: CVE-2026-63872 was patched at 2026-07-14
debian: CVE-2026-63875 was patched at 2026-07-14
debian: CVE-2026-63879 was patched at 2026-07-14
debian: CVE-2026-63883 was patched at 2026-07-14
debian: CVE-2026-63884 was patched at 2026-07-14
debian: CVE-2026-63886 was patched at 2026-07-14
debian: CVE-2026-63887 was patched at 2026-07-14
debian: CVE-2026-63888 was patched at 2026-07-14
debian: CVE-2026-63890 was patched at 2026-07-14
debian: CVE-2026-63891 was patched at 2026-07-14
debian: CVE-2026-63892 was patched at 2026-07-14
debian: CVE-2026-63893 was patched at 2026-07-14
debian: CVE-2026-63895 was patched at 2026-07-14
debian: CVE-2026-63896 was patched at 2026-07-14
debian: CVE-2026-63897 was patched at 2026-07-14
debian: CVE-2026-63900 was patched at 2026-07-14
debian: CVE-2026-63902 was patched at 2026-07-14
debian: CVE-2026-63903 was patched at 2026-07-14
debian: CVE-2026-63908 was patched at 2026-07-14
debian: CVE-2026-63909 was patched at 2026-07-14
debian: CVE-2026-63912 was patched at 2026-07-14
debian: CVE-2026-63913 was patched at 2026-07-14
debian: CVE-2026-63914 was patched at 2026-07-14
debian: CVE-2026-63917 was patched at 2026-07-14
debian: CVE-2026-63919 was patched at 2026-07-14
debian: CVE-2026-63921 was patched at 2026-07-14
debian: CVE-2026-63922 was patched at 2026-07-14
debian: CVE-2026-63924 was patched at 2026-07-14
debian: CVE-2026-63925 was patched at 2026-07-14
debian: CVE-2026-63926 was patched at 2026-07-14
debian: CVE-2026-63927 was patched at 2026-07-14
debian: CVE-2026-63929 was patched at 2026-07-14
debian: CVE-2026-63931 was patched at 2026-07-14
debian: CVE-2026-63933 was patched at 2026-07-14
debian: CVE-2026-63934 was patched at 2026-07-14
debian: CVE-2026-63936 was patched at 2026-07-14
debian: CVE-2026-63937 was patched at 2026-07-14
debian: CVE-2026-63938 was patched at 2026-07-14
debian: CVE-2026-63939 was patched at 2026-07-14
debian: CVE-2026-63940 was patched at 2026-07-14
debian: CVE-2026-63941 was patched at 2026-07-14
debian: CVE-2026-63943 was patched at 2026-07-14
debian: CVE-2026-63948 was patched at 2026-07-14
debian: CVE-2026-63949 was patched at 2026-07-14
debian: CVE-2026-63952 was patched at 2026-07-14
debian: CVE-2026-63954 was patched at 2026-07-14
debian: CVE-2026-63958 was patched at 2026-07-14
debian: CVE-2026-63959 was patched at 2026-07-14
debian: CVE-2026-63960 was patched at 2026-07-14
debian: CVE-2026-63961 was patched at 2026-07-14
debian: CVE-2026-63962 was patched at 2026-07-14
debian: CVE-2026-63963 was patched at 2026-07-14
debian: CVE-2026-63964 was patched at 2026-07-14
debian: CVE-2026-63967 was patched at 2026-07-14
debian: CVE-2026-63968 was patched at 2026-07-14
debian: CVE-2026-63969 was patched at 2026-07-14
debian: CVE-2026-63970 was patched at 2026-07-14
debian: CVE-2026-63971 was patched at 2026-07-14
debian: CVE-2026-63974 was patched at 2026-07-14
debian: CVE-2026-63975 was patched at 2026-07-14
debian: CVE-2026-63976 was patched at 2026-07-14
debian: CVE-2026-63978 was patched at 2026-07-14
debian: CVE-2026-63979 was patched at 2026-07-14
debian: CVE-2026-63980 was patched at 2026-07-14
debian: CVE-2026-63983 was patched at 2026-07-14
debian: CVE-2026-63984 was patched at 2026-07-14
debian: CVE-2026-63985 was patched at 2026-07-14
debian: CVE-2026-63987 was patched at 2026-07-14
debian: CVE-2026-63990 was patched at 2026-07-14
debian: CVE-2026-63992 was patched at 2026-07-14
debian: CVE-2026-63993 was patched at 2026-07-14
debian: CVE-2026-63994 was patched at 2026-07-14
debian: CVE-2026-63995 was patched at 2026-07-14
debian: CVE-2026-63996 was patched at 2026-07-14
debian: CVE-2026-63997 was patched at 2026-07-14
debian: CVE-2026-63998 was patched at 2026-07-14
debian: CVE-2026-63999 was patched at 2026-07-14
debian: CVE-2026-64000 was patched at 2026-07-14
debian: CVE-2026-64001 was patched at 2026-07-14
debian: CVE-2026-64002 was patched at 2026-07-14
debian: CVE-2026-64003 was patched at 2026-07-14
debian: CVE-2026-64005 was patched at 2026-07-14
debian: CVE-2026-64006 was patched at 2026-07-14
debian: CVE-2026-64007 was patched at 2026-07-14
debian: CVE-2026-64009 was patched at 2026-07-14
debian: CVE-2026-64012 was patched at 2026-07-14
debian: CVE-2026-64015 was patched at 2026-07-14
debian: CVE-2026-64018 was patched at 2026-07-14
debian: CVE-2026-64024 was patched at 2026-07-14
debian: CVE-2026-64026 was patched at 2026-07-14
debian: CVE-2026-64034 was patched at 2026-07-14
debian: CVE-2026-64036 was patched at 2026-07-14
debian: CVE-2026-64038 was patched at 2026-07-14
debian: CVE-2026-64039 was patched at 2026-07-14
debian: CVE-2026-64046 was patched at 2026-07-14
debian: CVE-2026-64047 was patched at 2026-07-14
debian: CVE-2026-64048 was patched at 2026-07-14
debian: CVE-2026-64051 was patched at 2026-07-14
debian: CVE-2026-64052 was patched at 2026-07-14
debian: CVE-2026-64053 was patched at 2026-07-14
debian: CVE-2026-64055 was patched at 2026-07-14
debian: CVE-2026-64056 was patched at 2026-07-14
debian: CVE-2026-64058 was patched at 2026-07-14
debian: CVE-2026-64059 was patched at 2026-07-14
debian: CVE-2026-64060 was patched at 2026-07-14
debian: CVE-2026-64062 was patched at 2026-07-14
debian: CVE-2026-64063 was patched at 2026-07-14
debian: CVE-2026-64064 was patched at 2026-07-14
debian: CVE-2026-64065 was patched at 2026-07-14
debian: CVE-2026-64066 was patched at 2026-07-14
debian: CVE-2026-64067 was patched at 2026-07-14
debian: CVE-2026-64068 was patched at 2026-07-14
debian: CVE-2026-64070 was patched at 2026-07-14
debian: CVE-2026-64076 was patched at 2026-07-14
debian: CVE-2026-64077 was patched at 2026-07-14
debian: CVE-2026-64078 was patched at 2026-07-14
debian: CVE-2026-64079 was patched at 2026-07-14
debian: CVE-2026-64082 was patched at 2026-07-14
debian: CVE-2026-64083 was patched at 2026-07-14
debian: CVE-2026-64084 was patched at 2026-07-14
debian: CVE-2026-64085 was patched at 2026-07-14
debian: CVE-2026-64086 was patched at 2026-07-14
debian: CVE-2026-64087 was patched at 2026-07-14
debian: CVE-2026-64088 was patched at 2026-07-14
debian: CVE-2026-64089 was patched at 2026-07-14
debian: CVE-2026-64090 was patched at 2026-07-14
debian: CVE-2026-64091 was patched at 2026-07-14
debian: CVE-2026-64092 was patched at 2026-07-14
debian: CVE-2026-64093 was patched at 2026-07-14
debian: CVE-2026-64094 was patched at 2026-07-14
debian: CVE-2026-64095 was patched at 2026-07-14
debian: CVE-2026-64098 was patched at 2026-07-14
debian: CVE-2026-64105 was patched at 2026-07-14
debian: CVE-2026-64106 was patched at 2026-07-14
debian: CVE-2026-64108 was patched at 2026-07-14
debian: CVE-2026-64109 was patched at 2026-07-14
debian: CVE-2026-64111 was patched at 2026-07-14
debian: CVE-2026-64112 was patched at 2026-07-14
debian: CVE-2026-64114 was patched at 2026-07-14
debian: CVE-2026-64118 was patched at 2026-07-14
debian: CVE-2026-64119 was patched at 2026-07-14
debian: CVE-2026-64121 was patched at 2026-07-14
debian: CVE-2026-64125 was patched at 2026-07-14
debian: CVE-2026-64127 was patched at 2026-07-14
debian: CVE-2026-64128 was patched at 2026-07-14
debian: CVE-2026-64131 was patched at 2026-07-14
debian: CVE-2026-64132 was patched at 2026-07-14
debian: CVE-2026-64133 was patched at 2026-07-14
debian: CVE-2026-64134 was patched at 2026-07-14
debian: CVE-2026-64135 was patched at 2026-07-14
debian: CVE-2026-64136 was patched at 2026-07-14
debian: CVE-2026-64137 was patched at 2026-07-14
debian: CVE-2026-64138 was patched at 2026-07-14
debian: CVE-2026-64142 was patched at 2026-07-14
debian: CVE-2026-64144 was patched at 2026-07-14
debian: CVE-2026-64146 was patched at 2026-07-14
debian: CVE-2026-64147 was patched at 2026-07-14
debian: CVE-2026-64148 was patched at 2026-07-14
debian: CVE-2026-64153 was patched at 2026-07-14
debian: CVE-2026-64154 was patched at 2026-07-14
debian: CVE-2026-64157 was patched at 2026-07-14
debian: CVE-2026-64158 was patched at 2026-07-14
debian: CVE-2026-64159 was patched at 2026-07-14
debian: CVE-2026-64160 was patched at 2026-07-14
debian: CVE-2026-64163 was patched at 2026-07-14
debian: CVE-2026-64164 was patched at 2026-07-14
debian: CVE-2026-64166 was patched at 2026-07-14
debian: CVE-2026-64168 was patched at 2026-07-14
debian: CVE-2026-64169 was patched at 2026-07-14
debian: CVE-2026-64170 was patched at 2026-07-14
debian: CVE-2026-64173 was patched at 2026-07-14
debian: CVE-2026-64174 was patched at 2026-07-14
debian: CVE-2026-64177 was patched at 2026-07-14
debian: CVE-2026-64178 was patched at 2026-07-14
debian: CVE-2026-64179 was patched at 2026-07-14
debian: CVE-2026-64180 was patched at 2026-07-14
debian: CVE-2026-64182 was patched at 2026-07-14
debian: CVE-2026-64184 was patched at 2026-07-14
debian: CVE-2026-64185 was patched at 2026-07-14
debian: CVE-2026-64187 was patched at 2026-07-14, 2026-07-21
debian: CVE-2026-64191 was patched at 2026-07-14, 2026-07-30
debian: CVE-2026-64192 was patched at 2026-07-14
debian: CVE-2026-64205 was patched at 2026-07-14
debian: CVE-2026-64206 was patched at 2026-07-14
oraclelinux: CVE-2026-23473 was patched at 2026-07-02
oraclelinux: CVE-2026-53266 was patched at 2026-07-14
redhat: CVE-2026-53266 was patched at 2026-07-08, 2026-07-14
ubuntu: CVE-2026-53174 was patched at 2026-07-30
ubuntu: CVE-2026-53354 was patched at 2026-07-30
ubuntu: CVE-2026-53368 was patched at 2026-07-30
ubuntu: CVE-2026-53369 was patched at 2026-07-30
ubuntu: CVE-2026-53374 was patched at 2026-07-30
ubuntu: CVE-2026-53375 was patched at 2026-07-30
ubuntu: CVE-2026-53376 was patched at 2026-07-30
ubuntu: CVE-2026-53377 was patched at 2026-07-30
ubuntu: CVE-2026-53379 was patched at 2026-07-30
ubuntu: CVE-2026-63838 was patched at 2026-07-30
ubuntu: CVE-2026-63842 was patched at 2026-07-30
ubuntu: CVE-2026-63843 was patched at 2026-07-30
ubuntu: CVE-2026-63844 was patched at 2026-07-30
ubuntu: CVE-2026-63845 was patched at 2026-07-30
ubuntu: CVE-2026-63846 was patched at 2026-07-30
ubuntu: CVE-2026-63847 was patched at 2026-07-30
ubuntu: CVE-2026-63848 was patched at 2026-07-30
ubuntu: CVE-2026-63850 was patched at 2026-07-30
ubuntu: CVE-2026-63851 was patched at 2026-07-30
ubuntu: CVE-2026-63852 was patched at 2026-07-30
ubuntu: CVE-2026-63853 was patched at 2026-07-30
ubuntu: CVE-2026-63854 was patched at 2026-07-30
ubuntu: CVE-2026-63855 was patched at 2026-07-30
ubuntu: CVE-2026-63856 was patched at 2026-07-30
ubuntu: CVE-2026-63857 was patched at 2026-07-30
ubuntu: CVE-2026-63858 was patched at 2026-07-30
ubuntu: CVE-2026-63859 was patched at 2026-07-30
ubuntu: CVE-2026-63860 was patched at 2026-07-30
ubuntu: CVE-2026-63861 was patched at 2026-07-30
ubuntu: CVE-2026-63862 was patched at 2026-07-30
ubuntu: CVE-2026-63865 was patched at 2026-07-30
ubuntu: CVE-2026-63875 was patched at 2026-07-30
ubuntu: CVE-2026-63879 was patched at 2026-07-30
ubuntu: CVE-2026-63883 was patched at 2026-07-30
ubuntu: CVE-2026-63884 was patched at 2026-07-30
ubuntu: CVE-2026-63886 was patched at 2026-07-30
ubuntu: CVE-2026-63887 was patched at 2026-07-30
ubuntu: CVE-2026-63888 was patched at 2026-07-30
ubuntu: CVE-2026-63890 was patched at 2026-07-30
ubuntu: CVE-2026-63891 was patched at 2026-07-30
ubuntu: CVE-2026-63892 was patched at 2026-07-30
ubuntu: CVE-2026-63893 was patched at 2026-07-30
ubuntu: CVE-2026-63895 was patched at 2026-07-30
ubuntu: CVE-2026-63896 was patched at 2026-07-30
ubuntu: CVE-2026-63897 was patched at 2026-07-30
ubuntu: CVE-2026-63900 was patched at 2026-07-30
ubuntu: CVE-2026-63902 was patched at 2026-07-30
ubuntu: CVE-2026-63903 was patched at 2026-07-30
ubuntu: CVE-2026-63908 was patched at 2026-07-30
ubuntu: CVE-2026-63909 was patched at 2026-07-30
ubuntu: CVE-2026-63912 was patched at 2026-07-30
ubuntu: CVE-2026-63913 was patched at 2026-07-30
ubuntu: CVE-2026-63914 was patched at 2026-07-30
ubuntu: CVE-2026-63917 was patched at 2026-07-30
ubuntu: CVE-2026-63919 was patched at 2026-07-30
ubuntu: CVE-2026-63921 was patched at 2026-07-30
ubuntu: CVE-2026-63922 was patched at 2026-07-30
ubuntu: CVE-2026-63924 was patched at 2026-07-30
ubuntu: CVE-2026-63925 was patched at 2026-07-30
ubuntu: CVE-2026-63926 was patched at 2026-07-30
ubuntu: CVE-2026-63927 was patched at 2026-07-30
ubuntu: CVE-2026-63929 was patched at 2026-07-30
ubuntu: CVE-2026-63931 was patched at 2026-07-30
ubuntu: CVE-2026-63933 was patched at 2026-07-30
ubuntu: CVE-2026-63934 was patched at 2026-07-30
ubuntu: CVE-2026-63936 was patched at 2026-07-30
ubuntu: CVE-2026-63937 was patched at 2026-07-30
ubuntu: CVE-2026-63938 was patched at 2026-07-30
ubuntu: CVE-2026-63939 was patched at 2026-07-30
ubuntu: CVE-2026-63940 was patched at 2026-07-30
ubuntu: CVE-2026-63941 was patched at 2026-07-30
ubuntu: CVE-2026-63943 was patched at 2026-07-30
ubuntu: CVE-2026-63948 was patched at 2026-07-30
ubuntu: CVE-2026-63949 was patched at 2026-07-30
ubuntu: CVE-2026-63952 was patched at 2026-07-30
ubuntu: CVE-2026-63954 was patched at 2026-07-30
ubuntu: CVE-2026-63958 was patched at 2026-07-30
ubuntu: CVE-2026-63959 was patched at 2026-07-30
ubuntu: CVE-2026-63960 was patched at 2026-07-30
ubuntu: CVE-2026-63961 was patched at 2026-07-30
ubuntu: CVE-2026-63962 was patched at 2026-07-30
ubuntu: CVE-2026-63963 was patched at 2026-07-30
ubuntu: CVE-2026-63964 was patched at 2026-07-30
ubuntu: CVE-2026-63967 was patched at 2026-07-30
ubuntu: CVE-2026-63968 was patched at 2026-07-30
ubuntu: CVE-2026-63969 was patched at 2026-07-30
ubuntu: CVE-2026-63970 was patched at 2026-07-30
ubuntu: CVE-2026-63971 was patched at 2026-07-30
ubuntu: CVE-2026-63974 was patched at 2026-07-30
ubuntu: CVE-2026-63975 was patched at 2026-07-30
ubuntu: CVE-2026-63976 was patched at 2026-07-30
ubuntu: CVE-2026-63978 was patched at 2026-07-30
ubuntu: CVE-2026-63979 was patched at 2026-07-30
ubuntu: CVE-2026-63980 was patched at 2026-07-30
ubuntu: CVE-2026-63983 was patched at 2026-07-30
ubuntu: CVE-2026-63984 was patched at 2026-07-30
ubuntu: CVE-2026-63985 was patched at 2026-07-30
ubuntu: CVE-2026-63987 was patched at 2026-07-30
ubuntu: CVE-2026-63990 was patched at 2026-07-30
ubuntu: CVE-2026-63992 was patched at 2026-07-30
ubuntu: CVE-2026-63993 was patched at 2026-07-30
ubuntu: CVE-2026-63994 was patched at 2026-07-30
ubuntu: CVE-2026-63995 was patched at 2026-07-30
ubuntu: CVE-2026-63996 was patched at 2026-07-30
ubuntu: CVE-2026-63997 was patched at 2026-07-30
ubuntu: CVE-2026-63998 was patched at 2026-07-30
ubuntu: CVE-2026-63999 was patched at 2026-07-30
ubuntu: CVE-2026-64000 was patched at 2026-07-30
ubuntu: CVE-2026-64001 was patched at 2026-07-30
ubuntu: CVE-2026-64002 was patched at 2026-07-30
ubuntu: CVE-2026-64003 was patched at 2026-07-30
ubuntu: CVE-2026-64005 was patched at 2026-07-30
ubuntu: CVE-2026-64006 was patched at 2026-07-30
ubuntu: CVE-2026-64007 was patched at 2026-07-30
ubuntu: CVE-2026-64009 was patched at 2026-07-30
ubuntu: CVE-2026-64012 was patched at 2026-07-30
ubuntu: CVE-2026-64015 was patched at 2026-07-30
ubuntu: CVE-2026-64018 was patched at 2026-07-30
ubuntu: CVE-2026-64024 was patched at 2026-07-30
ubuntu: CVE-2026-64026 was patched at 2026-07-30
ubuntu: CVE-2026-64034 was patched at 2026-07-30
ubuntu: CVE-2026-64036 was patched at 2026-07-30
ubuntu: CVE-2026-64038 was patched at 2026-07-30
ubuntu: CVE-2026-64039 was patched at 2026-07-30
ubuntu: CVE-2026-64046 was patched at 2026-07-30
ubuntu: CVE-2026-64047 was patched at 2026-07-30
ubuntu: CVE-2026-64048 was patched at 2026-07-30
ubuntu: CVE-2026-64051 was patched at 2026-07-30
ubuntu: CVE-2026-64052 was patched at 2026-07-30
ubuntu: CVE-2026-64053 was patched at 2026-07-30
ubuntu: CVE-2026-64055 was patched at 2026-07-30
ubuntu: CVE-2026-64056 was patched at 2026-07-30
ubuntu: CVE-2026-64058 was patched at 2026-07-30
ubuntu: CVE-2026-64059 was patched at 2026-07-30
ubuntu: CVE-2026-64060 was patched at 2026-07-30
ubuntu: CVE-2026-64062 was patched at 2026-07-30
ubuntu: CVE-2026-64063 was patched at 2026-07-30
ubuntu: CVE-2026-64064 was patched at 2026-07-30
ubuntu: CVE-2026-64065 was patched at 2026-07-30
ubuntu: CVE-2026-64066 was patched at 2026-07-30
ubuntu: CVE-2026-64067 was patched at 2026-07-30
ubuntu: CVE-2026-64068 was patched at 2026-07-30
ubuntu: CVE-2026-64070 was patched at 2026-07-30
ubuntu: CVE-2026-64076 was patched at 2026-07-30
ubuntu: CVE-2026-64077 was patched at 2026-07-30
ubuntu: CVE-2026-64078 was patched at 2026-07-30
ubuntu: CVE-2026-64079 was patched at 2026-07-30
ubuntu: CVE-2026-64082 was patched at 2026-07-30
ubuntu: CVE-2026-64083 was patched at 2026-07-30
ubuntu: CVE-2026-64084 was patched at 2026-07-30
ubuntu: CVE-2026-64085 was patched at 2026-07-30
ubuntu: CVE-2026-64086 was patched at 2026-07-30
ubuntu: CVE-2026-64087 was patched at 2026-07-30
ubuntu: CVE-2026-64088 was patched at 2026-07-30
ubuntu: CVE-2026-64089 was patched at 2026-07-30
ubuntu: CVE-2026-64090 was patched at 2026-07-30
ubuntu: CVE-2026-64091 was patched at 2026-07-30
ubuntu: CVE-2026-64093 was patched at 2026-07-30
ubuntu: CVE-2026-64094 was patched at 2026-07-30
ubuntu: CVE-2026-64095 was patched at 2026-07-30
ubuntu: CVE-2026-64098 was patched at 2026-07-30
ubuntu: CVE-2026-64105 was patched at 2026-07-30
ubuntu: CVE-2026-64106 was patched at 2026-07-30
ubuntu: CVE-2026-64108 was patched at 2026-07-30
ubuntu: CVE-2026-64109 was patched at 2026-07-30
ubuntu: CVE-2026-64111 was patched at 2026-07-30
ubuntu: CVE-2026-64112 was patched at 2026-07-30
ubuntu: CVE-2026-64114 was patched at 2026-07-30
ubuntu: CVE-2026-64118 was patched at 2026-07-30
ubuntu: CVE-2026-64119 was patched at 2026-07-30
ubuntu: CVE-2026-64121 was patched at 2026-07-30
ubuntu: CVE-2026-64125 was patched at 2026-07-30
ubuntu: CVE-2026-64127 was patched at 2026-07-30
ubuntu: CVE-2026-64128 was patched at 2026-07-30
ubuntu: CVE-2026-64131 was patched at 2026-07-30
ubuntu: CVE-2026-64132 was patched at 2026-07-30
ubuntu: CVE-2026-64133 was patched at 2026-07-30
ubuntu: CVE-2026-64134 was patched at 2026-07-30
ubuntu: CVE-2026-64135 was patched at 2026-07-30
ubuntu: CVE-2026-64136 was patched at 2026-07-30
ubuntu: CVE-2026-64137 was patched at 2026-07-30
ubuntu: CVE-2026-64138 was patched at 2026-07-30
ubuntu: CVE-2026-64142 was patched at 2026-07-30
ubuntu: CVE-2026-64144 was patched at 2026-07-30
ubuntu: CVE-2026-64146 was patched at 2026-07-30
ubuntu: CVE-2026-64147 was patched at 2026-07-30
ubuntu: CVE-2026-64148 was patched at 2026-07-30
ubuntu: CVE-2026-64153 was patched at 2026-07-30
ubuntu: CVE-2026-64154 was patched at 2026-07-30
ubuntu: CVE-2026-64157 was patched at 2026-07-30
ubuntu: CVE-2026-64158 was patched at 2026-07-30
ubuntu: CVE-2026-64159 was patched at 2026-07-30
ubuntu: CVE-2026-64160 was patched at 2026-07-30
ubuntu: CVE-2026-64163 was patched at 2026-07-30
ubuntu: CVE-2026-64164 was patched at 2026-07-30
ubuntu: CVE-2026-64166 was patched at 2026-07-30
ubuntu: CVE-2026-64168 was patched at 2026-07-30
ubuntu: CVE-2026-64169 was patched at 2026-07-30
ubuntu: CVE-2026-64170 was patched at 2026-07-30
ubuntu: CVE-2026-64173 was patched at 2026-07-30
ubuntu: CVE-2026-64174 was patched at 2026-07-30
ubuntu: CVE-2026-64177 was patched at 2026-07-30
ubuntu: CVE-2026-64178 was patched at 2026-07-30
ubuntu: CVE-2026-64179 was patched at 2026-07-30
ubuntu: CVE-2026-64180 was patched at 2026-07-30
ubuntu: CVE-2026-64182 was patched at 2026-07-30
ubuntu: CVE-2026-64184 was patched at 2026-07-30
ubuntu: CVE-2026-64185 was patched at 2026-07-30
almalinux: CVE-2026-14474 was patched at 2026-07-20
debian: CVE-2026-14474 was patched at 2026-07-14
oraclelinux: CVE-2026-14474 was patched at 2026-07-20, 2026-07-22
redhat: CVE-2026-14474 was patched at 2026-07-20, 2026-07-28
altlinux: CVE-2026-53404 was patched at 2026-06-24, 2026-07-10, 2026-07-20
altlinux: CVE-2026-53434 was patched at 2026-06-24, 2026-07-10, 2026-07-20
altlinux: CVE-2026-55276 was patched at 2026-06-24, 2026-07-10, 2026-07-20
altlinux: CVE-2026-59084 was patched at 2026-07-13, 2026-07-17, 2026-07-20
debian: CVE-2026-53404 was patched at 2026-07-14
debian: CVE-2026-53434 was patched at 2026-07-14
debian: CVE-2026-55276 was patched at 2026-07-14
debian: CVE-2026-59084 was patched at 2026-07-14
redhat: CVE-2026-53404 was patched at 2026-07-22
ubuntu: CVE-2026-53404 was patched at 2026-07-30
ubuntu: CVE-2026-55276 was patched at 2026-07-30
debian: CVE-2026-49844 was patched at 2026-07-14
debian: CVE-2026-54475 was patched at 2026-07-14
almalinux: CVE-2026-43721 was patched at 2026-07-20
debian: CVE-2026-43721 was patched at 2026-07-14, 2026-07-23
oraclelinux: CVE-2026-43721 was patched at 2026-07-20
redhat: CVE-2026-43721 was patched at 2026-07-20
debian: CVE-2026-13758 was patched at 2026-07-14
debian: CVE-2026-15043 was patched at 2026-07-14
debian: CVE-2026-15747 was patched at 2026-07-14
debian: CVE-2026-49147 was patched at 2026-07-14
debian: CVE-2026-9537 was patched at 2026-07-14
altlinux: CVE-2026-11986 was patched at 2026-07-11, 2026-07-13, 2026-07-14, 2026-07-16
altlinux: CVE-2026-9099 was patched at 2026-06-28, 2026-07-01, 2026-07-02
redos: CVE-2026-33419 was patched at 2026-07-14
altlinux: CVE-2026-48588 was patched at 2026-07-27
altlinux: CVE-2026-53878 was patched at 2026-07-27
debian: CVE-2026-48588 was patched at 2026-07-14
debian: CVE-2026-53878 was patched at 2026-07-14
redos: CVE-2026-25714 was patched at 2026-07-14
redos: CVE-2026-26231 was patched at 2026-07-14
redos: CVE-2026-27783 was patched at 2026-07-14
debian: CVE-2026-44722 was patched at 2026-07-14
debian: CVE-2026-47180 was patched at 2026-07-14
debian: CVE-2026-48487 was patched at 2026-07-14
debian: CVE-2026-49854 was patched at 2026-07-14
debian: CVE-2026-49855 was patched at 2026-07-14
debian: CVE-2026-55195 was patched at 2026-07-14
debian: CVE-2026-55206 was patched at 2026-07-14
altlinux: CVE-2026-13874 was patched at 2026-07-03
altlinux: CVE-2026-13905 was patched at 2026-07-03
altlinux: CVE-2026-13923 was patched at 2026-07-03
altlinux: CVE-2026-13940 was patched at 2026-07-03
altlinux: CVE-2026-13943 was patched at 2026-07-03
altlinux: CVE-2026-13947 was patched at 2026-07-03
altlinux: CVE-2026-13950 was patched at 2026-07-03
altlinux: CVE-2026-13958 was patched at 2026-07-03
altlinux: CVE-2026-13969 was patched at 2026-07-03
altlinux: CVE-2026-13970 was patched at 2026-07-03
altlinux: CVE-2026-13971 was patched at 2026-07-03
altlinux: CVE-2026-14008 was patched at 2026-07-03
altlinux: CVE-2026-14010 was patched at 2026-07-03
altlinux: CVE-2026-14051 was patched at 2026-07-03
altlinux: CVE-2026-14088 was patched at 2026-07-03
altlinux: CVE-2026-14125 was patched at 2026-07-03
altlinux: CVE-2026-14399 was patched at 2026-07-03
altlinux: CVE-2026-14402 was patched at 2026-07-03
altlinux: CVE-2026-14408 was patched at 2026-07-03
altlinux: CVE-2026-14421 was patched at 2026-07-03
altlinux: CVE-2026-15109 was patched at 2026-07-09
altlinux: CVE-2026-15766 was patched at 2026-07-15
altlinux: CVE-2026-15770 was patched at 2026-07-15
debian: CVE-2026-13023 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13030 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-13874 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13905 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13923 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13940 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13943 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13947 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13950 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13958 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13969 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13970 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-13971 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14008 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14010 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14051 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14088 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14125 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14399 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14402 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14408 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-14421 was patched at 2026-07-05, 2026-07-14
debian: CVE-2026-15109 was patched at 2026-07-11, 2026-07-14
debian: CVE-2026-15766 was patched at 2026-07-14, 2026-07-16
debian: CVE-2026-15770 was patched at 2026-07-14, 2026-07-16
altlinux: CVE-2022-24329 was patched at 2026-06-26, 2026-07-06
altlinux: CVE-2026-60005 was patched at 2026-07-17, 2026-07-21, 2026-07-22
debian: CVE-2026-60005 was patched at 2026-07-14
ubuntu: CVE-2026-60005 was patched at 2026-07-30
debian: CVE-2026-49268 was patched at 2026-06-24
debian: CVE-2026-47767 was patched at 2026-07-14
altlinux: CVE-2026-49472 was patched at 2026-06-24, 2026-06-26, 2026-07-16
altlinux: CVE-2026-49841 was patched at 2026-06-24, 2026-06-26, 2026-07-16
altlinux: CVE-2026-49847 was patched at 2026-06-24, 2026-06-26, 2026-07-16
debian: CVE-2026-14454 was patched at 2026-07-14
debian: CVE-2026-54266 was patched at 2026-06-24
almalinux: CVE-2026-55655 was patched at 2026-07-29
almalinux: CVE-2026-59996 was patched at 2026-07-29
debian: CVE-2026-55655 was patched at 2026-06-24
debian: CVE-2026-59995 was patched at 2026-07-14
debian: CVE-2026-59996 was patched at 2026-07-14
debian: CVE-2026-59997 was patched at 2026-07-14
debian: CVE-2026-59998 was patched at 2026-07-14
oraclelinux: CVE-2026-55655 was patched at 2026-07-30
oraclelinux: CVE-2026-59996 was patched at 2026-07-30
redhat: CVE-2026-55655 was patched at 2026-07-29, 2026-07-30
redhat: CVE-2026-59996 was patched at 2026-07-29
ubuntu: CVE-2026-59995 was patched at 2026-07-30
ubuntu: CVE-2026-59996 was patched at 2026-07-30
ubuntu: CVE-2026-59997 was patched at 2026-07-30
ubuntu: CVE-2026-59998 was patched at 2026-07-30
debian: CVE-2026-46608 was patched at 2026-07-14
altlinux: CVE-2026-55404 was patched at 2026-07-27
debian: CVE-2026-55404 was patched at 2026-07-14
altlinux: CVE-2026-47692 was patched at 2026-06-25, 2026-07-02
altlinux: CVE-2026-48497 was patched at 2026-06-25, 2026-07-02
almalinux: CVE-2026-48615 was patched at 2026-07-06, 2026-07-15, 2026-07-20
altlinux: CVE-2026-48615 was patched at 2026-07-23
debian: CVE-2026-48615 was patched at 2026-06-24
debian: CVE-2026-59875 was patched at 2026-07-14
oraclelinux: CVE-2026-48615 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-48615 was patched at 2026-07-06, 2026-07-15, 2026-07-20
altlinux: CVE-2026-14355 was patched at 2026-07-12, 2026-07-15, 2026-07-23
debian: CVE-2026-14355 was patched at 2026-07-04, 2026-07-14
oraclelinux: CVE-2026-14355 was patched at 2026-07-17
ubuntu: CVE-2026-14355 was patched at 2026-07-30
debian: CVE-2026-35025 was patched at 2026-07-14
debian: CVE-2026-54906 was patched at 2026-07-14
debian: CVE-2026-13676 was patched at 2026-07-14
altlinux: CVE-2026-58208 was patched at 2026-07-10, 2026-07-13, 2026-07-14
altlinux: CVE-2026-58209 was patched at 2026-07-10, 2026-07-13, 2026-07-14
altlinux: CVE-2026-58211 was patched at 2026-07-10, 2026-07-13, 2026-07-14
altlinux: CVE-2026-58214 was patched at 2026-07-10, 2026-07-13, 2026-07-14
altlinux: CVE-2026-58254 was patched at 2026-07-10, 2026-07-13, 2026-07-14
debian: CVE-2026-58208 was patched at 2026-07-14
debian: CVE-2026-58209 was patched at 2026-07-14
debian: CVE-2026-58211 was patched at 2026-07-14
debian: CVE-2026-58214 was patched at 2026-07-14
debian: CVE-2026-58254 was patched at 2026-07-14
debian: CVE-2026-55952 was patched at 2026-07-14
redos: CVE-2026-42186 was patched at 2026-06-26
debian: CVE-2026-59947 was patched at 2026-07-14
debian: CVE-2026-54171 was patched at 2026-07-14
almalinux: CVE-2026-39822 was patched at 2026-07-09, 2026-07-13
altlinux: CVE-2026-39822 was patched at 2026-07-08, 2026-07-09, 2026-07-22, 2026-07-25
altlinux: CVE-2026-42505 was patched at 2026-07-08, 2026-07-09, 2026-07-22, 2026-07-25
debian: CVE-2026-39822 was patched at 2026-07-14
debian: CVE-2026-42505 was patched at 2026-07-14
oraclelinux: CVE-2026-39822 was patched at 2026-07-10, 2026-07-14, 2026-07-16
redhat: CVE-2026-39822 was patched at 2026-07-09, 2026-07-13
debian: CVE-2026-54515 was patched at 2026-07-14
debian: CVE-2026-54516 was patched at 2026-07-14
debian: CVE-2026-54517 was patched at 2026-07-14
debian: CVE-2026-54518 was patched at 2026-07-14
almalinux: CVE-2026-11525 was patched at 2026-07-06, 2026-07-15, 2026-07-20
almalinux: CVE-2026-6733 was patched at 2026-07-06, 2026-07-15, 2026-07-20
almalinux: CVE-2026-9678 was patched at 2026-07-06, 2026-07-15, 2026-07-20
debian: CVE-2026-11525 was patched at 2026-06-24
debian: CVE-2026-6733 was patched at 2026-06-24
debian: CVE-2026-9678 was patched at 2026-06-24
oraclelinux: CVE-2026-11525 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
oraclelinux: CVE-2026-6733 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
oraclelinux: CVE-2026-9678 was patched at 2026-07-07, 2026-07-08, 2026-07-20, 2026-07-21
redhat: CVE-2026-11525 was patched at 2026-07-06, 2026-07-15, 2026-07-20
redhat: CVE-2026-6733 was patched at 2026-07-06, 2026-07-15, 2026-07-20
redhat: CVE-2026-9678 was patched at 2026-07-06, 2026-07-15, 2026-07-20
altlinux: CVE-2026-61858 was patched at 2026-07-11, 2026-07-15, 2026-07-16
altlinux: CVE-2026-61859 was patched at 2026-07-11, 2026-07-15, 2026-07-16
debian: CVE-2026-55628 was patched at 2026-07-07, 2026-07-14
debian: CVE-2026-61858 was patched at 2026-07-14
debian: CVE-2026-61859 was patched at 2026-07-14
altlinux: CVE-2026-23632 was patched at 2026-06-25
altlinux: CVE-2026-26196 was patched at 2026-06-25
debian: CVE-2026-52761 was patched at 2026-07-14
debian: CVE-2026-55766 was patched at 2026-06-24
debian: CVE-2026-59882 was patched at 2026-07-14
altlinux: CVE-2026-53489 was patched at 2026-06-19, 2026-07-14, 2026-07-15
ubuntu: CVE-2026-53489 was patched at 2026-07-30
debian: CVE-2026-55967 was patched at 2026-07-14
redos: CVE-2026-6959 was patched at 2026-07-07
debian: CVE-2026-54291 was patched at 2026-07-14
debian: CVE-2026-6291 was patched at 2026-07-14
debian: CVE-2026-14969 was patched at 2026-07-14
debian: CVE-2026-15041 was patched at 2026-07-14
altlinux: CVE-2026-41115 was patched at 2026-06-24, 2026-07-03
redos: CVE-2026-41115 was patched at 2026-07-07
debian: CVE-2026-48817 was patched at 2026-06-24
debian: CVE-2026-54282 was patched at 2026-06-24
debian: CVE-2026-53422 was patched at 2026-07-14
altlinux: CVE-2026-13757 was patched at 2026-07-08, 2026-07-13
debian: CVE-2026-13757 was patched at 2026-07-14
debian: CVE-2026-41514 was patched at 2026-07-14
debian: CVE-2026-41515 was patched at 2026-07-14
debian: CVE-2026-44362 was patched at 2026-07-14
debian: CVE-2026-41991 was patched at 2026-07-14
ubuntu: CVE-2026-41991 was patched at 2026-07-30
almalinux: CVE-2026-33630 was patched at 2026-07-20
almalinux: CVE-2026-53166 was patched at 2026-07-13, 2026-07-14
altlinux: CVE-2025-8263 was patched at 2026-06-26
altlinux: CVE-2026-14935 was patched at 2026-07-09
altlinux: CVE-2026-33630 was patched at 2026-07-11, 2026-07-15
altlinux: CVE-2026-40011 was patched at 2026-06-29, 2026-06-30
altlinux: CVE-2026-40208 was patched at 2026-06-29, 2026-06-30
altlinux: CVE-2026-42004 was patched at 2026-06-29, 2026-06-30
altlinux: CVE-2026-53533 was patched at 2026-07-06
altlinux: CVE-2026-55191 was patched at 2026-06-20, 2026-06-22, 2026-06-24
altlinux: CVE-2026-55192 was patched at 2026-06-20, 2026-06-22, 2026-06-24
altlinux: CVE-2026-55193 was patched at 2026-06-20, 2026-06-22, 2026-06-24
altlinux: CVE-2026-55194 was patched at 2026-06-20, 2026-06-22, 2026-06-24
altlinux: CVE-2026-55648 was patched at 2026-06-20, 2026-06-22, 2026-06-24
altlinux: CVE-2026-55770 was patched at 2026-07-08, 2026-07-14, 2026-07-15
altlinux: CVE-2026-55774 was patched at 2026-07-08, 2026-07-14, 2026-07-15
altlinux: CVE-2026-55775 was patched at 2026-07-08, 2026-07-14, 2026-07-15
altlinux: CVE-2026-55776 was patched at 2026-07-08, 2026-07-14, 2026-07-15
debian: CVE-2026-0864 was patched at 2026-07-14
debian: CVE-2026-11972 was patched at 2026-07-14
debian: CVE-2026-12893 was patched at 2026-07-14
debian: CVE-2026-13324 was patched at 2026-07-14
debian: CVE-2026-13502 was patched at 2026-07-14
debian: CVE-2026-13606 was patched at 2026-07-14
debian: CVE-2026-14685 was patched at 2026-07-14
debian: CVE-2026-14686 was patched at 2026-07-14
debian: CVE-2026-14935 was patched at 2026-07-14
debian: CVE-2026-33630 was patched at 2026-07-14
debian: CVE-2026-35505 was patched at 2026-07-14
debian: CVE-2026-3886 was patched at 2026-07-14
debian: CVE-2026-40011 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-40012 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-40208 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-42004 was patched at 2026-06-25, 2026-07-14
debian: CVE-2026-42616 was patched at 2026-07-14, 2026-07-15
debian: CVE-2026-42617 was patched at 2026-07-14, 2026-07-15
debian: CVE-2026-42618 was patched at 2026-07-14, 2026-07-15
debian: CVE-2026-44517 was patched at 2026-06-24
debian: CVE-2026-44605 was patched at 2026-07-14
debian: CVE-2026-44918 was patched at 2026-07-14
debian: CVE-2026-45092 was patched at 2026-07-14
debian: CVE-2026-45093 was patched at 2026-07-14
debian: CVE-2026-45094 was patched at 2026-07-14
debian: CVE-2026-45095 was patched at 2026-07-14
debian: CVE-2026-45096 was patched at 2026-07-14
debian: CVE-2026-45097 was patched at 2026-07-14
debian: CVE-2026-45098 was patched at 2026-07-14
debian: CVE-2026-46377 was patched at 2026-07-14
debian: CVE-2026-46569 was patched at 2026-07-14, 2026-07-15
debian: CVE-2026-46570 was patched at 2026-07-14, 2026-07-15
debian: CVE-2026-46571 was patched at 2026-07-14, 2026-07-15
debian: CVE-2026-46572 was patched at 2026-07-14, 2026-07-15
debian: CVE-2026-46601 was patched at 2026-07-14
debian: CVE-2026-47081 was patched at 2026-07-14
debian: CVE-2026-47082 was patched at 2026-07-14
debian: CVE-2026-47083 was patched at 2026-07-14
debian: CVE-2026-47084 was patched at 2026-07-14
debian: CVE-2026-47086 was patched at 2026-07-14
debian: CVE-2026-47087 was patched at 2026-07-14
debian: CVE-2026-47088 was patched at 2026-07-14
debian: CVE-2026-47089 was patched at 2026-07-14
debian: CVE-2026-47241 was patched at 2026-07-14
debian: CVE-2026-48002 was patched at 2026-07-14
debian: CVE-2026-48003 was patched at 2026-07-14
debian: CVE-2026-48004 was patched at 2026-07-14
debian: CVE-2026-48749 was patched at 2026-06-26, 2026-06-28, 2026-07-14
debian: CVE-2026-48750 was patched at 2026-06-26, 2026-06-28, 2026-07-14
debian: CVE-2026-48751 was patched at 2026-06-26, 2026-06-28, 2026-07-14
debian: CVE-2026-48752 was patched at 2026-06-26, 2026-06-28, 2026-07-14
debian: CVE-2026-48755 was patched at 2026-06-26, 2026-06-28, 2026-07-14
debian: CVE-2026-48769 was patched at 2026-06-26, 2026-06-28, 2026-07-14
debian: CVE-2026-48915 was patched at 2026-07-14
debian: CVE-2026-49838 was patched at 2026-07-14
debian: CVE-2026-49861 was patched at 2026-07-14
debian: CVE-2026-49862 was patched at 2026-07-14
debian: CVE-2026-49863 was patched at 2026-07-14
debian: CVE-2026-50142 was patched at 2026-07-14
debian: CVE-2026-50162 was patched at 2026-07-14
debian: CVE-2026-50190 was patched at 2026-06-24
debian: CVE-2026-50254 was patched at 2026-07-14
debian: CVE-2026-53588 was patched at 2026-07-14
debian: CVE-2026-53589 was patched at 2026-07-14
debian: CVE-2026-53590 was patched at 2026-07-14
debian: CVE-2026-54161 was patched at 2026-07-14
debian: CVE-2026-54240 was patched at 2026-07-14
debian: CVE-2026-54241 was patched at 2026-07-14
debian: CVE-2026-54466 was patched at 2026-07-14
debian: CVE-2026-54548 was patched at 2026-07-14
debian: CVE-2026-54604 was patched at 2026-06-24
debian: CVE-2026-54706 was patched at 2026-07-14
debian: CVE-2026-54707 was patched at 2026-07-14
debian: CVE-2026-55063 was patched at 2026-07-14
debian: CVE-2026-55191 was patched at 2026-07-14
debian: CVE-2026-55192 was patched at 2026-07-14
debian: CVE-2026-55193 was patched at 2026-07-14
debian: CVE-2026-55194 was patched at 2026-07-14
debian: CVE-2026-55392 was patched at 2026-06-24
debian: CVE-2026-55520 was patched at 2026-07-14
debian: CVE-2026-55556 was patched at 2026-06-24
debian: CVE-2026-55564 was patched at 2026-07-14
debian: CVE-2026-55621 was patched at 2026-06-26, 2026-06-28, 2026-07-14
debian: CVE-2026-55622 was patched at 2026-06-26, 2026-06-28, 2026-07-14
debian: CVE-2026-55648 was patched at 2026-07-14
debian: CVE-2026-55688 was patched at 2026-07-14
debian: CVE-2026-55748 was patched at 2026-06-24
debian: CVE-2026-56135 was patched at 2026-07-14, 2026-07-15
debian: CVE-2026-56136 was patched at 2026-07-14, 2026-07-15
debian: CVE-2026-57062 was patched at 2026-06-24
debian: CVE-2026-57825 was patched at 2026-07-10, 2026-07-14
debian: CVE-2026-58382 was patched at 2026-07-14
debian: CVE-2026-58383 was patched at 2026-07-14
debian: CVE-2026-58385 was patched at 2026-07-14
debian: CVE-2026-58386 was patched at 2026-07-14
debian: CVE-2026-58387 was patched at 2026-07-14
debian: CVE-2026-58388 was patched at 2026-07-14
debian: CVE-2026-61627 was patched at 2026-07-14
debian: CVE-2026-62294 was patched at 2026-07-14
debian: CVE-2026-62318 was patched at 2026-07-14
debian: CVE-2026-62319 was patched at 2026-07-14
debian: CVE-2026-62320 was patched at 2026-07-14
debian: CVE-2026-62321 was patched at 2026-07-14
debian: CVE-2026-6425 was patched at 2026-07-14
debian: CVE-2026-8343 was patched at 2026-07-14
oraclelinux: CVE-2026-33630 was patched at 2026-07-21
oraclelinux: CVE-2026-45992 was patched at 2026-07-02
oraclelinux: CVE-2026-48002 was patched at 2026-06-23
oraclelinux: CVE-2026-48003 was patched at 2026-06-23
oraclelinux: CVE-2026-53166 was patched at 2026-07-14, 2026-07-15
oraclelinux: CVE-2026-8343 was patched at 2026-06-23
redhat: CVE-2026-53166 was patched at 2026-07-13, 2026-07-14, 2026-07-15, 2026-07-16, 2026-07-17
redos: CVE-2023-53502 was patched at 2026-06-29
redos: CVE-2023-53805 was patched at 2026-07-01
redos: CVE-2023-54054 was patched at 2026-07-02
redos: CVE-2023-54103 was patched at 2026-07-02
redos: CVE-2026-24791 was patched at 2026-07-14
ubuntu: CVE-2026-42616 was patched at 2026-07-30
ubuntu: CVE-2026-42617 was patched at 2026-07-30
ubuntu: CVE-2026-42618 was patched at 2026-07-30
ubuntu: CVE-2026-46569 was patched at 2026-07-30
ubuntu: CVE-2026-46570 was patched at 2026-07-30
ubuntu: CVE-2026-46571 was patched at 2026-07-30
ubuntu: CVE-2026-46572 was patched at 2026-07-30
ubuntu: CVE-2026-50142 was patched at 2026-07-30
ubuntu: CVE-2026-54240 was patched at 2026-07-30
ubuntu: CVE-2026-54241 was patched at 2026-07-30
ubuntu: CVE-2026-55191 was patched at 2026-07-30
ubuntu: CVE-2026-55192 was patched at 2026-07-30
ubuntu: CVE-2026-55193 was patched at 2026-07-30
ubuntu: CVE-2026-55194 was patched at 2026-07-30
ubuntu: CVE-2026-55564 was patched at 2026-07-30
ubuntu: CVE-2026-55648 was patched at 2026-07-30
ubuntu: CVE-2026-56135 was patched at 2026-07-30
ubuntu: CVE-2026-56136 was patched at 2026-07-30
altlinux: CVE-2026-53540 was patched at 2026-07-01
debian: CVE-2026-53540 was patched at 2026-06-24
debian: CVE-2026-49460 was patched at 2026-06-24
redos: CVE-2026-49460 was patched at 2026-07-29
altlinux: CVE-2026-39894 was patched at 2026-07-25, 2026-07-29
debian: CVE-2026-39894 was patched at 2026-07-14
debian: CVE-2026-59831 was patched at 2026-07-14
debian: CVE-2026-13523 was patched at 2026-07-14
debian: CVE-2026-57234 was patched at 2026-07-14