CVE-2026-12996Exploitation status Not known exploited Fix YesPublished 07/30/2026 Severity Medium CVE-2026-14355ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD Exploitation status Not known exploited Fix YesPublished 07/03/2026 Severity Medium CVE-2026-56968Exploitation status Not known exploited Fix YesPublished 06/23/2026 Severity Low CVE-2026-49975Apache HTTP Server: mod_http2 denial of service Exploitation status Public exploit Fix YesPublished 06/08/2026 Severity High CVE-2026-9256NGINX ngx_http_rewrite_module vulnerability Exploitation status Not known exploited Fix YesPublished 05/22/2026 Severity Critical CVE-2026-46333ptrace: slightly saner 'get_dumpable()' logic Exploitation status Public exploit Fix YesPublished 05/15/2026 Severity High CVE-2026-31431crypto: algif_aead - Revert to operating out-of-place Exploitation status KEV Fix YesPublished 04/22/2026 Severity High CVE-2026-41082Exploitation status Public exploit Fix YesPublished 04/16/2026 Severity High CVE-2026-34757LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure Exploitation status Public exploit Fix YesPublished 04/09/2026 Severity Medium CVE-2026-4775Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing Exploitation status Not known exploited Fix Not confirmed Published 03/24/2026 Severity High CVE-2026-1940Gstreamer: incomplete fix of cve-2026-1940 Exploitation status Not known exploited Fix Not confirmed Published 03/23/2026 Severity Medium CVE-2025-63261Exploitation status Not known exploited Fix Not confirmed Published 03/20/2026 Severity High CVE-2026-3497Exploitation status Not known exploited Fix YesPublished 03/12/2026 Severity Low CVE-2026-25506MUNGE has a buffer overflow in message unpacking allows key leakage and credential forgery Exploitation status Not known exploited Fix YesPublished 02/10/2026 Severity High CVE-2025-64098FastDDS has Out-of-memory in readOctetVector via Manipulated DATA Submessage when DDS Security is enabled Exploitation status Not known exploited Fix YesPublished 02/03/2026 Severity Low CVE-2025-62799FastDDS's heap buffer overflow in RTPS DATA_FRAG enables unauthenticated DoS (potential RCE) Exploitation status Not known exploited Fix YesPublished 02/03/2026 Severity High CVE-2025-62603FastDDS has Out-of-memory while parsing GenericMessage when DDS Security is enabled Exploitation status Not known exploited Fix YesPublished 02/03/2026 Severity Low CVE-2025-62602FastDDS has heap buffer overflow in readData via Manipulated DATA Submessage when DDS Security is enabled Exploitation status Not known exploited Fix YesPublished 02/03/2026 Severity Low CVE-2025-62600eprosima Fast DDS affected by Out-of-Memory in readBinaryPropertySeq via Manipulated DATA Submessage when DDS Security is enabled Exploitation status Public exploit Fix YesPublished 02/03/2026 Severity High CVE-2025-62599eprosima Fast DDS affected by Out-of-Memory in readPropertySeq via Manipulated DATA Submessage when DDS Security is enabled Exploitation status Not known exploited Fix YesPublished 02/03/2026 Severity High CVE-2026-25061tcpflow has TIM Element OOB Write in wifipcap Exploitation status Not known exploited Fix Not confirmed Published 01/29/2026 Severity Medium CVE-2026-24765PHPUnit Vulnerable to Unsafe Deserialization in PHPT Code Coverage Handling Exploitation status Not known exploited Fix Not confirmed Published 01/27/2026 Severity High CVE-2025-68670xrdp improperly checks bounds of domain string length, which leads to Stack-based Buffer Overflow Exploitation status Not known exploited Fix Not confirmed Published 01/27/2026 Severity Critical CVE-2026-24061Exploitation status KEV Fix Not confirmed Published 01/21/2026 Severity Critical CVE-2026-23490pyasn1 has a DoS vulnerability in decoder Exploitation status Public exploit Fix YesPublished 01/16/2026 Severity High CVE-2025-68615Net-SNMP snmptrapd crash Exploitation status Not known exploited Fix YesPublished 12/22/2025 Severity Critical CVE-2025-6966Null-pointer dereference in python-apt TagSection.keys() Exploitation status Not known exploited Fix YesPublished 12/05/2025 Severity Medium CVE-2025-63498Exploitation status Public exploit Fix Not confirmed Published 11/24/2025 Severity Medium CVE-2025-64512pdfminer.six vulnerable to Arbitrary Code Execution via Crafted PDF Input Exploitation status Public exploit Fix Not confirmed Published 11/10/2025 Severity High CVE-2025-62230Xorg: xwayland: use-after-free in xkb client resource removal Exploitation status Not known exploited Fix YesPublished 10/30/2025 Severity High CVE-2025-62231Xorg: xmayland: value overflow in xkbsetcompatmap() Exploitation status Not known exploited Fix YesPublished 10/30/2025 Severity High CVE-2025-10934GIMP XWD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability Exploitation status Not known exploited Fix Not confirmed Published 10/29/2025 Severity High CVE-2025-10922GIMP DCM File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability Exploitation status Not known exploited Fix Not confirmed Published 10/29/2025 Severity High CVE-2025-10921GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability Exploitation status Not known exploited Fix Not confirmed Published 10/29/2025 Severity High CVE-2025-39923dmaengine: qcom: bam_dma: Fix DT error handling for num-channels/ees Exploitation status Not confirmed Fix YesPublished 10/01/2025 Severity Unknown CVE-2025-39920pcmcia: Add error handling for add_interval() in do_validate_mem() Exploitation status Not confirmed Fix YesPublished 10/01/2025 Severity Unknown CVE-2025-39916mm/damon/reclaim: avoid divide-by-zero in damon_reclaim_apply_parameters() Exploitation status Not confirmed Fix YesPublished 10/01/2025 Severity Unknown CVE-2025-39914tracing: Silence warning when chunk allocation fails in trace_pid_write Exploitation status Not confirmed Fix YesPublished 10/01/2025 Severity Unknown CVE-2025-39913tcp_bpf: Call sk_msg_free() when tcp_bpf_send_verdict() fails to allocate psock->cork. Exploitation status Not known exploited Fix YesPublished 10/01/2025 Severity Unknown CVE-2025-39911i40e: fix IRQ freeing in i40e_vsi_request_irq_msix error path Exploitation status Not known exploited Fix YesPublished 10/01/2025 Severity Unknown CVE-2025-39909mm/damon/lru_sort: avoid divide-by-zero in damon_lru_sort_apply_parameters() Exploitation status Not confirmed Fix YesPublished 10/01/2025 Severity Unknown CVE-2025-39907mtd: rawnand: stm32_fmc2: avoid overlapping mappings on ECC buffer Exploitation status Not confirmed Fix YesPublished 10/01/2025 Severity Unknown CVE-2025-39902mm/slub: avoid accessing metadata when pointer is invalid in object_err() Exploitation status Not confirmed Fix YesPublished 10/01/2025 Severity High CVE-2025-39894netfilter: br_netfilter: do not check confirmed bit in br_nf_local_in() after confirm Exploitation status Not confirmed Fix YesPublished 10/01/2025 Severity High CVE-2025-39891wifi: mwifiex: Initialize the chan_stats array to zero Exploitation status Not confirmed Fix YesPublished 10/01/2025 Severity Unknown CVE-2025-41244VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246) Exploitation status KEV Fix YesPublished 09/29/2025 Severity High CVE-2025-39885ocfs2: fix recursive semaphore deadlock in fiemap call Exploitation status Not confirmed Fix YesPublished 09/23/2025 Severity Unknown CVE-2025-39883mm/memory-failure: fix VM_BUG_ON_PAGE(PagePoisoned(page)) when unpoison memory Exploitation status Not known exploited Fix YesPublished 09/23/2025 Severity Unknown CVE-2025-39881kernfs: Fix UAF in polling when open file is released Exploitation status Not confirmed Fix YesPublished 09/23/2025 Severity High CVE-2025-39880libceph: fix invalid accesses to ceph_connection_v1_info Exploitation status Not confirmed Fix YesPublished 09/23/2025 Severity Critical CVE-2025-39877mm/damon/sysfs: fix use-after-free in state_show() Exploitation status Not confirmed Fix YesPublished 09/23/2025 Severity Unknown CVE-2025-39876net: fec: Fix possible NPD in fec_enet_phy_reset_after_clk_enable() Exploitation status Not confirmed Fix YesPublished 09/23/2025 Severity Unknown CVE-2025-39873can: xilinx_can: xcan_write_frame(): fix use-after-free of transmitted SKB Exploitation status Not confirmed Fix YesPublished 09/23/2025 Severity High CVE-2025-39870dmaengine: idxd: Fix double free in idxd_setup_wqs() Exploitation status Not confirmed Fix YesPublished 09/23/2025 Severity Unknown CVE-2025-39869dmaengine: ti: edma: Fix memory allocation size for queue_priority_map Exploitation status Not confirmed Fix YesPublished 09/23/2025 Severity High CVE-2025-39866fs: writeback: fix use-after-free in __mark_inode_dirty() Exploitation status Not confirmed Fix YesPublished 09/19/2025 Severity High CVE-2025-39865tee: fix NULL pointer dereference in tee_shm_put Exploitation status Not confirmed Fix YesPublished 09/19/2025 Severity Unknown CVE-2025-39864wifi: cfg80211: fix use-after-free in cmp_bss() Exploitation status Not known exploited Fix YesPublished 09/19/2025 Severity High CVE-2025-39860Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen() Exploitation status Not confirmed Fix YesPublished 09/19/2025 Severity High CVE-2025-39857net/smc: fix one NULL pointer dereference in smc_ib_is_sg_need_sync() Exploitation status Not confirmed Fix YesPublished 09/19/2025 Severity High CVE-2025-39853i40e: Fix potential invalid access when MAC list is empty Exploitation status Not confirmed Fix YesPublished 09/19/2025 Severity Unknown CVE-2025-39849wifi: cfg80211: sme: cap SSID length in __cfg80211_connect_result() Exploitation status Not known exploited Fix YesPublished 09/19/2025 Severity High CVE-2025-39848ax25: properly unshare skbs in ax25_kiss_rcv() Exploitation status Not confirmed Fix YesPublished 09/19/2025 Severity High CVE-2025-39847ppp: fix memory leak in pad_compress_skb Exploitation status Not confirmed Fix YesPublished 09/19/2025 Severity Unknown CVE-2025-39846pcmcia: Fix a NULL pointer dereference in __iodyn_find_io_region() Exploitation status Not confirmed Fix YesPublished 09/19/2025 Severity Unknown CVE-2025-39845x86/mm/64: define ARCH_PAGE_TABLE_SYNC_MASK and arch_sync_kernel_mappings() Exploitation status Not confirmed Fix YesPublished 09/19/2025 Severity Unknown CVE-2025-39844mm: move page table sync declarations to linux/pgtable.h Exploitation status Not confirmed Fix YesPublished 09/19/2025 Severity Unknown CVE-2025-39843mm: slub: avoid wake up kswapd in set_track_prepare Exploitation status Not confirmed Fix YesPublished 09/19/2025 Severity Unknown CVE-2025-39842ocfs2: prevent release journal inode after journal shutdown Exploitation status Not confirmed Fix YesPublished 09/19/2025 Severity Unknown CVE-2025-39841scsi: lpfc: Fix buffer free/clear order in deferred receive path Exploitation status Not known exploited Fix YesPublished 09/19/2025 Severity Critical CVE-2025-39839batman-adv: fix OOB read/write in network-coding decode Exploitation status Not confirmed Fix YesPublished 09/19/2025 Severity High CVE-2025-39838cifs: prevent NULL pointer dereference in UTF16 conversion Exploitation status Not confirmed Fix YesPublished 09/19/2025 Severity Unknown CVE-2025-39835xfs: do not propagate ENODATA disk errors into xattr code Exploitation status Not confirmed Fix YesPublished 09/16/2025 Severity Unknown CVE-2025-39828atm: atmtcp: Prevent arbitrary write in atmtcp_recv_control(). Exploitation status Not confirmed Fix YesPublished 09/16/2025 Severity Unknown CVE-2025-39827net: rose: include node references in rose_neigh refcount Exploitation status Not confirmed Fix YesPublished 09/16/2025 Severity High CVE-2025-39826net: rose: convert 'use' field to refcount_t Exploitation status Not confirmed Fix YesPublished 09/16/2025 Severity High CVE-2025-39825smb: client: fix race with concurrent opens in rename(2) Exploitation status Not known exploited Fix YesPublished 09/16/2025 Severity High CVE-2025-39824HID: asus: fix UAF via HID_CLAIMED_INPUT validation Exploitation status Not confirmed Fix YesPublished 09/16/2025 Severity Unknown CVE-2025-39823KVM: x86: use array_index_nospec with indices that come from guest Exploitation status Not confirmed Fix YesPublished 09/16/2025 Severity Unknown CVE-2025-39819fs/smb: Fix inconsistent refcnt update Exploitation status Not confirmed Fix YesPublished 09/16/2025 Severity Unknown CVE-2025-39817efivarfs: Fix slab-out-of-bounds in efivarfs_d_compare Exploitation status Not known exploited Fix YesPublished 09/16/2025 Severity High CVE-2025-39813ftrace: Fix potential warning in trace_printk_seq during ftrace_dump Exploitation status Not confirmed Fix YesPublished 09/16/2025 Severity Unknown CVE-2025-39812sctp: initialize more fields in sctp_v6_from_sk() Exploitation status Not confirmed Fix YesPublished 09/16/2025 Severity Unknown CVE-2025-39808HID: hid-ntrig: fix unable to handle page fault in ntrig_report_version() Exploitation status Not confirmed Fix YesPublished 09/16/2025 Severity Unknown CVE-2025-39806HID: multitouch: fix slab out-of-bounds access in mt_report_fixup() Exploitation status Not known exploited Fix YesPublished 09/16/2025 Severity High CVE-2022-50327ACPI: processor: idle: Check acpi_fetch_acpi_dev() return value Exploitation status Not confirmed Fix YesPublished 09/15/2025 Severity Unknown CVE-2023-53259VMCI: check context->notify_page after call to get_user_pages_fast() to avoid GPF Exploitation status Not confirmed Fix YesPublished 09/15/2025 Severity Unknown CVE-2025-39801usb: dwc3: Remove WARN_ON for device endpoint command timeouts Exploitation status Not confirmed Fix YesPublished 09/15/2025 Severity Unknown CVE-2025-39800btrfs: abort transaction on unexpected eb generation at btrfs_copy_root() Exploitation status Not confirmed Fix YesPublished 09/15/2025 Severity High CVE-2025-39798NFS: Fix the setting of capabilities when automounting a new filesystem Exploitation status Not confirmed Fix YesPublished 09/12/2025 Severity High CVE-2025-39795block: avoid possible overflow for chunk_sectors check in blk_stack_limits() Exploitation status Not confirmed Fix YesPublished 09/12/2025 Severity Unknown CVE-2025-39794ARM: tegra: Use I/O memcpy to write to IRAM Exploitation status Not confirmed Fix YesPublished 09/12/2025 Severity Unknown CVE-2025-9086Out of bounds read for cookie path Exploitation status Not known exploited Fix YesPublished 09/12/2025 Severity High CVE-2025-39790bus: mhi: host: Detect events pointing to unexpected TREs Exploitation status Not confirmed Fix YesPublished 09/11/2025 Severity High CVE-2025-39788scsi: ufs: exynos: Fix programming of HCI_UTRL_NEXUS_TYPE Exploitation status Not confirmed Fix YesPublished 09/11/2025 Severity Unknown CVE-2025-39787soc: qcom: mdt_loader: Ensure we don't read past the ELF header Exploitation status Not confirmed Fix YesPublished 09/11/2025 Severity High CVE-2025-39783PCI: endpoint: Fix configfs group list head handling Exploitation status Not confirmed Fix YesPublished 09/11/2025 Severity Unknown CVE-2025-39782jbd2: prevent softlockup in jbd2_log_do_checkpoint() Exploitation status Not confirmed Fix YesPublished 09/11/2025 Severity Unknown CVE-2025-39776mm/debug_vm_pgtable: clear page table entries at destroy_args() Exploitation status Not confirmed Fix YesPublished 09/11/2025 Severity High CVE-2025-39773net: bridge: fix soft lockup in br_multicast_query_expired() Exploitation status Not confirmed Fix YesPublished 09/11/2025 Severity Unknown