Skip to content
← All tracked CVEs

Updated 04:00

High severity

High15d SLA

Our service-level agreement (SLA) gives a high vulnerability a fix within 15 days of publication. 416 CVEs are tracked here: open, or fixed in the last 30 days.

Status
CVEStatusSummaryReleaseClock startedDeadlineFixedTime to fix
OpenPostgreSQL refint type confusion enables arbitrary code execution as DB OS user; affects <18.5/17.11/16.15/15.19/14.24secure-packages-25.11Aug 25, 2026Sep 9, 2026
OpenPostgreSQL stack buffer overflow via OUT parameter count in argument name matching; 0x0/0x1 writessecure-packages-25.11Aug 25, 2026Sep 9, 2026
Fixed within SLAUse-after-free in ieee80211_prepare_and_rx_handle from mesh skb->cb reuse during fast-RXsecure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 27, 20262 days
Fixed within SLAUse-after-free from skb->cb reuse in mac80211 mesh fast-RX rate handlingsecure-packages-rollingAug 24, 2026Sep 8, 2026Aug 27, 20263 days
Fixed within SLAV8 type confusion enables remote code execution within Chrome sandbox pre-151.0.7922.169secure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAANGLE buffer overflow in Chrome Android <151.0.7922.169 enables sandbox escape remote code executionsecure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAWebGL use-after-free in Chrome <151.0.7922.169 enables sandbox RCE via crafted HTMLsecure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAChrome <151.0.7922.169 USB race enables code execution outside sandbox via crafted HTMLsecure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAV8 miscalculation enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.169secure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAChrome Mac <151.0.7922.169 Browser use-after-free enables remote sandbox-escape RCE via crafted HTMLsecure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAGoogle Chrome <151.0.7922.169 V8 type confusion allows sandboxed RCE via crafted HTMLsecure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAChrome CredentialProvider link-following on Windows allows local sandbox escape pre-151.0.7922.169secure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLABuffer overflow in Chrome WebGL before 151.0.7922.169 enables RCE outside sandbox via crafted HTML page.secure-packages-rollingAug 24, 2026Sep 8, 2026Aug 25, 20261 day
Fixed within SLAV8 type confusion in Chrome pre-151.0.7922.169 enables sandboxed RCE via crafted HTMLsecure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAChrome Android ANGLE buffer overflow before 151.0.7922.169 enables out-of-sandbox RCEsecure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAUse-after-free in Chrome WebGL pre-151.0.7922.169 allows sandboxed RCE via crafted HTML pagesecure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAChrome <151.0.7922.169 USB race leads to sandbox escape RCE from crafted HTMLsecure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAIncorrect calculation in V8 allows sandboxed RCE via crafted HTML in Chrome <151.0.7922.169secure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAHigh-severity Chrome Mac Browser use-after-free pre-151.0.7922.169 allows RCE outside sandbox via crafted HTMLsecure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAChrome V8 type confusion allows sandboxed RCE via crafted HTML pre-151.0.7922.169secure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAChrome Windows CredentialProvider link-following bug allows local arbitrary code execution outside sandbox pre-151.0.7922.169secure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLACritical WebGL buffer overflow in Chrome <151.0.7922.169 enables sandbox-escape RCE via crafted HTMLsecure-packages-26.05Aug 25, 2026Sep 9, 2026Aug 25, 2026same day
Fixed within SLAKVM guest_memfd memslot offset+size signed overflow bypasses i_size bound checksecure-packages-rollingAug 18, 2026Sep 2, 2026Aug 25, 20267 days
Fixed within SLAHSR RCU readers race with RTM_DELLINK node frees, causing use-after-freesecure-packages-rollingAug 18, 2026Sep 2, 2026Aug 25, 20267 days
Fixed within SLAKVM guest_memfd uses signed offset/size; sum overflow bypasses memslot binding file-size checksecure-packages-26.05Aug 19, 2026Sep 3, 2026Aug 19, 2026same day
Fixed within SLAHSR RTM_DELLINK frees nodes without RCU, causing generic-netlink reader use-after-freesecure-packages-26.05Aug 19, 2026Sep 3, 2026Aug 19, 2026same day
Fixed within SLABlink use-after-free enables sandboxed RCE via crafted HTML in Chrome <151.0.7922.137secure-packages-25.11Aug 18, 2026Sep 2, 2026Aug 19, 20261 day
Fixed within SLAChrome <151.0.7922.137 HTML use-after-free enables sandboxed remote code execution via crafted pagesecure-packages-25.11Aug 18, 2026Sep 2, 2026Aug 19, 20261 day
Fixed within SLAUse-after-free in Chrome Extensions pre-151.0.7922.137 enables sandboxed code execution via malicious extensionsecure-packages-25.11Aug 18, 2026Sep 2, 2026Aug 19, 20261 day
Fixed within SLAGoogle Chrome Mac TabStrip use-after-free enables sandbox escape from compromised renderer via crafted HTML (pre-151.0.7922.137)secure-packages-25.11Aug 18, 2026Sep 2, 2026Aug 19, 20261 day
Fixed within SLAHigh-severity V8 use-after-free in Chrome <151.0.7922.137 enables sandboxed RCE via crafted HTMLsecure-packages-25.11Aug 18, 2026Sep 2, 2026Aug 19, 20261 day
Fixed within SLAChrome <151.0.7922.137 Blink use-after-free allows sandboxed remote code execution via crafted HTMLsecure-packages-rollingAug 18, 2026Sep 2, 2026Aug 19, 20261 day
Fixed within SLAChrome <151.0.7922.137 HTML use-after-free enables sandboxed RCE via crafted pagesecure-packages-rollingAug 18, 2026Sep 2, 2026Aug 19, 20261 day
Fixed within SLAUse-after-free in Chrome Extensions pre-151.0.7922.137 enables sandboxed arbitrary code executionsecure-packages-rollingAug 18, 2026Sep 2, 2026Aug 19, 20261 day
Fixed within SLAHigh-severity TabStrip use-after-free enables sandbox escape via HTML on Chrome Mac <151.0.7922.137secure-packages-rollingAug 18, 2026Sep 2, 2026Aug 19, 20261 day
Fixed within SLAUse-after-free in Chrome V8 pre-151.0.7922.137 allows sandboxed remote code executionsecure-packages-rollingAug 18, 2026Sep 2, 2026Aug 19, 20261 day
Fixed within SLAKVM guest_memfd offset+size treated signed, letting negative sum bypass file size checksecure-packages-25.11Aug 17, 2026Sep 1, 2026Aug 18, 20261 day
Fixed within SLAFFmpeg 7.0–8.1.2 vf_quirc heap OOB write via crafted PGS/SUP subtitles mismatched dimensionssecure-packages-rollingAug 10, 2026Aug 25, 2026Aug 18, 20268 days
Fixed within SLAHeap out-of-bounds write in FFmpeg PNG/APNG encoder eXIf handling (≤8.1.2)secure-packages-rollingAug 10, 2026Aug 25, 2026Aug 18, 20268 days
Fixed within SLAFFmpeg <=8.1.2 MACE6 CAF bytes_per_packet integer overflow causes heap OOB write, RCEsecure-packages-rollingAug 10, 2026Aug 25, 2026Aug 18, 20268 days
Fixed within SLAFFmpeg up to 8.1.2 LCL/ZLIB decoder leaks uninitialized heap; short inflate enables ASLR bypasssecure-packages-rollingAug 10, 2026Aug 25, 2026Aug 18, 20268 days
Fixed within SLAFFmpeg ≤8.1.2 IAMF demuxer uncontrolled allocation from 17-byte input via count_labelsecure-packages-rollingAug 10, 2026Aug 25, 2026Aug 18, 20268 days
Fixed within SLAFFmpeg ≤8.1.2 vf_hqdn3d heap OOB write when -reinit_filter 0 and resolution increasessecure-packages-rollingAug 10, 2026Aug 25, 2026Aug 18, 20268 days
Fixed within SLAFFmpeg 3.0-8.1.2 vf_swaprect OOB write on odd-width NV12 frames causing heap corruptionsecure-packages-rollingAug 10, 2026Aug 25, 2026Aug 18, 20268 days
Fixed within SLAFFmpeg 3.4-8.1.2 vf_floodfill OOB write with -reinit_filter 0, heap corruptionsecure-packages-rollingAug 10, 2026Aug 25, 2026Aug 18, 20268 days
Fixed within SLAFFmpeg <=8.1.2 heap corruption via TY demuxer OOB write using crafted ffconcat with -safe 0secure-packages-rollingAug 10, 2026Aug 25, 2026Aug 18, 20268 days
Fixed within SLAFFmpeg 2.7–8.1.2 TDSC decoder OOB write causing heap corruption and potential RCEsecure-packages-rollingAug 10, 2026Aug 25, 2026Aug 18, 20268 days
Fixed within SLAmlx5e XSK race: unlocked ICOSQ IRQ trigger during NAPI affinity change causes CQE errorssecure-packages-rollingAug 12, 2026Aug 27, 2026Aug 15, 20262 days
Fixed within SLAmlx5e XSK: Unprotected ICOSQ IRQ trigger races with NAPI and CPU affinity changessecure-packages-26.05Aug 12, 2026Aug 27, 2026Aug 15, 20262 days
Fixed within SLALinux iwlwifi BA handlers use ffs on zero sta_mask, causing out-of-bounds accesssecure-packages-25.11Aug 14, 2026Aug 29, 2026Aug 15, 2026same day