VendorsLinuxlinux_kernelall versions
Vulnerabilities

Linux Kernel

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19321CVEs
CVE-2026-65083
NVIDIA OpenShell for Linux contains a vulnerability in its sandbox provisioning API, where an attacker could cause an incomplete list of disallowed inputs. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, data tampering, and denial of service.
Published 2026-08-25 · Analyzed
9.9EPSS 0.009
CVE-2026-9135
Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation
Published 2026-07-17 · Analyzed
9.9EPSS 0.008
CVE-2026-82013
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-09-22 · Analyzed
9.9EPSS 0.008
CVE-2026-65093
NVIDIA OpenShell for Linux contains a vulnerability where an attacker could cause a sandbox escape. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.
Published 2026-08-25 · Analyzed
9.9EPSS 0.008
CVE-2026-64878
Command Injection
Published 2026-07-21 · Analyzed
9.9EPSS 0.008
CVE-2026-2749
Path traversal in Centreon Open Tickets
Published 2026-02-27 · Analyzed
9.9EPSS 0.006
CVE-2026-8859
Path Traversal in APIRequest Component via Content-Disposition Header
Published 2026-07-17 · Analyzed
9.9EPSS 0.006
CVE-2026-82008
Adobe Campaign Classic (ACC) | Improper Input Validation (CWE-20)
Published 2026-09-22 · Analyzed
9.9EPSS 0.005
CVE-2026-8635
Arbitrary Code Execution in Python Interpreter Component
Published 2026-07-17 · Analyzed
9.9EPSS 0.005
CVE-2026-89276
Adobe Campaign Classic (ACC) | Improper Control of Generation of Code ('Code Injection') (CWE-94)
Published 2026-09-22 · Analyzed
9.9EPSS 0.005
CVE-2026-82443
Adobe Campaign Classic (ACC) | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-09-22 · Analyzed
9.9EPSS 0.004
CVE-2022-47986
IBM Aspera Faspex code execution
Published 2023-02-17 · Analyzed
9.8KEV1 PoCEPSS 1.000
CVE-2020-13160
AnyDesk before 5.5.3 on Linux and FreeBSD has a format string vulnerability that can be exploited for remote code execution.
Published 2020-06-09 · Modified
9.81 PoCEPSS 0.806
CVE-2024-1222
Incorrect authorization controls in PaperCut NG/MF APIs
Published 2024-03-14 · Analyzed
9.8EPSS 0.640
CVE-2023-28503
Authentication bypass in UniRPC's udadmin service
Published 2023-03-29 · Modified
9.8EPSS 0.621
CVE-2023-28502
Stack buffer overflow in UniRPC's udadmin_server service
Published 2023-03-29 · Modified
9.8EPSS 0.611
CVE-2021-43267
An issue was discovered in net/tipc/crypto.c in the Linux kernel before 5.14.16. The Transparent Inter-Process Communication (TIPC) functionality allows remote attackers to exploit insufficient validation of user-supplied sizes for the MSG_CRYPTO message type.
Published 2021-11-02 · Modified
9.8EPSS 0.579
CVE-2022-22972
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
Published 2022-05-20 · Modified
9.8EPSS 0.563
CVE-2022-22956
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
Published 2022-04-13 · Modified
9.8EPSS 0.498
CVE-2022-47939
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. fs/ksmbd/smb2pdu.c has a use-after-free and OOPS for SMB2_TREE_DISCONNECT.
Published 2022-12-23 · Modified
9.8EPSS 0.464
CVE-2017-11282
Adobe Flash Player has an exploitable memory corruption vulnerability in the MP4 atom parser. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
Published 2017-12-01 · Modified
9.81 PoCEPSS 0.348
CVE-2017-11281
Adobe Flash Player has an exploitable memory corruption vulnerability in the text handling function. Successful exploitation could lead to arbitrary code execution. This affects 26.0.0.151 and earlier.
Published 2017-12-01 · Modified
9.82 PoCEPSS 0.339
CVE-2025-13315
Unauthenticated log access in Twonky Server
Published 2025-11-19 · Analyzed
9.8EPSS 0.323
CVE-2023-52755
ksmbd: fix slab out of bounds write in smb_inherit_dacl()
Published 2024-05-21 · Modified
9.8EPSS 0.279
CVE-2025-8868
Chef Automate compliance service SQL Injection Vulnerability
Published 2025-09-29 · Analyzed
9.8EPSS 0.243
CVE-2022-31656
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability affecting local domain users. A malicious actor with network access to the UI may be able to obtain administrative access without the need to authenticate.
Published 2022-08-05 · Modified
9.8EPSS 0.229
CVE-2023-52440
ksmbd: fix slub overflow in ksmbd_decode_ntlmssp_auth_blob()
Published 2024-02-21 · Modified
9.8EPSS 0.219
CVE-2019-12409
The 8.1.1 and 8.2.0 releases of Apache Solr contain an insecure setting for the ENABLE_REMOTE_JMX_OPTS configuration option in the default solr.in.sh configuration file shipping with Solr. If you use the default solr.in.sh file from the affected releases, then JMX monitoring will be enabled and exposed on RMI_PORT (default=18983), without any authentication. If this port is opened for inbound traffic in your firewall, then anyone with network access to your Solr nodes will be able to access JMX, which may in turn allow them to upload malicious code for execution on the Solr server.
Published 2019-11-18 · Modified
9.8EPSS 0.214
CVE-2025-37924
ksmbd: fix use-after-free in kerberos authentication
Published 2025-05-20 · Modified
9.8EPSS 0.212
CVE-2019-16746
An issue was discovered in net/wireless/nl80211.c in the Linux kernel through 5.2.17. It does not check the length of variable elements in a beacon head, leading to a buffer overflow.
Published 2019-09-24 · Modified
9.8EPSS 0.127
CVE-2025-36038
IBM WebSphere Application Server code execution
Published 2025-06-25 · Analyzed
9.8EPSS 0.108
CVE-2016-4121
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.352 and 19.x through 21.x before 21.0.0.242 on Windows and OS X and before 11.2.202.621 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-1097, CVE-2016-1106, CVE-2016-1107, CVE-2016-1108, CVE-2016-1109, CVE-2016-1110, CVE-2016-4108, and CVE-2016-4110.
Published 2016-06-16 · Modified
9.8EPSS 0.100
CVE-2025-39946
tls: make sure to abort the stream if headers are bogus
Published 2025-10-04 · Analyzed
9.8EPSS 0.096
CVE-2026-0907
Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published 2026-01-20 · Analyzed
9.8EPSS 0.086
CVE-2022-22955
VMware Workspace ONE Access has two authentication bypass vulnerabilities (CVE-2022-22955 & CVE-2022-22956) in the OAuth2 ACS framework. A malicious actor may bypass the authentication mechanism and execute any operation due to exposed endpoints in the authentication framework.
Published 2022-04-13 · Modified
9.8EPSS 0.079
CVE-2019-14895
A heap-based buffer overflow was discovered in the Linux kernel, all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw could occur when the station attempts a connection negotiation during the handling of the remote devices country settings. This could allow the remote device to cause a denial of service (system crash) or possibly execute arbitrary code.
Published 2019-11-29 · Modified
9.8EPSS 0.078
CVE-2018-12825
Adobe Flash Player 30.0.0.134 and earlier have a security bypass vulnerability. Successful exploitation could lead to security mitigation bypass.
Published 2018-08-29 · Modified
9.8EPSS 0.071
CVE-2018-12828
Adobe Flash Player 30.0.0.134 and earlier have a "use of a component with a known vulnerability" vulnerability. Successful exploitation could lead to privilege escalation.
Published 2018-08-29 · Modified
9.8EPSS 0.071
CVE-2019-10126
A flaw was found in the Linux kernel. A heap based buffer overflow in mwifiex_uap_parse_tail_ies function in drivers/net/wireless/marvell/mwifiex/ie.c might lead to memory corruption and possibly other consequences.
Published 2019-06-14 · Modified
9.8EPSS 0.068
CVE-2019-17133
In the Linux kernel through 5.3.2, cfg80211_mgd_wext_giwessid in net/wireless/wext-sme.c does not reject a long SSID IE, leading to a Buffer Overflow.
Published 2019-10-04 · Modified
9.8EPSS 0.067
← Prev15 / 484Next →