VendorsLinuxlinux_kernelall versions
Vulnerabilities

Linux Kernel

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19321CVEs
CVE-2020-13417
An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters.
Published 2020-05-22 · Modified
9.8EPSS 0.023
CVE-2025-23317
NVIDIA Triton Inference Server contains a vulnerability in the HTTP server, where an attacker could start a reverse shell by sending a specially crafted HTTP request. A successful exploit of this vulnerability might lead to remote code execution, denial of service, data tampering, or information disclosure.
Published 2025-08-06 · Analyzed
9.8EPSS 0.020
CVE-2011-4120
Yubico PAM Module before 2.10 performed user authentication when 'use_first_pass' PAM configuration option was not used and the module was configured as 'sufficient' in the PAM configuration. A remote attacker could use this flaw to circumvent common authentication process and obtain access to the account in question by providing a NULL value (pressing Ctrl-D keyboard sequence) as the password string.
Published 2019-11-26 · Modified
9.8EPSS 0.020
CVE-2022-41158
eyoom builder Remote Code Execution Vulnerability
Published 2022-11-25 · Modified
9.8EPSS 0.020
CVE-2023-23477
IBM WebSphere Application Server code execution
Published 2023-02-03 · Modified
9.8EPSS 0.019
CVE-2025-23242
NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, or information disclosure.
Published 2025-03-11 · Analyzed
9.8EPSS 0.019
CVE-2025-23310
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where an attacker could cause stack buffer overflow by specially crafted inputs. A successful exploit of this vulnerability might lead to remote code execution, denial of service, information disclosure, and data tampering.
Published 2025-08-06 · Analyzed
9.8EPSS 0.019
CVE-2010-0748
Transmission before 1.92 allows an attacker to cause a denial of service (crash) or possibly have other unspecified impact via a large number of tr arguments in a magnet link.
Published 2019-10-30 · Modified
9.8EPSS 0.019
CVE-2022-40752
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID:  236687.
Published 2022-11-16 · Modified
9.8EPSS 0.018
CVE-2022-38221
A buffer overflow in the FTcpListener thread in The Isle Evrima (the dedicated server on Windows and Linux) 0.9.88.07 before 2022-08-12 allows a remote attacker to crash any server with an accessible RCON port, or possibly execute arbitrary code.
Published 2022-08-15 · Modified
9.8EPSS 0.018
CVE-2010-4041
The sandbox implementation in Google Chrome before 7.0.517.41 on Linux does not properly constrain worker processes, which might allow remote attackers to bypass intended access restrictions via unspecified vectors.
Published 2010-10-21 · Modified
9.8EPSS 0.018
CVE-2016-5344
Multiple integer overflows in the MDSS driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allow attackers to cause a denial of service or possibly have unspecified other impact via a large size value, related to mdss_compat_utils.c, mdss_fb.c, and mdss_rotator.c.
Published 2016-08-30 · Modified
9.8EPSS 0.017
CVE-2015-0573
drivers/media/platform/msm/broadcast/tsc.c in the TSC driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, allows attackers to cause a denial of service (invalid pointer dereference) or possibly have unspecified other impact via a crafted application that makes a TSC_GET_CARD_STATUS ioctl call.
Published 2016-08-07 · Modified
9.8EPSS 0.017
CVE-2020-35712
Esri ArcGIS Server before 10.8 is vulnerable to SSRF in some configurations.
Published 2020-12-25 · Modified
9.8EPSS 0.017
CVE-2025-23319
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write by sending a request. A successful exploit of this vulnerability might lead to remote code execution, denial of service, data tampering, or information disclosure.
Published 2025-08-06 · Analyzed
9.8EPSS 0.016
CVE-2022-39243
NuProcess vulnerable to command-line injection through insertion of NUL character(s)
Published 2022-09-26 · Modified
9.8EPSS 0.016
CVE-2022-23770
WISA Smart Wing CMS Remote Command Execution Vulnerability
Published 2022-10-17 · Modified
9.8EPSS 0.015
CVE-2013-4486
Zanata 3.0.0 through 3.1.2 has RCE due to EL interpolation in logging
Published 2019-12-03 · Modified
9.8EPSS 0.015
CVE-2023-25539
Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. This is a high severity vulnerability as the exploitation allows an attacker to take complete control of a system, so Dell recommends customers to upgrade at the earliest opportunity.
Published 2023-05-31 · Modified
9.8EPSS 0.015
CVE-2022-22487
An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to both the IBM Spectrum Protect storage agent and the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 with which it communicates. IBM X-Force ID: 226326.
Published 2022-06-30 · Modified
9.8EPSS 0.015
CVE-2022-22997
Command Injection Vulnerability on My Cloud Home
Published 2022-07-12 · Modified
9.8EPSS 0.015
CVE-2023-28501
Heap buffer overflow in unirpcd
Published 2023-03-29 · Modified
9.8EPSS 0.014
CVE-2023-28504
Stack buffer overflow in UniRPC library function
Published 2023-03-29 · Modified
9.8EPSS 0.014
CVE-2023-32336
IBM InfoSphere Information Server code execution
Published 2023-05-22 · Modified
9.8EPSS 0.014
CVE-2021-47548
ethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port()
Published 2024-05-24 · Analyzed
9.8EPSS 0.014
CVE-2023-26512
Apache EventMesh RabbitMQ-Connector plugin allows RCE through deserialization of untrusted data
Published 2023-07-17 · Analyzed
9.8EPSS 0.013
CVE-2022-31657
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain.
Published 2022-08-05 · Modified
9.8EPSS 0.013
CVE-2010-4039
Google Chrome before 7.0.517.41 on Linux does not properly set the PATH environment variable, which has unspecified impact and attack vectors.
Published 2010-10-21 · Modified
9.8EPSS 0.013
CVE-2024-36886
tipc: fix UAF in error path
Published 2024-05-30 · Modified
9.8EPSS 0.013
CVE-2014-9410
The vfe31_proc_general function in drivers/media/video/msm/vfe/msm_vfe31.c in the MSM-VFE31 driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate a certain id value, which allows attackers to gain privileges or cause a denial of service (memory corruption) via an application that makes a crafted ioctl call.
Published 2016-08-07 · Modified
9.8EPSS 0.013
CVE-2021-26634
Maxboard multiple vulnerabilities
Published 2022-06-01 · Modified
9.8EPSS 0.013
CVE-2010-4202
Multiple integer overflows in Google Chrome before 7.0.517.44 on Linux allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted font.
Published 2010-11-05 · Modified
9.8EPSS 0.013
CVE-2019-4576
IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166803.
Published 2020-06-10 · Modified
9.8EPSS 0.013
CVE-2023-38427
An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts.
Published 2023-07-17 · Modified
9.8EPSS 0.012
CVE-2010-3416
Google Chrome before 6.0.472.59 on Linux does not properly implement the Khmer locale, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Published 2010-09-16 · Modified
9.8EPSS 0.012
CVE-2026-9181
Directory Traversal in ArcGIS Server
Published 2026-07-06 · Modified
9.8EPSS 0.012
CVE-2023-34865
Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.
Published 2023-06-14 · Modified
9.8EPSS 0.012
CVE-2021-22002
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers to facilitate access to the /cfg web app, in addition a malicious actor could access /cfg diagnostic endpoints without authentication.
Published 2021-08-31 · Modified
9.8EPSS 0.012
CVE-2026-8665
OS Command Injection in Rapid7 InsightConnect Translate Plugin
Published 2026-06-25 · Analyzed
9.8EPSS 0.012
CVE-2026-8660
OS Command Injection in Rapid7 InsightConnect Ping Plugin
Published 2026-06-25 · Analyzed
9.8EPSS 0.012
← Prev17 / 484Next →