VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18467CVEs
CVE-2023-25539
Dell NetWorker 19.6.1.2, contains an OS command injection Vulnerability in the NetWorker client. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the application's underlying OS, with the privileges of the vulnerable application. This is a high severity vulnerability as the exploitation allows an attacker to take complete control of a system, so Dell recommends customers to upgrade at the earliest opportunity.
Published 2023-05-31 · Modified
9.8EPSS 0.015
CVE-2022-22487
An IBM Spectrum Protect storage agent could allow a remote attacker to perform a brute force attack by allowing unlimited attempts to login to the storage agent without locking the administrative ID. A remote attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to both the IBM Spectrum Protect storage agent and the IBM Spectrum Protect Server 8.1.0.000 through 8.1.14 with which it communicates. IBM X-Force ID: 226326.
Published 2022-06-30 · Modified
9.8EPSS 0.015
CVE-2022-22997
Command Injection Vulnerability on My Cloud Home
Published 2022-07-12 · Modified
9.8EPSS 0.015
CVE-2023-28501
Heap buffer overflow in unirpcd
Published 2023-03-29 · Modified
9.8EPSS 0.014
CVE-2023-28504
Stack buffer overflow in UniRPC library function
Published 2023-03-29 · Modified
9.8EPSS 0.014
CVE-2023-32336
IBM InfoSphere Information Server code execution
Published 2023-05-22 · Modified
9.8EPSS 0.014
CVE-2021-47548
ethernet: hisilicon: hns: hns_dsaf_misc: fix a possible array overflow in hns_dsaf_ge_srst_by_port()
Published 2024-05-24 · Analyzed
9.8EPSS 0.014
CVE-2023-26512
Apache EventMesh RabbitMQ-Connector plugin allows RCE through deserialization of untrusted data
Published 2023-07-17 · Analyzed
9.8EPSS 0.013
CVE-2022-31657
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network access may be able to redirect an authenticated user to an arbitrary domain.
Published 2022-08-05 · Modified
9.8EPSS 0.013
CVE-2010-4039
Google Chrome before 7.0.517.41 on Linux does not properly set the PATH environment variable, which has unspecified impact and attack vectors.
Published 2010-10-21 · Modified
9.8EPSS 0.013
CVE-2024-36886
tipc: fix UAF in error path
Published 2024-05-30 · Modified
9.8EPSS 0.013
CVE-2014-9410
The vfe31_proc_general function in drivers/media/video/msm/vfe/msm_vfe31.c in the MSM-VFE31 driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate a certain id value, which allows attackers to gain privileges or cause a denial of service (memory corruption) via an application that makes a crafted ioctl call.
Published 2016-08-07 · Modified
9.8EPSS 0.013
CVE-2021-26634
Maxboard multiple vulnerabilities
Published 2022-06-01 · Modified
9.8EPSS 0.013
CVE-2010-4202
Multiple integer overflows in Google Chrome before 7.0.517.44 on Linux allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted font.
Published 2010-11-05 · Modified
9.8EPSS 0.013
CVE-2019-4576
IBM QRadar Network Packet Capture 7.3.0 - 7.3.3 Patch 1 and 7.4.0 GA does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 166803.
Published 2020-06-10 · Modified
9.8EPSS 0.013
CVE-2023-38427
An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/smb2pdu.c in ksmbd has an integer underflow and out-of-bounds read in deassemble_neg_contexts.
Published 2023-07-17 · Modified
9.8EPSS 0.012
CVE-2010-3416
Google Chrome before 6.0.472.59 on Linux does not properly implement the Khmer locale, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.
Published 2010-09-16 · Modified
9.8EPSS 0.012
CVE-2026-9181
Directory Traversal in ArcGIS Server
Published 2026-07-06 · Modified
9.8EPSS 0.012
CVE-2023-34865
Directory traversal vulnerability in ujcms 6.0.2 allows attackers to move files via the rename feature.
Published 2023-06-14 · Modified
9.8EPSS 0.012
CVE-2021-22002
VMware Workspace ONE Access and Identity Manager, allow the /cfg web app and diagnostic endpoints, on port 8443, to be accessed via port 443 using a custom host header. A malicious actor with network access to port 443 could tamper with host headers to facilitate access to the /cfg web app, in addition a malicious actor could access /cfg diagnostic endpoints without authentication.
Published 2021-08-31 · Modified
9.8EPSS 0.012
CVE-2026-8665
OS Command Injection in Rapid7 InsightConnect Translate Plugin
Published 2026-06-25 · Analyzed
9.8EPSS 0.012
CVE-2026-8660
OS Command Injection in Rapid7 InsightConnect Ping Plugin
Published 2026-06-25 · Analyzed
9.8EPSS 0.012
CVE-2026-8592
OS Command Injection in Rapid7 InsightConnect AWK Plugin
Published 2026-06-25 · Analyzed
9.8EPSS 0.012
CVE-2026-8666
OS Command Injection in Rapid7 InsightConnect Traceroute Plugin
Published 2026-06-25 · Analyzed
9.8EPSS 0.012
CVE-2018-20764
A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege escalation.
Published 2019-02-08 · Modified
9.8EPSS 0.012
CVE-2023-38429
An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.
Published 2023-07-17 · Modified
9.8EPSS 0.012
CVE-2021-47378
nvme-rdma: destroy cm id before destroy qp to avoid use after free
Published 2024-05-21 · Analyzed
9.8EPSS 0.012
CVE-2022-22425
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."
Published 2022-11-03 · Modified
9.8EPSS 0.012
CVE-2021-39052
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-Force ID: 214523.
Published 2021-12-13 · Modified
9.8EPSS 0.011
CVE-2021-29798
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 203734.
Published 2021-10-06 · Modified
9.8EPSS 0.011
CVE-2021-33391
An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.
Published 2023-02-17 · Modified
9.8EPSS 0.011
CVE-2022-22485
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to the IBM Spectrum Protect Server. IBM X-Force ID: 226325.
Published 2022-06-17 · Modified
9.8EPSS 0.011
CVE-2025-37778
ksmbd: Fix dangling pointer in krb_authenticate
Published 2025-05-01 · Modified
9.8EPSS 0.011
CVE-2025-23304
NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loading .nemo files with maliciously crafted metadata. A successful exploit of this vulnerability may lead to remote code execution and data tampering.
Published 2025-08-13 · Analyzed
9.8EPSS 0.011
CVE-2026-8505
Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution
Published 2026-07-17 · Modified
9.8EPSS 0.010
CVE-2026-46195
smb: client: validate dacloffset before building DACL pointers
Published 2026-05-28 · Modified
9.8EPSS 0.010
CVE-2024-41040
net/sched: Fix UAF when resolving a clash
Published 2024-07-29 · Modified
9.8EPSS 0.010
CVE-2026-43501
ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
Published 2026-05-21 · Modified
9.8EPSS 0.010
CVE-2026-65098
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
Published 2026-08-25 · Analyzed
9.8EPSS 0.010
CVE-2024-26592
ksmbd: fix UAF issue in ksmbd_tcp_new_connection()
Published 2024-02-22 · Modified
9.8EPSS 0.010
← Prev17 / 462Next →