VendorsLinuxlinux_kernelall versions
Vulnerabilities

Linux Kernel

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19321CVEs
CVE-2026-8666
OS Command Injection in Rapid7 InsightConnect Traceroute Plugin
Published 2026-06-25 · Analyzed
9.8EPSS 0.012
CVE-2026-8660
OS Command Injection in Rapid7 InsightConnect Ping Plugin
Published 2026-06-25 · Analyzed
9.8EPSS 0.012
CVE-2018-20764
A buffer overflow exists in HelpSystems tcpcrypt on Linux, used for BoKS encrypted telnet through BoKS version 6.7.1. Since tcpcrypt is setuid, exploitation leads to privilege escalation.
Published 2019-02-08 · Modified
9.8EPSS 0.012
CVE-2023-38429
An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/connection.c in ksmbd has an off-by-one error in memory allocation (because of ksmbd_smb2_check_message) that may lead to out-of-bounds access.
Published 2023-07-17 · Modified
9.8EPSS 0.012
CVE-2021-47378
nvme-rdma: destroy cm id before destroy qp to avoid use after free
Published 2024-05-21 · Analyzed
9.8EPSS 0.012
CVE-2022-22425
"IBM InfoSphere Information Server 11.7 is potentially vulnerable to CSV Injection. A remote attacker could execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 223598."
Published 2022-11-03 · Modified
9.8EPSS 0.012
CVE-2021-39052
IBM Spectrum Copy Data Management 2.2.13 and earlier could allow a remote attacker to access the Spring Boot console without authorization. IBM X-Force ID: 214523.
Published 2021-12-13 · Modified
9.8EPSS 0.011
CVE-2021-29798
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.1.1.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 203734.
Published 2021-10-06 · Modified
9.8EPSS 0.011
CVE-2021-33391
An issue in HTACG HTML Tidy v5.7.28 allows attacker to execute arbitrary code via the -g option of the CleanNode() function in gdoc.c.
Published 2023-02-17 · Modified
9.8EPSS 0.011
CVE-2022-22485
In some cases, an unsuccessful attempt to log into IBM Spectrum Protect Operations Center 8.1.0.000 through 8.1.14.000 does not cause the administrator's invalid sign-on count to be incremented on the IBM Spectrum Protect Server. An attacker could exploit this vulnerability using brute force techniques to gain unauthorized administrative access to the IBM Spectrum Protect Server. IBM X-Force ID: 226325.
Published 2022-06-17 · Modified
9.8EPSS 0.011
CVE-2025-37778
ksmbd: Fix dangling pointer in krb_authenticate
Published 2025-05-01 · Modified
9.8EPSS 0.011
CVE-2025-23304
NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loading .nemo files with maliciously crafted metadata. A successful exploit of this vulnerability may lead to remote code execution and data tampering.
Published 2025-08-13 · Analyzed
9.8EPSS 0.011
CVE-2026-8505
Authentication Bypass in Webhook Endpoints Allowed Unauthorized Flow Execution
Published 2026-07-17 · Modified
9.8EPSS 0.010
CVE-2026-46195
smb: client: validate dacloffset before building DACL pointers
Published 2026-05-28 · Modified
9.8EPSS 0.010
CVE-2024-41040
net/sched: Fix UAF when resolving a clash
Published 2024-07-29 · Modified
9.8EPSS 0.010
CVE-2026-43501
ipv6: rpl: reserve mac_len headroom when recompressed SRH grows
Published 2026-05-21 · Modified
9.8EPSS 0.010
CVE-2026-65098
NVIDIA NemoClaw for Linux contains a vulnerability in its remote-access helper workflow, where an attacker could cause weak authentication. A successful exploit of this vulnerability might lead to code execution, information disclosure, and data tampering.
Published 2026-08-25 · Analyzed
9.8EPSS 0.010
CVE-2024-26592
ksmbd: fix UAF issue in ksmbd_tcp_new_connection()
Published 2024-02-22 · Modified
9.8EPSS 0.010
CVE-2021-20426
IBM Security Guardium 11.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 196313.
Published 2021-05-24 · Modified
9.8EPSS 0.010
CVE-2021-20418
IBM Security Guardium 11.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 196279.
Published 2021-08-11 · Modified
9.8EPSS 0.010
CVE-2025-34192
Vasion Print (formerly PrinterLogic) Usage of Outdated and Unsupported OpenSSL Version
Published 2025-09-19 · Modified
9.8EPSS 0.010
CVE-2024-27388
SUNRPC: fix some memleaks in gssx_dec_option_array
Published 2024-05-01 · Modified
9.8EPSS 0.010
CVE-2021-47103
inet: fully convert sk->sk_rx_dst to RCU rules
Published 2024-03-04 · Modified
9.8EPSS 0.010
CVE-2026-48333
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Published 2026-08-03 · Analyzed
9.8EPSS 0.009
CVE-2026-3843
SQL Injection in Nefteprodukttekhnika BUK TS-G Allows Remote Code Execution
Published 2026-03-10 · Analyzed
9.8EPSS 0.009
CVE-2022-48788
nvme-rdma: fix possible use-after-free in transport error_recovery work
Published 2024-07-16 · Modified
9.8EPSS 0.009
CVE-2021-39085
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 215888.
Published 2022-08-16 · Modified
9.8EPSS 0.009
CVE-2023-28507
Memory exhaustion in LZ4 decompression in UniRPC daemon
Published 2023-03-29 · Modified
9.8EPSS 0.009
CVE-2025-69269
Spectrum command injection in NCM service
Published 2026-01-12 · Analyzed
9.8EPSS 0.009
CVE-2024-38541
of: module: add buffer overflow check in of_modalias()
Published 2024-06-19 · Modified
9.8EPSS 0.009
CVE-2026-24254
NVIDIA Dynamo for Linux contains a vulnerability in the multimodal serving topology, where an attacker could cause an out-of-bounds write. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, denial of service, and information disclosure.
Published 2026-08-04 · Analyzed
9.8EPSS 0.009
CVE-2021-38869
IBM QRadar SIEM 7.3, 7.4, and 7.5 in some situations may not automatically log users out after they exceede their idle timeout. IBM X-Force ID: 208341.
Published 2022-04-27 · Modified
9.8EPSS 0.009
CVE-2021-26633
Maxboard SQL injection and LFI vulnerability
Published 2022-06-01 · Modified
9.8EPSS 0.009
CVE-2024-40983
tipc: force a dst refcount before doing decryption
Published 2024-07-12 · Modified
9.8EPSS 0.009
CVE-2024-44985
ipv6: prevent possible UAF in ip6_xmit()
Published 2024-09-04 · Modified
9.8EPSS 0.009
CVE-2024-41081
ila: block BH in ila_output()
Published 2024-07-29 · Modified
9.8EPSS 0.009
CVE-2024-42285
RDMA/iwcm: Fix a use-after-free related to destroying CM IDs
Published 2024-08-17 · Modified
9.8EPSS 0.009
CVE-2026-43011
net/x25: Fix potential double free of skb
Published 2026-05-01 · Modified
9.8EPSS 0.009
CVE-2026-31649
net: stmmac: fix integer underflow in chain mode
Published 2026-04-24 · Modified
9.8EPSS 0.009
CVE-2022-49407
dlm: fix plock invalid read
Published 2025-02-26 · Modified
9.8EPSS 0.009
← Prev18 / 484Next →