VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18467CVEs
CVE-2025-21805
RDMA/rtrs: Add missing deinit() call
Published 2025-02-27 · Modified
9.8EPSS 0.004
CVE-2022-50373
fs: dlm: fix race in lowcomms
Published 2025-09-17 · Modified
9.8EPSS 0.004
CVE-2026-22984
libceph: prevent potential out-of-bounds reads in handle_auth_done()
Published 2026-01-23 · Modified
9.8EPSS 0.004
CVE-2025-38660
[ceph] parse_longname(): strrchr() expects NUL-terminated string
Published 2025-08-22 · Modified
9.8EPSS 0.004
CVE-2025-38724
nfsd: handle get_client_locked() failure in nfsd4_setclientid_confirm()
Published 2025-09-04 · Modified
9.8EPSS 0.004
CVE-2025-37750
smb: client: fix UAF in decryption with multichannel
Published 2025-05-01 · Modified
9.8EPSS 0.004
CVE-2026-13446
Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
Published 2026-07-17 · Analyzed
9.8EPSS 0.004
CVE-2025-21988
fs/netfs/read_collect: add to next->prev_donated
Published 2025-04-02 · Modified
9.8EPSS 0.004
CVE-2025-22110
netfilter: nfnetlink_queue: Initialize ctx to avoid memory allocation error
Published 2025-04-16 · Modified
9.8EPSS 0.004
CVE-2023-53192
vxlan: Fix nexthop hash size
Published 2025-09-15 · Modified
9.8EPSS 0.004
CVE-2025-38737
cifs: Fix oops due to uninitialised variable
Published 2025-09-05 · Modified
9.8EPSS 0.004
CVE-2024-45013
nvme: move stopping keep-alive into nvme_uninit_ctrl()
Published 2024-09-11 · Modified
9.8EPSS 0.004
CVE-2025-38211
RDMA/iwcm: Fix use-after-free of work objects after cm_id destruction
Published 2025-07-04 · Modified
9.8EPSS 0.004
CVE-2025-38708
drbd: add missing kref_get in handle_write_conflicts
Published 2025-09-04 · Modified
9.8EPSS 0.004
CVE-2022-50335
9p: set req refcount to zero to avoid uninitialized usage
Published 2025-09-15 · Modified
9.8EPSS 0.004
CVE-2025-22077
Revert "smb: client: fix TCP timers deadlock after rmmod"
Published 2025-04-16 · Modified
9.8EPSS 0.004
CVE-2025-39703
net, hsr: reject HSR frame if skb can't hold tag
Published 2025-09-05 · Modified
9.8EPSS 0.004
CVE-2024-56656
bnxt_en: Fix aggregation ID mask to prevent oops on 5760X chips
Published 2024-12-27 · Modified
9.8EPSS 0.004
CVE-2026-3062
Out of bounds read and write in Tint in Google Chrome on Mac prior to 145.0.7632.116 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Published 2026-02-23 · Modified
9.8EPSS 0.004
CVE-2024-50206
net: ethernet: mtk_eth_soc: fix memory corruption during fq dma init
Published 2024-11-08 · Modified
9.8EPSS 0.004
CVE-2024-5828
EL Injection Vulnerability in Hitachi Tuning Manager
Published 2024-08-06 · Analyzed
9.8EPSS 0.004
CVE-2025-3940
Improper Use of Validation Framework
Published 2025-05-22 · Analyzed
9.8EPSS 0.004
CVE-2025-3937
Use of Password Hash with Insufficient Computational Effort
Published 2025-05-22 · Analyzed
9.8EPSS 0.004
CVE-2025-3938
Missing Cryptographic Step
Published 2025-05-22 · Analyzed
9.8EPSS 0.003
CVE-2025-71068
svcrdma: bound check rq_pages index in inline path
Published 2026-01-13 · Modified
9.8EPSS 0.003
CVE-2025-38476
rpl: Fix use-after-free in rpl_do_srh_inline().
Published 2025-07-28 · Modified
9.8EPSS 0.003
CVE-2026-13776
Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-30 · Modified
9.8EPSS 0.003
CVE-2026-0906
Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
Published 2026-01-20 · Analyzed
9.8EPSS 0.003
CVE-2026-64162
idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()
Published 2026-07-19 · Analyzed
9.8EPSS 0.003
CVE-2026-30793
RustDesk Flutter URI Handler Sets Permanent Password Without Privilege Check or User Confirmation
Published 2026-03-05 · Analyzed
9.8EPSS 0.003
CVE-2025-38411
netfs: Fix double put of request
Published 2025-07-25 · Modified
9.8EPSS 0.003
CVE-2025-38209
nvme-tcp: remove tag set when second admin queue config fails
Published 2025-07-04 · Modified
9.8EPSS 0.003
CVE-2026-23428
ksmbd: fix use-after-free of share_conf in compound request
Published 2026-04-03 · Modified
9.8EPSS 0.003
CVE-2026-5902
Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium security severity: Low)
Published 2026-04-08 · Analyzed
9.8EPSS 0.003
CVE-2024-58240
tls: separate no-async decryption request handling from async
Published 2025-08-28 · Modified
9.8EPSS 0.003
CVE-2026-30789
RustDesk Auth Proof Uses Server-Controlled Salt/Challenge and Fast Double-SHA256, Enabling Offline Brute-Force
Published 2026-03-05 · Modified
9.8EPSS 0.003
CVE-2025-39880
libceph: fix invalid accesses to ceph_connection_v1_info
Published 2025-09-23 · Modified
9.8EPSS 0.003
CVE-2025-69270
Spectrum session token in URL
Published 2026-01-12 · Analyzed
9.8EPSS 0.003
CVE-2026-53363
xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()
Published 2026-07-10 · Analyzed
9.8EPSS 0.003
CVE-2026-13775
Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-30 · Modified
9.8EPSS 0.003
← Prev27 / 462Next →