VendorsLinuxlinux_kernelall versions
Vulnerabilities

Linux Kernel

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19321CVEs
CVE-2025-3940
Improper Use of Validation Framework
Published 2025-05-22 · Analyzed
9.8EPSS 0.004
CVE-2025-3937
Use of Password Hash with Insufficient Computational Effort
Published 2025-05-22 · Analyzed
9.8EPSS 0.004
CVE-2025-3938
Missing Cryptographic Step
Published 2025-05-22 · Analyzed
9.8EPSS 0.003
CVE-2025-71068
svcrdma: bound check rq_pages index in inline path
Published 2026-01-13 · Modified
9.8EPSS 0.003
CVE-2026-13776
Type Confusion in Dawn in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-30 · Modified
9.8EPSS 0.003
CVE-2026-64162
idpf: fix read_dev_clk_lock spinlock init in idpf_ptp_init()
Published 2026-07-19 · Analyzed
9.8EPSS 0.003
CVE-2026-0906
Incorrect security UI in Google Chrome on Android prior to 144.0.7559.59 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page. (Chromium security severity: Low)
Published 2026-01-20 · Analyzed
9.8EPSS 0.003
CVE-2026-30793
RustDesk Flutter URI Handler Sets Permanent Password Without Privilege Check or User Confirmation
Published 2026-03-05 · Analyzed
9.8EPSS 0.003
CVE-2025-38476
rpl: Fix use-after-free in rpl_do_srh_inline().
Published 2025-07-28 · Modified
9.8EPSS 0.003
CVE-2025-38209
nvme-tcp: remove tag set when second admin queue config fails
Published 2025-07-04 · Modified
9.8EPSS 0.003
CVE-2025-38411
netfs: Fix double put of request
Published 2025-07-25 · Modified
9.8EPSS 0.003
CVE-2026-23428
ksmbd: fix use-after-free of share_conf in compound request
Published 2026-04-03 · Modified
9.8EPSS 0.003
CVE-2026-5902
Race in Media in Google Chrome on Android prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to corrupt media stream metadata via a crafted HTML page. (Chromium security severity: Low)
Published 2026-04-08 · Analyzed
9.8EPSS 0.003
CVE-2024-58240
tls: separate no-async decryption request handling from async
Published 2025-08-28 · Modified
9.8EPSS 0.003
CVE-2026-30789
RustDesk Auth Proof Uses Server-Controlled Salt/Challenge and Fast Double-SHA256, Enabling Offline Brute-Force
Published 2026-03-05 · Modified
9.8EPSS 0.003
CVE-2025-39880
libceph: fix invalid accesses to ceph_connection_v1_info
Published 2025-09-23 · Modified
9.8EPSS 0.003
CVE-2025-69270
Spectrum session token in URL
Published 2026-01-12 · Analyzed
9.8EPSS 0.003
CVE-2026-53363
xfrm: iptfs: preserve shared-frag marker in iptfs_consume_frags()
Published 2026-07-10 · Analyzed
9.8EPSS 0.003
CVE-2026-13775
Use after free in GPU in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-30 · Modified
9.8EPSS 0.003
CVE-2024-39293
Revert "xsk: Support redirect to any socket bound to the same umem"
Published 2024-06-25 · Modified
9.8EPSS 0.003
CVE-2025-39673
ppp: fix race conditions in ppp_fill_forward_path
Published 2025-09-05 · Modified
9.8EPSS 0.003
CVE-2025-38490
net: libwx: remove duplicate page_pool_put_full_page()
Published 2025-07-28 · Modified
9.8EPSS 0.003
CVE-2025-38246
bnxt: properly flush XDP redirect lists
Published 2025-07-09 · Modified
9.8EPSS 0.003
CVE-2025-38533
net: libwx: fix the using of Rx buffer DMA
Published 2025-08-16 · Modified
9.8EPSS 0.003
CVE-2023-53517
tipc: do not update mtu if msg_max is too small in mtu negotiation
Published 2025-10-01 · Modified
9.8EPSS 0.003
CVE-2025-38264
nvme-tcp: sanitize request list handling
Published 2025-07-09 · Modified
9.8EPSS 0.003
CVE-2025-39948
ice: fix Rx page leak on multi-buffer frames
Published 2025-10-04 · Modified
9.8EPSS 0.003
CVE-2026-23427
ksmbd: fix use-after-free in durable v2 replay of active file handles
Published 2026-04-03 · Modified
9.8EPSS 0.003
CVE-2023-53382
net/smc: Reset connection when trying to use SMCRv2 fails.
Published 2025-09-18 · Modified
9.8EPSS 0.003
CVE-2025-39932
smb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work)
Published 2025-10-04 · Modified
9.8EPSS 0.003
CVE-2026-47304
.NET Security Feature Bypass Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.003
CVE-2022-50350
scsi: target: iscsi: Fix a race condition between login_work and the login thread
Published 2025-09-16 · Modified
9.8EPSS 0.003
CVE-2026-0905
Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially obtain potentially sensitive information via a network log file. (Chromium security severity: Medium)
Published 2026-01-20 · Analyzed
9.8EPSS 0.002
CVE-2025-71159
btrfs: fix use-after-free warning in btrfs_get_or_create_delayed_node()
Published 2026-01-23 · Modified
9.8EPSS 0.002
CVE-2025-39726
s390/ism: fix concurrency management in ism_cmd()
Published 2025-09-05 · Modified
9.8EPSS 0.002
CVE-2026-10886
Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-04 · Analyzed
9.6EPSS 0.062
CVE-2017-5053
An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to Array.prototype.indexOf.
Published 2017-10-27 · Modified
9.6EPSS 0.026
CVE-2023-2317
Typora DOM-Based Cross-site Scripting leading to Remote Code Execution
Published 2023-08-19 · Modified
9.6EPSS 0.024
CVE-2019-20374
A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to improper HTML sanitization. Given that the application is based on the Electron framework, the XSS leads to remote code execution in an unsandboxed environment.
Published 2020-01-09 · Modified
9.6EPSS 0.023
CVE-2021-26636
Maxboard Remote Code Execution
Published 2022-06-22 · Modified
9.6EPSS 0.015
← Prev28 / 484Next →