VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18467CVEs
CVE-2025-38490
net: libwx: remove duplicate page_pool_put_full_page()
Published 2025-07-28 · Modified
9.8EPSS 0.003
CVE-2024-39293
Revert "xsk: Support redirect to any socket bound to the same umem"
Published 2024-06-25 · Modified
9.8EPSS 0.003
CVE-2025-39673
ppp: fix race conditions in ppp_fill_forward_path
Published 2025-09-05 · Modified
9.8EPSS 0.003
CVE-2025-38246
bnxt: properly flush XDP redirect lists
Published 2025-07-09 · Modified
9.8EPSS 0.003
CVE-2025-38533
net: libwx: fix the using of Rx buffer DMA
Published 2025-08-16 · Modified
9.8EPSS 0.003
CVE-2023-53517
tipc: do not update mtu if msg_max is too small in mtu negotiation
Published 2025-10-01 · Modified
9.8EPSS 0.003
CVE-2025-39948
ice: fix Rx page leak on multi-buffer frames
Published 2025-10-04 · Modified
9.8EPSS 0.003
CVE-2026-23427
ksmbd: fix use-after-free in durable v2 replay of active file handles
Published 2026-04-03 · Modified
9.8EPSS 0.003
CVE-2025-38264
nvme-tcp: sanitize request list handling
Published 2025-07-09 · Modified
9.8EPSS 0.003
CVE-2023-53382
net/smc: Reset connection when trying to use SMCRv2 fails.
Published 2025-09-18 · Modified
9.8EPSS 0.003
CVE-2025-39932
smb: client: let smbd_destroy() call disable_work_sync(&info->post_send_credits_work)
Published 2025-10-04 · Modified
9.8EPSS 0.003
CVE-2026-47304
.NET Security Feature Bypass Vulnerability
Published 2026-07-14 · Analyzed
9.8EPSS 0.003
CVE-2022-50350
scsi: target: iscsi: Fix a race condition between login_work and the login thread
Published 2025-09-16 · Modified
9.8EPSS 0.003
CVE-2026-0905
Insufficient policy enforcement in Network in Google Chrome prior to 144.0.7559.59 allowed an attack who obtained a network log file to potentially obtain potentially sensitive information via a network log file. (Chromium security severity: Medium)
Published 2026-01-20 · Analyzed
9.8EPSS 0.002
CVE-2025-39726
s390/ism: fix concurrency management in ism_cmd()
Published 2025-09-05 · Modified
9.8EPSS 0.002
CVE-2025-71159
btrfs: fix use-after-free warning in btrfs_get_or_create_delayed_node()
Published 2026-01-23 · Modified
9.8EPSS 0.002
CVE-2026-10886
Use after free in FileSystem in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-04 · Analyzed
9.6EPSS 0.062
CVE-2017-5053
An out-of-bounds read in V8 in Google Chrome prior to 57.0.2987.133 for Linux, Windows, and Mac, and 57.0.2987.132 for Android, allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page, related to Array.prototype.indexOf.
Published 2017-10-27 · Modified
9.6EPSS 0.026
CVE-2023-2317
Typora DOM-Based Cross-site Scripting leading to Remote Code Execution
Published 2023-08-19 · Modified
9.6EPSS 0.024
CVE-2019-20374
A mutation cross-site scripting (XSS) issue in Typora through 0.9.9.31.2 on macOS and through 0.9.81 on Linux leads to Remote Code Execution through Mermaid code blocks. To exploit this vulnerability, one must open a file in Typora. The XSS vulnerability is then triggered due to improper HTML sanitization. Given that the application is based on the Electron framework, the XSS leads to remote code execution in an unsandboxed environment.
Published 2020-01-09 · Modified
9.6EPSS 0.023
CVE-2021-26636
Maxboard Remote Code Execution
Published 2022-06-22 · Modified
9.6EPSS 0.015
CVE-2021-21107
Use after free in drag and drop in Google Chrome on Linux prior to 87.0.4280.141 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.
Published 2021-01-08 · Modified
9.6EPSS 0.011
CVE-2024-36912
Drivers: hv: vmbus: Track decrypted status in vmbus_gpadl
Published 2024-05-30 · Modified
9.6EPSS 0.010
CVE-2026-48317
Adobe Campaign Classic (ACC) | Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') (CWE-95)
Published 2026-08-03 · Analyzed
9.6EPSS 0.009
CVE-2024-52053
Stored Cross-Site Scripting in Wowza Streaming Engine
Published 2024-11-21 · Analyzed
9.6EPSS 0.007
CVE-2023-23482
IBM Sterling Partner Engagement Manager clickjacking
Published 2023-06-08 · Modified
9.6EPSS 0.006
CVE-2023-2318
MarkText DOM-Based Cross-site Scripting leading to Remote Code Execution
Published 2023-08-19 · Modified
9.6EPSS 0.005
CVE-2021-44458
Lack of websocket authentication in Lens causes remote code execution when visiting a malicious website
Published 2022-01-10 · Modified
9.6EPSS 0.004
CVE-2026-8670
Insecure session handling on metrics web server
Published 2026-05-22 · Analyzed
9.6EPSS 0.004
CVE-2026-10881
Out of bounds read and write in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-04 · Analyzed
9.6EPSS 0.004
CVE-2026-6296
Heap buffer overflow in ANGLE in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-04-15 · Modified
9.6EPSS 0.004
CVE-2026-13798
Heap buffer overflow in Chromecast in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-30 · Analyzed
9.6EPSS 0.004
CVE-2026-3916
Out of bounds read in Web Speech in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published 2026-03-11 · Analyzed
9.6EPSS 0.003
CVE-2026-6920
Out of bounds read in GPU in Google Chrome on Android prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-23 · Modified
9.6EPSS 0.003
CVE-2026-6919
Use after free in DevTools in Google Chrome prior to 147.0.7727.117 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-23 · Modified
9.6EPSS 0.003
CVE-2026-9967
Out of bounds write in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-28 · Analyzed
9.6EPSS 0.003
CVE-2026-19149
Use after free in Aura in Google Chrome on Linux prior to 151.0.7922.109 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-08-06 · Analyzed
9.6EPSS 0.003
CVE-2026-5874
Use after free in PrivateAI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-04-08 · Analyzed
9.6EPSS 0.003
CVE-2026-11651
Use after free in Network in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
9.6EPSS 0.003
CVE-2026-13883
Type Confusion in ANGLE in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-30 · Modified
9.6EPSS 0.003
← Prev28 / 462Next →