VendorsLinuxlinux_kernelall versions
Vulnerabilities

Linux Kernel

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19321CVEs
CVE-2015-9004
kernel/events/core.c in the Linux kernel before 3.19 mishandles counter grouping, which allows local users to gain privileges via a crafted application, related to the perf_pmu_register and perf_event_open functions.
Published 2017-05-02 · Modified
9.3EPSS 0.008
CVE-2015-8967
arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protection mechanism and modify the system-call table, and consequently gain privileges, by leveraging write access.
Published 2016-12-08 · Modified
9.3EPSS 0.008
CVE-2026-34691
Adobe Experience Manager Forms JEE | Cross-site Scripting (Stored XSS) (CWE-79)
Published 2026-06-09 · Analyzed
9.3EPSS 0.007
CVE-2017-0331
An elevation of privilege vulnerability in the NVIDIA video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel 3.10. Android ID: A-34113000. References: N-CVE-2017-0331.
Published 2017-05-02 · Modified
9.3EPSS 0.007
CVE-2016-2067
drivers/gpu/msm/kgsl.c in the MSM graphics driver (aka GPU driver) for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, mishandles the KGSL_MEMFLAGS_GPUREADONLY flag, which allows attackers to gain privileges by leveraging accidental read-write mappings, aka Qualcomm internal bug CR988993.
Published 2016-07-11 · Modified
9.3EPSS 0.007
CVE-2016-8436
An elevation of privilege vulnerability in the Qualcomm video driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device compromise, which may require reflashing the operating system to repair the device. Product: Android. Versions: Kernel-3.18. Android ID: A-32450261. References: QC-CR#1007860.
Published 2017-01-12 · Modified
9.3EPSS 0.007
CVE-2024-36913
Drivers: hv: vmbus: Leak pages if set_memory_encrypted() fails
Published 2024-05-30 · Modified
9.3EPSS 0.007
CVE-2014-9803
arch/arm64/include/asm/pgtable.h in the Linux kernel before 3.15-rc5-next-20140519, as used in Android before 2016-07-05 on Nexus 5X and 6P devices, mishandles execute-only pages, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28557020.
Published 2016-07-11 · Modified
9.3EPSS 0.006
CVE-2026-30797
RustDesk rustdesk://config/ URI Silently Re-homes Client to Attacker-Controlled Server
Published 2026-03-05 · Analyzed
9.3EPSS 0.006
CVE-2026-14973
Path Traversal in IBM Desktop App
Published 2026-07-28 · Analyzed
9.3EPSS 0.005
CVE-2026-11707
Multiple vulnerabilities have been identified in IBM WebSphere Application Server shipped with Tivoli System Automation Application Manager
Published 2026-07-30 · Analyzed
9.3EPSS 0.004
CVE-2024-36909
Drivers: hv: vmbus: Don't free ring buffers that couldn't be re-encrypted
Published 2024-05-30 · Modified
9.3EPSS 0.002
CVE-2024-35939
dma-direct: Leak pages on dma_set_decrypted() failure
Published 2024-05-19 · Modified
9.3EPSS 0.002
CVE-2026-46316
KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry
Published 2026-06-09 · Modified
9.3EPSS 0.002
CVE-2024-57793
virt: tdx-guest: Just leak decrypted memory on unrecoverable errors
Published 2025-01-11 · Modified
9.3EPSS 0.002
CVE-2026-64080
firmware: arm_ffa: Snapshot notifier callbacks under lock
Published 2026-07-19 · Analyzed
9.3EPSS 0.002
CVE-2025-38560
x86/sev: Evict cache lines during SNP memory validation
Published 2025-08-19 · Modified
9.3EPSS 0.002
CVE-2024-26594
ksmbd: validate mech token in session setup
Published 2024-02-23 · Modified
9.1EPSS 0.510
CVE-2023-52442
ksmbd: validate session id and tree id in compound request
Published 2024-02-21 · Modified
9.1EPSS 0.296
CVE-2020-4006
VMware Workspace One Access, Access Connector, Identity Manager, and Identity Manager Connector address have a command injection vulnerability.
Published 2020-11-23 · Analyzed
9.1KEVEPSS 0.173
CVE-2023-3867
ksmbd: fix out of bounds read in smb2_sess_setup
Published 2025-08-16 · Modified
9.1EPSS 0.054
CVE-2022-0742
Memory leak in ICMP6 in Linux Kernel
Published 2022-03-18 · Modified
9.1EPSS 0.050
CVE-2011-3188
The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets.
Published 2012-05-24 · Modified
9.1EPSS 0.050
CVE-2023-38428
An issue was discovered in the Linux kernel before 6.3.4. fs/ksmbd/smb2pdu.c in ksmbd does not properly check the UserName value because it does not consider the address of security buffer, leading to an out-of-bounds read.
Published 2023-07-17 · Modified
9.1EPSS 0.032
CVE-2023-38426
An issue was discovered in the Linux kernel before 6.3.4. ksmbd has an out-of-bounds read in smb2_find_context_vals when create_context's name_len is larger than the tag length.
Published 2023-07-17 · Modified
9.1EPSS 0.030
CVE-2022-26629
An Access Control vulnerability exists in SoroushPlus+ Messenger 1.0.30 in the Lock Screen Security Feature function due to insufficient permissions and privileges, which allows a malicious attacker bypass the lock screen function.
Published 2022-03-24 · Modified
9.1EPSS 0.028
CVE-2023-38432
An issue was discovered in the Linux kernel before 6.3.10. fs/smb/server/smb2misc.c in ksmbd does not validate the relationship between the command payload size and the RFC1002 length specification, leading to an out-of-bounds read.
Published 2023-07-17 · Modified
9.1EPSS 0.025
CVE-2018-1426
IBM GSKit (IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1) duplicates the PRNG state across fork() system calls when multiple ICC instances are loaded which could result in duplicate Session IDs and a risk of duplicate key material. IBM X-Force ID: 139071.
Published 2018-03-22 · Modified
9.1EPSS 0.024
CVE-2025-23243
NVIDIA Riva contains a vulnerability where a user could cause an improper access control issue. A successful exploit of this vulnerability might lead to data tampering or denial of service.
Published 2025-03-11 · Analyzed
9.1EPSS 0.021
CVE-2021-38948
IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 211402.
Published 2021-11-02 · Modified
9.1EPSS 0.020
CVE-2021-20399
IBM Qradar SIEM 7.3.0 to 7.3.3 Patch 8 and 7.4.0 to 7.4.3 GA is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 196073.
Published 2021-07-27 · Modified
9.1EPSS 0.018
CVE-2022-22489
IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 226339.
Published 2022-08-19 · Modified
9.1EPSS 0.017
CVE-2024-27053
wifi: wilc1000: fix RCU usage in connect path
Published 2024-05-01 · Modified
9.1EPSS 0.016
CVE-2026-14959
OS Command Injection in IBM Aspera Faspex
Published 2026-07-28 · Analyzed
9.1EPSS 0.016
CVE-2024-35960
net/mlx5: Properly link new fs rules into the tree
Published 2024-05-20 · Modified
9.1EPSS 0.014
CVE-2024-47685
netfilter: nf_reject_ipv6: fix nf_reject_ip6_tcphdr_put()
Published 2024-10-21 · Modified
9.1EPSS 0.014
CVE-2021-21982
VMware Carbon Black Cloud Workload appliance 1.0.0 and 1.01 has an authentication bypass vulnerability that may allow a malicious actor with network access to the administrative interface of the VMware Carbon Black Cloud Workload appliance to obtain a valid authentication token. Successful exploitation of this issue would result in the attacker being able to view and alter administrative configuration settings.
Published 2021-04-01 · Modified
9.1EPSS 0.014
CVE-2026-23455
netfilter: nf_conntrack_h323: check for zero length in DecodeQ931()
Published 2026-04-03 · Modified
9.1EPSS 0.013
CVE-2023-52832
wifi: mac80211: don't return unset power in ieee80211_get_tx_power()
Published 2024-05-21 · Modified
9.1EPSS 0.013
CVE-2023-52735
bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself
Published 2024-05-21 · Analyzed
9.1EPSS 0.012
← Prev43 / 484Next →