VendorsLinuxlinux_kernelall versions
Vulnerabilities

Linux Kernel

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19329CVEs
CVE-2023-52832
wifi: mac80211: don't return unset power in ieee80211_get_tx_power()
Published 2024-05-21 · Modified
9.1EPSS 0.013
CVE-2023-52735
bpf, sockmap: Don't let sock_map_{close,destroy,unhash} call itself
Published 2024-05-21 · Analyzed
9.1EPSS 0.012
CVE-2024-35845
wifi: iwlwifi: dbg-tlv: ensure NUL termination
Published 2024-05-17 · Modified
9.1EPSS 0.012
CVE-2023-38430
An issue was discovered in the Linux kernel before 6.3.9. ksmbd does not validate the SMB request protocol ID, leading to an out-of-bounds read.
Published 2023-07-17 · Modified
9.1EPSS 0.012
CVE-2023-38431
An issue was discovered in the Linux kernel before 6.3.8. fs/smb/server/connection.c in ksmbd does not validate the relationship between the NetBIOS header's length field and the SMB header sizes, via pdu_size in ksmbd_conn_handler_loop, leading to an out-of-bounds read.
Published 2023-07-17 · Modified
9.1EPSS 0.012
CVE-2024-2362
Path Traversal in parisneo/lollms-webui
Published 2024-06-06 · Analyzed
9.1EPSS 0.012
CVE-2020-11580
An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, accepts an arbitrary SSL certificate.
Published 2020-04-06 · Modified
9.1EPSS 0.011
CVE-2014-3180
In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible out-of-bounds read. restart_syscall uses uninitialized data when restarting compat_sys_nanosleep. NOTE: this is disputed because the code path is unreachable
Published 2019-11-06 · Modified
9.1EPSS 0.010
CVE-2026-75728
Adobe Campaign Classic (ACC) | Incorrect Authorization (CWE-863)
Published 2026-09-22 · Analyzed
9.1EPSS 0.010
CVE-2022-40747
"IBM InfoSphere Information Server 11.7 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 236584."
Published 2022-11-03 · Modified
9.1EPSS 0.010
CVE-2026-82009
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-09-22 · Analyzed
9.1EPSS 0.010
CVE-2021-47348
drm/amd/display: Avoid HDCP over-read and corruption
Published 2024-05-21 · Analyzed
9.1EPSS 0.010
CVE-2023-44206
Sensitive information disclosure and manipulation due to improper authorization. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 35979.
Published 2023-09-27 · Modified
9.1EPSS 0.010
CVE-2023-47702
IBM Security Guardium Key Lifecycle Manager directory traversal
Published 2023-12-20 · Modified
9.1EPSS 0.010
CVE-2024-36896
USB: core: Fix access violation during port device removal
Published 2024-05-30 · Analyzed
9.1EPSS 0.009
CVE-2024-42284
tipc: Return non-zero value from tipc_udp_addr2str() on error
Published 2024-08-17 · Modified
9.1EPSS 0.009
CVE-2022-49058
cifs: potential buffer overflow in handling symlinks
Published 2025-02-26 · Modified
9.1EPSS 0.009
CVE-2023-44152
Sensitive information disclosure and manipulation due to improper authentication. The following products are affected: Acronis Cyber Protect 15 (Linux, macOS, Windows) before build 35979.
Published 2023-09-27 · Modified
9.1EPSS 0.009
CVE-2026-31682
bridge: br_nd_send: linearize skb before parsing ND options
Published 2026-04-25 · Modified
9.1EPSS 0.008
CVE-2026-52999
netfilter: nfnetlink_osf: fix out-of-bounds read on option matching
Published 2026-06-24 · Modified
9.1EPSS 0.008
CVE-2026-14958
OS command injection in IBM Aspera Faspex
Published 2026-07-28 · Analyzed
9.1EPSS 0.008
CVE-2016-5202
browser/extensions/api/dial/dial_registry.cc in Google Chrome before 54.0.2840.98 on macOS, before 54.0.2840.99 on Windows, and before 54.0.2840.100 on Linux neglects to copy a device ID before an erase() call, which causes the erase operation to access data that that erase operation will destroy.
Published 2019-10-25 · Modified
9.1EPSS 0.008
CVE-2024-47659
smack: tcp: ipv4, fix incorrect labeling
Published 2024-10-09 · Modified
9.1EPSS 0.008
CVE-2023-28365
A backup file vulnerability found in UniFi applications (Version 7.3.83 and earlier) running on Linux operating systems allows application administrators to execute malicious commands on the host device being restored.
Published 2023-06-30 · Analyzed
9.1EPSS 0.008
CVE-2019-25160
netlabel: fix out-of-bounds memory accesses
Published 2024-02-26 · Modified
9.1EPSS 0.008
CVE-2026-64320
nvmet: fix pre-auth out-of-bounds heap read in Discovery Get Log Page
Published 2026-07-25 · Analyzed
9.1EPSS 0.007
CVE-2026-53224
sctp: validate embedded INIT chunk and address list lengths in cookie
Published 2026-06-25 · Analyzed
9.1EPSS 0.007
CVE-2026-47606
NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path traversal. A successful exploit might lead to code execution and information disclosure.
Published 2026-08-18 · Analyzed
9.1EPSS 0.007
CVE-2026-43117
btrfs: tracepoints: get correct superblock from dentry in event btrfs_sync_file()
Published 2026-05-06 · Modified
9.1EPSS 0.007
CVE-2026-53043
ocfs2/dlm: validate qr_numregions in dlm_match_regions()
Published 2026-06-24 · Analyzed
9.1EPSS 0.007
CVE-2026-53186
RDMA/srp: bound SRP_RSP sense copy by the received length
Published 2026-06-25 · Analyzed
9.1EPSS 0.007
CVE-2026-43071
dcache: Limit the minimal number of bucket to two
Published 2026-05-05 · Modified
9.1EPSS 0.007
CVE-2026-43407
libceph: Fix potential out-of-bounds access in ceph_handle_auth_reply()
Published 2026-05-08 · Analyzed
9.1EPSS 0.007
CVE-2026-53225
sctp: fix uninit-value in __sctp_rcv_asconf_lookup()
Published 2026-06-25 · Analyzed
9.1EPSS 0.007
CVE-2026-52958
libceph: Fix potential out-of-bounds access in osdmap_decode()
Published 2026-06-24 · Analyzed
9.1EPSS 0.007
CVE-2021-47354
drm/sched: Avoid data corruptions
Published 2024-05-21 · Modified
9.1EPSS 0.007
CVE-2026-43406
libceph: prevent potential out-of-bounds reads in process_message_header()
Published 2026-05-08 · Analyzed
9.1EPSS 0.007
CVE-2026-46119
libceph: Fix slab-out-of-bounds access in auth message processing
Published 2026-05-28 · Undergoing Analysis
9.1EPSS 0.007
CVE-2026-64269
RDMA/rtrs-srv: Bound RDMA-Write length to chunk size in rdma_write_sg
Published 2026-07-25 · Modified
9.1EPSS 0.007
CVE-2026-46266
inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
Published 2026-06-03 · Modified
9.1EPSS 0.007
← Prev44 / 484Next →