VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18475CVEs
CVE-2023-31036
CVE
Published 2024-01-12 · Modified
8.8EPSS 0.009
CVE-2017-5051
An integer overflow in FFmpeg in Google Chrome prior to 57.0.2987.98 for Mac, Windows, and Linux and 57.0.2987.108 for Android allowed a remote attacker to perform an out of bounds memory write via a crafted video file, related to ChunkDemuxer.
Published 2017-04-25 · Modified
8.8EPSS 0.009
CVE-2023-52776
wifi: ath12k: fix dfs-radar and temperature event locking
Published 2024-05-21 · Modified
8.8EPSS 0.008
CVE-2023-47706
IBM Security Guardium Key Lifecycle Manager file upload
Published 2023-12-20 · Modified
8.8EPSS 0.008
CVE-2026-47303
ASP.NET Core Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
8.8EPSS 0.008
CVE-2023-28505
Buffer overflow in UniRPC library function
Published 2023-03-29 · Modified
8.8EPSS 0.008
CVE-2021-1257
Cisco DNA Center Cross-Site Request Forgery Vulnerability
Published 2021-01-20 · Modified
8.8EPSS 0.008
CVE-2020-16022
Insufficient policy enforcement in networking in Google Chrome prior to 87.0.4280.66 allowed a remote attacker to potentially bypass firewall controls via a crafted HTML page.
Published 2021-01-08 · Modified
8.8EPSS 0.008
CVE-2024-43847
wifi: ath12k: fix invalid memory access while processing fragmented packets
Published 2024-08-17 · Modified
8.8EPSS 0.008
CVE-2021-47347
wl1251: Fix possible buffer overflow in wl1251_cmd_scan
Published 2024-05-21 · Modified
8.8EPSS 0.008
CVE-2022-0972
Use after free in Extensions in Google Chrome prior to 99.0.4844.74 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted HTML page.
Published 2022-07-21 · Modified
8.8EPSS 0.008
CVE-2022-45461
The Java Admin Console in Veritas NetBackup through 10.1 and related Veritas products on Linux and UNIX allows authenticated non-root users (that have been explicitly added to the auth.conf file) to execute arbitrary commands as root.
Published 2022-11-17 · Modified
8.8EPSS 0.008
CVE-2022-45412
When resolving a symlink such as <code>file:///proc/self/fd/1</code>, an error message may be produced where the symlink was resolved to a string containing unitialized memory in the buffer. <br>*This bug only affects Thunderbird on Unix-based operated systems (Android, Linux, MacOS). Windows is unaffected.*. This vulnerability affects Firefox ESR < 102.5, Thunderbird < 102.5, and Firefox < 107.
Published 2022-12-22 · Modified
8.8EPSS 0.008
CVE-2021-29686
IBM Security Identity Manager 7.0.2 could allow an authenticated user to bypass security and perform actions that they should not have access to. IBM X-Force ID: 200015
Published 2021-05-20 · Modified
8.8EPSS 0.008
CVE-2026-47300
ASP.NET Core Elevation of Privilege Vulnerability
Published 2026-07-14 · Analyzed
8.8EPSS 0.008
CVE-2025-22039
ksmbd: fix overflow in dacloffset bounds check
Published 2025-04-16 · Modified
8.8EPSS 0.008
CVE-2026-31450
ext4: publish jinode after initialization
Published 2026-04-22 · Modified
8.8EPSS 0.008
CVE-2026-24217
NVIDIA BioNeMo Core for Linux contains a vulnerability where a user could cause a path traversal by loading a malicious file. A successful exploit of this vulnerability might lead to code execution, denial of service, information disclosure, and data tampering.
Published 2026-05-20 · Analyzed
8.8EPSS 0.008
CVE-2019-14821
An out-of-bounds access issue was found in the Linux kernel, all versions through 5.3, in the way Linux kernel's KVM hypervisor implements the Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio' object, wherein write indices 'ring->first' and 'ring->last' value could be supplied by a host user-space process. An unprivileged host user or process with access to '/dev/kvm' device could use this flaw to crash the host kernel, resulting in a denial of service or potentially escalating privileges on the system.
Published 2019-09-19 · Modified
8.8EPSS 0.008
CVE-2024-38605
ALSA: core: Fix NULL module pointer assignment at card init
Published 2024-06-19 · Modified
8.8EPSS 0.007
CVE-2026-7755
MCP Server Configuration Validator Bypass via File Upload API
Published 2026-07-17 · Modified
8.8EPSS 0.007
CVE-2021-29754
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 is vulnerable to a privilege escalation vulnerability when using the SAML Web Inbound Trust Association Interceptor (TAI). IBM X-Force ID: 202006.
Published 2021-06-11 · Modified
8.8EPSS 0.007
CVE-2022-45052
Local File Inclusion in Axiell Iguana CMS
Published 2023-01-04 · Modified
8.8EPSS 0.007
CVE-2026-31433
ksmbd: fix potencial OOB in get_file_all_info() for compound requests
Published 2026-04-22 · Analyzed
8.8EPSS 0.007
CVE-2026-3909
Out of bounds write in Skia in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Published 2026-03-12 · Analyzed
8.8KEVEPSS 0.007
CVE-2026-5281
Use after free in Dawn in Google Chrome prior to 146.0.7680.178 allowed a remote attacker who had compromised the renderer process to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-01 · Analyzed
8.8KEVEPSS 0.007
CVE-2023-40683
IBM OpenPages with Watson privilege escalation
Published 2024-01-19 · Modified
8.8EPSS 0.007
CVE-2024-56626
ksmbd: fix Out-of-Bounds Write in ksmbd_vfs_stream_write
Published 2024-12-27 · Modified
8.8EPSS 0.007
CVE-2024-26689
ceph: prevent use-after-free in encode_cap_msg()
Published 2024-04-03 · Modified
8.8EPSS 0.007
CVE-2025-22040
ksmbd: fix session use-after-free in multichannel connection
Published 2025-04-16 · Analyzed
8.8EPSS 0.007
CVE-2022-0798
Use after free in MediaStream in Google Chrome prior to 99.0.4844.51 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension.
Published 2022-04-05 · Modified
8.8EPSS 0.007
CVE-2025-22041
ksmbd: fix use-after-free in ksmbd_sessions_deregister()
Published 2025-04-16 · Modified
8.8EPSS 0.007
CVE-2026-64394
ksmbd: add a WRITE_DAC/WRITE_OWNER check to SMB2 SET_INFO SECURITY
Published 2026-07-25 · Analyzed
8.8EPSS 0.007
CVE-2026-43187
xfs: delete attr leaf freemap entries when empty
Published 2026-05-06 · Analyzed
8.8EPSS 0.007
CVE-2026-43112
fs/smb/client: fix out-of-bounds read in cifs_sanitize_prepath
Published 2026-05-06 · Modified
8.8EPSS 0.007
CVE-2026-43158
xfs: fix freemap adjustments when adding xattrs to leaf blocks
Published 2026-05-06 · Analyzed
8.8EPSS 0.007
CVE-2026-14499
Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
Published 2026-07-17 · Analyzed
8.8EPSS 0.007
CVE-2026-52911
ksmbd: scope conn->binding slowpath to bound sessions only
Published 2026-06-21 · Analyzed
8.8EPSS 0.007
CVE-2026-31409
ksmbd: unset conn->binding on failed binding request
Published 2026-04-06 · Modified
8.8EPSS 0.007
CVE-2021-3656
A flaw was found in the KVM's AMD code for supporting SVM nested virtualization. The flaw occurs when processing the VMCB (virtual machine control block) provided by the L1 guest to spawn/handle a nested guest (L2). Due to improper validation of the "virt_ext" field, this issue could allow a malicious L1 to disable both VMLOAD/VMSAVE intercepts and VLS (Virtual VMLOAD/VMSAVE) for the L2 guest. As a result, the L2 guest would be allowed to read/write physical pages of the host, resulting in a crash of the entire system, leak of sensitive data or potential guest-to-host escape.
Published 2022-03-04 · Modified
8.8EPSS 0.007
← Prev49 / 462Next →