VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18475CVEs
CVE-2021-26615
bandisoft ARK library integer overflow vulnerability
Published 2021-11-26 · Modified
8.8EPSS 0.007
CVE-2025-36049
IBM webMethods Integration Sever XML external entity injection
Published 2025-06-18 · Analyzed
8.8EPSS 0.006
CVE-2026-53266
netfilter: bridge: make ebt_snat ARP rewrite writable
Published 2026-06-25 · Analyzed
8.8KEVEPSS 0.006
CVE-2021-3491
Linux kernel io_uring PROVIDE_BUFFERS MAX_RW_COUNT bypass
Published 2021-06-04 · Modified
8.8EPSS 0.006
CVE-2022-49017
tipc: re-fetch skb cb after tipc_msg_validate
Published 2024-10-21 · Modified
8.8EPSS 0.006
CVE-2026-31706
ksmbd: validate num_aces and harden ACE walk in smb_inherit_dacl()
Published 2026-05-01 · Analyzed
8.8EPSS 0.006
CVE-2026-64396
ksmbd: fix UAF of struct file_lock in SMB2_LOCK deferred-lock cancellation
Published 2026-07-25 · Analyzed
8.8EPSS 0.006
CVE-2025-37947
ksmbd: prevent out-of-bounds stream writes by validating *pos
Published 2025-05-20 · Modified
8.8EPSS 0.006
CVE-2026-64437
ksmbd: fix use-after-free of a deferred file_lock on SMB2_CLOSE then SMB2_CANCEL
Published 2026-07-25 · Analyzed
8.8EPSS 0.006
CVE-2024-49988
ksmbd: add refcnt to ksmbd_conn struct
Published 2024-10-21 · Modified
8.8EPSS 0.006
CVE-2026-12443
Use after free in Web Authentication in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-17 · Analyzed
8.8EPSS 0.006
CVE-2023-52479
ksmbd: fix uaf in smb20_oplock_break_ack
Published 2024-02-29 · Modified
8.8EPSS 0.006
CVE-2026-1862
Type Confusion in V8 in Google Chrome prior to 144.0.7559.132 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-02-03 · Analyzed
8.8EPSS 0.006
CVE-2026-31432
ksmbd: fix OOB write in QUERY_INFO for compound requests
Published 2026-04-22 · Modified
8.8EPSS 0.006
CVE-2026-31739
crypto: tegra - Add missing CRYPTO_ALG_ASYNC
Published 2026-05-01 · Analyzed
8.8EPSS 0.006
CVE-2026-64138
ksmbd: validate SID in parent security descriptor during ACL inheritance
Published 2026-07-19 · Analyzed
8.8EPSS 0.006
CVE-2026-43490
ksmbd: validate inherited ACE SID length
Published 2026-05-15 · Analyzed
8.8EPSS 0.006
CVE-2026-31717
ksmbd: validate owner of durable handle on reconnect
Published 2026-05-01 · Modified
8.8EPSS 0.006
CVE-2026-43232
net: wan: farsync: Fix use-after-free bugs caused by unfinished tasklets
Published 2026-05-06 · Analyzed
8.8EPSS 0.006
CVE-2024-1545
Fault Injection of RSA encryption in WolfCrypt
Published 2024-08-29 · Modified
8.8EPSS 0.006
CVE-2024-35854
mlxsw: spectrum_acl_tcam: Fix possible use-after-free during rehash
Published 2024-05-17 · Modified
8.8EPSS 0.006
CVE-2025-10200
Use after free in Serviceworker in Google Chrome on Desktop prior to 140.0.7339.127 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Published 2025-09-10 · Analyzed
8.8EPSS 0.006
CVE-2024-26362
HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note.
Published 2024-04-10 · Analyzed
8.8EPSS 0.006
CVE-2026-5858
Heap buffer overflow in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-04-08 · Analyzed
8.8EPSS 0.006
CVE-2026-9939
Heap buffer overflow in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-28 · Analyzed
8.8EPSS 0.006
CVE-2026-7667
Path Traversal Vulnerability in API Request Component Content-Disposition Header Processing
Published 2026-07-17 · Analyzed
8.8EPSS 0.006
CVE-2022-40231
IBM Sterling B2B Integrator Standard Edition improper access control
Published 2023-02-17 · Modified
8.8EPSS 0.006
CVE-2023-25922
IBM Security Guardium Key Lifecycle Manager file upload
Published 2024-02-28 · Analyzed
8.8EPSS 0.006
CVE-2026-4443
Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-03-20 · Analyzed
8.8EPSS 0.005
CVE-2025-37926
ksmbd: fix use-after-free in ksmbd_session_rpc_open
Published 2025-05-20 · Modified
8.8EPSS 0.005
CVE-2025-38052
net/tipc: fix slab-use-after-free Read in tipc_aead_encrypt_done
Published 2025-06-18 · Modified
8.8EPSS 0.005
CVE-2022-42438
IBM Cloud Pak for Multicloud Management Monitoring privilege escalation
Published 2023-02-08 · Modified
8.8EPSS 0.005
CVE-2026-8509
Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-05-14 · Analyzed
8.8EPSS 0.005
CVE-2026-9119
Heap buffer overflow in WebRTC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-20 · Analyzed
8.8EPSS 0.005
CVE-2026-8056
Parameter Injection Vulnerability in API Graph Execution Engine
Published 2026-07-17 · Analyzed
8.8EPSS 0.005
CVE-2026-8526
Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-14 · Analyzed
8.8EPSS 0.005
CVE-2026-8524
Out of bounds write in WebAudio in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-14 · Analyzed
8.8EPSS 0.005
CVE-2026-4678
Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-03-24 · Analyzed
8.8EPSS 0.005
CVE-2026-7951
Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-05-06 · Analyzed
8.8EPSS 0.005
CVE-2026-8016
Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Published 2026-05-06 · Analyzed
8.8EPSS 0.005
← Prev50 / 462Next →