VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18475CVEs
CVE-2026-8526
Out of bounds write in WebRTC in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-14 · Analyzed
8.8EPSS 0.005
CVE-2026-8016
Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Published 2026-05-06 · Analyzed
8.8EPSS 0.005
CVE-2026-63801
tipc: fix slab-use-after-free Read in tipc_aead_decrypt_done
Published 2026-07-19 · Analyzed
8.8EPSS 0.005
CVE-2026-31435
netfs: Fix read abandonment during retry
Published 2026-04-22 · Analyzed
8.8EPSS 0.005
CVE-2025-21945
ksmbd: fix use-after-free in smb2_lock
Published 2025-04-01 · Modified
8.8EPSS 0.005
CVE-2024-36964
fs/9p: only translate RWX permissions for plain 9P2000
Published 2024-06-03 · Modified
8.8EPSS 0.005
CVE-2026-7988
Type Confusion in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-05-06 · Analyzed
8.8EPSS 0.005
CVE-2026-75624
IBM App Connect Enterprise is vulnerable to privilege escalation and Denial of Service
Published 2026-09-10 · Analyzed
8.8EPSS 0.005
CVE-2026-19298
Langflow is vulnerable to remote code execution due to authorization policy bypass in the authenticated flow-build endpoint
Published 2026-09-04 · Analyzed
8.8EPSS 0.005
CVE-2026-10943
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.005
CVE-2026-10947
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.005
CVE-2026-10903
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.005
CVE-2026-10948
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.005
CVE-2021-29888
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 207123.
Published 2021-11-02 · Modified
8.8EPSS 0.005
CVE-2025-21955
ksmbd: prevent connection release during oplock break notification
Published 2025-04-01 · Modified
8.8EPSS 0.005
CVE-2025-22074
ksmbd: fix r_count dec/increment mismatch
Published 2025-04-16 · Modified
8.8EPSS 0.005
CVE-2026-7341
Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-28 · Analyzed
8.8EPSS 0.005
CVE-2026-7342
Use after free in WebView in Google Chrome on Android prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-28 · Analyzed
8.8EPSS 0.005
CVE-2026-7336
Use after free in WebRTC in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-28 · Analyzed
8.8EPSS 0.005
CVE-2026-9995
Use after free in WebXR in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-28 · Analyzed
8.8EPSS 0.005
CVE-2026-9962
Use after free in WebRTC in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-28 · Analyzed
8.8EPSS 0.005
CVE-2026-9120
Use after free in WebRTC in Google Chrome prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-20 · Analyzed
8.8EPSS 0.005
CVE-2026-9111
Use after free in WebRTC in Google Chrome on Linux prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-05-20 · Analyzed
8.8EPSS 0.005
CVE-2025-21946
ksmbd: fix out-of-bounds in parse_sec_desc()
Published 2025-04-01 · Modified
8.8EPSS 0.005
CVE-2026-63796
ocfs2: reject oversized group bitmap descriptors
Published 2026-07-19 · Analyzed
8.8EPSS 0.005
CVE-2025-12382
Path Traversal Allows Remote Code Execution in AlgoSec Firewall Analyzer
Published 2025-11-12 · Analyzed
8.8EPSS 0.005
CVE-2024-36013
Bluetooth: L2CAP: Fix slab-use-after-free in l2cap_connect()
Published 2024-05-23 · Modified
8.8EPSS 0.005
CVE-2025-13481
IBM Aspera Orchestrator Command Injection
Published 2025-12-11 · Analyzed
8.8EPSS 0.005
CVE-2026-24186
NVIDIA FLARE SDK contains a vulnerability in FOBS, where an attacker may cause deserialization of untrusted data by sending a malicious FOBS- encoded message. A successful exploit of this vulnerability might lead to code execution.
Published 2026-04-28 · Analyzed
8.8EPSS 0.005
CVE-2026-64445
staging: rtl8723bs: fix WEP length underflow and OOB read in OnAuth()
Published 2026-07-25 · Analyzed
8.8EPSS 0.005
CVE-2026-31709
smb: client: validate the whole DACL before rewriting it in cifsacl
Published 2026-05-01 · Modified
8.8EPSS 0.005
CVE-2022-48919
cifs: fix double free race when mount fails in cifs_get_root()
Published 2024-08-22 · Modified
8.8EPSS 0.005
CVE-2026-10882
Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-04 · Analyzed
8.8EPSS 0.005
CVE-2026-64390
ksmbd: track the connection owning a byte-range lock
Published 2026-07-25 · Analyzed
8.8EPSS 0.005
CVE-2025-13224
Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-17 · Analyzed
8.8EPSS 0.005
CVE-2024-2881
Fault Injection of EdDSA signature in WolfCrypt
Published 2024-08-29 · Analyzed
8.8EPSS 0.005
CVE-2026-7980
Use after free in WebAudio in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-05-06 · Analyzed
8.8EPSS 0.005
CVE-2026-5285
Use after free in WebGL in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-01 · Modified
8.8EPSS 0.005
CVE-2026-7987
Use after free in WebRTC in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-05-06 · Analyzed
8.8EPSS 0.005
CVE-2026-5278
Use after free in Web MIDI in Google Chrome on Android prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-01 · Analyzed
8.8EPSS 0.005
← Prev51 / 462Next →