VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18475CVEs
CVE-2026-31570
can: gw: fix OOB heap access in cgw_csum_crc8_rel()
Published 2026-04-24 · Analyzed
8.8EPSS 0.004
CVE-2026-46198
batman-adv: fix integer overflow on buff_pos
Published 2026-05-28 · Analyzed
8.8EPSS 0.004
CVE-2026-10904
Inappropriate implementation in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-10928
Script injection in Headless in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-43215
cifs: Fix locking usage for tcon fields
Published 2026-05-06 · Analyzed
8.8EPSS 0.004
CVE-2025-13633
Use after free in Digital Credentials in Google Chrome prior to 143.0.7499.41 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-12-02 · Analyzed
8.8EPSS 0.004
CVE-2024-40911
wifi: cfg80211: Lock wiphy in cfg80211_get_station
Published 2024-07-12 · Modified
8.8EPSS 0.004
CVE-2026-3538
Integer overflow in Skia in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-03-04 · Modified
8.8EPSS 0.004
CVE-2026-7899
Out of bounds read and write in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-06 · Analyzed
8.8EPSS 0.004
CVE-2026-64441
staging: rtl8723bs: fix OOB reads in rtw_get_sec_ie(), rtw_get_wapi_ie(), and rtw_get_wps_attr()
Published 2026-07-25 · Analyzed
8.8EPSS 0.004
CVE-2026-43495
net: wwan: t7xx: validate port_count against message length in t7xx_port_enum_msg_handler
Published 2026-05-21 · Analyzed
8.8EPSS 0.004
CVE-2026-9976
Inappropriate implementation in USB in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-28 · Analyzed
8.8EPSS 0.004
CVE-2026-43018
Bluetooth: hci_event: fix potential UAF in hci_le_remote_conn_param_req_evt
Published 2026-05-01 · Analyzed
8.8EPSS 0.004
CVE-2026-3931
Heap buffer overflow in Skia in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-03-11 · Analyzed
8.8EPSS 0.004
CVE-2026-31408
Bluetooth: SCO: Fix use-after-free in sco_recv_frame() due to missing sock_hold
Published 2026-04-06 · Modified
8.8EPSS 0.004
CVE-2026-64096
batman-adv: mcast: fix use-after-free in orig_node RCU release
Published 2026-07-19 · Analyzed
8.8EPSS 0.004
CVE-2026-46212
batman-adv: bla: prevent use-after-free when deleting claims
Published 2026-05-28 · Analyzed
8.8EPSS 0.004
CVE-2026-5272
Heap buffer overflow in GPU in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-01 · Analyzed
8.8EPSS 0.004
CVE-2022-49138
Bluetooth: hci_event: Ignore multiple conn complete events
Published 2025-02-26 · Modified
8.8EPSS 0.004
CVE-2026-5275
Heap buffer overflow in ANGLE in Google Chrome on Mac prior to 146.0.7680.178 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-01 · Analyzed
8.8EPSS 0.004
CVE-2026-7927
Type Confusion in Runtime in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-06 · Analyzed
8.8EPSS 0.004
CVE-2024-46755
wifi: mwifiex: Do not return unused priv in mwifiex_get_priv_by_id()
Published 2024-09-18 · Modified
8.8EPSS 0.004
CVE-2026-5863
Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-08 · Modified
8.8EPSS 0.004
CVE-2026-43048
HID: core: Mitigate potential OOB by removing bogus memset()
Published 2026-05-01 · Analyzed
8.8EPSS 0.004
CVE-2026-3921
Use after free in TextEncoding in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-03-11 · Analyzed
8.8EPSS 0.004
CVE-2026-5883
Use after free in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-04-08 · Modified
8.8EPSS 0.004
CVE-2026-4447
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-03-20 · Modified
8.8EPSS 0.004
CVE-2026-5884
Insufficient validation of untrusted input in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-04-08 · Analyzed
8.8EPSS 0.004
CVE-2018-6249
NVIDIA GPU Display Driver contains a vulnerability in kernel mode layer handler where a NULL pointer dereference may lead to denial of service or potential escalation of privileges.
Published 2018-04-02 · Modified
8.8EPSS 0.004
CVE-2026-10935
Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-10962
Type Confusion in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2020-29569
An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block backend expects the kernel thread handler to reset ring->xenblkd to NULL when stopped. However, the handler may not have time to run if the frontend quickly toggles between the states connect and disconnect. As a consequence, the block backend may re-use a pointer after it was freed. A misbehaving guest can trigger a dom0 crash by continuously connecting / disconnecting a block frontend. Privilege escalation and information leaks cannot be ruled out. This only affects systems with a Linux blkback.
Published 2020-12-15 · Modified
8.8EPSS 0.004
CVE-2026-10936
Type Confusion in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-10956
Use after free in MimeHandlerView in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-10954
Use after free in Actor in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-10895
Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-10883
Type Confusion in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-10902
Use after free in Ozone in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2025-38437
ksmbd: fix potential use-after-free in oplock/lease break ack
Published 2025-07-25 · Modified
8.8EPSS 0.004
CVE-2026-53240
xfrm: iptfs: fix use-after-free on first_skb in __input_process_payload
Published 2026-06-25 · Analyzed
8.8EPSS 0.004
← Prev54 / 462Next →