VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18475CVEs
CVE-2026-10963
Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-10965
Integer overflow in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-10957
Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-10987
Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-10893
Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-3537
Object lifecycle issue in PowerVR in Google Chrome on Android prior to 145.0.7632.159 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-03-04 · Modified
8.8EPSS 0.004
CVE-2018-16882
A use-after-free issue was found in the way the Linux kernel's KVM hypervisor processed posted interrupts when nested(=1) virtualization is enabled. In nested_get_vmcs12_pages(), in case of an error while processing posted interrupt address, it unmaps the 'pi_desc_page' without resetting 'pi_desc' descriptor address, which is later used in pi_test_and_clear_on(). A guest user/process could use this flaw to crash the host kernel resulting in DoS or potentially gain privileged access to a system. Kernel versions before 4.14.91 and before 4.19.13 are vulnerable.
Published 2019-01-03 · Modified
8.8EPSS 0.004
CVE-2026-10945
Use after free in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-11662
Type Confusion in Bindings in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.004
CVE-2026-4463
Heap buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-03-20 · Analyzed
8.8EPSS 0.004
CVE-2022-49114
scsi: libfc: Fix use after free in fc_exch_abts_resp()
Published 2025-02-26 · Modified
8.8EPSS 0.004
CVE-2026-4442
Heap buffer overflow in CSS in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-03-20 · Analyzed
8.8EPSS 0.004
CVE-2026-4444
Stack buffer overflow in WebRTC in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-03-20 · Analyzed
8.8EPSS 0.004
CVE-2022-50386
Bluetooth: L2CAP: Fix user-after-free
Published 2025-09-18 · Modified
8.8EPSS 0.004
CVE-2026-4448
Heap buffer overflow in ANGLE in Google Chrome prior to 146.0.7680.153 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-03-20 · Analyzed
8.8EPSS 0.004
CVE-2025-37952
ksmbd: Fix UAF in __close_file_table_ids
Published 2025-05-20 · Modified
8.8EPSS 0.004
CVE-2026-3544
Heap buffer overflow in WebCodecs in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)
Published 2026-03-04 · Analyzed
8.8EPSS 0.004
CVE-2024-27416
Bluetooth: hci_event: Fix handling of HCI_EV_IO_CAPA_REQUEST
Published 2024-05-17 · Modified
8.8EPSS 0.004
CVE-2026-11074
Use after free in WebRTC in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-3536
Integer overflow in ANGLE in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-03-04 · Modified
8.8EPSS 0.004
CVE-2026-3540
Inappropriate implementation in WebAudio in Google Chrome prior to 145.0.7632.159 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Published 2026-03-04 · Analyzed
8.8EPSS 0.004
CVE-2024-44988
net: dsa: mv88e6xxx: Fix out-of-bound access
Published 2024-09-04 · Modified
8.8EPSS 0.004
CVE-2026-11054
Use after free in WebRTC in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-11068
Use after free in WebSockets in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-4439
Out of bounds memory access in WebGL in Google Chrome on Android prior to 146.0.7680.153 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-03-20 · Analyzed
8.8EPSS 0.004
CVE-2026-64364
HID: multitouch: fix out-of-bounds bit access on mt_io_flags
Published 2026-07-25 · Analyzed
8.8EPSS 0.004
CVE-2026-64313
crypto: ecc - Fix carry overflow in vli multiplication
Published 2026-07-25 · Analyzed
8.8EPSS 0.004
CVE-2025-37776
ksmbd: fix use-after-free in smb_break_all_levII_oplock()
Published 2025-05-01 · Modified
8.8EPSS 0.004
CVE-2026-64382
smb: client: fix double-free in SMB2_open() replay
Published 2026-07-25 · Analyzed
8.8EPSS 0.004
CVE-2026-43239
smb: client: prevent races in ->query_interfaces()
Published 2026-05-06 · Analyzed
8.8EPSS 0.004
CVE-2026-14108
Use after free in PDFium in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted PDF file. (Chromium security severity: Low)
Published 2026-06-30 · Analyzed
8.8EPSS 0.004
CVE-2026-53248
net: airoha: Fix use-after-free in metadata dst teardown
Published 2026-06-25 · Analyzed
8.8EPSS 0.004
CVE-2026-9114
Use after free in QUIC in Google Chrome on prior to 148.0.7778.179 allowed a remote attacker to execute arbitrary code inside a sandbox via malicious network traffic. (Chromium security severity: High)
Published 2026-05-20 · Analyzed
8.8EPSS 0.004
CVE-2024-35811
wifi: brcmfmac: Fix use-after-free bug in brcmf_cfg80211_detach
Published 2024-05-17 · Modified
8.8EPSS 0.004
CVE-2026-11024
Stack buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially exploit stack corruption via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.004
CVE-2026-31629
nfc: llcp: add missing return after LLCP_CLOSED checks
Published 2026-04-24 · Modified
8.8EPSS 0.004
CVE-2026-0900
Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-01-20 · Analyzed
8.8EPSS 0.004
CVE-2022-48871
tty: serial: qcom-geni-serial: fix slab-out-of-bounds on RX FIFO buffer
Published 2024-08-21 · Modified
8.8EPSS 0.003
CVE-2022-49519
ath10k: skip ath10k_halt during suspend for driver state RESTARTING
Published 2025-02-26 · Modified
8.8EPSS 0.003
CVE-2022-50098
scsi: qla2xxx: Fix crash due to stale SRB access around I/O timeouts
Published 2025-06-18 · Modified
8.8EPSS 0.003
← Prev57 / 462Next →