VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18475CVEs
CVE-2024-41062
bluetooth/l2cap: sync sock recv cb and release
Published 2024-07-29 · Modified
8.8EPSS 0.003
CVE-2025-38495
HID: core: ensure the allocated report buffer can contain the reserved report ID
Published 2025-07-28 · Modified
8.8EPSS 0.003
CVE-2026-11683
Use after free in WebCodecs in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.003
CVE-2024-43881
wifi: ath12k: change DMA direction while mapping reinjected packets
Published 2024-08-21 · Modified
8.8EPSS 0.003
CVE-2024-38620
Bluetooth: HCI: Remove HCI_AMP support
Published 2024-06-20 · Modified
8.8EPSS 0.003
CVE-2026-7896
Integer overflow in Blink in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-05-06 · Analyzed
8.8EPSS 0.003
CVE-2026-5274
Integer overflow in Codecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-01 · Analyzed
8.8EPSS 0.003
CVE-2026-5292
Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-04-01 · Analyzed
8.8EPSS 0.003
CVE-2025-37885
KVM: x86: Reset IRTE to host control if *new* route isn't postable
Published 2025-05-09 · Modified
8.8EPSS 0.003
CVE-2026-10922
Insufficient validation of untrusted input in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via malicious network traffic. (Chromium security severity: High)
Published 2026-06-04 · Analyzed
8.8EPSS 0.003
CVE-2025-12429
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-10 · Analyzed
8.8EPSS 0.003
CVE-2022-48782
mctp: fix use after free
Published 2024-07-16 · Modified
8.8EPSS 0.003
CVE-2026-77105
CommServe Privilege Escalation
Published 2026-09-08 · Analyzed
8.8EPSS 0.003
CVE-2026-11042
Use after free in Views in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.003
CVE-2026-12441
Use after free in File Input in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-17 · Analyzed
8.8EPSS 0.003
CVE-2024-42318
landlock: Don't lose track of restrictions on cred_transfer
Published 2024-08-17 · Modified
8.8EPSS 0.003
CVE-2025-69276
Spectrum insecure deserialiation
Published 2026-01-12 · Analyzed
8.8EPSS 0.003
CVE-2023-38268
IBM InfoSphere Information Server cross-site request forgery
Published 2023-12-01 · Modified
8.8EPSS 0.003
CVE-2022-49238
ath11k: free peer for station when disconnect from AP for QCA6390/WCN6855
Published 2025-02-26 · Modified
8.8EPSS 0.003
CVE-2022-35286
IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 230814.
Published 2022-07-26 · Modified
8.8EPSS 0.003
CVE-2024-50113
firewire: core: fix invalid port index for parent device
Published 2024-11-05 · Modified
8.8EPSS 0.003
CVE-2025-22086
RDMA/mlx5: Fix mlx5_poll_one() cur_qp update flow
Published 2025-04-16 · Modified
8.8EPSS 0.003
CVE-2026-0902
Inappropriate implementation in V8 in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-01-20 · Analyzed
8.8EPSS 0.003
CVE-2022-22493
IBM WebSphere Automation for Cloud Pak for Watson AIOps 1.4.2 is vulnerable to cross-site request forgery, caused by improper cookie attribute setting. IBM X-Force ID: 226449.
Published 2022-10-07 · Modified
8.8EPSS 0.003
CVE-2026-11279
Out of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.003
CVE-2022-30608
"IBM InfoSphere Information Server 11.7 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a "user that the website trusts. IBM X-Force ID: 227295.
Published 2022-11-03 · Modified
8.8EPSS 0.003
CVE-2023-42027
IBM CICS TX cross-site request forgery
Published 2023-11-02 · Modified
8.8EPSS 0.003
CVE-2026-12878
In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin permissions.
Published 2026-08-25 · Analyzed
8.8EPSS 0.003
CVE-2026-23246
wifi: mac80211: bounds-check link_id in ieee80211_ml_reconfiguration
Published 2026-03-18 · Analyzed
8.8EPSS 0.003
CVE-2026-11116
Use after free in Chromoting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Medium)
Published 2026-06-04 · Modified
8.8EPSS 0.003
CVE-2026-46166
wifi: mac80211: use safe list iteration in radar detect work
Published 2026-05-28 · Modified
8.8EPSS 0.003
CVE-2026-9887
Use after free in Proxy in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted PAC script. (Chromium security severity: Critical)
Published 2026-05-28 · Analyzed
8.8EPSS 0.003
CVE-2022-48652
ice: Fix crash by keep old cfg when update TCs more than queues
Published 2024-04-28 · Modified
8.8EPSS 0.003
CVE-2022-2196
Speculative execution attacks in KVM VMX
Published 2023-01-09 · Modified
8.8EPSS 0.003
CVE-2025-8879
Heap buffer overflow in libaom in Google Chrome prior to 139.0.7258.127 allowed a remote attacker to potentially exploit heap corruption via a curated set of gestures. (Chromium security severity: High)
Published 2025-08-13 · Analyzed
8.8EPSS 0.003
CVE-2022-49974
HID: nintendo: fix rumble worker null pointer deref
Published 2025-06-18 · Modified
8.8EPSS 0.003
CVE-2024-56591
Bluetooth: hci_conn: Use disable_delayed_work_sync
Published 2024-12-27 · Modified
8.8EPSS 0.003
CVE-2025-10501
Use after free in WebRTC in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-09-24 · Analyzed
8.8EPSS 0.003
CVE-2026-64088
batman-adv: tt: fix negative tt_buff_len
Published 2026-07-19 · Analyzed
8.8EPSS 0.003
CVE-2026-11130
Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.003
← Prev61 / 462Next →