VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18475CVEs
CVE-2025-37849
KVM: arm64: Tear down vGIC on failed vCPU creation
Published 2025-05-09 · Modified
8.8EPSS 0.003
CVE-2026-52918
Bluetooth: serialize accept_q access
Published 2026-06-24 · Analyzed
8.8EPSS 0.003
CVE-2026-11646
Use after free in ViewTransitions in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.003
CVE-2026-23462
Bluetooth: HIDP: Fix possible UAF
Published 2026-04-03 · Analyzed
8.8EPSS 0.003
CVE-2025-12727
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.137 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-10 · Analyzed
8.8EPSS 0.003
CVE-2025-13042
Inappropriate implementation in V8 in Google Chrome prior to 142.0.7444.166 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-12 · Analyzed
8.8EPSS 0.003
CVE-2021-47390
KVM: x86: Fix stack-out-of-bounds memory access from ioapic_write_indirect()
Published 2024-05-21 · Modified
8.8EPSS 0.003
CVE-2026-64206
Bluetooth: L2CAP: cancel pending_rx_work before taking conn->lock
Published 2026-07-20 · Analyzed
8.8EPSS 0.003
CVE-2026-11144
Use after free in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted video file. (Chromium security severity: Medium)
Published 2026-06-04 · Modified
8.8EPSS 0.003
CVE-2025-13638
Use after free in Media Stream in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Low)
Published 2025-12-02 · Analyzed
8.8EPSS 0.003
CVE-2025-10201
Inappropriate implementation in Mojo in Google Chrome on Android, Linux, ChromeOS prior to 140.0.7339.127 allowed a remote attacker to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Published 2025-09-10 · Analyzed
8.8EPSS 0.003
CVE-2021-47035
iommu/vt-d: Remove WO permissions on second-level paging entries
Published 2024-02-28 · Modified
8.8EPSS 0.003
CVE-2026-10890
Use after free in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: Critical)
Published 2026-06-04 · Analyzed
8.8EPSS 0.003
CVE-2025-23133
wifi: ath11k: update channel list in reg notifier instead reg worker
Published 2025-04-16 · Modified
8.8EPSS 0.003
CVE-2026-11688
Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.003
CVE-2024-41090
tap: add missing verification for short frame
Published 2024-07-29 · Modified
8.8EPSS 0.003
CVE-2024-41091
tun: add missing verification for short frame
Published 2024-07-29 · Modified
8.8EPSS 0.003
CVE-2026-53275
ipv6: mcast: Fix use-after-free when processing MLD queries
Published 2026-06-25 · Modified
8.8EPSS 0.003
CVE-2026-64434
Bluetooth: L2CAP: Fix UAF in channel timeout by holding conn ref
Published 2026-07-25 · Analyzed
8.8EPSS 0.003
CVE-2026-53232
net: phy: clean the sfp upstream if phy probing fails
Published 2026-06-25 · Modified
8.8EPSS 0.003
CVE-2023-27272
IBM Aspera Console weak password requirements
Published 2025-04-14 · Analyzed
8.8EPSS 0.003
CVE-2023-52478
HID: logitech-hidpp: Fix kernel crash on receiver USB disconnect
Published 2024-02-29 · Modified
8.8EPSS 0.003
CVE-2022-48785
ipv6: mcast: use rcu-safe version of ipv6_get_lladdr()
Published 2024-07-16 · Modified
8.8EPSS 0.003
CVE-2025-39839
batman-adv: fix OOB read/write in network-coding decode
Published 2025-09-19 · Modified
8.8EPSS 0.003
CVE-2026-64366
HID: wacom: fix slab-out-of-bounds write in wacom_wac_queue_insert
Published 2026-07-25 · Analyzed
8.8EPSS 0.003
CVE-2025-13855
IBM Storage Protect Server is affected by a vulnerability that could allow authenticated users to access administrative metadata through the JSON-RPC endpoint .
Published 2026-04-01 · Analyzed
8.8EPSS 0.003
CVE-2022-48864
vdpa/mlx5: add validation for VIRTIO_NET_CTRL_MQ_VQ_PAIRS_SET command
Published 2024-07-16 · Modified
8.8EPSS 0.003
CVE-2026-2321
Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-02-11 · Modified
8.8EPSS 0.003
CVE-2026-10016
Use after free in DOM in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-28 · Analyzed
8.8EPSS 0.003
CVE-2026-10007
Use after free in SVG in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-28 · Analyzed
8.8EPSS 0.003
CVE-2025-12438
Use after free in Ozone in Google Chrome on Linux and ChromeOS prior to 142.0.7444.59 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page. (Chromium security severity: Medium)
Published 2025-11-10 · Analyzed
8.8EPSS 0.003
CVE-2026-11630
Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-08 · Analyzed
8.8EPSS 0.003
CVE-2024-27415
netfilter: bridge: confirm multicast packets before passing them up the stack
Published 2024-05-17 · Modified
8.8EPSS 0.003
CVE-2026-43334
Bluetooth: SMP: force responder MITM requirements before building the pairing response
Published 2026-05-08 · Analyzed
8.8EPSS 0.003
CVE-2026-10015
Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-28 · Analyzed
8.8EPSS 0.003
CVE-2026-4458
Use after free in Extensions in Google Chrome prior to 146.0.7680.153 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
Published 2026-03-20 · Analyzed
8.8EPSS 0.003
CVE-2026-11664
Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.003
CVE-2022-48991
mm/khugepaged: invoke MMU notifiers in shmem/file collapse paths
Published 2024-10-21 · Modified
8.8EPSS 0.003
CVE-2025-37943
wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi
Published 2025-05-20 · Modified
8.8EPSS 0.003
CVE-2025-38174
thunderbolt: Do not double dequeue a configuration request
Published 2025-07-04 · Modified
8.8EPSS 0.003
← Prev63 / 462Next →