VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18492CVEs
CVE-2026-10015
Integer overflow in WTF in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-05-28 · Analyzed
8.8EPSS 0.003
CVE-2026-11630
Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
Published 2026-06-08 · Analyzed
8.8EPSS 0.003
CVE-2026-4458
Use after free in Extensions in Google Chrome prior to 146.0.7680.153 allowed an attacker who convinced a user to install a malicious extension to potentially exploit heap corruption via a crafted Chrome Extension. (Chromium security severity: High)
Published 2026-03-20 · Analyzed
8.8EPSS 0.003
CVE-2026-11664
Use after free in Payments in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.003
CVE-2026-43334
Bluetooth: SMP: force responder MITM requirements before building the pairing response
Published 2026-05-08 · Analyzed
8.8EPSS 0.003
CVE-2026-2321
Use after free in Ozone in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-02-11 · Modified
8.8EPSS 0.003
CVE-2025-38174
thunderbolt: Do not double dequeue a configuration request
Published 2025-07-04 · Modified
8.8EPSS 0.003
CVE-2025-37943
wifi: ath12k: Fix invalid data access in ath12k_dp_rx_h_undecap_nwifi
Published 2025-05-20 · Modified
8.8EPSS 0.003
CVE-2022-48991
mm/khugepaged: invoke MMU notifiers in shmem/file collapse paths
Published 2024-10-21 · Modified
8.8EPSS 0.003
CVE-2024-58096
wifi: ath11k: add srng->lock for ath11k_hal_srng_* in monitor mode
Published 2025-04-16 · Modified
8.8EPSS 0.003
CVE-2025-37944
wifi: ath12k: Fix invalid entry fetch in ath12k_dp_mon_srng_process
Published 2025-05-20 · Modified
8.8EPSS 0.003
CVE-2021-47184
i40e: Fix NULL ptr dereference on VSI filter sync
Published 2024-04-10 · Modified
8.8EPSS 0.003
CVE-2026-23193
scsi: target: iscsi: Fix use-after-free in iscsit_dec_session_usage_count()
Published 2026-02-14 · Modified
8.8EPSS 0.003
CVE-2026-23395
Bluetooth: L2CAP: Fix accepting multiple L2CAP_ECRED_CONN_REQ
Published 2026-03-25 · Analyzed
8.8EPSS 0.002
CVE-2025-13227
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-17 · Analyzed
8.8EPSS 0.002
CVE-2025-13230
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-17 · Analyzed
8.8EPSS 0.002
CVE-2025-38377
rose: fix dangling neighbour pointers in rose_rt_device_down()
Published 2025-07-25 · Modified
8.8EPSS 0.002
CVE-2023-52502
net: nfc: fix races in nfc_llcp_sock_get() and nfc_llcp_sock_get_sn()
Published 2024-03-02 · Modified
8.8EPSS 0.002
CVE-2025-13228
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-17 · Analyzed
8.8EPSS 0.002
CVE-2025-13229
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-17 · Analyzed
8.8EPSS 0.002
CVE-2026-11091
Inappropriate implementation in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-23461
Bluetooth: L2CAP: Fix use-after-free in l2cap_unregister_user
Published 2026-04-03 · Analyzed
8.8EPSS 0.002
CVE-2025-13226
Type Confusion in V8 in Google Chrome prior to 142.0.7444.59 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-17 · Analyzed
8.8EPSS 0.002
CVE-2023-52910
iommu/iova: Fix alloc iova overflows issue
Published 2024-08-21 · Modified
8.8EPSS 0.002
CVE-2023-53673
Bluetooth: hci_event: call disconnect callback before deleting conn
Published 2025-10-07 · Modified
8.8EPSS 0.002
CVE-2026-11674
Use after free in Guest View in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.002
CVE-2026-11673
Use after free in InterestGroups in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.8EPSS 0.002
CVE-2022-49931
IB/hfi1: Correctly move list in sc_disable()
Published 2025-05-01 · Modified
8.8EPSS 0.002
CVE-2025-37790
net: mctp: Set SOCK_RCU_FREE
Published 2025-05-01 · Modified
8.8EPSS 0.002
CVE-2026-11230
Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-11235
Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2026-11248
Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.8EPSS 0.002
CVE-2025-38601
wifi: ath11k: clear initialized flag for deinit-ed srng lists
Published 2025-08-19 · Modified
8.8EPSS 0.002
CVE-2024-26598
KVM: arm64: vgic-its: Avoid potential UAF in LPI translation cache
Published 2024-02-23 · Modified
8.8EPSS 0.002
CVE-2024-26990
KVM: x86/mmu: Write-protect L2 SPTEs in TDP MMU when clearing dirty status
Published 2024-05-01 · Modified
8.8EPSS 0.002
CVE-2024-53135
KVM: VMX: Bury Intel PT virtualization (guest/host mode) behind CONFIG_BROKEN
Published 2024-12-04 · Modified
8.8EPSS 0.002
CVE-2025-37918
Bluetooth: btusb: avoid NULL pointer dereference in skb_dequeue()
Published 2025-05-20 · Modified
8.8EPSS 0.002
CVE-2021-47111
xen-netback: take a reference to the RX task thread
Published 2024-03-15 · Modified
8.8EPSS 0.002
CVE-2026-46152
wifi: mac80211: drop stray 'static' from fast-RX rx_result
Published 2026-05-28 · Modified
8.8EPSS 0.002
CVE-2024-35804
KVM: x86: Mark target gfn of emulated atomic instruction as dirty
Published 2024-05-17 · Modified
8.8EPSS 0.002
← Prev64 / 463Next →