VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18494CVEs
CVE-2022-28199
NVIDIA’s distribution of the Data Plane Development Kit (MLNX_DPDK) contains a vulnerability in the network stack, where error recovery is not handled properly, which can allow a remote attacker to cause denial of service and some impact to data integrity and confidentiality.
Published 2022-09-01 · Modified
8.6EPSS 0.022
CVE-2026-48448
Adobe Campaign Classic (ACC) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89)
Published 2026-07-30 · Analyzed
8.6EPSS 0.008
CVE-2022-46872
An attacker who compromised a content process could have partially escaped the sandbox to read arbitrary files via clipboard-related IPC messages.<br>*This bug only affects Thunderbird for Linux. Other operating systems are unaffected.*. This vulnerability affects Firefox < 108, Firefox ESR < 102.6, and Thunderbird < 102.6.
Published 2022-12-22 · Modified
8.6EPSS 0.008
CVE-2026-46273
ibmveth: Disable GSO for packets with small MSS
Published 2026-06-03 · Modified
8.6EPSS 0.007
CVE-2020-11862
Insecure renegotiation in SSL protocol caused Denial of service attack in Privileged Account Manager
Published 2024-03-13 · Analyzed
8.6EPSS 0.007
CVE-2024-26641
ip6_tunnel: make sure to pull inner header in __ip6_tnl_rcv()
Published 2024-03-18 · Modified
8.6EPSS 0.006
CVE-2021-47136
net: zero-initialize tc skb extension on allocation
Published 2024-03-25 · Modified
8.6EPSS 0.005
CVE-2024-47682
scsi: sd: Fix off-by-one error in sd_read_block_characteristics()
Published 2024-10-21 · Modified
8.6EPSS 0.005
CVE-2026-43139
xfrm6: fix uninitialized saddr in xfrm6_get_saddr()
Published 2026-05-06 · Analyzed
8.6EPSS 0.005
CVE-2026-31611
ksmbd: require 3 sub-authorities before reading sub_auth[2]
Published 2026-04-24 · Modified
8.6EPSS 0.005
CVE-2026-64400
ksmbd: prevent path traversal bypass by restricting caseless retry
Published 2026-07-25 · Analyzed
8.6EPSS 0.005
CVE-2022-1055
Use after Free in tc_new_tfilter allowing for privilege escalation in Linux Kernel
Published 2022-03-29 · Analyzed
8.6EPSS 0.005
CVE-2026-23457
netfilter: nf_conntrack_sip: fix Content-Length u32 truncation in sip_help_tcp()
Published 2026-04-03 · Modified
8.6EPSS 0.004
CVE-2025-21855
ibmvnic: Don't reference skb after sending to VIOS
Published 2025-03-12 · Modified
8.6EPSS 0.004
CVE-2025-38608
bpf, ktls: Fix data corruption when using bpf_msg_pop_data() in ktls
Published 2025-08-19 · Modified
8.6EPSS 0.004
CVE-2026-53217
net: mvpp2: sync RX data at the hardware packet offset
Published 2026-06-25 · Analyzed
8.6EPSS 0.004
CVE-2024-35889
idpf: fix kernel panic on unknown packet types
Published 2024-05-19 · Modified
8.6EPSS 0.004
CVE-2025-38574
pptp: ensure minimal skb length in pptp_xmit()
Published 2025-08-19 · Modified
8.6EPSS 0.004
CVE-2025-22108
bnxt_en: Mask the bd_cnt field in the TX BD properly
Published 2025-04-16 · Modified
8.6EPSS 0.004
CVE-2025-37799
vmxnet3: Fix malformed packet sizing in vmxnet3_process_xdp
Published 2025-05-03 · Modified
8.6EPSS 0.004
CVE-2025-22004
net: atm: fix use after free in lec_send()
Published 2025-04-03 · Modified
8.6EPSS 0.003
CVE-2024-58099
vmxnet3: Fix packet corruption in vmxnet3_xdp_xmit_frame
Published 2025-04-29 · Modified
8.6EPSS 0.003
CVE-2026-19305
Langflow is vulnerable to Server-Side Request Forgery due to missing or bypassable URL validation in multiple components
Published 2026-09-04 · Analyzed
8.6EPSS 0.003
CVE-2022-4895
Man-in-the-middle attack Vulnerability in Hitachi Infrastructure Analytics Advisor, Hitachi Ops Center Analyzer
Published 2023-02-28 · Modified
8.6EPSS 0.003
CVE-2015-4004
The OZWPAN driver in the Linux kernel through 4.0.5 relies on an untrusted length field during packet parsing, which allows remote attackers to obtain sensitive information from kernel memory or cause a denial of service (out-of-bounds read and system crash) via a crafted packet.
Published 2015-06-07 · Modified
8.5EPSS 0.081
CVE-2015-0307
Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe AIR SDK & Compiler before 16.0.0.272 allow remote attackers to obtain sensitive information from process memory or cause a denial of service (out-of-bounds read) via unspecified vectors.
Published 2015-01-13 · Modified
8.5EPSS 0.053
CVE-2014-3094
Stack-based buffer overflow in IBM DB2 9.7 through FP9a, 9.8 through FP5, 10.1 through FP4, and 10.5 before FP4 on Linux, UNIX, and Windows allows remote authenticated users to execute arbitrary code via a crafted ALTER MODULE statement.
Published 2014-09-04 · Modified
8.5EPSS 0.050
CVE-2024-25699
Portal for ArcGIS has an invalid authentication vulnerability
Published 2024-04-04 · Analyzed
8.5EPSS 0.007
CVE-2026-65092
NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7 REST network policy. A successful exploit of this vulnerability might lead to information disclosure and data tampering.
Published 2026-08-25 · Analyzed
8.5EPSS 0.006
CVE-2026-82003
Adobe Campaign Classic (ACC) | Improper Input Validation (CWE-20)
Published 2026-09-22 · Analyzed
8.5EPSS 0.005
CVE-2025-52452
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - duplicate-data-source modules) allows Absolute Path Traversal. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Published 2025-07-25 · Analyzed
8.5EPSS 0.004
CVE-2025-34190
Vasion Print (formerly PrinterLogic) PrinterInstallerClientService Authentication Bypass via LD_PRELOAD Hooking
Published 2025-09-19 · Modified
8.5EPSS 0.004
CVE-2024-51954
Unauthorized access to secure services in ArcGIS Server
Published 2025-03-03 · Analyzed
8.5EPSS 0.003
CVE-2025-34191
Vasion Print (formerly PrinterLogic) Arbitrary File Write as Root via Response Path Symlink Follow
Published 2025-09-19 · Modified
8.5EPSS 0.003
CVE-2025-52449
Unrestricted Upload of File with Dangerous Type vulnerability in Salesforce Tableau Server on Windows, Linux (Extensible Protocol Service modules) allows Alternative Execution Due to Deceptive Filenames (RCE). This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Published 2025-07-25 · Analyzed
8.5EPSS 0.003
CVE-2025-52451
Improper Input Validation vulnerability in Salesforce Tableau Server on Windows, Linux (tabdoc api - create-data-source-from-file-upload modules) allows Absolute Path Traversal.This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Published 2025-08-22 · Analyzed
8.5EPSS 0.002
CVE-2026-45175
Idira Endpoint Privilege Manager Agent: Security Control and Cryptographic Validation Bypass in Internal Agent Validation Processes
Published 2026-06-11 · Analyzed
8.5EPSS 0.002
CVE-2026-45174
Idira Endpoint Privilege Manager Linux Agent: Potential bypass of Agent Daemon Initialization
Published 2026-06-11 · Analyzed
8.5EPSS 0.002
CVE-2013-2094
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.
Published 2013-05-14 · Analyzed
8.4KEV3 PoCEPSS 0.477
CVE-2022-0185
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
Published 2022-02-11 · Analyzed
8.4KEVEPSS 0.252
← Prev69 / 463Next →