VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18523CVEs
CVE-2026-53268
netfilter: conntrack_irc: fix possible out-of-bounds read
Published 2026-06-25 · Modified
8.2EPSS 0.004
CVE-2025-21890
idpf: fix checksums set in idpf_rx_rsc()
Published 2025-03-27 · Modified
8.2EPSS 0.004
CVE-2023-53372
sctp: fix a potential overflow in sctp_ifwdtsn_skip
Published 2025-09-18 · Modified
8.2EPSS 0.004
CVE-2024-49782
IBM OpenPages improper certificate validation
Published 2025-02-20 · Analyzed
8.2EPSS 0.004
CVE-2023-2110
Obsidian Local File Disclosure
Published 2023-08-19 · Modified
8.2EPSS 0.004
CVE-2024-58239
tls: stop recv() if initial process_rx_list gave us non-DATA
Published 2025-08-22 · Modified
8.2EPSS 0.003
CVE-2026-30798
RustDesk Client Accepts Unauthenticated stop-service Command via Strategy Payload
Published 2026-03-05 · Modified
8.2EPSS 0.003
CVE-2026-14996
Multiple vulnerabilities in IBM Aspera Faspex
Published 2026-07-28 · Analyzed
8.2EPSS 0.003
CVE-2025-38571
sunrpc: fix client side handling of tls alerts
Published 2025-08-19 · Modified
8.2EPSS 0.003
CVE-2025-71311
fs/ntfs3: Initialize new folios before use
Published 2026-05-27 · Modified
8.2EPSS 0.003
CVE-2025-52453
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Flow Data Source modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Published 2025-07-25 · Analyzed
8.2EPSS 0.003
CVE-2025-52454
Server-Side Request Forgery (SSRF) vulnerability in Salesforce Tableau Server on Windows, Linux (Amazon S3 Connector modules) allows Resource Location Spoofing. This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Published 2025-07-25 · Modified
8.2EPSS 0.003
CVE-2026-48290
CAI Content Credentials | Server-Side Request Forgery (SSRF) (CWE-918)
Published 2026-07-14 · Analyzed
8.2EPSS 0.003
CVE-2025-71072
shmem: fix recovery on rename failures
Published 2026-01-13 · Modified
8.2EPSS 0.003
CVE-2023-53333
netfilter: conntrack: dccp: copy entire header to stack buffer, not just basic one
Published 2025-09-16 · Modified
8.2EPSS 0.003
CVE-2025-21710
tcp: correct handling of extreme memory squeeze
Published 2025-02-27 · Modified
8.2EPSS 0.003
CVE-2022-36396
Improper access control in some Intel(R) Aptio* V UEFI Firmware Integrator Tools before version iDmiEdit-Linux-5.27.06.0017 may allow a privileged user to potentially enable escalation of privilege via local access.
Published 2023-11-14 · Modified
8.2EPSS 0.002
CVE-2025-38491
mptcp: make fallback action and fallback decision atomic
Published 2025-07-28 · Modified
8.2EPSS 0.002
CVE-2026-31788
xen/privcmd: restrict usage in unprivileged domU
Published 2026-03-25 · Analyzed
8.2EPSS 0.002
CVE-2026-64286
KVM: arm64: Clear __hyp_running_vcpu when flushing the pKVM hyp vCPU
Published 2026-07-25 · Analyzed
8.2EPSS 0.002
CVE-2026-64287
KVM: arm64: Bound used_lrs when flushing the pKVM hyp vCPU
Published 2026-07-25 · Analyzed
8.2EPSS 0.002
CVE-2026-30785
RustDesk Encrypts Local Passwords with World-Readable Machine ID and Fixed Zero Nonce (XSalsa20-Poly1305)
Published 2026-03-05 · Analyzed
8.2EPSS 0.002
CVE-2025-21760
ndisc: extend RCU protection in ndisc_send_skb()
Published 2025-02-27 · Modified
8.1EPSS 0.368
CVE-2024-0088
CVE
Published 2024-05-09 · Analyzed
8.1EPSS 0.189
CVE-2010-2943
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode buffers, which allows remote authenticated users to read unlinked files, or read or overwrite disk blocks that are currently assigned to an active file but were previously assigned to an unlinked file, by accessing a stale NFS filehandle.
Published 2010-09-30 · Modified
8.11 PoCEPSS 0.170
CVE-2019-6974
In the Linux kernel before 4.20.8, kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandles reference counting because of a race condition, leading to a use-after-free.
Published 2019-02-15 · Modified
8.11 PoCEPSS 0.165
CVE-2019-15637
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to information disclosure or a DoS. This affects Tableau Server, Tableau Desktop, Tableau Reader, and Tableau Public Desktop.
Published 2019-08-26 · Modified
8.11 PoCEPSS 0.143
CVE-2025-6554
Type confusion in V8 in Google Chrome prior to 138.0.7204.96 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: High)
Published 2025-06-30 · Analyzed
8.1KEVEPSS 0.141
CVE-2020-28374
In drivers/target/target_core_xcopy.c in the Linux kernel before 5.10.7, insufficient identifier checking in the LIO SCSI target code can be used by remote attackers to read or write files via directory traversal in an XCOPY request, aka CID-2896c93811e3. For example, an attack can occur over a network if the attacker has access to one iSCSI LUN. The attacker gains control over file access because I/O operations are proxied via an attacker-selected backstore.
Published 2021-01-13 · Modified
8.1EPSS 0.063
CVE-2016-1030
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to bypass intended access restrictions via unspecified vectors.
Published 2016-04-09 · Modified
8.1EPSS 0.048
CVE-2016-1006
Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to bypass the ASLR protection mechanism via JIT data.
Published 2016-04-09 · Modified
8.1EPSS 0.039
CVE-2022-41674
An issue was discovered in the Linux kernel before 5.19.16. Attackers able to inject WLAN frames could cause a buffer overflow in the ieee80211_bss_info_update function in net/mac80211/scan.c.
Published 2022-10-13 · Modified
8.1EPSS 0.039
CVE-2022-47943
An issue was discovered in ksmbd in the Linux kernel 5.15 through 5.19 before 5.19.2. There is an out-of-bounds read and OOPS for SMB2_WRITE, when there is a large length in the zero DataOffset case.
Published 2022-12-23 · Modified
8.1EPSS 0.035
CVE-2018-18559
In the Linux kernel through 4.19, a use-after-free can occur due to a race condition between fanout_add from setsockopt and bind on an AF_PACKET socket. This issue exists because of the 15fe076edea787807a7cdc168df832544b58eba6 incomplete fix for a race condition. The code mishandles a certain multithreaded case involving a packet_do_bind unregister action followed by a packet_notifier register action. Later, packet_release operates on only one of the two applicable linked lists. The attacker can achieve Program Counter control.
Published 2018-10-22 · Modified
8.1EPSS 0.026
CVE-2018-1000621
Mycroft AI mycroft-core version 18.2.8b and earlier contains a Incorrect Access Control vulnerability in Websocket configuration that can result in code execution. This impacts ONLY the Mycroft for Linux and "non-enclosure" installs - Mark 1 and Picroft unaffected. This attack appear to be exploitable remote access to the unsecured websocket server. This vulnerability appears to have been fixed in No fix currently available.
Published 2018-07-09 · Modified
8.1EPSS 0.026
CVE-2023-32258
Session race condition remote code execution vulnerability
Published 2023-07-24 · Modified
8.1EPSS 0.025
CVE-2023-32257
Session race condition remote code execution vulnerability
Published 2023-07-24 · Modified
8.1EPSS 0.024
CVE-2024-38229
.NET and Visual Studio Remote Code Execution Vulnerability
Published 2024-10-08 · Modified
8.1EPSS 0.021
CVE-2016-10086
RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticated users to read or modify task information by leveraging incorrect permissions applied to a RESTful request.
Published 2017-01-18 · Modified
8.1EPSS 0.016
CVE-2016-8980
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.
Published 2017-02-01 · Modified
8.1EPSS 0.015
← Prev77 / 464Next →