VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18523CVEs
CVE-2023-4130
ksmbd: fix wrong next length validation of ea buffer in smb2_set_ea()
Published 2025-08-16 · Modified
8.1EPSS 0.005
CVE-2021-39057
IBM Spectrum Protect Plus 10.1.0.0 through 10.1.8.x is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 214616.
Published 2021-12-13 · Modified
8.1EPSS 0.005
CVE-2026-65105
NVIDIA NemoClaw for Linux contains a vulnerability in its inference server setup, where a remote attacker may access the inference service without authentication. A successful exploit of this vulnerability may lead to information disclosure and denial of service.
Published 2026-08-25 · Analyzed
8.1EPSS 0.005
CVE-2025-22043
ksmbd: add bounds check for durable handle context
Published 2025-04-16 · Modified
8.1EPSS 0.005
CVE-2026-53390
ksmbd: fix out-of-bounds read in smb_check_perm_dacl()
Published 2026-07-19 · Analyzed
8.1EPSS 0.005
CVE-2021-26639
WISA Smart Wing CMS File Download Vulnerability
Published 2022-08-17 · Modified
8.1EPSS 0.005
CVE-2021-20411
IBM Security Verify Information Queue 1.0.6 and 1.0.7 could allow a user to impersonate another user on the system due to incorrectly updating the session identifier. IBM X-Force ID: 198191.
Published 2021-02-12 · Modified
8.1EPSS 0.004
CVE-2026-65124
NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service.
Published 2026-09-22 · Analyzed
8.1EPSS 0.004
CVE-2024-44973
mm, slub: do not call do_slab_free for kfence object
Published 2024-09-04 · Modified
8.1EPSS 0.004
CVE-2026-64442
staging: rtl8723bs: fix OOB reads in IE loops in issue_assocreq() and join_cmd_hdl()
Published 2026-07-25 · Analyzed
8.1EPSS 0.004
CVE-2026-31393
Bluetooth: L2CAP: Validate L2CAP_INFO_RSP payload length before access
Published 2026-04-03 · Analyzed
8.1EPSS 0.004
CVE-2026-31464
scsi: ibmvfc: Fix OOB access in ibmvfc_discover_targets_done()
Published 2026-04-22 · Analyzed
8.1EPSS 0.004
CVE-2026-43051
HID: wacom: fix out-of-bounds read in wacom_intuos_bt_irq
Published 2026-05-01 · Analyzed
8.1EPSS 0.004
CVE-2026-64440
staging: rtl8723bs: fix OOB write in HT_caps_handler()
Published 2026-07-25 · Analyzed
8.1EPSS 0.004
CVE-2026-64368
mm/slab: do not limit zeroing to orig_size when only red zoning is enabled
Published 2026-07-25 · Analyzed
8.1EPSS 0.004
CVE-2024-43878
xfrm: Fix input error path memory access
Published 2024-08-21 · Modified
8.1EPSS 0.004
CVE-2026-46099
net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels
Published 2026-05-27 · Modified
8.1EPSS 0.004
CVE-2026-31779
wifi: iwlwifi: mvm: fix potential out-of-bounds read in iwl_mvm_nd_match_info_handler()
Published 2026-05-01 · Analyzed
8.1EPSS 0.004
CVE-2026-64444
staging: rtl8723bs: fix OOB read in OnAssocRsp() IE loop
Published 2026-07-25 · Analyzed
8.1EPSS 0.004
CVE-2026-64443
staging: rtl8723bs: fix OOB read in update_beacon_info() IE loop
Published 2026-07-25 · Analyzed
8.1EPSS 0.004
CVE-2026-46232
HID: playstation: Clamp num_touch_reports
Published 2026-05-28 · Analyzed
8.1EPSS 0.004
CVE-2026-46138
Bluetooth: hci_event: Fix OOB read and infinite loop in hci_le_create_big_complete_evt
Published 2026-05-28 · Undergoing Analysis
8.1EPSS 0.004
CVE-2024-40941
wifi: iwlwifi: mvm: don't read past the mfuart notifcation
Published 2024-07-12 · Modified
8.1EPSS 0.004
CVE-2026-19303
Langflow is vulnerable to arbitrary file write and arbitrary file deletion due to unvalidated paths in file-processing components
Published 2026-09-04 · Analyzed
8.1EPSS 0.004
CVE-2026-7347
Use after free in Chromoting in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: High)
Published 2026-04-28 · Analyzed
8.1EPSS 0.004
CVE-2026-84842
IBM Guardium Data Protection is affected by multiple vulnerabilities.
Published 2026-09-29 · Analyzed
8.1EPSS 0.004
CVE-2026-31513
Bluetooth: L2CAP: Fix stack-out-of-bounds read in l2cap_ecred_conn_req
Published 2026-04-22 · Analyzed
8.1EPSS 0.004
CVE-2026-64223
wifi: mac80211: consume only present negotiated TTLM maps
Published 2026-07-24 · Analyzed
8.1EPSS 0.004
CVE-2026-14111
Use after free in WebProtect in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Low)
Published 2026-06-30 · Analyzed
8.1EPSS 0.004
CVE-2025-21947
ksmbd: fix type confusion via race condition when using ipc_msg_send_request
Published 2025-04-01 · Modified
8.1EPSS 0.004
CVE-2024-45761
Dell OpenManage Server Administrator, versions 11.0.1.0 and prior, contains an improper input validation vulnerability. A remote low-privileged malicious user could potentially exploit this vulnerability to load any web plugins or Java class leading to the possibility of altering the behavior of certain apps/OS or Denial of Service.
Published 2024-12-09 · Analyzed
8.1EPSS 0.004
CVE-2025-52447
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (set-initial-sql tabdoc command modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Published 2025-07-25 · Analyzed
8.1EPSS 0.004
CVE-2025-52448
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (validate-initial-sql api modules) allows Interface Manipulation (data access to the production database cluster). This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Published 2025-07-25 · Analyzed
8.1EPSS 0.004
CVE-2024-36032
Bluetooth: qca: fix info leak when fetching fw build id
Published 2024-05-30 · Modified
8.1EPSS 0.004
CVE-2026-13445
Langflow is affected by remote code execution, denial of service, path traversal, and exposed credentials due to multiple unauthenticated and insufficiently authorized API endpoints
Published 2026-07-17 · Analyzed
8.1EPSS 0.004
CVE-2026-13791
Insufficient validation of untrusted input in Downloads in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: High)
Published 2026-06-30 · Analyzed
8.1EPSS 0.003
CVE-2024-35937
wifi: cfg80211: check A-MSDU format more carefully
Published 2024-05-19 · Modified
8.1EPSS 0.003
CVE-2026-8018
Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to potentially perform a sandbox escape via malicious network traffic. (Chromium security severity: Low)
Published 2026-05-06 · Modified
8.1EPSS 0.003
CVE-2022-49022
wifi: mac8021: fix possible oob access in ieee80211_get_rate_duration
Published 2024-10-21 · Modified
8.1EPSS 0.003
CVE-2021-47611
mac80211: validate extended element ID is present
Published 2024-06-19 · Modified
8.1EPSS 0.003
← Prev79 / 464Next →