VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18523CVEs
CVE-2026-43377
ksmbd: Don't log keys in SMB3 signing and encryption key generation
Published 2026-05-08 · Analyzed
8.1EPSS 0.003
CVE-2021-47160
net: dsa: mt7530: fix VLAN traffic leaks
Published 2024-03-25 · Modified
8.1EPSS 0.003
CVE-2025-6505
Unauthorized access and impersonation can occur in versions 4.6.2.3226 and below of Progress Software's Hybrid Data Pipeline Server on Linux. This vulnerability allows attackers to combine credentials from different sources, potentially leading to client impersonation and unauthorized access.  When OAuth Clients perform an OAuth handshake with the Hybrid Data Pipeline Server, the server accepts client credentials from both HTTP headers and request parameters.
Published 2025-07-29 · Analyzed
8.1EPSS 0.003
CVE-2023-3297
In Ubuntu's accountsservice an unprivileged local attacker can trigger a use-after-free vulnerability in accountsservice by sending a D-Bus message to the accounts-daemon process.
Published 2023-09-01 · Modified
8.1EPSS 0.003
CVE-2026-5913
Out of bounds read in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Low)
Published 2026-04-08 · Modified
8.1EPSS 0.003
CVE-2021-47620
Bluetooth: refactor malicious adv data check
Published 2024-06-20 · Modified
8.1EPSS 0.003
CVE-2026-13799
Use after free in QUIC in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
Published 2026-06-30 · Analyzed
8.1EPSS 0.003
CVE-2026-7346
Inappropriate implementation in Tint in Google Chrome prior to 147.0.7727.138 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-28 · Analyzed
8.1EPSS 0.003
CVE-2026-11015
Out of bounds read in WebGPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.1EPSS 0.003
CVE-2026-43362
smb: client: fix in-place encryption corruption in SMB2_write()
Published 2026-05-08 · Analyzed
8.1EPSS 0.003
CVE-2026-5915
Insufficient validation of untrusted input in WebML in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Low)
Published 2026-04-08 · Modified
8.1EPSS 0.003
CVE-2026-31771
Bluetooth: hci_event: move wake reason storage into validated event handlers
Published 2026-05-01 · Analyzed
8.1EPSS 0.003
CVE-2026-11011
Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.1EPSS 0.003
CVE-2026-13774
Use after free in Extensions in Google Chrome prior to 150.0.7871.47 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension. (Chromium security severity: Critical)
Published 2026-06-30 · Analyzed
8.1EPSS 0.003
CVE-2026-5907
Insufficient data validation in Media in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform an out of bounds memory read via a crafted video file. (Chromium security severity: Low)
Published 2026-04-08 · Analyzed
8.1EPSS 0.003
CVE-2026-5282
Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7680.178 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2026-04-01 · Analyzed
8.1EPSS 0.003
CVE-2025-11458
Heap buffer overflow in Sync in Google Chrome prior to 141.0.7390.65 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)
Published 2025-11-06 · Analyzed
8.1EPSS 0.003
CVE-2025-13148
IBM Aspera Orchestrator Unverified Password Change
Published 2025-12-11 · Analyzed
8.1EPSS 0.003
CVE-2026-11643
Use after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Critical)
Published 2026-06-08 · Analyzed
8.1EPSS 0.003
CVE-2026-53254
Bluetooth: RFCOMM: validate skb length in MCC handlers
Published 2026-06-25 · Analyzed
8.1EPSS 0.003
CVE-2026-53147
thunderbolt: Validate XDomain request packet size before type cast
Published 2026-06-25 · Analyzed
8.1EPSS 0.003
CVE-2026-7981
Out of bounds read in Codecs in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a malicious file. (Chromium security severity: Medium)
Published 2026-05-06 · Analyzed
8.1EPSS 0.003
CVE-2023-53186
skbuff: Fix a race between coalescing and releasing SKBs
Published 2025-09-15 · Modified
8.1EPSS 0.003
CVE-2025-13639
Inappropriate implementation in WebRTC in Google Chrome prior to 143.0.7499.41 allowed a remote attacker to perform arbitrary read/write via a crafted HTML page. (Chromium security severity: Low)
Published 2025-12-02 · Modified
8.1EPSS 0.003
CVE-2026-11224
Use after free in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code via malicious network traffic. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.1EPSS 0.002
CVE-2026-11111
Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Published 2026-06-04 · Modified
8.1EPSS 0.002
CVE-2023-53213
wifi: brcmfmac: slab-out-of-bounds read in brcmf_get_assoc_ies()
Published 2025-09-15 · Modified
8.1EPSS 0.002
CVE-2023-34143
Improper Validation of Certificate Vulnerability in Hitachi Device Manager
Published 2023-07-18 · Modified
8.1EPSS 0.002
CVE-2026-11170
Inappropriate implementation in Chromoting in Google Chrome on Linux prior to 149.0.7827.53 allowed a remote attacker to perform OS-level privilege escalation via malicious network traffic. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.1EPSS 0.002
CVE-2026-43134
Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ
Published 2026-05-06 · Analyzed
8.1EPSS 0.002
CVE-2025-37973
wifi: cfg80211: fix out-of-bounds access during multi-link element defragmentation
Published 2025-05-20 · Modified
8.1EPSS 0.002
CVE-2026-12012
Use after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploit heap corruption via malicious network traffic. (Chromium security severity: High)
Published 2026-06-11 · Analyzed
8.1EPSS 0.002
CVE-2026-53178
staging: rtl8723bs: rtw_mlme: add bounds checks before ie_length subtraction
Published 2026-06-25 · Modified
8.1EPSS 0.002
CVE-2026-11689
Insufficient policy enforcement in Passwords in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.1EPSS 0.002
CVE-2026-11169
Inappropriate implementation in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted XML file. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.1EPSS 0.002
CVE-2026-64176
wifi: iwlwifi: mvm: fix driver-set TX rates on old devices
Published 2026-07-19 · Analyzed
8.1EPSS 0.002
CVE-2026-11185
Use after free in V8 in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code inside a sandbox via a crafted Chrome Extension. (Chromium security severity: Medium)
Published 2026-06-04 · Analyzed
8.1EPSS 0.002
CVE-2026-23401
KVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTE
Published 2026-04-01 · Modified
8.1EPSS 0.002
CVE-2026-11693
Inappropriate implementation in Plugins in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)
Published 2026-06-08 · Analyzed
8.1EPSS 0.002
CVE-2025-21659
netdev: prevent accessing NAPI instances from another namespace
Published 2025-01-21 · Modified
8.1EPSS 0.002
← Prev80 / 464Next →