VendorsLinuxlinux_kernelany version
Vulnerabilities

Linux Kernel any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

18523CVEs
CVE-2026-31392
smb: client: fix krb5 mount with username option
Published 2026-04-03 · Analyzed
8.1EPSS 0.002
CVE-2025-39889
Bluetooth: l2cap: Check encryption key size on incoming connection
Published 2025-09-24 · Modified
8.1EPSS 0.001
CVE-2017-1000251
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.
Published 2017-09-12 · Modified
8.01 PoCEPSS 0.162
CVE-2019-18909
The VPN software within HP ThinPro does not safely handle user supplied input, which may be leveraged by an attacker to inject commands that will execute with root privileges.
Published 2019-11-22 · Modified
8.0EPSS 0.022
CVE-2021-4157
An out of memory bounds write flaw (1 or 2 bytes of memory) in the Linux kernel NFS subsystem was found in the way users use mirroring (replication of files with NFS). A user, having access to the NFS mount, could potentially use this flaw to crash the system or escalate privileges on the system.
Published 2022-03-25 · Modified
8.0EPSS 0.016
CVE-2018-16884
A flaw was found in the Linux kernel's NFS41+ subsystem. NFS41+ shares mounted in different network namespaces at the same time can make bc_svc_process() use wrong back-channel IDs and cause a use-after-free vulnerability. Thus a malicious container user can cause a host kernel memory corruption and a system panic. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.
Published 2018-12-18 · Modified
8.0EPSS 0.015
CVE-2025-26646
.NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability
Published 2025-05-13 · Analyzed
8.0EPSS 0.012
CVE-2022-3534
Linux Kernel libbpf btf_dump.c btf_dump_name_dups use after free
Published 2022-10-17 · Analyzed
8.0EPSS 0.009
CVE-2024-27398
Bluetooth: Fix use-after-free bugs caused by sco_sock_timeout
Published 2024-05-13 · Modified
8.0EPSS 0.008
CVE-2022-22998
Protecting AWS credentials stored in plaintext on My Cloud Home
Published 2022-07-12 · Modified
8.0EPSS 0.008
CVE-2021-38963
IBM Aspera Console CSV injection
Published 2024-09-24 · Analyzed
8.0EPSS 0.006
CVE-2026-34693
Adobe Experience Manager Forms JEE | Cross-site Scripting (Reflected XSS) (CWE-79)
Published 2026-06-09 · Analyzed
8.0EPSS 0.006
CVE-2026-64406
Bluetooth: fix UAF in bt_accept_dequeue()
Published 2026-07-25 · Analyzed
8.0EPSS 0.004
CVE-2026-53357
Bluetooth: fix UAF in l2cap_sock_cleanup_listen() vs l2cap_conn_del()
Published 2026-07-02 · Analyzed
8.0EPSS 0.004
CVE-2024-35789
wifi: mac80211: check/clear fast rx for non-4addr sta VLAN changes
Published 2024-05-17 · Modified
8.0EPSS 0.004
CVE-2026-8834
IBM HTTP Server is affected by multiple vulnerabilities
Published 2026-05-26 · Analyzed
8.0EPSS 0.003
CVE-2024-50125
Bluetooth: SCO: Fix UAF on sco_sock_timeout
Published 2024-11-05 · Modified
8.0EPSS 0.003
CVE-2026-46332
greybus: gb-beagleplay: bound bootloader receive buffering
Published 2026-06-09 · Analyzed
8.0EPSS 0.003
CVE-2024-50124
Bluetooth: ISO: Fix UAF on iso_sock_timeout
Published 2024-11-05 · Modified
8.0EPSS 0.003
CVE-2022-49968
ieee802154/adf7242: defer destroy_workqueue call
Published 2025-06-18 · Modified
8.0EPSS 0.003
CVE-2026-53256
Bluetooth: RFCOMM: hold listener socket in rfcomm_connect_ind()
Published 2026-06-25 · Analyzed
8.0EPSS 0.002
CVE-2025-52446
Authorization Bypass Through User-Controlled Key vulnerability in Salesforce Tableau Server on Windows, Linux (tab-doc api modules) allows Interface Manipulation (data access to the production database cluster).This issue affects Tableau Server: before 2025.1.3, before 2024.2.12, before 2023.3.19.
Published 2025-07-25 · Analyzed
8.0EPSS 0.002
CVE-2025-39860
Bluetooth: Fix use-after-free in l2cap_sock_cleanup_listen()
Published 2025-09-19 · Modified
8.0EPSS 0.002
CVE-2024-50075
xhci: tegra: fix checked USB2 port number
Published 2024-10-29 · Modified
8.0EPSS 0.002
CVE-2024-46862
ASoC: Intel: soc-acpi-intel-mtl-match: add missing empty item
Published 2024-09-27 · Modified
8.0EPSS 0.002
CVE-2026-11241
Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)
Published 2026-06-04 · Analyzed
8.0EPSS 0.001
CVE-2013-2850
Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in the Linux kernel through 3.9.4 allows remote attackers to cause a denial of service (memory corruption and OOPS) or possibly execute arbitrary code via a long key that is not properly handled during construction of an error-response packet.
Published 2013-06-07 · Modified
7.9EPSS 0.073
CVE-2023-0266
Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel
Published 2023-01-30 · Analyzed
7.9KEVEPSS 0.037
CVE-2010-4263
The igb_receive_skb function in drivers/net/igb/igb_main.c in the Intel Gigabit Ethernet (aka igb) subsystem in the Linux kernel before 2.6.34, when Single Root I/O Virtualization (SR-IOV) and promiscuous mode are enabled but no VLANs are registered, allows remote attackers to cause a denial of service (NULL pointer dereference and panic) and possibly have unspecified other impact via a VLAN tagged frame.
Published 2011-01-18 · Modified
7.9EPSS 0.029
CVE-2021-3752
A use-after-free flaw was found in the Linux kernel’s Bluetooth subsystem in the way user calls connect to the socket and disconnect simultaneously due to a race condition. This flaw allows a user to crash the system or escalate their privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Published 2022-02-16 · Modified
7.9EPSS 0.017
CVE-2024-50139
KVM: arm64: Fix shift-out-of-bounds bug
Published 2024-11-07 · Modified
7.9EPSS 0.002
CVE-2024-40953
KVM: Fix a data race on last_boosted_vcpu in kvm_vcpu_on_spin()
Published 2024-07-12 · Modified
7.9EPSS 0.002
CVE-2026-43133
KVM: nSVM: Always use vmcb01 in VMLOAD/VMSAVE emulation
Published 2026-05-06 · Modified
7.9EPSS 0.001
CVE-2026-46076
KVM: nSVM: Raise #UD if unhandled VMMCALL isn't intercepted by L1
Published 2026-05-27 · Undergoing Analysis
7.9EPSS 0.001
CVE-2019-11477
Integer overflow in TCP_SKB_CB(skb)->tcp_gso_segs
Published 2019-06-18 · Modified
7.8EPSS 0.987
CVE-2022-0847
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.
Published 2022-03-07 · Analyzed
7.8KEV1 PoCEPSS 0.928
CVE-2018-4878
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to a dangling pointer in the Primetime SDK related to media player handling of listener objects. A successful attack can lead to arbitrary code execution. This was exploited in the wild in January and February 2018.
Published 2018-02-06 · Analyzed
7.8KEV3 PoCEPSS 0.895
CVE-2018-5390
Linux kernel versions 4.9+ can be forced to make very expensive calls to tcp_collapse_ofo_queue() and tcp_prune_ofo_queue() for every incoming packet which can lead to a denial of service
Published 2018-08-06 · Modified
7.8EPSS 0.737
CVE-2023-31102
Ppmd7.c in 7-Zip before 23.00 allows an integer underflow and invalid read operation via a crafted 7Z archive.
Published 2023-11-03 · Modified
7.8EPSS 0.571
CVE-2019-13272
In the Linux kernel before 5.1.17, ptrace_link in kernel/ptrace.c mishandles the recording of the credentials of a process that wants to create a ptrace relationship, which allows local users to obtain root access by leveraging certain scenarios with a parent-child process relationship, where a parent drops privileges and calls execve (potentially allowing control by an attacker). One contributing factor is an object lifetime issue (which can also cause a panic). Another contributing factor is incorrect marking of a ptrace relationship as privileged, which is exploitable through (for example) Polkit's pkexec helper with PTRACE_TRACEME. NOTE: SELinux deny_ptrace might be a usable workaround in some environments.
Published 2019-07-17 · Analyzed
7.8KEV4 PoCEPSS 0.522
← Prev81 / 464Next →