Linux
19,044 known vulnerabilities
Top Products
DOM-based XSS in src/muya/lib/contentState/pasteCtrl.js in MarkText 0.17.1 and before on Windows, Linux and macOS allows
DOM-based XSS in updater/update.html in Typora before 1.6.7 on Windows and Linux allows a crafted markdown file to run a
Improper path handling in Typora before 1.6.7 on Windows and Linux allows a crafted webpage to access local files and ex
Improper path handling in Obsidian desktop before 1.2.8 on Windows, Linux and macOS allows a crafted webpage to access l
A use-after-free flaw was found in btrfs_get_dev_args_from_path in fs/btrfs/volumes.c in btrfs file-system in the Linux
IBM Security Guardium 10.6, 11.3, 11.4, and 11.5 could allow a remote authenticated attacker to execute arbitrary comman
A flaw was found in btrfs_get_root_ref in fs/btrfs/disk-io.c in the btrfs filesystem in the Linux Kernel due to a double
A use-after-free flaw was found in vmxnet3_rq_alloc_rx_buf in drivers/net/vmxnet3/vmxnet3_drv.c in VMware's vmxnet3 ethe
A NULL pointer dereference flaw was found in dbFree in fs/jfs/jfs_dmap.c in the journaling file system (JFS) in the Linu
Broadcom RAID Controller Web server (nginx) is serving private server-side files without any authentication on Linux
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are
Broadcom RAID Controller web interface is vulnerable to exposure of sensitive data and the keys used for encryption are
IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement
An issue was discovered in l2cap_sock_release in net/bluetooth/l2cap_sock.c in the Linux kernel before 6.4.10. There is
Genesys Administrator Extension (GAX) before 9.0.105.15 is vulnerable to Cross Site Scripting (XSS) via the Business Str
Uncontrolled search path element in some Intel(R) Quartus(R) Prime Pro and Standard edition software for linux may allow
A flaw was found in the exFAT driver of the Linux kernel. The vulnerability exists in the implementation of the file nam
Insufficient validation in the IOCTL (Input Output Control) input buffer in AMD uProf may allow an authenticated user
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated
Insufficient validation of the IOCTL (Input Output Control) input buffer in AMD μProf may allow an authenticated us
A flaw was found in the Linux kernel's TUN/TAP functionality. This issue could allow a local user to bypass network filt
A use-after-free flaw was found in the Linux kernel’s Netfilter functionality when adding a rule with NFTA_RULE_CHAIN_ID
In IOMMU, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of
In IOMMU, there is a possible information disclosure due to improper input validation. This could lead to local informat
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in CrafterCMS Engine
A use-after-free vulnerability was found in the cxgb4 driver in the Linux kernel. The bug occurs when the cxgb4 device i
A use-after-free vulnerability was found in the siano smsusb module in the Linux kernel. The bug occurs during device in
A use-after-free flaw was found in the Linux kernel's netfilter in the way a user triggers the nft_pipapo_remove functio
A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a ma
A flaw was found in the Linux kernel’s IP framework for transforming packets (XFRM subsystem). This issue may allow a ma
An out-of-bounds memory access flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user ge
A possible unauthorized memory access flaw was found in the Linux kernel's cpu_entry_area mapping of X86 CPU data to mem
A use-after-free flaw was found in vcs_read in drivers/tty/vt/vc_screen.c in vc_screen in the Linux Kernel. This issue m
A double-free vulnerability was found in handling vmw_buffer_object objects in the vmwgfx driver in the Linux kernel. Th
A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling o
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within t
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within t
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within t
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within t
A flaw was found in the Linux kernel's ksmbd, a high-performance in-kernel SMB server. The specific flaw exists within t
An out-of-bounds read vulnerability was found in the SR-IPv6 implementation in the Linux kernel. The flaw exists within
A use-after-free flaw was found in nfc_llcp_find_local in net/nfc/llcp_core.c in NFC in the Linux kernel. This flaw allo
A vulnerability was found due to missing lock for IOPOLL flaw in io_cqring_event_overflow() in io_uring.c in Linux Kerne
A use-after-free vulnerability in the Linux kernel's net/sched: cls_fw component can be exploited to achieve local privi
An out-of-bounds write vulnerability in the Linux kernel's net/sched: sch_qfq component can be exploited to achieve loca
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local pr
A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local priv
There is a stored Cross-site Scripting vulnerability in Esri ArcGIS Server versions 11.0 and below on Windows and Linux
There is a Cross-site Scripting vulnerability in ArcGIS Server in versions 11.1 and below that may allow a remote, authe
IBM Security Guardium 11.3 could allow a local user to escalate their privileges due to improper permission controls.
Frequently Asked Questions
How many CVEs affect Linux?
Linux has 19,044 CVE records in our database, including 767 critical and 8163 high severity vulnerabilities. 47 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Linux vulnerabilities?
Linux has 767 critical severity (CVSS 9.0+) and 8163 high severity (CVSS 7.0-8.9) vulnerabilities. 47 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Linux vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Linux products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Linux Vulnerabilities
CyberStrike scans your infrastructure for Linux vulnerabilities and provides real-time remediation guidance.
Get Started