Linux
19,044 known vulnerabilities
Top Products
A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory lo
A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL in the XFS filesystem allowed for size increase of files wit
A vulnerability was found in the fs/inode.c:inode_init_owner() function logic of the LInux kernel that allows local user
A flaw in the Linux kernel's implementation of RDMA communications manager listener code allowed an attacker with local
VMware Tools (12.0.0, 11.x.y and 10.x.y) contains a local privilege escalation vulnerability. A malicious actor with loc
A flaw was found in the Linux kernel's implementation of Pressure Stall Information. While the feature is disabled by de
A memory leak flaw was found in the Linux kernel's ccp_run_aes_gcm_cmd() function that allows an attacker to cause a den
A memory overflow vulnerability was found in the Linux kernel’s ipc functionality of the memcg subsystem, in the way a u
A flaw was found in the Linux kernel. A memory leak problem was found in mbochs_ioctl in samples/vfio-mdev/mbochs.c in V
A flaw was found in the Linux kernels memory deduplication mechanism. Previous work has shown that memory deduplication
An out-of-bounds memory access flaw was found in the Linux kernel Intel’s iSMT SMBus host controller driver in the way a
A NULL pointer dereference flaw was found in the Linux kernel’s IEEE 802.15.4 wireless networking subsystem in the way t
IBM MQ 8.0, (9.0, 9.1, 9.2 LTS), and (9.1 and 9.2 CD) are vulnerable to an XML External Entity Injection (XXE) attack wh
In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service targeting the build informati
In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service using the Variable Project Te
In affected versions of Octopus Deploy it is possible to perform a Regex Denial of Service via the package upload functi
In affected versions of Octopus Deploy it is possible to unmask sensitive variables by using variable preview.
This vulnerability is caused by the lack of validation of input values for specific functions if WISA Smart Wing CMS. Re
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1
IBM Sterling File Gateway 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1.1 could allow a re
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1
IBM Sterling B2B Integrator Standard Edition 6.0.0.0 through 6.0.3.5, 6.1.0.0 through 6.1.0.4, and 6.1.1.0 through 6.1.1
A buffer overflow in the FTcpListener thread in The Isle Evrima (the dedicated server on Windows and Linux) 0.9.88.07 be
Dm-verity is used for extending root-of-trust to root filesystems. LoadPin builds on this property to restrict module/fi
Linux deployments of StorageGRID (formerly StorageGRID Webscale) versions 11.6.0 through 11.6.0.2 deployed with a Linux
IBM InfoSphere Information Server 11.7 could allow a remote attacker to obtain sensitive information when a detailed tec
IBM Spectrum Scale Data Access Services (DAS) 5.1.3.1 could allow an authenticated user to insert code which could allow
A use-after-free flaw was found in the Linux kernel in log_replay in fs/ntfs3/fslog.c in the NTFS journal. This flaw all
A flaw was found in KVM. When updating a guest's page table entry, vm_pgoff was improperly used as the offset to get the
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A m
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability. A ma
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a reflected cross-site scripting (XSS) vul
VMware Workspace ONE Access, Identity Manager, Connectors and vRealize Automation contain a path traversal vulnerability
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain two privilege escalation vulnerabilities.
VMware Workspace ONE Access, Identity Manager and vRealize Automation contains a privilege escalation vulnerability. A m
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability. A malicious actor with a
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a remote code execution vulnerability. A m
VMware Workspace ONE Access and Identity Manager contain a URL injection vulnerability. A malicious actor with network a
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain an authentication bypass vulnerability aff
A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table per
On MacOS and Linux, it may be possible to perform a symlink attack by replacing this predictable file name with a symlin
The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV
IBM QRadar SIEM 7.3, 7.4, and 7.5 is vulnerable to local privilege escalation if this could be combined with other unkno
nfqnl_mangle in net/netfilter/nfnetlink_queue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a d
An issue was discovered in the Linux kernel through 5.18.14. xfrm_expand_policies in net/xfrm/xfrm_policy.c can cause a
A NULL pointer dereference flaw was found in rxrpc_preparse_s in net/rxrpc/server_key.c in the Linux kernel. This flaw a
A memory leak flaw was found in the Linux kernel in acrn_dev_ioctl in the drivers/virt/acrn/hsm.c function in how the AC
IBM Sterling Partner Engagement Manager 6.1, 6.2, and Cloud 22.2 do not limit the length of a connection which could cau
IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker t
IBM Security Verify Information Queue 10.0.2 is vulnerable to cross-site request forgery which could allow an attacker t
Frequently Asked Questions
How many CVEs affect Linux?
Linux has 19,044 CVE records in our database, including 767 critical and 8163 high severity vulnerabilities. 47 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Linux vulnerabilities?
Linux has 767 critical severity (CVSS 9.0+) and 8163 high severity (CVSS 7.0-8.9) vulnerabilities. 47 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Linux vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Linux products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Linux Vulnerabilities
CyberStrike scans your infrastructure for Linux vulnerabilities and provides real-time remediation guidance.
Get Started