Linux
19,044 known vulnerabilities
Top Products
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execu
An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application t
An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application t
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arb
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execu
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute a
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute a
An elevation of privilege vulnerability in the kernel file system could enable a local malicious application to execute
An elevation of privilege vulnerability in the Qualcomm sound driver could enable a local malicious application to execu
An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execu
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execu
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execu
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execu
An information disclosure vulnerability in the Qualcomm Secure Execution Environment Communicator could enable a local m
The aio_mount function in fs/aio.c in the Linux kernel before 4.7.7 does not properly restrict execute access, which mak
Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows l
The vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 d
Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux k
The simple_set_acl function in fs/posix_acl.c in the Linux kernel before 4.9.6 preserves the setgid bit during a setxatt
Off-by-one error in the pipe_advance function in lib/iov_iter.c in the Linux kernel before 4.9.5 allows local users to o
The klsi_105_get_line_state function in drivers/usb/serial/kl5kusb105.c in the Linux kernel before 4.9.5 places uninitia
drivers/net/ieee802154/atusb.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK o
drivers/hid/hid-corsair.c in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK option
The freelist-randomization feature in mm/slab.c in the Linux kernel 4.8.x and 4.9.x before 4.9.5 allows local users to c
The nested_vmx_check_vmptr function in arch/x86/kvm/vmx.c in the Linux kernel through 4.9.8 improperly emulates the VMXO
The load_segment_descriptor implementation in arch/x86/kvm/emulate.c in the Linux kernel before 4.9.5 improperly emulate
The ext4_fill_super function in fs/ext4/super.c in the Linux kernel through 4.9.8 does not properly validate meta block
The smbhash function in fs/cifs/smbencrypt.c in the Linux kernel 4.9.x before 4.9.1 interacts incorrectly with the CONFI
The crypto scatterlist API in the Linux kernel 4.9.x before 4.9.6 interacts incorrectly with the CONFIG_VMAP_STACK optio
Use-after-free vulnerability in the kvm_ioctl_create_device function in virt/kvm/kvm_main.c in the Linux kernel before 4
include/linux/init_task.h in the Linux kernel before 2.6.35 does not prevent signals with a process group ID of zero fro
IBM BigFix Inventory v9 could disclose sensitive information to an unauthorized user using HTTP GET requests. This infor
IBM BigFix Inventory v9 stores potentially sensitive information in log files that could be read by a local user.
IBM Tivoli Storage Manager discloses unencrypted login credentials to Vmware vCenter that could be obtained by a local u
IBM BigFix Inventory v9 9.2 stores user credentials in plain in clear text which can be read by a local user.
The Tivoli Storage Manager (TSM) password may be displayed in plain text via application trace output while application
IBM BigFix Inventory v9 allows web pages to be stored locally which can be read by another user on the system.
IBM BigFix Inventory v9 is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error whe
IBM BigFix Inventory v9 could allow a remote attacker to obtain sensitive information, caused by the failure to properly
IBM BigFix Inventory v9 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By per
The casrvc program in CA Common Services, as used in CA Client Automation 12.8, 12.9, and 14.0; CA SystemEDGE 5.8.2 and
V8 in Google Chrome prior to 54.0.2840.90 for Linux, and 54.0.2840.85 for Android, and 54.0.2840.87 for Windows and Mac
RESTful web services in CA Service Desk Manager 12.9 and CA Service Desk Management 14.1 might allow remote authenticate
crypto/mcryptd.c in the Linux kernel before 4.8.15 allows local users to cause a denial of service (NULL pointer derefer
arch/x86/kvm/emulate.c in the Linux kernel through 4.9.3 allows local users to obtain sensitive information from kernel
An elevation of privilege vulnerability in the kernel sound subsystem could enable a local malicious application to exec
An elevation of privilege vulnerability in the kernel performance subsystem could enable a local malicious application t
An information disclosure vulnerability in the HTC input driver could enable a local malicious application to access dat
An information disclosure vulnerability in the STMicroelectronics driver could enable a local malicious application to a
Frequently Asked Questions
How many CVEs affect Linux?
Linux has 19,044 CVE records in our database, including 767 critical and 8163 high severity vulnerabilities. 47 of these are listed in CISA's Known Exploited Vulnerabilities catalog.
What are the most severe Linux vulnerabilities?
Linux has 767 critical severity (CVSS 9.0+) and 8163 high severity (CVSS 7.0-8.9) vulnerabilities. 47 vulnerabilities are confirmed as actively exploited in the wild.
How can I scan for Linux vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Linux products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Linux Vulnerabilities
CyberStrike scans your infrastructure for Linux vulnerabilities and provides real-time remediation guidance.
Get Started