Kernel
Vendor:
First CVE: Dec 1, 2021 · Active for 4 years
33
Total CVEs
More Total CVEs than 96% of tracked products
6.6
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Kernel over time
Volume of CVEsAvg CVSS Base Score
First CVE
Dec 1, 2021
4 years ago
Most Recent CVE
May 15, 2025
435 days ago
CVE Severity & Scoring
Kernel33 CVEs
42%
55%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local29 (87.9%)
Network3 (9.1%)
Unknown0 (0.0%)
Physical1 (3.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (36.4%)
High21 (63.6%)
Unknown0 (0.0%)
User Interaction
None32 (97.0%)
Unknown0 (0.0%)
Required1 (3.0%)
Privileges Required
Low10 (30.3%)
High20 (60.6%)
None3 (9.1%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (33 CVEs).
33 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-38578CRITICAL Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize. | Mar 3, 2022 | 9.8 | 31 | NO | NO |
CVE-2022-30771HIGH Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization function in PnpSmm could lead to SMRAM corruption when using | Nov 15, 2022 | 8.2 | 27 | NO | NO |
CVE-2022-36337HIGH An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. Co | Nov 23, 2022 | 8.2 | 26 | NO | NO |
CVE-2022-29276HIGH SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. This issue was dis | Nov 15, 2022 | 8.2 | 26 | NO | NO |
CVE-2022-30772HIGH Manipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memory. Function 0x52 of the PnpSmm driver is passed the address | Nov 15, 2022 | 8.2 | 26 | NO | NO |
CVE-2021-38575HIGH NetworkPkg/IScsiDxe has remotely exploitable buffer overflows. | Dec 1, 2021 | 8.1 | 26 | NO | NO |
CVE-2022-35407HIGH An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtility driver on Intel platforms. An | Nov 22, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-29278HIGH Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory Incorrect pointer checks within the NvmExpressDxe driver can allow tampering w | Nov 15, 2022 | 8.2 | 25 | NO | NO |
CVE-2022-30283HIGH In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in process leads to a TOCTOU problem that could be used by an atta | Nov 15, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-29275HIGH In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation of privileges. This i | Nov 15, 2022 | 8.2 | 25 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (33 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (33 CVEs).
Media Mentions
Signals from CVEs in this product scope (33 CVEs).
Top CNAs Publishing CVEs For Kernel
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.7 | 1 | 6.4 | 0.4% | 0 | 0 |
| 5.6 | 1 | 6.4 | 0.4% | 0 | 0 |
| 5.5 | 3 | 8.1 | 1.1% | 0 | 0 |
| 5.4 | 3 | 8.1 | 1.1% | 0 | 0 |
| 5.3 | 3 | 8.1 | 1.1% | 0 | 0 |
| 5.2 | 3 | 8.1 | 1.1% | 0 | 0 |
| 5.1 | 2 | 8.9 | 1.4% | 0 | 0 |
| 5.0 | 2 | 8.9 | 1.4% | 0 | 0 |