Kernel

Vendor:

First CVE: Dec 1, 2021 · Active for 4 years

33
Total CVEs
More Total CVEs than 96% of tracked products
6.6
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 44% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Kernel over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 1, 2021
4 years ago
Most Recent CVE
May 15, 2025
435 days ago

CVE Severity & Scoring

Kernel33 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local29 (87.9%)
Network3 (9.1%)
Unknown0 (0.0%)
Physical1 (3.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (36.4%)
High21 (63.6%)
Unknown0 (0.0%)
User Interaction
None32 (97.0%)
Unknown0 (0.0%)
Required1 (3.0%)
Privileges Required
Low10 (30.3%)
High20 (60.6%)
None3 (9.1%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (33 CVEs).

33 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Existing CommBuffer checks in SmmEntryPoint will not catch underflow when computing BufferSize.
Mar 3, 20229.831NONO
Initialization function in PnpSmm could lead to SMRAM corruption when using subsequent PNP SMI functions Initialization function in PnpSmm could lead to SMRAM corruption when using
Nov 15, 20228.227NONO
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow vulnerability in the MebxConfiguration driver leads to arbitrary code execution. Co
Nov 23, 20228.226NONO
SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. SMI functions in AhciBusDxe use untrusted inputs leading to corruption of SMRAM. This issue was dis
Nov 15, 20228.226NONO
Manipulation of the input address in PnpSmm function 0x52 could be used by malware to overwrite SMRAM or OS kernel memory. Function 0x52 of the PnpSmm driver is passed the address
Nov 15, 20228.226NONO
NetworkPkg/IScsiDxe has remotely exploitable buffer overflows.
Dec 1, 20218.126NONO
An issue was discovered in Insyde InsydeH2O with kernel 5.0 through 5.5. A stack buffer overflow leads to arbitrary code execution in the SetupUtility driver on Intel platforms. An
Nov 22, 20227.825NONO
Incorrect pointer checks within the NvmExpressDxe driver can allow tampering with SMRAM and OS memory Incorrect pointer checks within the NvmExpressDxe driver can allow tampering w
Nov 15, 20228.225NONO
In UsbCoreDxe, tampering with the contents of the USB working buffer using DMA while certain USB transactions are in process leads to a TOCTOU problem that could be used by an atta
Nov 15, 20227.525NONO
In UsbCoreDxe, untrusted input may allow SMRAM or OS memory tampering Use of untrusted pointers could allow OS or SMRAM memory tampering leading to escalation of privileges. This i
Nov 15, 20228.225NONO

Exploit Exposure

Signals from CVEs in this product scope (33 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (33 CVEs).

Media Mentions

Signals from CVEs in this product scope (33 CVEs).

Top CNAs Publishing CVEs For Kernel

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
5.716.40.4%00
5.616.40.4%00
5.538.11.1%00
5.438.11.1%00
5.338.11.1%00
5.238.11.1%00
5.128.91.4%00
5.028.91.4%00