Linux

Vendor:

First CVE: Sep 7, 1995 · Active for 30 years

18,932
Total CVEs
Bottom 1%
591.6
Avg CVEs / Year
Bottom 1%
6.4
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.4%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Linux over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 1995
30 years ago
Most Recent CVE
Jul 20, 2026
4 days ago

CVE Severity & Scoring

Linux18,932 CVEs
All CVEs352,231 CVEs
LowMediumHighCriticalUnknown
Attack Vector
Local13,018 (68.8%)
Network3,334 (17.6%)
Unknown2,267 (12.0%)
Physical143 (0.8%)
Adjacent Network170 (0.9%)
Attack Complexity
Low15,249 (80.5%)
High1,416 (7.5%)
Unknown2,267 (12.0%)
User Interaction
None14,537 (76.8%)
Unknown2,267 (12.0%)
Required2,128 (11.2%)
Privileges Required
Low12,770 (67.5%)
High337 (1.8%)
None3,558 (18.8%)
Unknown2,267 (12.0%)

Top CVEs

Signals from CVEs in this product scope (18932 CVEs).

18,932 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the c
Apr 22, 20267.899YESYES
The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vu
Apr 22, 202510.098YESYES
IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a special
Feb 17, 20239.898YESYES
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trig
Apr 11, 20229.898YESYES
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux ker
Mar 10, 20227.898YESYES
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 1
Jul 14, 20159.898YESYES
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows
Jul 8, 20159.898YESYES
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attack
Jun 23, 20159.898YESYES
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote atta
Feb 2, 20159.898YESYES
Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote atta
Feb 5, 20149.898YESYES

Exploit Exposure

Signals from CVEs in this product scope (18932 CVEs).

CISA KEV
83 CVEs
0.4% of CVEs· Bottom 1%
Metasploit
78 CVEs
0.4% of CVEs· Bottom 1%
Nuclei
13 CVEs
0.1% of CVEs· Bottom 1%
ExploitDB
485 CVEs
2.6% of CVEs· 93rd percentile

Social Chatter

Signals from CVEs in this product scope (18932 CVEs).

Media Mentions

Signals from CVEs in this product scope (18932 CVEs).

Top CNAs Publishing CVEs For Linux

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
7.14327.10.3%03
7.0.915.50.1%00
7.08246.60.3%11
6.9.615.50.3%00
6.93296.20.3%00
6.8.915.50.1%00
6.8.114.70.2%00
6.82955.90.3%10
6.7.517.80.2%00
6.7.217.80.1%00
6.7516.50.7%00
6.6.9615.50.1%00
6.6.9315.50.2%00
6.6.9015.50.2%00
6.6.8715.50.3%00
6.6.7414.70.2%00
6.6.6615.50.2%00
6.6.5815.50.2%00
6.6.5126.30.2%00
6.6.3515.50.3%00