Linux
Vendor:
First CVE: Sep 7, 1995 · Active for 30 years
18,932
Total CVEs
Bottom 1%
591.6
Avg CVEs / Year
Bottom 1%
6.4
Avg CVSS
Higher Avg CVSS than 7% of tracked products
0.4%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Linux over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 7, 1995
30 years ago
Most Recent CVE
Jul 20, 2026
4 days ago
CVE Severity & Scoring
Linux18,932 CVEs
57%
36%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHighCriticalUnknown
Attack Vector
Local13,018 (68.8%)
Network3,334 (17.6%)
Unknown2,267 (12.0%)
Physical143 (0.8%)
Adjacent Network170 (0.9%)
Attack Complexity
Low15,249 (80.5%)
High1,416 (7.5%)
Unknown2,267 (12.0%)
User Interaction
None14,537 (76.8%)
Unknown2,267 (12.0%)
Required2,128 (11.2%)
Privileges Required
Low12,770 (67.5%)
High337 (1.8%)
None3,558 (18.8%)
Unknown2,267 (12.0%)
Top CVEs
Signals from CVEs in this product scope (18932 CVEs).
18,932 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31431HIGH In the Linux kernel, the following vulnerability has been resolved:
crypto: algif_aead - Revert to operating out-of-place
This mostly reverts commit 72548b093ee3 except for the c | Apr 22, 2026 | 7.8 | 99 | YES | YES |
CVE-2025-34028CRITICAL The Commvault Command Center Innovation Release allows an unauthenticated actor to upload ZIP files that represent install packages that, when expanded by the target server, are vu | Apr 22, 2025 | 10.0 | 98 | YES | YES |
CVE-2022-47986CRITICAL IBM Aspera Faspex 4.4.2 Patch Level 1 and earlier could allow a remote attacker to execute arbitrary code on the system, caused by a YAML deserialization flaw. By sending a special | Feb 17, 2023 | 9.8 | 98 | YES | YES |
CVE-2022-22954CRITICAL VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trig | Apr 11, 2022 | 9.8 | 98 | YES | YES |
CVE-2022-0847HIGH A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux ker | Mar 10, 2022 | 7.8 | 98 | YES | YES |
CVE-2015-5122CRITICAL Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 1 | Jul 14, 2015 | 9.8 | 98 | YES | YES |
CVE-2015-5119CRITICAL Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.296 and 14.x through 18.0.0.194 on Windows | Jul 8, 2015 | 9.8 | 98 | YES | YES |
CVE-2015-3113CRITICAL Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attack | Jun 23, 2015 | 9.8 | 98 | YES | YES |
CVE-2015-0313CRITICAL Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote atta | Feb 2, 2015 | 9.8 | 98 | YES | YES |
CVE-2014-0497CRITICAL Integer underflow in Adobe Flash Player before 11.7.700.261 and 11.8.x through 12.0.x before 12.0.0.44 on Windows and Mac OS X, and before 11.2.202.336 on Linux, allows remote atta | Feb 5, 2014 | 9.8 | 98 | YES | YES |
Exploit Exposure
Signals from CVEs in this product scope (18932 CVEs).
CISA KEV
83 CVEs
0.4% of CVEs· Bottom 1%
Metasploit
78 CVEs
0.4% of CVEs· Bottom 1%
Nuclei
13 CVEs
0.1% of CVEs· Bottom 1%
ExploitDB
485 CVEs
2.6% of CVEs· 93rd percentile
Social Chatter
Signals from CVEs in this product scope (18932 CVEs).
Media Mentions
Signals from CVEs in this product scope (18932 CVEs).
Top CNAs Publishing CVEs For Linux
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.1 | 432 | 7.1 | 0.3% | 0 | 3 |
| 7.0.9 | 1 | 5.5 | 0.1% | 0 | 0 |
| 7.0 | 824 | 6.6 | 0.3% | 1 | 1 |
| 6.9.6 | 1 | 5.5 | 0.3% | 0 | 0 |
| 6.9 | 329 | 6.2 | 0.3% | 0 | 0 |
| 6.8.9 | 1 | 5.5 | 0.1% | 0 | 0 |
| 6.8.1 | 1 | 4.7 | 0.2% | 0 | 0 |
| 6.8 | 295 | 5.9 | 0.3% | 1 | 0 |
| 6.7.5 | 1 | 7.8 | 0.2% | 0 | 0 |
| 6.7.2 | 1 | 7.8 | 0.1% | 0 | 0 |
| 6.7 | 51 | 6.5 | 0.7% | 0 | 0 |
| 6.6.96 | 1 | 5.5 | 0.1% | 0 | 0 |
| 6.6.93 | 1 | 5.5 | 0.2% | 0 | 0 |
| 6.6.90 | 1 | 5.5 | 0.2% | 0 | 0 |
| 6.6.87 | 1 | 5.5 | 0.3% | 0 | 0 |
| 6.6.74 | 1 | 4.7 | 0.2% | 0 | 0 |
| 6.6.66 | 1 | 5.5 | 0.2% | 0 | 0 |
| 6.6.58 | 1 | 5.5 | 0.2% | 0 | 0 |
| 6.6.51 | 2 | 6.3 | 0.2% | 0 | 0 |
| 6.6.35 | 1 | 5.5 | 0.3% | 0 | 0 |