boxscore/security
VENDOR · referenceVendors · latest edition

Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

Linux

Vendor reference — Linux · sector: Operating Systems & Platforms. Cumulative disclosure record across the archive.

Follow Linux — Atom feed

Career totals

Disclosures & known-exploited
All-timeYTD
CVEs70463580
KEV entries273
Rate & severity
KEV/100Med CVSSMed EPSSCHML
0.47.8.00204273639214114

KEV/100 = KEV entries ÷ CVEs × 100. Med CVSS / Med EPSS are medians over all disclosures. C/H/M/L = disclosures by CVSS severity band.

Monthly disclosures

Trend (by first-seen month, full archive): ▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▁▂▁▂▃▂▂▂▂▂▂▂▁▃▁▂▂▂▂▁▂▂▁▃▁▁▁▂▅▄▆█

Last 12 months (new CVEs by first-seen day)
MonthNew CVEs
2025-09229
2025-10232
2025-1145
2025-12331
2026-0180
2026-0241
2026-0341
2026-04165
2026-05641
2026-06514
2026-07835
2026-081263

Notable CVEs

Ranked by the published formula: KEV → EPSS → CVSS → CVE ID.

Notable (ranked)
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-314317.8100.0HIGHYES2026-05-01
CVE-2022-084799.8YES2022-04-25
CVE-2016-519599.7YES2022-03-03
CVE-2021-2255599.6YES2025-10-06
CVE-2019-1327298.9YES2021-12-10
CVE-2021-349398.8YES2022-10-20
CVE-2013-209498.8YES2022-09-15
CVE-2013-628298.5YES2022-09-15
CVE-2014-315398.4YES2022-05-25
CVE-2024-10867.898.0HIGHYES2024-05-30
CVE-2022-018597.8YES2024-08-21
CVE-2014-019697.5YES2023-05-12
CVE-2018-1463496.4YES2026-01-26
CVE-2010-390495.8YES2023-05-12
CVE-2017-100025395.4YES2024-09-09

Recent CVEs

Most recently seen
CVECVSSEPSS %ileSeverityKEVFirst seen
CVE-2026-745795.42026-08-17
CVE-2026-745787.14.4HIGH2026-08-16
CVE-2026-744486.52026-08-15
CVE-2026-744497.82.2HIGH2026-08-15
CVE-2026-722438.45.8HIGH2026-08-15
CVE-2026-722119.841.8CRITICAL2026-08-15
CVE-2026-744245.82026-08-15
CVE-2026-722089.841.8CRITICAL2026-08-15
CVE-2026-722079.841.8CRITICAL2026-08-15
CVE-2026-722069.841.8CRITICAL2026-08-15
CVE-2026-7220510.02026-08-15
CVE-2026-722019.841.8CRITICAL2026-08-15
CVE-2026-722048.46.5HIGH2026-08-15
CVE-2026-722027.538.7HIGH2026-08-15
CVE-2026-721999.841.8CRITICAL2026-08-15

Products

This vendor's products with a reference page (≥2 disclosures), by CVE count. A monolithic vendor total dilutes signal; product pages sharpen it.

Products (by CVE count)
ProductCVEsKEV
Linux70033
Kernel3724
Linux Kernel60

KEV entries

CISA Known Exploited Vulnerabilities (newest addition first)
CVEKEV addedCVSSEPSS %ileSeverity
CVE-2022-04922026-06-0292.2
CVE-2026-314312026-05-017.8100.0HIGH
CVE-2018-146342026-01-2696.4
CVE-2021-225552025-10-0699.6
CVE-2025-383522025-09-047.867.7HIGH
CVE-2023-03862025-06-1794.2
CVE-2024-531972025-04-0988.4
CVE-2024-531502025-04-0969.3
CVE-2024-503022025-03-0454.1
CVE-2024-531042025-02-0587.5
CVE-2017-10002532024-09-0995.4
CVE-2022-01852024-08-2197.8
CVE-2024-369712024-08-077.884.7HIGH
CVE-2022-25862024-06-267.895.4HIGH
CVE-2024-10862024-05-307.898.0HIGH
CVE-2010-39042023-05-1295.8
CVE-2014-01962023-05-1297.5
CVE-2023-02662023-03-3088.8
CVE-2021-34932022-10-2098.8
CVE-2013-20942022-09-1598.8
CVE-2013-25962022-09-1587.7
CVE-2013-62822022-09-1598.5
CVE-2014-31532022-05-2598.4
CVE-2022-08472022-04-2599.8
CVE-2021-226002022-04-1192.6

KEV timing

Longest unpatched (KEV due date passed)
CVEDueDays over
CVE-2016-51952022-03-241609
CVE-2021-226002022-05-021570
CVE-2022-08472022-05-161556
CVE-2019-132722022-06-101531
CVE-2014-31532022-06-151526
CVE-2013-62822022-10-061413
CVE-2013-25962022-10-061413
CVE-2013-20942022-10-061413
CVE-2021-34932022-11-101378
CVE-2023-02662023-04-201217

Methodology

Rate statistics are arithmetic over published figures: KEV/100 = KEV entries ÷ CVEs × 100; medians are taken over this vendor's disclosures. Vendor names are normalized (case, punctuation, common aliases) before aggregation; monthly counts are keyed to first-seen day, the day this archive first observed the record, not the upstream publication date.

Raw counts are not comparable across vendors: disclosure practices, product breadth, and CNA conventions differ widely, so a larger number here does not mean less secure software. This is a reference page assembled from the public record — not a record of its own, and not a ranking of vendors by our judgment.

Sources. CVE records from the CVE Program (cvelistV5); enrichment from NVD (NIST); known-exploited status from the CISA KEV catalog; exploit probability from FIRST EPSS.