Linux Kernel CVE Statistics

All-time vulnerability data, 1997–present · Updated daily from NIST NVD

The Linux kernel has accumulated 16,084 CVEs since 1997, making it one of the most extensively tracked software components in the NIST National Vulnerability Database. Of these, 240 are rated Critical, 4,399 High, and 25 have been confirmed as actively exploited via the CISA Known Exploited Vulnerabilities catalog. CVE volume has grown sharply — 2025 alone accounted for 5,681 vulnerabilities, representing 35% of all Linux kernel CVEs ever published.

16,084
Total CVEs
240
Critical
4,399
High
9,360
Medium
25
KEV — Exploited

Linux Kernel CVE Trends by Year

1997–2026 · stacked by severity

Critical
High
Medium
Low
Key trend

Linux kernel CVE volume increased dramatically from 2024 onward. 2025 saw 5,681 CVEs — the highest single-year total ever recorded for the Linux kernel. The 2024–2026 period accounts for the majority of all CVEs ever recorded for the Linux kernel, driven by increased security research and reporting.

Data sourced from NIST NVD API. Current year figures are partial (year to date).

Monthly Trend — 2026

CVEs published by month, 2026

Current month is partial.

Severity Breakdown — All Time

Distribution across 16,084 CVEs since 1997

Critical 1%
High 27%
Medium 58%
Low 2%
Severity distribution:

Medium severity CVEs dominate at 58%, followed by High at 27%. Critical CVEs account for only 1% but represent the highest-risk vulnerabilities requiring immediate attention.

Percentages rounded to nearest integer.

Notable observations

  • Record CVE volume in recent years

    2025 was the highest-ever year for Linux kernel CVEs, with 5,681 published. The Linux kernel has averaged 555 CVEs/year since 1997, but the 2024–2026 average is significantly higher, driven by increased security research and automated vulnerability discovery.

  • Critical severity concentration

    Despite record CVE volumes, Critical severity CVEs remain a small fraction of total — 240 of 16,084 total (1%). Of these, 25 are confirmed actively exploited via CISA KEV, representing the highest-priority patching targets.

  • Why CVE counts vary year to year

    CVE count changes reflect both real security trends and shifts in reporting practices. The Linux kernel security team has increased systematic CVE assignment for bug fixes since 2023, which explains much of the volume increase — not necessarily more vulnerabilities, but more comprehensive tracking of existing fixes.

Year-by-Year Breakdown

CVE counts by severity, 1997–2026

Year Total Critical High Medium Low Share of all-time
2026 3101 170 1158 1417 3
19%
2025 5681 1 1088 3243 6
35%
2024 4353 20 1150 3148 35
27%
2023 265 7 120 135 3
2%
2022 279 1 119 151 8
2%
2021 151 1 70 74 6
1%
2020 119 0 36 80 3
1%
2019 281 21 103 145 12
2%
2018 174 4 53 115 2
1%
2017 215 6 113 94 2
1%
2016 189 6 80 102 1
1%
2015 81 1 19 45 16
1%
2014 137 0 33 86 18
1%
2013 188 1 19 122 46
1%
2012 114 1 23 68 22
1%
2011 84 0 22 44 18
1%
2010 122 0 39 48 35
1%
2009 106 0 41 56 9
1%
2008 76 0 31 37 8
0%
2007 72 0 16 37 19
0%
2006 83 0 21 41 21
1%
2005 116 0 21 43 52
1%
2004 40 0 11 12 17
0%
2003 17 0 5 8 4
0%
2002 12 0 2 2 8
0%
2001 19 0 2 4 13
0%
2000 4 0 1 1 2
0%
1999 4 0 2 2 0
0%
1998 1 0 1 0 0
0%
Current year is partial. Click a year to filter the CVE list.

Frequently Asked Questions

How many Linux kernel CVEs have been published in total?

16,084 Linux kernel CVEs have been published since 1997 and are indexed in this database, sourced from the NIST National Vulnerability Database. The count updates daily as new CVEs are published. Browse all CVEs →

Which year had the most Linux kernel CVEs?

2025 had the most Linux kernel CVEs with 5,681 published — the highest single-year total ever recorded. View 2025 statistics →

What percentage of Linux kernel CVEs are Critical severity?

1% of all Linux kernel CVEs are rated Critical severity — 240 out of 16,084 total. Medium severity is the most common at 58%, followed by High at 27%.

Why did Linux kernel CVEs increase so dramatically after 2023?

The sharp increase from 2024 onward is largely attributed to the Linux kernel security team systematically assigning CVE IDs to bug fixes that previously would not have received them. This reflects improved vulnerability tracking practices rather than a proportional increase in actual security risk. Many of these CVEs are Low or Medium severity fixes backported to stable kernels.