CVE Tools

Soobschestvo-svobodnogo-programmnogo-obespecheniya

21,299 CVEs tracked since 1999. Since Jun 2021, 84 of them reached CISA KEV.

Soobschestvo-svobodnogo-programmnogo-obespecheniya CVEs per month

Jun 2021 to Jun 2026. Point at a month, or focus the strip and use the arrow keys.
Soobschestvo-svobodnogo-programmnogo-obespecheniya CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2021-062605
2021-071361
2021-082273
2021-091889
2021-10792
2021-11871
2021-121174
2022-011064
2022-021594
2022-031603
2022-041821
2022-051151
2022-06820
2022-071752
2022-081691
2022-091281
2022-101100
2022-111480
2022-122100
2023-011021
2023-021320
2023-03null or fewer
2023-041020
2023-051490
2023-061711
2023-071521
2023-082010
2023-091253
2023-101483
2023-111341
2023-121032
2024-011523
2024-024050
2024-033330
2024-044740
2024-0512441
2024-063602
2024-075370
2024-084102
2024-093660
2024-105422
2024-113754
2024-124563
2025-014230
2025-027151
2025-033122
2025-043902
2025-055020
2025-064070
2025-075361
2025-082760
2025-095400
2025-105410
2025-111730
2025-124503
2026-012060
2026-02520
2026-031452
2026-04330
2026-052662
2026-06550

Products

The products that kept showing up in Soobschestvo-svobodnogo-programmnogo-obespecheniya's monthly top three, with their CVEs summed over those months.

  1. Linux9,36257 months
  2. Debian Gnu/linux9,11460 months
  3. Vim13111 months
  4. Gpac1267 months
  5. Xwiki Platform616 months
  6. Freescout462 months
  7. Cgal381 month
  8. Open Webui361 month
  9. Openclaw361 month
  10. Webkitgtk354 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Soobschestvo-svobodnogo-programmnogo-obespecheniya.

  1. CVE-2026-27771Gitea Composer package source links use insufficient permission checks8.2
  2. CVE-2026-56396phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRights()8.8
  3. CVE-2026-46331net/sched: fix pedit partial COW leading to page cache corruption7.8
  4. CVE-2026-48853Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc9.8
  5. CVE-2026-53430grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/17.5
  6. CVE-2026-50020Netty's HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted5.3
  7. CVE-2026-50011Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length7.5
  8. CVE-2026-50010Netty's wrapping plain trust manager silently disables hostname verification7.5
  9. CVE-2026-48748Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion7.5
  10. CVE-2026-44705tmp: Path Traversal via unsanitized prefix/postfix enables directory escape8.2
  11. CVE-2026-46520ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions7.5
  12. CVE-2026-45664ImageMagick: Policy Bypass in MNG coder could5.3
  13. CVE-2026-46316KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry9.3
  14. BDU:2026-07974Уязвимость функционала форматирования модуля парсера SQL для Python Sqlparse, позволяющая нарушителю вызвать отказ в обслуживании5.3
  15. CVE-2026-49975Apache HTTP Server: mod_http2 denial of service7.5

The record

Peak rank
#1 in Nov 2025
Busiest month shown
May 2024, 1,244 CVEs
Months with a KEV entry
36 since Jun 2021
Monthly snapshots
271 since 1999
Soobschestvo-svobodnogo-programmnogo-obespecheniya's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store