Soobschestvo-svobodnogo-programmnogo-obespecheniya
21,299 CVEs tracked since 1999. Since Jun 2021, 84 of them reached CISA KEV.
Soobschestvo-svobodnogo-programmnogo-obespecheniya CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2021-06 | 260 | 5 |
| 2021-07 | 136 | 1 |
| 2021-08 | 227 | 3 |
| 2021-09 | 188 | 9 |
| 2021-10 | 79 | 2 |
| 2021-11 | 87 | 1 |
| 2021-12 | 117 | 4 |
| 2022-01 | 106 | 4 |
| 2022-02 | 159 | 4 |
| 2022-03 | 160 | 3 |
| 2022-04 | 182 | 1 |
| 2022-05 | 115 | 1 |
| 2022-06 | 82 | 0 |
| 2022-07 | 175 | 2 |
| 2022-08 | 169 | 1 |
| 2022-09 | 128 | 1 |
| 2022-10 | 110 | 0 |
| 2022-11 | 148 | 0 |
| 2022-12 | 210 | 0 |
| 2023-01 | 102 | 1 |
| 2023-02 | 132 | 0 |
| 2023-03 | null or fewer | |
| 2023-04 | 102 | 0 |
| 2023-05 | 149 | 0 |
| 2023-06 | 171 | 1 |
| 2023-07 | 152 | 1 |
| 2023-08 | 201 | 0 |
| 2023-09 | 125 | 3 |
| 2023-10 | 148 | 3 |
| 2023-11 | 134 | 1 |
| 2023-12 | 103 | 2 |
| 2024-01 | 152 | 3 |
| 2024-02 | 405 | 0 |
| 2024-03 | 333 | 0 |
| 2024-04 | 474 | 0 |
| 2024-05 | 1244 | 1 |
| 2024-06 | 360 | 2 |
| 2024-07 | 537 | 0 |
| 2024-08 | 410 | 2 |
| 2024-09 | 366 | 0 |
| 2024-10 | 542 | 2 |
| 2024-11 | 375 | 4 |
| 2024-12 | 456 | 3 |
| 2025-01 | 423 | 0 |
| 2025-02 | 715 | 1 |
| 2025-03 | 312 | 2 |
| 2025-04 | 390 | 2 |
| 2025-05 | 502 | 0 |
| 2025-06 | 407 | 0 |
| 2025-07 | 536 | 1 |
| 2025-08 | 276 | 0 |
| 2025-09 | 540 | 0 |
| 2025-10 | 541 | 0 |
| 2025-11 | 173 | 0 |
| 2025-12 | 450 | 3 |
| 2026-01 | 206 | 0 |
| 2026-02 | 52 | 0 |
| 2026-03 | 145 | 2 |
| 2026-04 | 33 | 0 |
| 2026-05 | 266 | 2 |
| 2026-06 | 55 | 0 |
Products
The products that kept showing up in Soobschestvo-svobodnogo-programmnogo-obespecheniya's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Soobschestvo-svobodnogo-programmnogo-obespecheniya.
- CVE-2026-27771Gitea Composer package source links use insufficient permission checks8.2
- CVE-2026-56396phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRights()8.8
- CVE-2026-46331net/sched: fix pedit partial COW leading to page cache corruption7.8
- CVE-2026-48853Remote code execution and denial of service via unsafe Erlang term deserialization in elixir-grpc/grpc9.8
- CVE-2026-53430grpc gzip decompression bomb in GRPC.Compressor.Gzip.decompress/17.5
- CVE-2026-50020Netty's HttpObjectDecoder skips arbitrary initial control characters when only initial CRLF characters are permitted5.3
- CVE-2026-50011Netty has unbounded pre-allocation in RedisArrayAggregator from RESP array length7.5
- CVE-2026-50010Netty's wrapping plain trust manager silently disables hostname verification7.5
- CVE-2026-48748Netty HTTP/3 QPACK Blocked Streams Memory Exhaustion7.5
- CVE-2026-44705tmp: Path Traversal via unsanitized prefix/postfix enables directory escape8.2
- CVE-2026-46520ImageMagick: Heap Buffer Over-Write in IPL decoder when reading multiple images of different dimensions7.5
- CVE-2026-45664ImageMagick: Policy Bypass in MNG coder could5.3
- CVE-2026-46316KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry9.3
- BDU:2026-07974Уязвимость функционала форматирования модуля парсера SQL для Python Sqlparse, позволяющая нарушителю вызвать отказ в обслуживании5.3
- CVE-2026-49975Apache HTTP Server: mod_http2 denial of service7.5
The record
- Peak rank
- #1 in Nov 2025
- Busiest month shown
- May 2024, 1,244 CVEs
- Months with a KEV entry
- 36 since Jun 2021
- Monthly snapshots
- 271 since 1999