Rosa Virtualization
545 CVEs tracked. 9 of them are in CISA KEV.
This hub aggregates every CVE we track for Rosa Virtualization, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.
Rosa Virtualization CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 2 |
| 2024-11 | 2 |
| 2024-12 | 2 |
| 2025-01 | 6 |
| 2025-02 | 2 |
| 2025-03 | 2 |
| 2025-04 | 11 |
| 2025-05 | 2 |
| 2025-06 | 7 |
| 2025-07 | 9 |
| 2025-08 | 0 |
| 2025-09 | 3 |
| 2025-10 | 1 |
| 2025-11 | 1 |
| 2025-12 | 1 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 545 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical82
- High246
- Medium199
- Low18
Latest CVEs
The 15 most recently published vulnerabilities affecting Rosa Virtualization.
- CVE-2025-66293LIBPNG has an out-of-bounds read in png_image_read_composite7.1
- CVE-2025-65018LIBPNG is vulnerable to a heap buffer overflow in `png_combine_row` triggered via `png_image_finish_read`7.1
- CVE-2025-40778Cache poisoning attacks with unsolicited RRs8.6
- CVE-2025-9086Out of bounds read for cookie path7.5
- CVE-2025-58364cups: Remote DoS via null dereference6.5
- CVE-2025-58060cups has Authentication bypass with AuthType Negotiate8.0
- CVE-2025-5994Cache poisoning via the ECS-enabled Rebirthday Attack7.5
- CVE-2025-53906Vim has path traversal issue with zip.vim and special crafted zip archives4.1
- CVE-2025-53905Vim has path traversial issue with tar.vim and special crafted tar files4.1
- CVE-2025-6965Integer Truncation on SQLite7.7
- CVE-2025-6395Gnutls: null pointer dereference in _gnutls_figure_common_ciphersuite()6.5
- CVE-2025-32990Gnutls: vulnerability in gnutls certtool template parsing6.5
- CVE-2025-32988Gnutls: vulnerability in gnutls othername san export6.5
- CVE-2025-7345Gdk‑pixbuf: heap‑buffer‑overflow in gdk‑pixbuf7.5
- CVE-2025-5372Libssh: incorrect return code handling in ssh_kdf() in libssh5.0
Product grouping is registry-driven, with AI assist and human review. How it works