CVE Tools

Debian

8,689 CVEs tracked since 1999. Since Sep 2020, 71 of them reached CISA KEV.

Debian CVEs per month

Sep 2020 to Feb 2026. Point at a month, or focus the strip and use the arrow keys.
Debian CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2020-091040
2020-10650
2020-11954
2020-12961
2021-01822
2021-02622
2021-03null or fewer
2021-041163
2021-051000
2021-06710
2021-07470
2021-081223
2021-09891
2021-10753
2021-11883
2021-121083
2022-011112
2022-02952
2022-03991
2022-041080
2022-05731
2022-06450
2022-07680
2022-08691
2022-09800
2022-10660
2022-11650
2022-12780
2023-01231
2023-02140
2023-03null or fewer
2023-04482
2023-05480
2023-06342
2023-07370
2023-08980
2023-09545
2023-10484
2023-11363
2023-12392
2024-01221
2024-02330
2024-03470
2024-041240
2024-051890
2024-06132
2024-0750
2024-08null or fewer
2024-09120
2024-10161
2024-11143
2024-1283
2025-01100
2025-02100
2025-03103
2025-04141
2025-051450
2025-06552
2025-072013
2025-08770
2025-091391
2025-10140
2025-11null or fewer
2025-12null or fewer
2026-01null or fewer
2026-0270

Products

The products that kept showing up in Debian's monthly top three, with their CVEs summed over those months.

  1. Debian Linux3,90460 months
  2. Advanced Package Tool21 month
  3. Dpkg22 months
  4. Yubiserver21 month
  5. Debian Based Gnu Grub11 month
  6. Debian Cpio11 month
  7. Debian-edu-config11 month
  8. Devscripts11 month
  9. Duck11 month
  10. Freedombox11 month

Latest CVEs

The 15 most recently published vulnerabilities affecting Debian.

  1. CVE-2026-89169live-boot ff8867c allows attackers to bypass the dm-verity-enforce-roothash-signature protection mechanism when the .verity file is missing.—
  2. CVE-2026-77118Out-of-bounds write in GraphicsMagick PCD decoder—
  3. CVE-2026-12996A use-after-free in OpenVPN 2.6.0 through 2.6.20 and 2.7_alpha1 through 2.7.4 allows remote authenticated peers to potentially cause a denial of service or leak memory via crafted packets during TL...8.1
  4. CVE-2026-14355ext/openssl: Memory corruption in openssl_encrypt with AES-WRAP-PAD5.6
  5. CVE-2026-56968GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could result in memory disclosure via a crafted server.3.7
  6. CVE-2026-11853Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts (.changes) are manifest files that name the file...6.5
  7. CVE-2026-11852Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifacts. The endpoints that create and delete relati...6.5
  8. CVE-2026-49975Apache HTTP Server: mod_http2 denial of service7.5
  9. CVE-2026-9256NGINX ngx_http_rewrite_module vulnerability8.1
  10. CVE-2026-46333ptrace: slightly saner 'get_dumpable()' logic7.1
  11. CVE-2026-31431crypto: algif_aead - Revert to operating out-of-place7.8
  12. CVE-2026-41082In OCaml opam before 2.5.1, a .install field containing a destination filepath can use ../ to reach a parent directory.7.3
  13. CVE-2026-34757LIBPNG has a yse-after-free in png_set_PLTE, png_set_tRNS and png_set_hIST leading to corrupted chunk data and potential heap information disclosure5.1
  14. CVE-2026-4775Libtiff: libtiff: arbitrary code execution or denial of service via signed integer overflow in tiff file processing7.8
  15. CVE-2026-1940Gstreamer: incomplete fix of cve-2026-19405.1

The record

Peak rank
#1 in Sep 2018
Busiest month shown
Jul 2025, 201 CVEs
Months with a KEV entry
32 since Sep 2020
Monthly snapshots
263 since 1999
Debian's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store